Skocz do zawartości

Infekcja "Shopper Pro" i "YouTube Accelerator" - zablokowane połączenie z internetem


Rekomendowane odpowiedzi

Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Problem braku sieci to skutek niepoprawej próby usunięcia "YouTube Accelerator" - usunięto z dysku plik, który był wpięty w łańcuch Winsock. Skutki: uszkodzony Winsock.

 

Winsock: Catalog9 01 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 02 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 03 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 04 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 05 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 06 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 07 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 08 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 09 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 10 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 11 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

Winsock: Catalog9 23 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll File Not found ()

 

 

1. Otwórz Notatnik i wklej w nim:

 

CloseProcesses:
CreateRestorePoint:
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-02-12] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-02-12] (globalUpdate) [File not signed]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
R2 SPDRIVER_1501.0.0.0; C:\Program Files (x86)\ShopperPro\JSDriver\1501.0.0.0\jsdrv.sys [52584 2015-02-27] ()
R2 YouTubeAcceleratorService; C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe [1510248 2015-02-12] (GOOBZO)
R4 GUBootStartup; \??\C:\Windows\System32\drivers\GUBootStartup.sys [X]
Task: {00CE9143-56D6-46B6-B278-326111FC439D} - System32\Tasks\{23D1FE0F-AE38-44F6-A780-E3303909F8D8} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe"
Task: {0B838895-1D6F-4511-B1F4-5D4474D121CB} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-11 => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-11.exe 
Task: {223B3252-6AF4-4E39-ACF7-77053C953383} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-02-12] (globalUpdate) 
Task: {2B568104-4279-4435-AA08-503C122C8214} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-02-12] (globalUpdate) 
Task: {37D497B3-D19A-4515-8EB5-DC4377FAD64B} - System32\Tasks\UNELEVATE_9778 => C:\Program Files (x86)\ShopperPro\JSDriver\1501.0.0.0\jsdrv.exe [2015-02-27] () 
Task: {45DF4740-6125-426B-B23F-7581CFB9614A} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-11 => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-11.exe 
Task: {46CAFD29-FA9D-48A2-A18B-D2F88E811924} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-7 => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-7.exe 
Task: {55DE4861-669E-4FFD-A7D3-DD3951998893} - System32\Tasks\SPBIW_UpdateTask_Time_313731313739363233342d5a556c6c4a5a575750414134 => Wscript.exe //B "C:\ProgramData\ShopperPro\spbihe.js" spbiu.exe /invoke /f:check_services /l:0 
Task: {57C2F0A6-0744-40C1-AE6E-733772E35359} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-7 => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-7.exe 
Task: {5B830A62-16C5-486D-94C5-1C008F2BC1AB} - System32\Tasks\YTAUpdate_logon => C:\Program 
Task: {68150F0D-870C-47D3-890F-B7F8D1352D73} - System32\Tasks\ShopperPro => C:\Program Files (x86)\ShopperPro\ShopperPro.exe [2015-02-27] (Goobzo LTD) 
Task: {6A8F3860-D66A-4541-8619-A57084BC5DF1} - System32\Tasks\YTAHelper => C:\Program Files (x86)\YTAHelper\YTAHelper.exe 
Task: {6E769582-34F0-4698-B866-36E37A737A6F} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-6 => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-6.exe 
Task: {83E44F6A-C74D-4C2A-A286-3FA2A55A1168} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-1-6 => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-1-6.exe 
Task: {8A07C8A2-9742-43E6-9269-6CCF19D695DA} - System32\Tasks\SPDriver => C:\Program Files (x86)\ShopperPro\JSDriver\1501.0.0.0\jsdrv.exe [2015-02-27] () 
Task: {9E8FB32B-F1CA-4ADE-9C62-4D3F3B4262A7} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-4 => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-4.exe 
Task: {A03FC3A9-DA31-4784-BD39-AEEB5FD60AAC} - System32\Tasks\ZJDZSSU => C:\Users\Samsung\AppData\Roaming\ZJDZSSU.exe 
Task: {ABEAEE0A-B7CC-4708-86BD-B0D224FA8209} - System32\Tasks\ShopperProJSUpd => C:\Program Files (x86)\ShopperPro\updater.exe [2015-02-27] (Goobzo) 
Task: {B4EA139B-26EB-478C-8E4B-A3C76F134284} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-4 => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-4.exe 
Task: {BD03365C-603B-48D9-A675-2431A91671C6} - System32\Tasks\YTAUpdate => C:\Program 
Task: {BE678C65-FC21-4EC6-BCBE-4DD3B6AF1687} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5 => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5.exe 
Task: {C4D9EBBF-BB31-4601-A1A9-91C4EF42CACF} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5_user => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5.exe 
Task: {EDFFD5AF-E6C8-4900-8A77-26958362A137} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-6 => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-6.exe 
Task: {F3DCF8B0-9BAB-4785-B367-F14998C3DA79} - System32\Tasks\LGXGTRI => C:\Users\Samsung\AppData\Roaming\LGXGTRI.exe 
Task: {F68262FE-440E-4CF0-B86C-0ED365A34DC7} - System32\Tasks\{D7351ADF-794C-4455-8AB5-217308A0C56D} => pcalua.exe -a C:\Users\Samsung\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt
Task: {F8DE7E25-0E3D-419E-9019-C646535F5D5A} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-6 => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-6.exe 
Task: {FA31A5CC-F1B9-4C85-B4DC-68D7062AC1A2} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-5 => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-5.exe 
Task: {FBBE12C2-1ACF-46C4-B4DF-457C2314DFD7} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-5_user => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-5.exe 
Task: {FDCA3B55-25B3-42F3-80B0-3C75DE967320} - System32\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-1-7 => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-1-7.exe 
Task: {FF690562-7F74-4F20-A975-6140B2D9A8FA} - System32\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-7 => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-7.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-6.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-6.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-7.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-1-7.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-11.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-11.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-4.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-4.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5_user.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-5.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-6.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-6.exe 
Task: C:\Windows\Tasks\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-7.job => C:\Program Files (x86)\iWebar\c21c6fb6-3e79-48f1-87c5-b8b648d5faf9-7.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-1-6.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-1-6.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-1-7.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-1-7.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-11.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-11.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-4.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-4.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-5.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-5.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-5_user.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-5.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-6.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-6.exe 
Task: C:\Windows\Tasks\d495a1a5-2910-4445-9452-0fa90678852b-7.job => C:\Program Files (x86)\SensePlus\d495a1a5-2910-4445-9452-0fa90678852b-7.exe 
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\LGXGTRI.job => C:\Users\Samsung\AppData\Roaming\LGXGTRI.exe 
Task: C:\Windows\Tasks\ZJDZSSU.job => C:\Users\Samsung\AppData\Roaming\ZJDZSSU.exe 
HKLM-x32\...\Run: [sPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1501.0.0.0\jsdrv.exe [3224576 2015-02-27] ()
HKU\S-1-5-21-2139329922-3582906400-648950646-1000\...\Run: [AVG-Secure-Search-Update_0614i] => C:\Users\Samsung\AppData\Roaming\Avg_Update_0614i\AVG-Secure-Search-Update_0614i.exe /PROMPT /mid=121d34194f4a47d2b2bcd16ff0331473-5b96fcc5a9e0febf72a66af30b8d73181ebf1606 /CMPID=0614i
HKU\S-1-5-21-2139329922-3582906400-648950646-1000\...\Run: [sPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1501.0.0.0\jsdrv.exe [3224576 2015-02-27] ()
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1423739800&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1423739800&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1423739800&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1423739800&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
HKU\S-1-5-21-2139329922-3582906400-648950646-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=dspp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
HKU\S-1-5-21-2139329922-3582906400-648950646-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ
HKU\S-1-5-21-2139329922-3582906400-648950646-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2139329922-3582906400-648950646-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2139329922-3582906400-648950646-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&ts=1423739948&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2139329922-3582906400-648950646-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&ts=1423739948&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2139329922-3582906400-648950646-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2139329922-3582906400-648950646-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ&ts=1423739948&type=default&q={searchTerms}
BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro64.dll [2015-02-27] (Goobzo Ltd.)
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\XTab\SupTab.dll [2015-01-16] (Thinknice Co. Limited)
BHO-x32: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll [2015-02-27] (Goobzo Ltd.)
BHO-x32: PriceFountain -> {b608cc98-54de-4775-96c9-097de398500c} -> C:\Users\Samsung\AppData\Local\PriceFountain\PriceFountainIE.dll [2015-01-11] ()
BHO-x32: No Name -> {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} -> No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.mystartsearch.com/?type=sc&ts=1423739800&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-02-12] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-02-12] (globalUpdate)
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\q994nzu3.default\extensions\fftoolbar2014@etech.com
CHR HomePage: Default -> hxxp://www.mystartsearch.com/?type=hppp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ
CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hppp&ts=1423739854&from=smt&uid=ST160LT015-1AE141_W1901JXJXXXXW1901JXJ"
CHR DefaultSearchKeyword: Default -> mystartsearch
C:\Program Files (x86)\23af37cf-7ebb-43b3-abee-ab37a958f983
C:\Program Files (x86)\35337f0e-62ee-49a9-9540-47759e3302f2
C:\Program Files (x86)\globalUpdate
C:\Program Files (x86)\iWebar
C:\Program Files (x86)\SensePlus
C:\Program Files (x86)\ShopperPro
C:\Program Files (x86)\XTab
C:\Program Files (x86)\YTAHelper
C:\Program Files (x86)\YouTube Accelerator
C:\Program Files\Common Files\ShopperPro
C:\ProgramData\Avg_Update_0215tb
C:\ProgramData\ShopperPro
C:\ProgramData\TEMP
C:\ProgramData\YTAHelper
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts Inc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
C:\Users\Samsung\AppData\Local\Google\Chrome\User Data\Default\Preferences
C:\Users\Samsung\AppData\Local\PriceFountain
C:\Users\Samsung\AppData\Roaming\LGXGTRI
C:\Users\Samsung\AppData\Roaming\ZJDZSSU
C:\Users\Samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceFountain
Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro /f
Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator" /f
CMD: netsh winsock reset
EmptyTemp:

 

Adnotacja dla innych czytających: skrypt unikatowy - dopasowany tylko i wyłącznie pod ten system, proszę nie stosować na swoich systemach.

 

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Czekaj cierpliwie, nie przerywaj działania. Gdy Fix ukończy pracę, system zostanie zresetowany. W tym samym katalogu skąd uruchamiano FRST powstanie plik fixlog.txt.

 

2. W Google Chrome:

  • Ustawienia > karta Ustawienia > Pokaż ustawienia zaawansowane > zjedź na sam spód i uruchom opcję Zresetuj ustawienia przeglądarki. Zakładki i hasła nie zostaną naruszone.
  • Ustawienia > karta Ustawienia > sekcja Wyszukiwanie > klik w Zarządzanie wyszukiwarkami > skasuj z listy mystartsearch oraz inne niedomyślne śmieci (o ile będą).
  • Zresetuj cache wtyczek. W pasku adresów wpisz chrome://plugins i ENTER. Na liście wtyczek wybierz dowolną i kliknij Wyłącz. Następnie wtyczkę ponownie Włącz.
3. W Operze: na liście Rozszerzeń odmontuj adware iWebar, SensePlus.

 

4. Napraw uszkodzony specjalny skrót IE. W pasku eksploratora wklej poniższą ścieżkę i ENTER:

 

C:\Users\Samsung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools

 

Prawoklik na zlokalizowany tam skrót Internet explorer (bez dodatków) > Właściwości > w polu Element docelowy po ścieżce "C:\Program Files\Internet Explorer\iexplore.exe" dopisz dwie spacje i -extoff

 

5. Zrób nowy log FRST z opcji Scan, zaznacz ponownie pole Addition. Dołącz też plik fixlog.txt.

Odnośnik do komentarza

1. Uruchom AdwCleaner ponownie i wybierz po kolei opcje Szukaj + Usuń. Gdy program ukończy czyszczenie:

 

2. Otwórz Notatnik i wklej w nim:

 

RemoveDirectory: C:\AdwCleaner
RemoveDirectory: C:\FRST\Quarantine
RemoveDirectory: C:\ProgramData\AVG2014
RemoveDirectory: C:\ProgramData\MFAData
RemoveDirectory: C:\Users\Samsung\Desktop\Stare dane programu Firefox
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f

 

Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Zaprezentuj wynikoy fixlog.txt.

Odnośnik do komentarza

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...