x-kom hosting

yoursites123 - proszę o pomoc

dziedziulowka
utworzono
utworzono

Widzę, że wiele osób ma z tym kłopot. Będę wdzięczna za pomoc!

Twój_Anioł_Stróż
komentarz
komentarz

Otwórz Notatnik i wklej w nim:

Task: {35E46A20-64E1-4EE4-A7E2-EF2A6C09BD65} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== UWAGA
C:\Program Files\MyPC Backup
Task: {43414EA4-F778-4E33-BA30-8CCCCD5CB800} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== UWAGA
Task: {7DA826F4-D7D5-4715-8B05-2B698C6E30FB} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== UWAGA
Task: {B6C8D34F-B9C9-457F-BF88-0511533B5FBB} - \SMupdate1 -> Brak pliku <==== UWAGA
ShortcutWithArgument: C:\Users\Natalia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Natalia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome\Adblock Plus.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Natalia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Natalia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Natalia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Natalia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera 25.lnk -> C:\Program Files\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera 34.lnk -> C:\Program Files\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files\Opera\opera.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
ShortcutWithArgument: C:\Users\Public\Desktop\Opera 34.lnk -> C:\Program Files\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW <==== UWAGA
HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\Software\Classes\.exe: exefile =>  <===== UWAGA
HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\Software\Classes\exefile:  <===== UWAGA
C:\Program Files\SFK
C:\ProgramData\OWdMO
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Natalia\AppData\Local\MEGAsync\ShellExtX32.dll Brak pliku
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Natalia\AppData\Local\MEGAsync\ShellExtX32.dll Brak pliku
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Natalia\AppData\Local\MEGAsync\ShellExtX32.dll Brak pliku
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW
HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=1448359044&z=47ae2ae3e0b5cfd47edd22egcz8zab9c7wft7e3o9o&from=ient07031&uid=ST9320325AS_5VD0N6BW&q={searchTerms}
HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW
HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1448359044&z=47ae2ae3e0b5cfd47edd22egcz8zab9c7wft7e3o9o&from=ient07031&uid=ST9320325AS_5VD0N6BW&q={searchTerms}
SearchScopes: HKLM -> DefaultScope - brak wartości
SearchScopes: HKU\S-1-5-21-2309792143-1752319118-4107762069-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={47E45F87-CF06-476F-88F2-1B720F9F32E4}&mid=e398dcc0d64947d39953d16d3869ace6-a0c6b9f3fc1776fe07f29bdfe1b803f731fd5b6e&lang=en&ds=sc011&coid=avgtbdissc&cmpid=1015tb&pr=sa&d=2015-09-29 18:02:54&v=18.9.0.231&pid=safeguard&sg=&sap=dsp&q={searchTerms}
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: yoursites123
FF Homepage: hxxp://www.omniboxes.com/?type=hp&ts=1448359044&z=47ae2ae3e0b5cfd47edd22egcz8zab9c7wft7e3o9o&from=ient07031&uid=ST9320325AS_5VD0N6BW
FF SearchPlugin: C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\se8spj5t.default-1404865103046\searchplugins\yoursites123.xml [2015-12-10]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml [2015-11-30]
FF Extension: AA052FD6366A4771A5910D8DC551585D - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\se8spj5t.default-1404865103046\extensions\{AA052FD6-366A-4771-A591-0D8DC551585D} [2015-03-09] [Brak podpisu cyfrowego]
FF Extension: Default NewTab - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\se8spj5t.default-1404865103046\extensions\default_newtabff@gmail.com [2015-11-24] [Brak podpisu cyfrowego]
FF Extension: YahooToolsProtected  - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\se8spj5t.default-1404865103046\extensions\yahooprotected@gmail.com [2015-11-24] [Brak podpisu cyfrowego]
FF Extension: Jungle Net - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\se8spj5t.default-1404865103046\Extensions\{0b15b4ec-34b2-4f77-9abf-d796b553e74f}.xpi [2015-09-29] [Brak podpisu cyfrowego]
FF Extension: Brak nazwy - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-12] [Brak podpisu cyfrowego]
FF HKLM\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\se8spj5t.default-1404865103046\extensions\default_newtabff@gmail.com
FF HKLM\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Natalia\AppData\Roaming\Mozilla\Firefox\Profiles\se8spj5t.default-1404865103046\extensions\yahooprotected@gmail.com
FF HKU\S-1-5-21-2309792143-1752319118-4107762069-1000\...\Firefox\Extensions: [lyrmix@lyrmix.net] - C:\Program Files\Lyrmix\FF => nie znaleziono
CHR HomePage: Default -> hxxp://www.omniboxes.com/?type=hp&ts=1448359044&z=47ae2ae3e0b5cfd47edd22egcz8zab9c7wft7e3o9o&from=ient07031&uid=ST9320325AS_5VD0N6BW
CHR StartupUrls: Default -> "hxxp://www.omniboxes.com/?type=hp&ts=1448359044&z=47ae2ae3e0b5cfd47edd22egcz8zab9c7wft7e3o9o&from=ient07031&uid=ST9320325AS_5VD0N6BW"
CHR DefaultSearchURL: Default -> hxxp://www.omniboxes.com/web/?type=ds&ts=1448359044&z=47ae2ae3e0b5cfd47edd22egcz8zab9c7wft7e3o9o&from=ient07031&uid=ST9320325AS_5VD0N6BW&q={searchTerms}
CHR DefaultSearchKeyword: Default -> omniboxes
StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW
StartMenuInternet: (HKLM) Opera.exe - c:\program files\opera\opera.exe hxxp://www.yoursites123.com/?type=sc&ts=1449655765&z=bb2cd87fad964f1a19505aeg8zfz8tbqew8w4mcq2z&from=ient07021&uid=ST9320325AS_5VD0N6BW
R2 IhPul; C:\Users\Natalia\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
C:\Users\Natalia\AppData\Roaming\TSv
R2 SSFK; C:\Program Files\SFK\SSFK.exe [170144 2015-11-27] (TODO: <公司名>)
R2 WdMan; C:\ProgramData\OWdMO\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
S2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [X] <==== UWAGA
S3 cpuz134; \??\C:\Users\Natalia\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S1 iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]
C:\Windows\system32\pl.html
2015-12-09 11:12 - 2015-12-10 20:18 - 00000000 ____D C:\Program Files\SFK
2015-12-09 11:12 - 2015-12-09 11:13 - 00000000 ____D C:\ProgramData\OWdMO
2015-12-09 11:09 - 2015-12-09 11:10 - 00000000 ____D C:\ProgramData\7WdM7
C:\Windows\Minidump\Mini111115-01.dmp
C:\Program Files\WinZipper
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
EmptyTemp:

Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe
Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW).


----------------------
Jeśli będzie OK, to będziemy kończyć:
Otwórz Notatnik i wklej w nim:

DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).
przez SHIFT+DEL usuń pozostały folder C:\FRST.


Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie.
.
dziedziulowka
komentarz
komentarz

Zadziałało. Bardzo dziękuję! Prawdziwy Anioł Stróż dla zagubionych duszyczek.

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.