@panprezes3 odinstaluj:
Browser Configuration Utility
McAfee Security Scan Plus
Solution Real
Uzyj AdwCleaner, opcja Scan i Clean/Szukaj i Usun:
https://toolslib.net/downloads/viewdownload/1-adwcleaner/
Obok frst.exe utworz plik fixlist.txt z zawartoscia:
(tsvr.com) E:\Documents and Settings\Dawid\Dane aplikacji\TSv\TSvr.exe
(TODO: <公司名>) E:\Program Files\SFK\SSFK.exe
(TODO: <公司名>) E:\Program Files\SFK\SSFK.exe
(DeviceVM, Inc.) E:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
(McAfee, Inc.) E:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
() E:\Program Files\Solution Real\bin\utilSolutionReal.exe
() E:\Program Files\Solution Real\bin\SolutionReal.BrowserAdapter.exe
() E:\Program Files\Solution Real\bin\SolutionReal.expext.exe
() E:\Program Files\Solution Real\bin\SolutionReal.PurBrowse.exe
() E:\Program Files\Solution Real\updateSolutionReal.exe
HKLM\...\Run: [] => [X]
Startup: E:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk [2014-12-04]
ShortcutTarget: McAfee Security Scan Plus.lnk -> E:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.omniboxes.com/?type=hp&ts=1447428330&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1420295356&from=cor&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.omniboxes.com/?type=hp&ts=1447428330&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1420295356&from=cor&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172&q={searchTerms}
HKU\S-1-5-21-1757981266-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.omniboxes.com/?type=hp&ts=1447428330&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172
HKU\S-1-5-21-1757981266-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1420295356&from=cor&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172&q={searchTerms}
HKU\S-1-5-21-1757981266-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.omniboxes.com/?type=hp&ts=1447428330&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172
HKU\S-1-5-21-1757981266-706699826-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1420295356&from=cor&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172&q={searchTerms}
URLSearchHook: HKU\S-1-5-21-1757981266-706699826-725345543-1003 - SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - E:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll Brak pliku
URLSearchHook: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "hxxp://searchsimple-a.akamaihd.net/?m=tab&affID=mt-is" <======= UWAGA
SearchScopes: HKLM -> DefaultScope - brak wartości
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> OldSearch URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {0D6D7C1C-E892-47D7-9C56-A389382502C6} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {469DFD71-3EDF-40b7-8CAE-85EC09B3E2FC} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {4F1553A7-7107-4B0A-AC4A-B45AB189415D} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {5FBF545E-2FE2-4e93-ACA6-6221E737AF8B} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {96F94B72-94B2-4B16-B305-3B54C9E9DFFA} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {CC350A38-20A5-40EF-BC5F-2BCC15E4D686} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1757981266-706699826-725345543-1003 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> E:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: Solution Real 1.0.0.7 -> {1bb456da-878f-44a5-b013-4bfe0ae02fce} -> E:\Program Files\Solution Real\SolutionRealBHO.dll => Brak pliku
StartMenuInternet: IEXPLORE.EXE - E:\Program Files\Internet Explorer\iexplore.exe hxxp://www.omniboxes.com/?type=sc&ts=1447428330&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172
FF SearchPlugin: E:\Program Files\mozilla firefox\browser\searchplugins\omiga-plus.xml [2015-01-03]
FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - E:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\dbz2ewa0.default\extensions\faststartff@gmail.com => nie znaleziono
FF HKLM\...\Firefox\Extensions: [quick_searchff@gmail.com] - E:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\dbz2ewa0.default\extensions\quick_searchff@gmail.com => nie znaleziono
FF HKLM\...\Firefox\Extensions: [sweetsearch@gmail.com] - E:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\dbz2ewa0.default\extensions\sweetsearch@gmail.com => nie znaleziono
FF HKLM\...\Firefox\Extensions: [defsearchp@gmail.com] - E:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\dbz2ewa0.default\extensions\defsearchp@gmail.com => nie znaleziono
FF HKLM\...\Firefox\Extensions: [sidebarff@gmail.com] - E:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\dbz2ewa0.default\extensions\sidebarff@gmail.com => nie znaleziono
FF HKLM\...\Firefox\Extensions: [default_newtabff@gmail.com] - E:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\dbz2ewa0.default\extensions\default_newtabff@gmail.com => nie znaleziono
FF HKU\S-1-5-21-1757981266-706699826-725345543-1003\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - E:\Documents and Settings\All Users\Dane aplikacji\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - E:\Documents and Settings\All Users\Dane aplikacji\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [Brak podpisu cyfrowego]
StartMenuInternet: FIREFOX.EXE - E:\Program Files\Mozilla Firefox\firefox.exe hxxp://www.omniboxes.com/?type=sc&ts=1447428330&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=WDCXWD5000AAKS-00E4A0_WD-WCATR301917219172
CHR Extension: (Solution Real) - E:\Documents and Settings\Dawid\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fcgkbggajkpcgaiggodgomjabjhffogj [2015-11-13] [UpdateUrl: hxxp://wwwsolutionrealc-a.akamaihd.net/update/chrome] <==== UWAGA
CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
R2 IhPul; E:\Documents and Settings\Dawid\Dane aplikacji\TSv\TSvr.exe [580752 2015-11-06] (tsvr.com)
S3 McComponentHostService; E:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 SSFK; E:\Program Files\SFK\SSFK.exe [171168 2015-11-12] (TODO: <公司名>)
R2 Update Solution Real; E:\Program Files\Solution Real\updateSolutionReal.exe [649944 2015-11-14] ()
R2 Util Solution Real; E:\Program Files\Solution Real\bin\utilSolutionReal.exe [649944 2015-11-14] ()
R1 {31c21995-b861-4864-ab50-4a53fbca73d4}Gt; E:\WINDOWS\System32\drivers\{31c21995-b861-4864-ab50-4a53fbca73d4}Gt.sys [55800 2015-11-13] (StdLib)
S4 IntelIde; Brak ImagePath
U1 WS2IFSL; Brak ImagePath
2015-11-14 13:13 - 2015-11-14 13:13 - 00001197 _____ E:\Documents and Settings\All Users\Menu Start\Programy\zc1h3r7o5m4e.lnk
2015-11-13 20:16 - 2015-11-13 09:11 - 00055800 _____ (StdLib) E:\WINDOWS\system32\Drivers\{31c21995-b861-4864-ab50-4a53fbca73d4}Gt.sys
2015-11-13 16:27 - 2015-11-13 16:27 - 00000170 _____ E:\Documents and Settings\All Users\Dane aplikacji\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-11-13 16:27 - 2015-11-13 16:27 - 00000000 ____D E:\Program Files\SFK
2015-11-13 16:27 - 2015-11-13 16:27 - 00000000 ____D E:\Documents and Settings\All Users\Dane aplikacji\6WMiniPro6
2015-11-13 16:26 - 2015-11-13 16:26 - 00000000 ____D E:\Documents and Settings\Dawid\Dane aplikacji\TSv
2015-11-14 13:22 - 2015-01-03 15:28 - 00000000 ____D E:\Program Files\Solution Real
2015-11-13 18:20 - 2015-07-16 13:09 - 00000000 ____D E:\Program Files\MiuiTab
2015-11-13 18:20 - 2015-05-06 08:44 - 00000000 ____D E:\Program Files\XTab
2015-11-13 18:20 - 2015-01-03 15:30 - 00000000 ____D E:\Program Files\SupTab
2015-11-13 18:20 - 2015-01-03 15:30 - 00000000 ____D E:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect
2015-11-13 18:20 - 2015-01-03 15:30 - 00000000 ____D E:\Documents and Settings\All Users\Dane aplikacji\IePluginServices
E:\Windows\Tasks\At1.job
E:\Windows\Tasks\At2.job
E:\Windows\Tasks\At3.job
E:\Windows\Tasks\At4.job
EmptyTemp:
W FRST wybierz Napraw.
Zrob pelny skan przy pomocy Mbam i usun to co wykryje:
http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
@cyberdelia taka pomoc to bardziej przeszkadzanie niz pomoc. Sam widzisz ile jest do kasacji, wiec nie wystarczy usunac jednego szkodliwego programu.