Unfortunately automated tool tend just to kill the offending files yet leave the folder there. The tasks then try to re-install the adware
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKU\S-1-5-21-632434008-909267790-2204689488-1000\...\Run: [suchypowiadamiacz] => C:\Users\PC\AppData\Roaming\Suchy Powiadamiacz\0.5.5175.39317\SuchyPowiadamiacz.exe [1012736 2014-03-11] ()
GroupPolicyUsers\S-1-5-21-632434008-909267790-2204689488-1004\User: Group Policy restriction detected <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-632434008-909267790-2204689488-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing.
CHR Extension: (amigcgbheognjmfkaieeeadojiibgbdp) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp [2015-04-01]
CHR Extension: (sun king) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlabcihlajghaekmikmkncdhekcaaenl [2015-04-01]
S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /svc [X]
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc [X]
2015-04-01 20:00 - 2015-04-03 02:01 - 00000646 _____ () C:\Windows\Tasks\sun_king_updating_service.job
2015-04-01 20:00 - 2015-04-02 17:33 - 00000980 _____ () C:\Windows\Tasks\ae0DzhZ4ch.job
2015-04-01 19:59 - 2015-04-03 02:02 - 00001284 _____ () C:\Windows\Tasks\sun_king_notification_service.job
2015-03-31 10:14 - 2015-04-02 19:23 - 00000385 _____ () C:\Users\PC\AppData\Roaming\36GAur5
2015-03-31 10:14 - 2015-03-31 10:14 - 00004387 _____ () C:\Users\PC\AppData\Roaming\ae0DzhZ4ch
2015-03-31 10:14 - 2015-04-02 19:23 - 0000385 _____ () C:\Users\PC\AppData\Roaming\36GAur5
2015-03-31 10:14 - 2015-03-31 10:14 - 0004387 _____ () C:\Users\PC\AppData\Roaming\ae0DzhZ4ch
Task: {15DBBE8D-683F-4549-ACB5-3DBB2EB09098} - System32\Tasks\sun_king_updating_service => C:\Program Files\sun king\sun_king_updating_service.exe
Task: {FFEBA1CC-3008-406B-A8CA-81E250258578} - System32\Tasks\sun_king_notification_service => C:\Program Files\sun king\sun_king_notification_service.exe
Task: C:\Windows\Tasks\sun_king_notification_service.job => C:\Program Files\sun king\sun_king_notification_service.exeä/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='sun king' /appid='73143' /srcid='2913' /bic='584ccd38d9b95877967ecdd8cfd7d7b9' /verifier='8e39d30b282e3c478c4974401556280c' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif
Task: C:\Windows\Tasks\sun_king_updating_service.job => C:\Program Files\sun king\sun_king_updating_service.exe© /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=sun_king_updating_service /funurl=http:/stats.buildomserv.com
Task: C:\Windows\Tasks\ae0DzhZ4ch.job => C:\Users\PC\AppData\Roaming\ae0DzhZ4ch.exe
C:\Program Files\globalUpdate
C:\Users\PC\jagex_cl_oldschool_LIVE.dat
C:\Users\PC\jagex_cl_runescape_LIVE.dat
C:\Users\PC\random.dat
C:\Windows\System32\libs.exe
C:\Program Files\sun king
C:\Users\PC\AppData\Roaming\ae0DzhZ4ch.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.