sfinxik Opublikowano 8 Stycznia 2016 Zgłoś Udostępnij Opublikowano 8 Stycznia 2016 WItam.Widze ze to jakas plaga z tym yoursite , probowalem juz kilku cleanerow oraz antywirusa ale nic nie dziala wiec prosze o jakas pomoc ! w zalacznikach logi.Pozdrawiam Addition.txt FRST.txt Odnośnik do komentarza
jessica Opublikowano 8 Stycznia 2016 Zgłoś Udostępnij Opublikowano 8 Stycznia 2016 Otwórz Notatnik i wklej w nim: DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123SoftwareShortcutWithArgument: C:\Users\sfinx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\sfinx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\sfinx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\sfinx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\sfinx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\sfinx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\sfinx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449646935&z=73ecd8ea6624ca1d5abd9c2gdzbz2t9qez2q3t9c2b&from=ient07021&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGAHKU\S-1-5-21-2510066527-1310542247-2234334929-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGAHKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61&q={searchTerms}HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61&q={searchTerms}HKU\S-1-5-21-2510066527-1310542247-2234334929-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61HKU\S-1-5-21-2510066527-1310542247-2234334929-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61&q={searchTerms}SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =SearchScopes: HKU\S-1-5-21-2510066527-1310542247-2234334929-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =CHR HomePage: Default -> hxxp://www.yoursites123.com/?type=hp&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61"StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.yoursites123.com/?type=sc&ts=1452246092&z=503abcb1b25ef8b9b4f9599g2z9w5ofo7z6qagacbm&from=wpm01073&uid=CrucialXCT128M550SSD1_14110C0B3A610C0B3A61R4 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X]DeleteKey: HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopesDeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopesDeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopesTask: {DA365A92-C0BD-4915-881F-88A9501ED7CD} - System32\Tasks\{8314BDBF-B782-4009-8284-4CA70F09AE51} => pcalua.exe -a "C:\Program Files (x86)\ESET\uninstall.exe"HKLM-x32\...\Run: [] => [X]2016-01-08 10:42 - 2016-01-08 16:07 - 00000000 ____D C:\Users\sfinx\AppData\Roaming\TSv2016-01-08 10:42 - 2016-01-08 16:07 - 00000000 ____D C:\Program Files (x86)\SFK2016-01-08 10:42 - 2016-01-08 10:48 - 00000000 ____D C:\Program Files (x86)\WinZipper2016-01-08 10:41 - 2016-01-08 16:07 - 00000000 ____D C:\ProgramData\nWdMn2016-01-08 10:41 - 2016-01-08 10:41 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat2015-12-09 08:44 - 2016-01-08 16:07 - 00000000 ____D C:\ProgramData\4WdM42015-12-09 08:42 - 2016-01-08 16:07 - 00000000 ____D C:\ProgramData\DWdMDEmptyTemp: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST.exeUruchom FRST i kliknij przycisk Fix (NAPRAW).----------------------Jeśli będzie OK, to będziemy kończyć:Otwórz Notatnik i wklej w nim: DeleteQuarantine: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).przez SHIFT+DEL usuń pozostały folder C:\FRST.W Adw-Cleaner kliknij na przycisk Odinstaluj (UNINSTALL).Jeśli natomiast problem nie zniknie, to przeinstalujesz przeglądarkę, na której to jeszcze będzie..jessi Odnośnik do komentarza
Rekomendowane odpowiedzi
Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto
Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.
Zarejestruj nowe konto
Załóż nowe konto. To bardzo proste!
Zarejestruj sięZaloguj się
Posiadasz już konto? Zaloguj się poniżej.
Zaloguj się