albeer utworzono 11 grudnia 2015 utworzono 11 grudnia 2015 Co z tym zrobić ? [attachment=45448:Addition_11-12-2015_10-03-48.txt] [attachment=45449:FRST_11-12-2015_10-03-48.txt]
Twój_Anioł_Stróż komentarz 11 grudnia 2015 komentarz 11 grudnia 2015 (edytowane) Otwórz Notatnik i wklej w nim: Task: {A802741E-A363-4A30-82D2-65DB09DB4724} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe C:\Program Files\Enigma Software Group Task: {FD0DFA7F-7303-433B-BDC8-C8182DE002B1} - System32\Tasks\{D8CDAFA6-1E88-43E2-B3A7-D64C1A0A4C5A} => pcalua.exe -a C:\Users\Albin\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=cornl C:\Users\Albin\AppData\Roaming\istartsurf ShortcutWithArgument: C:\Users\Albin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF <==== UWAGA ShortcutWithArgument: C:\Users\Albin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF <==== UWAGA ShortcutWithArgument: C:\Users\Albin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF <==== UWAGA ShortcutWithArgument: C:\Users\Albin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera (2).lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF <==== UWAGA ShortcutWithArgument: C:\Users\Albin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF <==== UWAGA ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF <==== UWAGA 2015-11-05 12:42 - 2015-12-09 09:23 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat 2015-12-09 09:23 - 2015-11-06 17:41 - 00000000 ____D C:\ProgramData\UWMiniProU 2015-12-09 10:04 - 2015-12-09 10:04 - 00003326 _____ C:\windows\System32\Tasks\SpyHunter4Startup 2015-12-09 10:04 - 2015-12-09 10:04 - 00000000 ____D C:\Users\Albin\AppData\Roaming\Enigma Software Group 2015-12-09 10:03 - 2015-12-09 10:03 - 00022704 _____ C:\windows\system32\Drivers\EsgScanner.sys 2015-12-09 09:24 - 2015-12-11 10:00 - 00000000 ____D C:\Program Files (x86)\SFK 2015-12-09 09:23 - 2015-12-09 09:24 - 00000000 ____D C:\ProgramData\gWdMg 2015-12-09 09:23 - 2015-12-09 09:23 - 00000000 ____D C:\Users\Albin\AppData\Roaming\TSv 2015-12-09 09:23 - 2015-12-09 09:23 - 00000000 ____D C:\ProgramData\8WdM8 2015-12-11 09:58 - 2015-12-11 09:58 - 00000001 _____ C:\windows\SysWOW64\pl.html S3 STHDA; system32\DRIVERS\stwrt64.sys [X] S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-09] () S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [X] R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: <公司名>) R2 IhPul; C:\Users\Albin\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) StartMenuInternet: (HKLM) Opera - C:\Program Files (x86)\Opera\Opera.exe hxxp://www.yoursites123.com/?type=sc&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF OPR Extension: (Middle Rush) - C:\Users\Albin\AppData\Roaming\Opera Software\Opera Stable\Extensions\cmlhkbleammgpbpgmdjofccdihhnmgla [2015-11-05] OPR Extension: (extensible) - C:\Users\Albin\AppData\Roaming\Opera Software\Opera Stable\Extensions\fopbkiidibcjjlcpnpldcpdiiafeclci [2014-11-12] Toolbar: HKU\S-1-5-21-3600292724-1680297373-2008538282-1001 -> Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Brak pliku StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1446723712&z=c472d12f949c2dd6c002465gezbz4qam8oec7z5cfw&from=cornl&uid=ST9320423AS_5VH5RTSF BHO-x32: Middle Rush -> {d00ab4cc-662c-40b6-a85f-d53086f4bb16} -> C:\Program Files (x86)\Middle Rush\Extensions\d00ab4cc-662c-40b6-a85f-d53086f4bb16.dll => Brak pliku HKU\S-1-5-21-3600292724-1680297373-2008538282-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF HKU\S-1-5-21-3600292724-1680297373-2008538282-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF HKU\S-1-5-21-3600292724-1680297373-2008538282-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF&q={searchTerms} HKU\S-1-5-21-3600292724-1680297373-2008538282-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449649395&z=ae5c7d8677e3f6013c08a71g2zez0t0q7zdt5c5tdz&from=ient07021&uid=ST9320423AS_5VH5RTSF&q={searchTerms} Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X] EmptyTemp: Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW). ---------------------- Jeśli będzie OK, to będziemy kończyć: Otwórz Notatnik i wklej w nim: DeleteQuarantine: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW). przez SHIFT+DEL usuń pozostały folder C:\FRST. Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie. .
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.