x-kom hosting

pozbycie się yoursites123

szymon211992
utworzono
utworzono

Witam

Proszę o pomoc w usunięciu yoursites123 z opery

Twój_Anioł_Stróż
komentarz
komentarz (edytowane)

1) Odinstaluj ten program:

WinZipper (HKLM-x32\...\WinZipper) (Version: 1.5.129 - Taiwan Shui Mu Chih Ching Technology Limited.) <==== UWAGA

 

2) Użyj >[url=http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner]Adw-cleaner[/url]
najpierw kliknij na SZUKAJ (SCAN), a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ (CLEANING), to kliknij na niego.

 

3) Otwórz Notatnik i wklej w nim:

DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software
StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.yoursites123.com/?type=sc&ts=1450945913&z=69d837118e0ad93ce586622gazew4e2t9zew3t8g9o&from=wpm07173&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
CHR HomePage: Default -> s.piesearch.com/?type=chhp
CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hppp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155"
CHR DefaultSearchURL: Default -> hxxp://www.istartsurf.com/web/?type=dspp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
CHR DefaultSearchKeyword: Default -> istartsurf
StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1450945913&z=69d837118e0ad93ce586622gazew4e2t9zew3t8g9o&from=wpm07173&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
SearchScopes: HKU\S-1-5-21-3456149020-3787918041-547472844-1002 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&ts=1437819073&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3456149020-3787918041-547472844-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&ts=1437819073&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3456149020-3787918041-547472844-1002 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&ts=1437819073&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3456149020-3787918041-547472844-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&ts=1437819073&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3456149020-3787918041-547472844-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&ts=1437819073&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3456149020-3787918041-547472844-1002 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&ts=1437819073&type=default&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
HKU\S-1-5-21-3456149020-3787918041-547472844-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449653695&z=ae9a6cf3a1662c3284708cdg5z6z2t0qawbc6q1t7z&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
HKU\S-1-5-21-3456149020-3787918041-547472844-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hppp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
HKU\S-1-5-21-3456149020-3787918041-547472844-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hppp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=dspp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hppp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hppp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449583708&z=495fd242daf7eec6aabec39g4z8zft9w2bfc7m4eeb&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449583708&z=495fd242daf7eec6aabec39g4z8zft9w2bfc7m4eeb&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hppp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hppp&ts=1437819060&z=3b1d27ead55b1923a7a001cgbzfc5mbb9getae6g9b&from=cor&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449583708&z=495fd242daf7eec6aabec39g4z8zft9w2bfc7m4eeb&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449583708&z=495fd242daf7eec6aabec39g4z8zft9w2bfc7m4eeb&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155&q={searchTerms}
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk [2015-05-12]
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe ()
DeleteKey: HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes
Task: {2C06B99C-BE63-4DE4-82DF-6A09ADE20071} - System32\Tasks\crxbroCheckTask => C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [2015-12-09] ()
C:\Program Files (x86)\crxbro Browser
Task: {8602436F-28AA-4024-A75C-D46825362640} - System32\Tasks\crxbroBrowserUpdateCore => C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [2015-12-09] ()
Task: {98CAF29E-4F6F-48AE-B264-50C4B9D18F00} - System32\Tasks\{86F0BEEA-D729-4496-953F-6D1FD0BAF468} => pcalua.exe -a "C:\Users\Szymon\AppData\Local\Temp\Temp1_WPU.zip\Wise Program Uninstaller\WiseProgramUninstaller.exe"
Task: {CCE43CC0-DB3E-4992-8C17-7B84D0EC9AED} - System32\Tasks\crxbroBrowserUpdateUA => C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [2015-12-09] ()
Task: {F7178E7D-E9D4-4ABC-B3DC-61F49784BC50} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
C:\Program Files\Enigma Software Group
Shortcut: C:\Users\Szymon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hugin\Enfuse Auto Align Droplet.lnk -> C:\Program Files\Hugin\bin\enfuse_auto_align_droplet.bat (Brak pliku)
ShortcutWithArgument: C:\Users\Szymon\Desktop\programy\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653695&z=ae9a6cf3a1662c3284708cdg5z6z2t0qawbc6q1t7z&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
ShortcutWithArgument: C:\Users\Szymon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653695&z=ae9a6cf3a1662c3284708cdg5z6z2t0qawbc6q1t7z&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
ShortcutWithArgument: C:\Users\Szymon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.piesearch.com/?type=sc&ts=1443703799&uid=da2773c4-2680-4ad9-ae6f-025af15edfe7&pid=etc1
ShortcutWithArgument: C:\Users\Szymon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653695&z=ae9a6cf3a1662c3284708cdg5z6z2t0qawbc6q1t7z&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
ShortcutWithArgument: C:\Users\Szymon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449583708&z=495fd242daf7eec6aabec39g4z8zft9w2bfc7m4eeb&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449583708&z=495fd242daf7eec6aabec39g4z8zft9w2bfc7m4eeb&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
ShortcutWithArgument: C:\Users\Public\Desktop\Internet.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653695&z=ae9a6cf3a1662c3284708cdg5z6z2t0qawbc6q1t7z&from=ient07021&uid=WDCXWD3200BPVT-80ZEST0_WD-WX91A410115501155
C:\Program Files (x86)\WinZipper
2015-12-08 15:08 - 2015-07-25 11:11 - 00000000 ____D C:\Program Files (x86)\MiuiTab
2015-12-24 09:31 - 2015-12-24 09:31 - 2770377 _____ (iBank) C:\Program Files (x86)\SSFK.exe
2015-12-09 10:34 - 2015-10-26 12:41 - 00000000 ____D C:\ProgramData\HWMiniProH
2015-12-24 09:32 - 2015-10-10 08:10 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-12-24 09:32 - 2015-09-22 13:42 - 00000000 ____D C:\Users\Szymon\AppData\Roaming\TSv
2015-12-24 13:25 - 2015-09-22 13:42 - 00000000 ____D C:\Program Files (x86)\SFK
2015-12-08 15:08 - 2015-12-08 15:09 - 00000000 ____D C:\ProgramData\7WdM7
2015-12-09 10:35 - 2015-12-09 10:36 - 00000000 ____D C:\ProgramData\FWdMF
2015-12-09 10:34 - 2015-12-09 10:34 - 00000000 ____D C:\ProgramData\ZWdMZ
2015-12-10 09:56 - 2015-12-24 09:32 - 00000000 ____D C:\Program Files (x86)\crxbro Browser
2015-12-10 09:56 - 2015-12-10 09:56 - 00015058 _____ C:\Windows\System32\Tasks\crxbroBrowserUpdateUA
2015-12-10 09:56 - 2015-12-10 09:56 - 00015048 _____ C:\Windows\System32\Tasks\crxbroCheckTask
2015-12-10 09:56 - 2015-12-10 09:56 - 00004118 _____ C:\Windows\System32\Tasks\crxbroBrowserUpdateCore
2015-12-10 09:56 - 2015-12-10 09:56 - 00000000 ____D C:\Users\Szymon\AppData\Local\crxbro
2015-12-10 09:56 - 2015-12-10 09:56 - 00000000 ____D C:\Users\Public\Documents\crxbro
2015-12-24 09:32 - 2015-12-24 09:33 - 00000000 ____D C:\ProgramData\iWdMi
2015-12-24 13:27 - 2015-12-24 13:28 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Szymon\Downloads\sh-remover.exe
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S1 qsafd_vt_1_10_0_20; system32\drivers\qsafd_vt_1_10_0_20.sys [X]
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-05-12] ()
C:\Windows\System32\DRIVERS\EsgScanner.sys
R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [711344 2015-12-09] (Taiwan Shui Mu Chih Ching Technology Limited) <==== UWAGA
S2 WSModules; C:\Program Files (x86)\crxbro Browser\crxbro\bin\browserServer.exe [470400 2015-12-09] () [Brak podpisu cyfrowego]
S3 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X]
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [X]
R2 WdMan; C:\ProgramData\iWdMi\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
R2 IHProtect Service; C:\Program Files (x86)\MiuiTab\ProtectService.exe [119808 2015-12-08] (XTab system) [Brak podpisu cyfrowego]
R2 IhPul; C:\Users\Szymon\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [172192 2015-12-24] (TODO: <公司名>)
EmptyTemp:

Plik zapisz pod nazwą [b]fixlist.txt[/b] i umieść obok FRST.exe
Uruchom [b]FRST[/b] i kliknij przycisk [b]Fix[/b] (NAPRAW).


----------------------
Jeśli będzie OK, to będziemy kończyć:
Otwórz Notatnik i wklej w nim:

DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).
przez SHIFT+DEL usuń pozostały folder C:\FRST.

W Adw-Cleaner kliknij na przycisk [b]Odinstaluj[/b] ([b]UNINSTALL[/b]).


Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie.
.
 

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.