x-kom hosting

yoursite123 Błagam, pomocy...

Moniapp
utworzono
utworzono

Proszę o pomoc, nie wiem jak to dziadostwo usunąć ;/
Co mam zrobić?

Moniapp
komentarz
komentarz

Proszę, oto pliki.

Twój_Anioł_Stróż
komentarz
komentarz

Otwórz Notatnik i wklej w nim:

DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software
ShortcutWithArgument: C:\Users\Massa\Desktop\Start Tor Browser.lnk -> C:\Users\Massa\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT <==== UWAGA
ShortcutWithArgument: C:\Users\Massa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT <==== UWAGA
ShortcutWithArgument: C:\Users\Massa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk -> C:\Users\Massa\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT <==== UWAGA
ShortcutWithArgument: C:\Users\Massa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT <==== UWAGA
ShortcutWithArgument: C:\Users\Massa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT <==== UWAGA
ShortcutWithArgument: C:\Users\Massa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT <==== UWAGA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT <==== UWAGA
2015-12-12 20:44 - 2015-12-12 20:44 - 0023552 _____ (KOP) C:\Users\Massa\AppData\Roaming\KOP.exe
2015-12-05 20:28 - 2015-12-05 20:28 - 0023552 _____ (new) C:\Users\Massa\AppData\Roaming\new.exe
2015-11-28 11:59 - 2015-12-09 11:06 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-11-10 20:04 - 2015-11-11 19:10 - 0000690 _____ () C:\Users\Massa\AppData\Roaming\chrome.vbs
2015-11-26 19:16 - 2015-11-26 19:16 - 0023552 _____ () C:\Users\Massa\AppData\Roaming\DEADD.exe
2015-11-04 19:14 - 2015-11-04 19:14 - 0054784 _____ (analisticsAD) C:\Users\Massa\AppData\Roaming\analisticsAD.exe
2015-12-12 20:45 - 2015-12-12 20:45 - 0109568 _____ (Lightshot) C:\Users\Massa\AppData\Roaming\BackADD.exe
2015-11-16 20:05 - 2015-11-16 20:05 - 00000000 __SHD C:\found.000
2015-11-28 11:59 - 2015-12-09 11:06 - 00000000 ____D C:\ProgramData\tWMiniProt
2015-11-28 11:59 - 2015-11-28 12:09 - 00000000 ____D C:\Users\Massa\AppData\Roaming\yoursearching
2015-12-09 11:07 - 2015-12-13 10:59 - 00000000 ____D C:\Program Files (x86)\SFK
2015-12-09 11:06 - 2015-12-09 11:08 - 00000000 ____D C:\ProgramData\5WdM5
2015-12-09 11:06 - 2015-12-09 11:06 - 00000000 ____D C:\Users\Massa\AppData\Roaming\TSv
2015-12-09 11:06 - 2015-12-09 11:06 - 00000000 ____D C:\ProgramData\MWdMM
2015-12-10 00:28 - 2015-12-10 00:28 - 00364800 _____ C:\Windows\Minidump\121015-21250-01.dmp
2015-12-13 00:43 - 2015-12-13 10:56 - 00000001 _____ C:\Windows\SysWOW64\pl.html
S3 MSICDSetup; \??\F:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X]
S3 NTIOLib_FastBoot; \??\C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [X]
R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: <公司名>)
R2 WdMan; C:\ProgramData\5WdM5\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
R2 IhPul; C:\Users\Massa\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Massa\AppData\Roaming\Mozilla\Firefox\Profiles\3kma9s67.default\extensions\default_newtabff@gmail.com
FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Massa\AppData\Roaming\Mozilla\Firefox\Profiles\3kma9s67.default\extensions\yahooprotected@gmail.com => nie znaleziono
FF NewTab: chrome://quick_start/content/index.html
FF SelectedSearchEngine: yoursites123
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
HKU\S-1-5-21-3726516693-2097094107-1916583325-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
HKU\S-1-5-21-3726516693-2097094107-1916583325-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3726516693-2097094107-1916583325-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449655572&z=7a638f2c86be6f8cba83783g3zdzetaq3wcw3w5qbc&from=ient07021&uid=ST500DM002-1BC142_Z2A8C9QTXXXXZ2A8C9QT&q={searchTerms}
Startup: C:\Users\Massa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BackADD.lnk [2015-12-13]
ShortcutTarget: BackADD.lnk -> C:\Users\Massa\AppData\Roaming\BackADD.exe (Lightshot)
Startup: C:\Users\Massa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hksynhd.lnk [2015-11-12]
ShortcutTarget: hksynhd.lnk -> C:\Users\Massa\AppData\Roaming\hksynhd.exe (Brak pliku)
Startup: C:\Users\Massa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows Explorer.lnk [2015-12-13]
ShortcutTarget: Windows Explorer.lnk -> C:\Users\Massa\AppData\Roaming\Windows Explorer.vbs ()
EmptyTemp:

Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe
Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW).


----------------------
Jeśli będzie OK, to będziemy kończyć:
Otwórz Notatnik i wklej w nim:

DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).
przez SHIFT+DEL usuń pozostały folder C:\FRST.

W Adw-Cleaner kliknij na przycisk [b]Odinstaluj[/b] ([b]UNINSTALL[/b]).


Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie.
.
 
Moniapp
komentarz
komentarz

Problem zniknął, dziękuje i pozdrawiam serdecznie :))

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.