olekmusic utworzono 11 grudnia 2015 utworzono 11 grudnia 2015 (edytowane) Proszę o pomoc w usunięciu tego syfu... chodzi o yoursites ze strony startowej. Prosiłbym o instrukcję.
Twój_Anioł_Stróż komentarz 11 grudnia 2015 komentarz 11 grudnia 2015 (edytowane) Otwórz Notatnik i wklej w nim: Task: {41E6A0E0-94BF-4AA7-BD56-374352E6F513} - System32\Tasks\{AD82DDAF-56AA-45D0-9CE7-0E7CEF7BB2E4} => pcalua.exe -a C:\Users\karolina\Desktop\fifa98.exe -d C:\Users\karolina\Desktop Task: {5EEA4A16-F7F7-4717-8983-073313E6C1D9} - System32\Tasks\{2431F0D0-1886-4D15-9053-1BC285063BC5} => pcalua.exe -a D:\SETUP.EXE -d D:\ Task: {C9F1C5AE-B6FC-4E58-821F-8781AF7BD7DC} - System32\Tasks\{70B397DB-A662-40CA-9EFD-A8F784C50CFC} => pcalua.exe -a "C:\Users\karolina\Desktop\www.PcGameFreeTop.Net\Cue Club - www.PcGameFreeTop.net\Setup.exe" -d "C:\Users\karolina\Desktop\www.PcGameFreeTop.Net\Cue Club - www.PcGameFreeTop.net" ShortcutWithArgument: C:\Users\karolina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T <==== UWAGA ShortcutWithArgument: C:\Users\karolina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T <==== UWAGA ShortcutWithArgument: C:\Users\karolina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T <==== UWAGA ShortcutWithArgument: C:\Users\karolina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T <==== UWAGA ShortcutWithArgument: C:\Users\karolina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\zc1h3r7o5m4e.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T <==== UWAGA 2015-12-11 13:08 - 2015-10-11 12:02 - 00001579 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\zc1h3r7o5m4e.lnk 2015-12-11 13:09 - 2015-12-11 13:10 - 00000000 ____D C:\ProgramData\4WdM4 R2 WdMan; C:\ProgramData\4WdM4\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T CHR Plugin: (Chrome NaCl) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.80\ppGoogleNaClPluginChrome.dll => Brak pliku CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.80\pdf.dll => Brak pliku CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => Brak pliku CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => Brak pliku BHO-x32: Brak nazwy -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> Brak pliku SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-205961238-1924060113-2715977037-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T&q={searchTerms} searchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T&q={searchTerms} HKU\S-1-5-21-205961238-1924060113-2715977037-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449835707&z=a8ec270b32764ac0cd3ff38g1z1z0t5b7cdwamfe7m&from=ient07021&uid=TOSHIBAXMQ01ABD032_22MNP1V5TXX22MNP1V5T&q={searchTerms} HKLM-x32\...\Run: [app] => C:\Program Files (x86)\Tencent\app.exe C:\Program Files (x86)\Tencent EmptyTemp: Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW). ---------------------- Jeśli będzie OK, to będziemy kończyć: Otwórz Notatnik i wklej w nim: DeleteQuarantine: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW). przez SHIFT+DEL usuń pozostały folder C:\FRST. W Adw-Cleaner kliknij na przycisk [b]Odinstaluj[/b] ([b]UNINSTALL[/b]). Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie. .
novy07 komentarz 14 grudnia 2015 komentarz 14 grudnia 2015 Witam,mam ten sam problem.W załaczniku dołączam pliki z FRST.Z góry dziekuję z pomoc.
Twój_Anioł_Stróż komentarz 14 grudnia 2015 komentarz 14 grudnia 2015 Witam,mam ten sam problem.W załaczniku dołączam pliki z FRST.Z góry dziekuję z pomoc. załóż swój własny temat
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.