x-kom hosting

yoursite 123 - chrome

Jaroch
utworzono
utworzono

Witam!

Proszę o pomoc w usunięciu yoursite 123. Moja przeglądarka to chrome, system to Windows 7. Załączam pliki ze skanowania.

 

 

Serdecznie pozdrawiam !

Twój_Anioł_Stróż
komentarz
komentarz (edytowane)

1) Odinstaluj te programy:

webssearches uninstall (HKLM\...\webssearches uninstall) (Version:  - webssearches) <==== UWAGA
WinZipper (HKLM\...\WinZipper) (Version: 1.5.130 - Taiwan Shui Mu Chih Ching Technology Limited.) <==== UWAGA

2) Otwórz Notatnik i wklej w nim:

DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software
ShortcutWithArgument: C:\Users\Chmielu\Desktop\Google Chrome.lnk -> C:\Users\Chmielu\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
ShortcutWithArgument: C:\Users\Chmielu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
ShortcutWithArgument: C:\Users\Chmielu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Users\Chmielu\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
ShortcutWithArgument: C:\Users\Chmielu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
ShortcutWithArgument: C:\Users\Chmielu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
ShortcutWithArgument: C:\Users\Chmielu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Users\Chmielu\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
ShortcutWithArgument: C:\Users\Chmielu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Users\Chmielu\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
2015-12-22 10:40 - 2015-12-22 10:40 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-11-27 19:10 - 2015-12-22 10:40 - 00000000 ____D C:\Program Files\RayDld
2015-12-22 10:41 - 2015-12-22 16:36 - 00000000 ____D C:\Program Files\WinZipper
2015-12-22 10:41 - 2015-12-22 10:41 - 00000000 ____D C:\Users\Chmielu\AppData\Roaming\WinZipper
2015-12-22 10:41 - 2015-12-22 10:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
2015-12-22 10:40 - 2015-12-22 16:35 - 00000000 ____D C:\Program Files\SFK
2015-12-22 10:40 - 2015-12-22 16:33 - 00000001 _____ C:\Windows\system32\pl.html
2015-12-22 10:40 - 2015-12-22 10:41 - 00000000 ____D C:\ProgramData\WWdMW
S3 catchme; \??\C:\Users\Chmielu\AppData\Local\Temp\catchme.sys [X]
S1 wfdrvr_vt_1_10_0_28; system32\drivers\wfdrvr_vt_1_10_0_28.sys [X]
R2 ihpmServer; C:\Program Files\RayDld\ihpmServer.exe [265960 2015-12-22] (RayDl)
R2 IhPul; C:\Users\Chmielu\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
R2 SSFK; C:\Program Files\SFK\SSFK.exe [175104 2015-12-22] (TODO: <公司名>) [Brak podpisu cyfrowego]
R2 WdMan; C:\ProgramData\WWdMW\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [711344 2015-12-14] (Taiwan Shui Mu Chih Ching Technology Limited) <==== UWAGA
StartMenuInternet: Google Chrome - C:\Users\Chmielu\AppData\Local\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
CHR HomePage: Default -> hxxp://www.yoursites123.com/?type=hp&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
HKU\S-1-5-21-125063247-1893170134-3150045939-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757&q={searchTerms}
HKU\S-1-5-21-125063247-1893170134-3150045939-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
HKU\S-1-5-21-125063247-1893170134-3150045939-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
HKU\S-1-5-21-125063247-1893170134-3150045939-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757&q={searchTerms}
SearchScopes: HKLM -> DefaultScope - brak wartości
SearchScopes: HKU\S-1-5-21-125063247-1893170134-3150045939-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://yoursites123.com/web?type=ds&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757&q={searchTerms}
SearchScopes: HKU\S-1-5-21-125063247-1893170134-3150045939-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.holasearch.com/?q={searchTerms}&affID=121962&tt=gc_&babsrc=SP_ss&mntrId=F8700022153ADE1C
SearchScopes: HKU\S-1-5-21-125063247-1893170134-3150045939-1001 -> {260318EF-3DA7-4937-87F6-1CEADDB3F114} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=chr
SearchScopes: HKU\S-1-5-21-125063247-1893170134-3150045939-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://yoursites123.com/web?type=ds&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757&q={searchTerms}
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-125063247-1893170134-3150045939-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartpageing.com/web/?type=ds&ts=1448647796&z=820b57f236aca866988f034gezezab6q9z5m6mftdq&from=cornl&uid=samsungxhd753lj_s13uj1cq811757&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450777192&z=0d34a2a2603e80627fb2514gez0w4e4mbm9mde1tcw&from=wpm07173&uid=SAMSUNGXHD753LJ_S13UJ1CQ811757
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartpageing.com/web/?type=ds&ts=1448647796&z=820b57f236aca866988f034gezezab6q9z5m6mftdq&from=cornl&uid=samsungxhd753lj_s13uj1cq811757&q={searchTerms}
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.135\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.99\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.25.5\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.27.5\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.79\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.23.9\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.28.1\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.145\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.123\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.153\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.28.13\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.24.15\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.149\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.22.3\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.165\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.26.9\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.115\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.25.11\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.28.15\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\Chmielu\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.22.5\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.21.111\psuser.dll => Brak pliku
CustomCLSID: HKU\S-1-5-21-125063247-1893170134-3150045939-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Chmielu\AppData\Local\Google\Update\1.3.24.7\psuser.dll => Brak pliku
Task: {2BD0FA38-669B-4717-84AE-37CCE109C84D} - System32\Tasks\{199F39A5-14E2-4C3A-917B-B0F8BCB945FA} => pcalua.exe -a "C:\Users\Chmielu\Desktop\Worms party\wwp-www.darkwarez.pl-kermitek321\WormsWorldParty\Daemon Tools 3.47.exe" -d "C:\Users\Chmielu\Desktop\Worms party\wwp-www.darkwarez.pl-kermitek321\WormsWorldParty"
Task: {6F4028CE-DFA6-48E9-9C6C-B7094985F031} - System32\Tasks\{51667B23-6BDF-4958-A32B-B47CE85594C4} => pcalua.exe -a C:\Users\Chmielu\AppData\Roaming\webssearches\UninstallManager.exe -c  -ptid=slbnew <==== UWAGA
Task: {98E822AF-D778-46B2-93A1-D0E6ACA8362C} - System32\Tasks\{B93FB498-DE43-4632-BCAD-7D59669E2388} => pcalua.exe -a C:\Windows\unvise32.exe -d C:\Windows -c \Microsoft\Windows\CurrentVersion\SharedDlls
Task: {A5B3F20B-EEF9-4FB1-B888-2A4E7D9DC71E} - System32\Tasks\{BFE7556C-C340-4990-8369-2558FCBA0B7D} => pcalua.exe -a H:\setup.exe -d H:\
C:\Program Files\WinZipper
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [Brak pliku]
BHO: Brak nazwy -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> Brak pliku
EmptyTemp:

Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe
Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW).


----------------------
Jeśli będzie OK, to będziemy kończyć:
Otwórz Notatnik i wklej w nim:

DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).
przez SHIFT+DEL usuń pozostały folder C:\FRST.


Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie.
.
 
  • Dobra wypowiedź 1
Jaroch
komentarz
komentarz

Dziekuje bardzo za pomoc! Teraz już jest dobrze :)

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.