alexnovak utworzono 24 grudnia 2015 utworzono 24 grudnia 2015 Witam! Bardzo proszę o pomoc z pozbyciem się yoursites123 z opery.
Twój_Anioł_Stróż komentarz 24 grudnia 2015 komentarz 24 grudnia 2015 (edytowane) 1) Masz już Adw-Cleaner, więc: najpierw kliknij na SZUKAJ (SCAN), a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ (CLEANING), to kliknij na niego. 2) Otwórz Notatnik i wklej w nim: DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450122011&z=1056f856564d8cae290e49bg5z9wde8geo2o5e6e9t&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450122011&z=1056f856564d8cae290e49bg5z9wde8geo2o5e6e9t&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450122011&z=1056f856564d8cae290e49bg5z9wde8geo2o5e6e9t&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\Users\Alex\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450122011&z=1056f856564d8cae290e49bg5z9wde8geo2o5e6e9t&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\crxbro Browser\crxbro\chrome.exe (The crxbro Authors) -> hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-24] () S2 WSModules; C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [493360 2015-12-22] () S2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe -s [X] S2 Update Primary Result; "C:\Program Files (x86)\Primary Result\updatePrimaryResult.exe" [X] C:\Program Files (x86)\Primary Result R2 WdMan; C:\ProgramData\UWdMU\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V CHR HomePage: Default -> hxxp://www.yoursites123.com/?type=hp&ts=1450122011&z=1056f856564d8cae290e49bg5z9wde8geo2o5e6e9t&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V CHR DefaultSearchURL: Default -> hxxp://yoursites123.com/web?type=ds&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} CHR DefaultSearchKeyword: Default -> yoursites123 FF HKLM-x32\...\Firefox\Extensions: [sidebarff@gmail.com] - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\sidebarff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\arthurj8283@gmail.com FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\default_newtabff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\defsearchp@gmail.com FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\deskCutv2@gmail.com FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\yahooprotected@gmail.com StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V FF Extension: Default SearchProtected - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\defsearchp@gmail.com [2015-11-22] [Brak podpisu cyfrowego] FF Extension: deskCut - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\deskCutv2@gmail.com [2015-11-22] [Brak podpisu cyfrowego] FF Extension: YahooToolsProtected - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\extensions\yahooprotected@gmail.com [2015-12-14] [Brak podpisu cyfrowego] FF SearchPlugin: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\searchplugins\istartsurf.xml [2015-12-10] FF SearchPlugin: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\searchplugins\v9-.xml [2015-11-10] FF SearchPlugin: C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\mlmxy8hi.default\searchplugins\yoursites123.xml [2015-12-24] FF NewTab: hxxp://www.yoursites123.com/newtab/?type=nt&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V FF DefaultSearchEngine: yoursites123 FF SelectedSearchEngine: yoursites123 FF Homepage: hxxp://www.yoursites123.com/?type=hp&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1450961221&z=7f6dbe877ad9ab51d17b7c3gbz4wae3tfqcg7o9o3e&from=wpm07173&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://do-search.com/?type=hp&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://do-search.com/?type=hp&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://do-search.com/?type=hp&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://do-search.com/?type=hp&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} HKU\S-1-5-21-2820750442-3180874420-4026514599-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=1447158036&z=cc3e1eef5fa74b6e92f0787g5z5z1m3g0w7bfe0c1w&from=wpm07163&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} HKU\S-1-5-21-2820750442-3180874420-4026514599-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://do-search.com/?type=hp&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V HKU\S-1-5-21-2820750442-3180874420-4026514599-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://do-search.com/?type=hp&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V HKU\S-1-5-21-2820750442-3180874420-4026514599-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1447158036&z=cc3e1eef5fa74b6e92f0787g5z5z1m3g0w7bfe0c1w&from=wpm07163&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://do-search.com/web/?type=ds&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1447066094&from=zzgbkk123&uid=st500lt012-9ws142_w0vhez0vxxxxw0vhez0v&z=d7716b97f6c5229142cfd8dgdzfzfmcebqbqfedt0w&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://do-search.com/web/?type=ds&ts=1430214689&from=cor&uid=ST500LT012-9WS142_W0VHEZ0VXXXXW0VHEZ0V&q={searchTerms} SearchScopes: HKLM-x32 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1447066094&from=zzgbkk123&uid=st500lt012-9ws142_w0vhez0vxxxxw0vhez0v&z=d7716b97f6c5229142cfd8dgdzfzfmcebqbqfedt0w&q={searchTerms} SearchScopes: HKU\S-1-5-21-2820750442-3180874420-4026514599-1001 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1447066094&from=zzgbkk123&uid=st500lt012-9ws142_w0vhez0vxxxxw0vhez0v&z=d7716b97f6c5229142cfd8dgdzfzfmcebqbqfedt0w&q={searchTerms} SearchScopes: HKU\S-1-5-21-2820750442-3180874420-4026514599-1001 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1447066094&from=zzgbkk123&uid=st500lt012-9ws142_w0vhez0vxxxxw0vhez0v&z=d7716b97f6c5229142cfd8dgdzfzfmcebqbqfedt0w&q={searchTerms} GroupPolicy: Ograniczenia - Chrome <======= UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA DeleteKey: HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes Task: {12297948-6E99-441D-A801-9854F92971DB} - System32\Tasks\crxbroBrowserUpdateUA => C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [2015-12-22] () Task: {486DF678-0FDB-431E-BD6A-BB3ED59309E6} - System32\Tasks\crxbroBrowserUpdateCore => C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [2015-12-22] () Task: {8EFC1C03-2656-4BF0-AF02-1F92E6AE4656} - System32\Tasks\{7D00E49E-4F20-4EC6-A312-012E69E15BB4} => pcalua.exe -a C:\Users\Alex\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=cornl Task: {C0966898-E34A-4818-9DBF-D10AF30664F0} - System32\Tasks\crxbroCheckTask => C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [2015-12-22] () Task: {DAFCB1D6-8B2B-49CF-9B8D-0EF53F907FB7} - System32\Tasks\{AAB62530-3C93-4677-BCE9-C56563C69B3B} => pcalua.exe -a C:\Users\Alex\Desktop\DTLiteInstaller.exe -d C:\Users\Alex\Desktop C:\Program Files (x86)\crxbro Browser 2015-12-24 13:47 - 2015-08-30 10:44 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\Program Files (x86)\SSFK.exe C:\Program Files (x86)\WinZipper 2015-12-22 13:45 - 2015-12-22 13:45 - 00015058 _____ C:\Windows\System32\Tasks\crxbroBrowserUpdateUA 2015-12-22 13:45 - 2015-12-22 13:45 - 00015040 _____ C:\Windows\System32\Tasks\crxbroCheckTask 2015-12-22 13:45 - 2015-12-22 13:45 - 00004118 _____ C:\Windows\System32\Tasks\crxbroBrowserUpdateCore 2015-12-22 13:44 - 2015-12-22 13:44 - 00000000 ____D C:\Users\Public\Documents\crxbro 2015-12-22 13:44 - 2015-12-22 13:44 - 00000000 ____D C:\Users\Alex\AppData\Local\crxbro 2015-12-22 13:43 - 2015-12-24 14:08 - 00000000 ____D C:\Program Files (x86)\crxbro Browser 2015-12-14 20:41 - 2015-12-14 20:42 - 00000000 ____D C:\ProgramData\4WdM4 2015-12-24 12:36 - 2015-12-24 12:36 - 00000001 _____ C:\Windows\SysWOW64\pl.html 2015-12-24 13:53 - 2015-12-24 13:53 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys 2015-12-24 13:52 - 2015-12-24 13:52 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\Alex\Downloads\SpyHunter-Installer.exe 2015-12-24 13:52 - 2015-12-24 13:52 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\Alex\Downloads\SpyHunter-Installer (1).exe 2015-12-24 13:47 - 2015-12-24 13:49 - 00000000 ____D C:\ProgramData\UWdMU 2015-12-24 13:46 - 2015-12-24 13:46 - 02770377 _____ (iBank) C:\Program Files (x86)\SSFK.exe 2015-12-24 13:46 - 2015-12-24 13:46 - 00000000 ____D C:\ProgramData\BWdMB R1 {1601c372-fdd4-4d07-81cb-8d80cd533a89}Gw64; C:\Windows\System32\drivers\{1601c372-fdd4-4d07-81cb-8d80cd533a89}Gw64.sys [48792 2015-03-18] (StdLib) R1 {7edae523-2f47-48a4-be5c-2db16c2cad61}Gw64; C:\Windows\System32\drivers\{7edae523-2f47-48a4-be5c-2db16c2cad61}Gw64.sys [48792 2015-03-15] (StdLib) R1 {af159d03-4801-4284-bdcb-4497403da962}Gw64; C:\Windows\System32\drivers\{af159d03-4801-4284-bdcb-4497403da962}Gw64.sys [48792 2015-03-13] (StdLib) R1 {c2812e93-4fef-423f-98ce-9a06fe4e2372}Gw64; C:\Windows\System32\drivers\{c2812e93-4fef-423f-98ce-9a06fe4e2372}Gw64.sys [48792 2015-03-24] (StdLib) R1 {fb7f80a9-0102-4cff-bdb6-f3761a4dd2df}Gw64; C:\Windows\System32\drivers\{fb7f80a9-0102-4cff-bdb6-f3761a4dd2df}Gw64.sys [48792 2015-03-21] (StdLib) S1 wfdrvr_vw_1_10_0_28; system32\drivers\wfdrvr_vw_1_10_0_28.sys [X] EmptyTemp: Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW). ---------------------- Jeśli będzie OK, to będziemy kończyć: Otwórz Notatnik i wklej w nim: DeleteQuarantine: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW). przez SHIFT+DEL usuń pozostały folder C:\FRST. W Adw-Cleaner kliknij na przycisk [b]Odinstaluj[/b] ([b]UNINSTALL[/b]). Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie. .
szymon211992 komentarz 24 grudnia 2015 komentarz 24 grudnia 2015 Również proszę o pomoc w pozbyciu się yoursites123 z opery
Twój_Anioł_Stróż komentarz 24 grudnia 2015 komentarz 24 grudnia 2015 Również proszę o pomoc w pozbyciu się yoursites123 z opery załóż swój własny temat
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.