Odinstaluj:
Adobe Reader 9.1 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated)
Java(TM) 6 Update 18 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216018FF}) (Version: 6.0.180 - Sun Microsystems, Inc.)
Zainstaluj
http://ninite.com/foxit/
Obok frst.exe utworz plik fixlist.txt z zawartoscia:
Task: {B94A6CBA-4EBF-4DCF-BA85-1048C22880CC} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files (x86)\Protected Search\ProtectedSearch.exe <==== ATTENTION
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
FF Extension: takesave - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\mox16a4a.default\Extensions\KS@j.edu [2014-12-19]
FF Extension: adsy - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\mox16a4a.default\Extensions\Ly@zTl.net [2014-12-19]
FF Extension: clickit - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\mox16a4a.default\Extensions\pPks@0.edu [2014-12-21]
FF Extension: shoppi - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\mox16a4a.default\Extensions\y7IwkPD@0k.edu [2014-12-21]
CHR Extension: (Citavi Picker) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2014-06-20]
CHR Extension: (adsy) - C:\ProgramData\ijdlccflbimgkdjlohenbckhcfgeccko\ [2012-01-24]
CHR Extension: (takeorleave) - C:\ProgramData\oakpjbejpajckcnbaajaabllfmihcpne\ [2012-01-24]
CHR HKLM-x32\...\Chrome\Extension: [gladcbhcbkdeddbidiblppadjdjalidb] - C:\Program Files (x86)\DownTangoFTToolbar\chrome\DownTangoFTToolbar.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [Not Found]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
2014-12-30 12:57 - 2014-12-30 13:48 - 00000000 ____D () C:\AdwCleaner
3014-12-21 18:02 - 2014-12-27 18:02 - 00000000 ____D () C:\ProgramData\takeshop
2014-12-21 18:02 - 2014-12-21 18:02 - 00000000 ____D () C:\ProgramData\ijdlccflbimgkdjlohenbckhcfgeccko
2014-12-19 00:02 - 2014-12-19 00:02 - 00000000 ____D () C:\ProgramData\oakpjbejpajckcnbaajaabllfmihcpne
2014-12-19 00:01 - 2014-12-27 17:58 - 00000000 ____D () C:\ProgramData\copunk
EmptyTemp:
W FRST wybierz Fix. Usun katalog C:\FRST i to wszystko.