pudel88 utworzono 12 grudnia 2015 utworzono 12 grudnia 2015 Witam. Niestety również zostałem przyatakowany przez yoursites. Od wczoraj nie mogę sobie z tym poradzić, więc bardzo proszę o pomoc w usunięciu problemu.
Twój_Anioł_Stróż komentarz 12 grudnia 2015 komentarz 12 grudnia 2015 (edytowane) Otwórz Notatnik i wklej w nim: ShortcutWithArgument: C:\Users\pudel_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\Users\pudel_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0\WSE on the Web.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\Users\pudel_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\Users\pudel_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\Users\pudel_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\Users\pudel_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX <==== UWAGA C:\ProgramData\rWdMr GroupPolicy: Ograniczenia - Chrome <======= UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX&q={searchTerms} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX&q={searchTerms} SearchScopes: HKU\S-1-5-21-3742839547-2934039265-1587003344-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST3250318AS_9VM2V1LZXXXX9VM2V1LZ&ts=1438883339&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3742839547-2934039265-1587003344-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST3250318AS_9VM2V1LZXXXX9VM2V1LZ&ts=1438883339&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3742839547-2934039265-1587003344-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX&q={searchTerms} SearchScopes: HKU\S-1-5-21-3742839547-2934039265-1587003344-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST3250318AS_9VM2V1LZXXXX9VM2V1LZ&ts=1438883339&type=default&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX FF NewTab: hxxp://www.yoursites123.com/newtab/?type=nt&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX FF Homepage: hxxp://www.yoursites123.com/?type=hp&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX FF SearchPlugin: C:\Users\pudel_000\AppData\Roaming\Mozilla\Firefox\Profiles\unwgypqo.default\searchplugins\istartsurf.xml [2015-10-08] FF Extension: YahooToolsProtected - C:\Users\pudel_000\AppData\Roaming\Mozilla\Firefox\Profiles\unwgypqo.default\Extensions\yahooprotected@gmail.com [2015-12-11] [Brak podpisu cyfrowego] FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\pudel_000\AppData\Roaming\Mozilla\Firefox\Profiles\unwgypqo.default\extensions\defsearchp@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\pudel_000\AppData\Roaming\Mozilla\Firefox\Profiles\unwgypqo.default\extensions\default_newtabff@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [sidebarff@gmail.com] - C:\Users\pudel_000\AppData\Roaming\Mozilla\Firefox\Profiles\unwgypqo.default\extensions\sidebarff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\pudel_000\AppData\Roaming\Mozilla\Firefox\Profiles\unwgypqo.default\extensions\yahooprotected@gmail.com StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449854018&z=db018853acf618e52b12ffcgezfz5t0bcw4z5e3g0t&from=ient07021&uid=TOSHIBAXDT01ACA050_44S10RDBSXX44S10RDBSX OPR Extension: (Filter Results) - C:\Users\pudel_000\AppData\Roaming\Opera Software\Opera Stable\Extensions\mcbcggkgjkfapollndmndmnejhemekkp [2015-08-06] R2 WdMan; C:\ProgramData\rWdMr\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] S1 tcfd_vw_1_10_0_21; system32\drivers\tcfd_vw_1_10_0_21.sys [X] 2015-12-02 19:22 - 2015-12-02 23:23 - 00000000 _____ C:\Windows\SysWOW64\pl0.exe 2015-12-11 18:15 - 2015-10-19 16:41 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat EmptyTemp: Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW). ---------------------- Jeśli będzie OK, to będziemy kończyć: Otwórz Notatnik i wklej w nim: DeleteQuarantine: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW). przez SHIFT+DEL usuń pozostały folder C:\FRST. Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie. .
pudel88 komentarz 12 grudnia 2015 Autor komentarz 12 grudnia 2015 Problem rozwiązany. Bardzo dziękuję za pomoc.
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.