
Po odinstalowaniu programu wooden seal oraz usunięciu wtyczki z ff nadal pojawiają się reklamy oraz następuje przekierowanie na oursurfing.com.
Będę bardzo wdzięczna za pomoc.
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hp&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hp&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hp&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hp&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
HKU\S-1-5-21-2414309298-2634315765-4227439743-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oursurfing.com/?type=hp&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
HKU\S-1-5-21-2414309298-2634315765-4227439743-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hp&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2414309298-2634315765-4227439743-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2414309298-2634315765-4227439743-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.oursurfing.com/web/?type=ds&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774&q={searchTerms}
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File
BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\progra~1\mcafee\msk\mskapbho.dll No File
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.oursurfing.com/?type=sc&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
FF HKLM-x32\...\Firefox\Extensions: [quick_searchff@gmail.com] - C:\Users\Aga\AppData\Roaming\Mozilla\Firefox\Profiles\ee8nkvrm.default\extensions\quick_searchff@gmail.com
StartMenuInternet: Google Chrome - C:\Users\Aga\AppData\Local\Google\Chrome\Application\chrome.exe http://www.oursurfing.com/?type=sc&ts=1430820455&z=5e4af2f52d98e969ea7d6feg5z3c0e4b7o3e5z1wcm&from=amt&uid=WDCXWD5000BPVT-22HXZT1_WD-WXG1E21MR774MR774
S2 Update Wooden Seal; "C:\Program Files (x86)\Wooden Seal\updateWoodenSeal.exe" [X]
R1 {2f5382ee-8543-4e85-88b0-1fbda91a5501}Gw64; C:\Windows\System32\drivers\{2f5382ee-8543-4e85-88b0-1fbda91a5501}Gw64.sys [48784 2015-05-04] (StdLib)
C:\Windows\System32\drivers\{2f5382ee-8543-4e85-88b0-1fbda91a5501}Gw64.sys
C:\Program Files (x86)\Wooden Seal
CustomCLSID: HKU\S-1-5-21-2414309298-2634315765-4227439743-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Aga\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2414309298-2634315765-4227439743-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Aga\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2414309298-2634315765-4227439743-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Aga\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2414309298-2634315765-4227439743-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Aga\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2414309298-2634315765-4227439743-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Aga\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
C:\Users\Aga\AppData\Local\t70rc.dat
EmptyTemp:
oursurfing
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 16 gości