Skocz do zawartości

Delta homes, uciążliwe reklamy, blue screen.


Rekomendowane odpowiedzi

Witam

 

Jest to komputer koleżanki z pracy, myślałam, że wystarczy przeskanowanie programem Malware anti-malware ale myliłam się. 

Wystepują dwa problemy: pierwszym z nich jest strona która uruchamia się po uruchomieniu przeglądarki - DELTA HOMES. W 

przypadku drugiego problemu troche przekombinowałam, mianowicie po przeskanowaniu komputera programem Malware anti-malware 

nie udało usunąć się delta homes, więc dorzuciłam jeszcze skan adwcleanerem po czym komputer już nie chciał się uruchomić w 

trybie normalnym, zaraz po zalogowaniu się na konto użytkownika pojawiał się blue screen. Tryb awaryjny działał normalnie 

więc przywrociłam system z zapisanego punktu przywracania. Ponownie przeskanowałam programem Malware anti-malware i 

ponownie pojawił się problem blue screena więc znowu przywrociłam system no i postanowiłam zwrócić się o fachwową pomoc bo 

jak widać nie radze sobie w ogóle :)

 

Kod błędu podczas pojawiania się blue screena to ***STOPL: 0x00000019 (0x0000000000000020, 0xFFFFFA8003cc5A90, 

 

0x000000000402000C)

 

Załączam wymagane logi i bardzo proszę o pomoc. 

Addition.txt

FRST.txt

GMER.txt

Shortcut.txt

Odnośnik do komentarza
Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

https://www.fixitpc.pl/topic/27096-nowy-moderator-w-dziale-malware/

Nie wiem, kiedy @Picasso lub @Naathim zaczną pomagać na forum.

 

Szkoda, że masz zepsuty komputer (bluescreeny), bo byłoby łatwiej usuwać śmieci.

 

1) Odinstaluj te programy:

EpicScale Application (HKU\S-1-5-21-592060492-1902354033-4240126978-1000\...\EpicScaleApp) (Version:  - EpicScale, Inc.) <==== ATTENTION
Faster Light (HKLM\...\Faster Light) (Version: 2014.12.27.152306 - Faster Light) <==== ATTENTION
omiga-plus uninstall (HKLM-x32\...\omiga-plus uninstall) (Version:  - omiga-plus) <==== ATTENTION

 

 

2) Otwórz Notatnik i wklej w nim:

 

 

Task: {3C17F78A-6C00-4C88-B810-A93C1201D7AD} - System32\Tasks\Yahoo! Search => C:\Users\internet\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.25.0\dsrlte.exe [2015-05-10] (Pay By Ads LTD) <==== ATTENTION
C:\Users\internet\AppData\Local\Pay-By-Ads
Task: {ED9CBCE7-CFB4-4B2F-94AF-64CC92996357} - System32\Tasks\Yahoo! Search Updater => C:\Users\internet\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.25.0\dsrsetup.exe [2015-05-10] (Pay By Ads LTD) <==== ATTENTION
C:\Program Files (x86)\Faster Light
C:\ProgramData\WindowsMangerProtect
C:\Program Files (x86)\XTab
C:\Program Files (x86)\MiuiTab
C:\ProgramData\EpicScale
C:\ProgramData\IHProtectUpDate
HKU\S-1-5-21-592060492-1902354033-4240126978-1000\...\Run: [EpicScale] => C:\ProgramData\EpicScale\10\EpicScale.exe EpicScale StartMinimized
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
HKU\S-1-5-21-592060492-1902354033-4240126978-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
HKU\S-1-5-21-592060492-1902354033-4240126978-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
HKU\S-1-5-21-592060492-1902354033-4240126978-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
HKU\S-1-5-21-592060492-1902354033-4240126978-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902&q={searchTerms}
SearchScopes: HKU\S-1-5-21-592060492-1902354033-4240126978-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-592060492-1902354033-4240126978-1000 -> OldSearch URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-592060492-1902354033-4240126978-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-592060492-1902354033-4240126978-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-592060492-1902354033-4240126978-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-592060492-1902354033-4240126978-1000 -> {DF1F2225-AF5F-4778-9649-3F4B619A8E46} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-592060492-1902354033-4240126978-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
BHO-x32: LuckyTab Class -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} -> C:\Program Files (x86)\MiuiTab\SupTab.dll [2015-06-03] (Thinknice Co. Limited)
BHO-x32: Faster Light 1.0.0.7 -> {950ef4df-b9dd-4b97-9e34-5c7d25a5eb88} -> C:\Program Files (x86)\Faster Light\FasterLightBHO.dll [2015-01-27] ()
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
FF NewTab: hxxp://www.delta-homes.com/newtab/?type=nt&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
FF DefaultSearchEngine: delta-homes
FF SelectedSearchEngine: delta-homes
FF Homepage: hxxp://www.delta-homes.com/?type=hp&ts=1433410501&z=1409fed43b5baa9938766efg3z3ccc6zagfeaw9e4g&from=wpm06043&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
FF Keyword.URL: hxxp://search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=pr__alt__ddc_dss_bd_com&p=
FF Extension: No Name - C:\Users\Grzesiek\AppData\Roaming\Mozilla\Firefox\Profiles\kdxrja3a.default\Extensions\faststartff@gmail.com [2014-12-27]
FF Extension: No Name - C:\Users\Grzesiek\AppData\Roaming\Mozilla\Firefox\Profiles\kdxrja3a.default\Extensions\quick_searchff@gmail.com [2015-05-08]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Grzesiek\AppData\Roaming\Mozilla\Firefox\Profiles\kdxrja3a.default\extensions\faststartff@gmail.com
FF HKLM-x32\...\Firefox\Extensions: [quick_searchff@gmail.com] - C:\Users\Grzesiek\AppData\Roaming\Mozilla\Firefox\Profiles\kdxrja3a.default\extensions\quick_searchff@gmail.com
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
CHR Extension: (No Name) - C:\Users\Grzesiek\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpjaeedhlmcojmmhngnbankkodcdlenh [2015-06-22]
OPR Extension: (No Name) - C:\Users\Grzesiek\AppData\Roaming\Opera Software\Opera Stable\Extensions\jpjaeedhlmcojmmhngnbankkodcdlenh [2015-06-21]
OPR Extension: (No Name) - C:\Users\Grzesiek\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbgbdinkchdlbniomfkieilppkmmfimc [2015-04-20]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158816 2015-05-08] (XTab system)
R2 Update Faster Light; C:\Program Files (x86)\Faster Light\updateFasterLight.exe [462064 2015-06-22] ()
R2 Util Faster Light; C:\Program Files (x86)\Faster Light\bin\utilFasterLight.exe [462064 2015-06-22] ()
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [347136 2015-06-04] (SysTool PasSame LIMITED) [File not signed] <==== ATTENTION
R1 {2c7e9044-6b3b-4ecc-9224-8b8c893f6fc1}Gw64; C:\Windows\System32\drivers\{2c7e9044-6b3b-4ecc-9224-8b8c893f6fc1}Gw64.sys [48792 2014-12-30] (StdLib)
R1 {5fa86e60-a54d-4e77-b1f1-f7bc1e215749}Gw64; C:\Windows\System32\drivers\{5fa86e60-a54d-4e77-b1f1-f7bc1e215749}Gw64.sys [48784 2015-01-30] (StdLib)
R1 {5fa86e60-a54d-4e77-b1f1-f7bc1e215749}w64; C:\Windows\System32\drivers\{5fa86e60-a54d-4e77-b1f1-f7bc1e215749}w64.sys [48784 2015-02-07] (StdLib)
R1 {82adbb5d-7d8c-4f2d-9936-53071e499858}Gw64; C:\Windows\System32\drivers\{82adbb5d-7d8c-4f2d-9936-53071e499858}Gw64.sys [48792 2015-01-03] (StdLib)
R1 {8fb4e628-35c6-4275-89be-ce3462febcc4}Gw64; C:\Windows\System32\drivers\{8fb4e628-35c6-4275-89be-ce3462febcc4}Gw64.sys [48792 2014-12-27] (StdLib)
R1 {a081059f-4e06-4f49-9a1e-4b92e171ba25}Gw64; C:\Windows\System32\drivers\{a081059f-4e06-4f49-9a1e-4b92e171ba25}Gw64.sys [48792 2015-01-05] (StdLib)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
C:\Windows\System32\drivers\{2c7e9044-6b3b-4ecc-9224-8b8c893f6fc1}Gw64.sys
C:\Windows\System32\drivers\{5fa86e60-a54d-4e77-b1f1-f7bc1e215749}Gw64.sys
C:\Windows\System32\drivers\{5fa86e60-a54d-4e77-b1f1-f7bc1e215749}w64.sys
C:\Windows\System32\drivers\{82adbb5d-7d8c-4f2d-9936-53071e499858}Gw64.sys
C:\Windows\System32\drivers\{8fb4e628-35c6-4275-89be-ce3462febcc4}Gw64.sys
C:\Windows\System32\drivers\{a081059f-4e06-4f49-9a1e-4b92e171ba25}Gw64.sys
C:\Users\Grzesiek\Downloads\p792bbbd6a3a60e297c50.html
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picexa
C:\Program Files (x86)\Picexa
C:\Users\Grzesiek\AppData\Roaming\omiga-plus
C:\Program Files (x86)\SupTab
C:\ProgramData\IePluginServices
C:\Users\Public\Desktop\Picexa.lnk
S2 PicexaService; C:\Program Files (x86)\Picexa\PicexaSvc.exe [393880 2015-05-06] () [File not signed]
C:\Users\Grzesiek\AppData\Roaming\Picexa Viewer
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picexa\Picexa.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picexa\uninstall.lnk
C:\Users\Grzesiek\Desktop\pierdoły\gry itd\Gimnazjum moduł 3 - Biologia.lnk
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.delta-homes.com/?type=sc&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (Tryb awaryjny).lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Grzesiek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.delta-homes.com/?type=sc&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\internet\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1419707919&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.delta-homes.com/?type=sc&ts=1431099740&z=ca2f74e1113b104620d088dg8z7ceg6e5t1tbm3c3q&from=wpm05083&uid=ST1000LM024XHN-M101MBB_S2U5J9CC956902
EmptyTemp:


Plik zapisz pod nazwą fixlist.txt i umieść obok FRST.exe
Uruchom FRST i kliknij przycisk Fix.
Powstanie plik fixlog.txt.
Daj ten log.

 

3) Zrób nowe logi z FRST.

 

jessi

Odnośnik do komentarza

Otwórz Notatnik i wklej w nim:

 

FF Extension: No Name - C:\Users\Grzesiek\AppData\Roaming\Mozilla\Firefox\Profiles\kdxrja3a.default\extensions\quick_searchff@gmail.com [not found]
C:\ProgramData\WindowsMangerProtect
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST.exe
Uruchom FRST i kliknij przycisk Fix.

 

Potem kończymy:

Otwórz Notatnik i wklej w nim:

 

DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix.
przez SHIFT+DEL usuń pozostały folder C:\FRST.

 

Java 6 Update 26 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216026FF}) (Version: 6.0.260 - Oracle)

Zainstaluj nowszą wersję Javy, wg https://www.fixitpc.pl/topic/5-dezynfekcja-kroki-finalizuj%C4%85ce-temat/?do=findComment&comment=43590

 

jessi

Odnośnik do komentarza

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...