Witam, mam podobny problem i proszę o pomoc. Adwcleaner tez niby cos usunal ale reklamy dalej sie otwieraja.
otl
http://www.wklej.eu/index.php?id=6af02a02e2
extras:
http://www.wklej.eu/index.php?id=9a40c6321f
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.101 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.101 Safari/537.36
UA: Mozilla/5.0 (Windows NT 6.2; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1411118413&from=smt&uid=WDCXWD5000BPVT-75HXZT3_WD-WXL1A91F8673F8673&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1411118413&from=smt&uid=WDCXWD5000BPVT-75HXZT3_WD-WXL1A91F8673F8673&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1411118413&from=smt&uid=WDCXWD5000BPVT-75HXZT3_WD-WXL1A91F8673F8673&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1411118413&from=smt&uid=WDCXWD5000BPVT-75HXZT3_WD-WXL1A91F8673F8673&q={searchTerms}
HKU\S-1-5-21-4265597010-2529115013-1479143746-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.com?cid={9078CEF1-24EF-400C-AAB4-E136980AF509}&mid=317f2e1132ef47d0b002f5ffbbec058a-300fe32ebf08790c89bc3ca420ec26aea5606547&lang=pl&ds=xn011&coid=&cmpid=&pr=sa&d=2012-09-12 14:26:31&v=18.3.0.885&pid=avg&sg=0&sap=hp
URLSearchHook: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000 - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
SearchScopes: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={9078CEF1-24EF-400C-AAB4-E136980AF509}&mid=317f2e1132ef47d0b002f5ffbbec058a-300fe32ebf08790c89bc3ca420ec26aea5606547&lang=pl&ds=xn011&pr=sa&d=2012-09-12 14:26:31&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID=121845&babsrc=SP_ss&mntrId=FA5386D53DA28400
SearchScopes: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000{95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={9078CEF1-24EF-400C-AAB4-E136980AF509}&mid=317f2e1132ef47d0b002f5ffbbec058a-300fe32ebf08790c89bc3ca420ec26aea5606547&lang=pl&ds=xn011&pr=sa&d=2012-09-12 14:26:31&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms}
BHO-x32: AVG Security Toolbar{95B7759C-8C7F-4BF1-B163-73684A933233}
C:\Program Files (x86)\AVG Secure Search\18.3.0.885\AVG Secure Search_toolbar.dll No File
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.3.0\ViProtocol.dll [2015-03-05] (AVG Secure Search)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1411118413&from=smt&uid=WDCXWD5000BPVT-75HXZT3_WD-WXL1A91F8673F8673
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-pluginC:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.3.0\\npsitesafety.dll No File
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\17.3.0.49
CHR Extension: (uTorrentControl_v2) - C:\Users\Agatka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx [Not Found]
R1 {00c97d86-accb-4288-9972-6d929c1fe93a}Gw64; C:\Windows\System32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys [44624 2014-09-18] (StdLib)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2015-03-31 19:00 - 2015-03-31 19:03 - 00000000 ____D () C:\AdwCleaner
2015-03-31 22:18 - 2013-06-07 21:09 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job
2015-03-31 22:18 - 2013-06-02 23:06 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2015-03-31 21:14 - 2014-09-19 11:20 - 00000000 ____D () C:\Users\Agatka\AppData\Roaming\istartsurf
2015-03-31 21:14 - 2014-04-27 16:50 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2015-03-31 21:14 - 2012-10-25 21:05 - 00000000 ____D () C:\Program Files (x86)\Conduit
C:\Windows\System32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys
CustomCLSID: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32C:\Users\Agatka\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32C:\Users\Agatka\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32C:\Users\Agatka\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32C:\Users\Agatka\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-4265597010-2529115013-1479143746-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32C:\Users\Agatka\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
Task: {03C5F1AA-58E8-429E-8003-8691B64C751C} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{6735F616-2B7F-477B-AF01-DBDB9629DC8B}.exe
Task: {16E1CDD5-276A-4090-B40A-4CCF29D6BC0E} - System32\Tasks\{0022CF6E-EC1D-41A8-BCBF-F53EA98B07B9} => pcalua.exe -a "C:\Users\Agatka\Local Settings\Application Data\Bundled software uninstaller\bi_client.exe" -c /initurl http://bi.bisrv.com/:affid:/:sid:/:uid:? /affid uninstall /id uninstall /name "Bundled software uninstaller"
Task: {1B3A6639-69B4-403D-9A54-79D55D599E35} - System32\Tasks\DealPly => C:\Users\Agatka\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
C:\Users\Agatka\AppData\Roaming\DealPly
Task: {F738D62E-00CF-46BD-BBCE-5DF52B10B51F} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{6D3A93E0-09C6-45B7-A16D-94974C972A5C}.exe
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{6735F616-2B7F-477B-AF01-DBDB9629DC8B}.exe <==== ATTENTION
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{6D3A93E0-09C6-45B7-A16D-94974C972A5C}.exe <==== ATTENTION
EmptyTemp:
Zarejestrowani użytkownicy: Bing [Bot]