Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Jak usunąć reklamy related shear aid ads itp?

tomekpiano92 29 Gru 2015 14:06 810 6
  • CControls
  • #2 29 Gru 2015 19:53
    Acorus 20
    Spec od komputerów

    Odinstaluj Bronze Aid. Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {54DEAF9C-2589-4597-A7B3-F84F2C440FC2} - System32\Tasks\psv_Latla => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\IceDox.reg" &amp; del "C:\ProgramData\Lightzap\IceDox.reg" &amp; SCHTASKS /Delete /TN "psv_Latla" /F <==== UWAGA
    Task: {712CA9D9-FCED-4668-9BC8-F049CD3D3447} - System32\Tasks\psv_Treedax => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\Supertip.reg" &amp; del "C:\ProgramData\Lightzap\Supertip.reg" &amp; SCHTASKS /Delete /TN "psv_Treedax" /F <==== UWAGA
    Task: {8FF4B1DD-DA56-4225-B329-47C145B588B3} - System32\Tasks\psv_Zummaeco => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\Zootip.reg" &amp; del "C:\ProgramData\Lightzap\Zootip.reg" &amp; SCHTASKS /Delete /TN "psv_Zummaeco" /F <==== UWAGA
    Task: {9F4E2DF8-E8F1-435F-8C26-B70E8EA83AB2} - System32\Tasks\psv_Faxphase => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\Toughtam.reg" &amp; del "C:\ProgramData\Lightzap\Toughtam.reg" &amp; SCHTASKS /Delete /TN "psv_Faxphase" /F <==== UWAGA
    Task: {A21D858A-3A65-4F84-80AB-8DA27A1428AF} - System32\Tasks\psv_Anphase => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\FreshSoloeco.reg" &amp; del "C:\ProgramData\Lightzap\FreshSoloeco.reg" &amp; SCHTASKS /Delete /TN "psv_Anphase" /F <==== UWAGA
    Task: {AD4A592B-4BA5-48C8-93EE-008CA98A988B} - System32\Tasks\psv_Salttough => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\KinQuadfind.reg" &amp; del "C:\ProgramData\Lightzap\KinQuadfind.reg" &amp; SCHTASKS /Delete /TN "psv_Salttough" /F <==== UWAGA
    Task: {C73AF8B1-F5C1-42B1-BA36-E13E9640DA09} - System32\Tasks\psv_Goldsing => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\Transing.reg" &amp; del "C:\ProgramData\Lightzap\Transing.reg" &amp; SCHTASKS /Delete /TN "psv_Goldsing" /F <==== UWAGA
    Task: {E90ED3BD-A22A-4E93-8EC3-E5928B4D2989} - System32\Tasks\psv_Year-Tip => cmd.exe /c regedit.exe /s "C:\ProgramData\Lightzap\Freshflex.reg" &amp; del "C:\ProgramData\Lightzap\Freshflex.reg" &amp; SCHTASKS /Delete /TN "psv_Year-Tip" /F <==== UWAGA
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1000\...\Run: [BingSvc] => C:\Users\lenovo\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-26] (© 2015 Microsoft Corporation)
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1000\...\RunOnce: [Chromium] => [X]
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}




    HKU\S-1-5-21-1573349097-1012807905-3323377729-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F...-SsV_Cj_RQlg36yJjVymBB0-eYCu6tdAJBDAdtCscmQ,,,,
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F...-SsV_Cj_RQlg36yJjVymBB0-eYCu6tdAJBDAdtCscmQ,,,,
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    HKU\S-1-5-21-1573349097-1012807905-3323377729-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-1573349097-1012807905-3323377729-1000 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1573349097-1012807905-3323377729-1000 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
    SearchScopes: HKU\S-1-5-21-1573349097-1012807905-3323377729-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SL5MDF&PC=SL5M&q={searchTerms}&src=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-1573349097-1012807905-3323377729-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1573349097-1012807905-3323377729-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1573349097-1012807905-3323377729-1001 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
    SearchScopes: HKU\S-1-5-21-1573349097-1012807905-3323377729-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...MSvev1cJbvPs6PIR_LFIEyBxNz8R_lkQIIiw,,&q={searchTerms}
    BHO-x32: Brak nazwy -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> Brak pliku
    BHO-x32: Bronze Aid -> {a5bfd1d3-18b6-4fc3-b3f9-262ae3552dbe} -> C:\Program Files (x86)\Bronze Aid\Extensions\a5bfd1d3-18b6-4fc3-b3f9-262ae3552dbe.dll [2015-12-18] ()
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe
    FF DefaultSearchEngine: istartsurf
    FF SelectedSearchEngine: istartsurf
    FF SearchPlugin: C:\Users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\x3642i3b.default\searchplugins\istartsurf.xml [2015-12-29]
    FF Extension: FirefixTab - C:\Users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\x3642i3b.default\extensions\deskCutv2@gmail.com [2015-12-18] [Brak podpisu cyfrowego]
    FF Extension: YahooToolsProtected - C:\Users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\x3642i3b.default\extensions\yahooprotected@gmail.com.xpi [2015-12-18] [Brak podpisu cyfrowego]
    FF Extension: Search Enginer - C:\Users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\x3642i3b.default\Extensions\1434649555_xpi [2015-06-18] [Brak podpisu cyfrowego]
    FF Extension: Bronze Aid - C:\Users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\x3642i3b.default\Extensions\{04a8167f-a37d-4da1-be2d-b06fa34e5ff6}.xpi [2015-12-18] [Brak podpisu cyfrowego]
    FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\x3642i3b.default\extensions\deskCutv2@gmail.com
    CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hp&ts=1447074112&z=379ec58867606fed3a2f093gcz9z4meeem0c1qfzbq&from=cor&uid=WDCXWD5000LPVT-00G33T0_WD-WX51C32T0909T0909"
    CHR DefaultSearchURL: Default -> hxxp://www.istartsurf.com/web/?type=ds&ts...D5000LPVT-00G33T0_WD-WX51C32T0909T0909&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> istartsurf
    CHR HKU\S-1-5-21-1573349097-1012807905-3323377729-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
    OPR Extension: (Glass Bottle) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\dkemfkimiodmfocfmnaomllkkneapgoj [2015-05-26]
    OPR Extension: (Glass Bottle) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\ehnckbambadcehdfddfcmhoabnbppadm [2015-06-15]
    OPR Extension: (Bronze Aid) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\fflhpnkiccpihhhnljkflpeccfjdoagc [2015-12-18]
    OPR Extension: (Brak nazwy) - C:\Users\lenovo\AppData\Roaming\Opera Software\Opera Stable\Extensions\gnigdaopdjegonneaholnnndkjfienno [2015-05-26]
    StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.istartsurf.com/?type=sc&ts=144...d=WDCXWD5000LPVT-00G33T0_WD-WX51C32T0909T0909
    R2 Service Mgr BronzeAid; C:\ProgramData\f7dd9bd0-5ea8-4002-b65f-bc21d39fe974\plugincontainer.exe [769248 2015-12-29] () <==== UWAGA
    R2 Update Mgr BronzeAid; C:\Program Files (x86)\Common Files\f7dd9bd0-5ea8-4002-b65f-bc21d39fe974\updater.exe [647904 2015-12-29] () <==== UWAGA
    S2 Update Special Box; "C:\Program Files (x86)\Special Box\updateSpecialBox.exe" [X]
    S2 Util Special Box; "C:\Program Files (x86)\Special Box\bin\utilSpecialBox.exe" [X]
    S3 ALSysIO; \??\C:\Users\lenovo\AppData\Local\Temp\ALSysIO64.sys [X]
    S3 cpuz134; \??\C:\Users\lenovo\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
    R1 wfdrvr_vt_1_10_0_28; system32\drivers\wfdrvr_vt_1_10_0_28.sys [X]
    S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
    2015-12-29 12:33 - 2015-12-29 12:33 - 00003274 _____ C:\Windows\System32\Tasks\psv_Year-Tip
    2015-12-29 12:31 - 2015-12-29 12:31 - 00003270 _____ C:\Windows\System32\Tasks\psv_Faxphase
    2015-12-29 12:31 - 2015-12-29 12:31 - 00003268 _____ C:\Windows\System32\Tasks\psv_Treedax
    2015-12-29 12:31 - 2015-12-29 12:31 - 00003262 _____ C:\Windows\System32\Tasks\psv_Zummaeco
    2015-12-18 23:07 - 2015-12-18 23:07 - 00003256 _____ C:\Windows\System32\Tasks\psv_Latla
    2015-12-18 18:02 - 2015-12-18 18:02 - 00003270 _____ C:\Windows\System32\Tasks\psv_Goldsing
    2015-12-18 18:01 - 2015-12-29 12:31 - 00002377 _____ C:\Windows\SysWOW64\findit.xml
    2015-12-18 18:01 - 2015-12-18 18:01 - 00003284 _____ C:\Windows\System32\Tasks\psv_Salttough
    2015-12-18 18:01 - 2015-12-18 18:01 - 00003284 _____ C:\Windows\System32\Tasks\psv_Anphase
    2015-12-18 18:01 - 2015-12-18 18:01 - 00000000 ____D C:\ProgramData\Lightzaps
    2015-12-18 18:00 - 2015-12-18 18:00 - 00000000 ____D C:\Program Files (x86)\Bronze Aid
    2015-12-29 13:19 - 2015-07-01 18:57 - 00000000 ____D C:\AdwCleaner
    2015-04-29 18:25 - 2015-11-02 21:09 - 0000005 _____ () C:\Program Files (x86)\is.dat
    2015-04-29 18:25 - 2015-04-29 18:25 - 0016384 _____ () C:\Program Files (x86)\uik.dat
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan i później Cleaning.

    1
  • CControls
  • #3 29 Gru 2015 22:18
    tomekpiano92
    Poziom 3  

    Niestety nie pomogło.. aplikacji nie udało sie odinstalować nie wiem jak.
    W panelu sterowania nie ma jej, w ccleaner tez nie. Pozostałe czynności wykonałem jednak adwcleaner nic nie znalazł.
    Wrzucam świeży log z tego programu FRST moze się coś zmieniło.

    0
  • Pomocny post
    #4 30 Gru 2015 08:22
    Kolobos
    Spec od komputerów

    Wykonaj jeszcze taki fixlist.txt:
    FF Extension: Bing Search - C:\Users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\x3642i3b.default\Extensions\bingsearch.full@microsoft.com.xpi [2015-11-03]
    2015-12-29 21:59 - 2015-12-29 22:08 - 00000000 ____D C:\AdwCleaner
    2015-12-14 14:49 - 2015-06-18 18:49 - 00000332 _____ C:\Windows\Tasks\Chromium.job
    2015-02-19 11:14 - 2015-02-19 11:14 - 0000000 ____H () C:\Users\lenovo\AppData\Local\BIT60F7.tmp

    0
  • #5 30 Gru 2015 12:07
    tomekpiano92
    Poziom 3  

    Zauważyłem pewna zmianę. Na przeglądarce mozilla firefox reklamy juz sie nie pojawiają jednak na google chrome problem dalej występuje. Jak to skasować na dobre ?

    0
  • Pomocny post
    #6 30 Gru 2015 12:19
    Kolobos
    Spec od komputerów

    Wykonaj: https://support.google.com/chrome/answer/3296214?hl=pl

    Jezeli nie pomoze to odinstaluj Chrome, usun katalog profilu z: %LOCALAPPDATA%\Google\Chrome\User Data\ i zainstaluj Chrome ponownie. Wczesniej zgraj zakladki.

    Ps. Synchronizujesz ustawienia Chrome z konta google?

    0
  • #7 30 Gru 2015 12:39
    tomekpiano92
    Poziom 3  

    Nie synchronizuje ustawień Chrome z konta google. Przeinstalowanie przeglądarki Chrome pomogło. Bardzo dziękuje za pomoc.

    0