Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Usuwanie SpyHunter i yoursite123

kubas2131 09 Gru 2015 21:24 1194 2
  • Pomocny post
    #2 09 Gru 2015 21:34
    Kolobos
    Spec od komputerów

    @kubas2131 Zainstaluj:
    http://ninite.com/java/
    oraz: https://support.microsoft.com/en-us/kb/2545227

    Odinstaluj:
    Java 6
    McAfee Security Scan Plus
    REACHit

    Fixlist.txt dla FRST:
    Task: {3411471C-F64E-4932-8C96-6E49FB5728F1} - System32\Tasks\Lenovo\REACHit Agent Update => C:\Program Files (x86)\Lenovo\REACHit\webAgent.exe [2015-11-11] (Lenovo)
    Task: {3CB374CE-0A1D-416F-B8E2-DF538462E6C9} - System32\Tasks\Lenovo\REACHit Agent Startup => C:\Program Files (x86)\Lenovo\REACHit\webAgent.exe [2015-11-11] (Lenovo)
    Task: {671F3853-2098-42FC-8C8D-B4D5EFB8ACE7} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-08] (Lenovo)
    ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6 <==== UWAGA
    ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6 <==== UWAGA
    ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6 <==== UWAGA
    ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6 <==== UWAGA




    ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6 <==== UWAGA
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKU\S-1-5-21-4094259356-3932169895-211043219-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...7021&uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6
    SearchScopes: HKU\S-1-5-21-4094259356-3932169895-211043219-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...p;uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6&q={searchTerms}
    BHO-x32: Brak nazwy -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> Brak pliku
    FF NewTab: chrome://quick_start/content/index.html
    FF DefaultSearchEngine: yoursites123
    FF SelectedSearchEngine: yoursites123
    FF Homepage: hxxp://www.yoursites123.com/?type=hp&ts=1...7021&uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6
    FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\e4bud3cx.default\searchplugins\yoursites123.xml [2015-12-09]
    FF Extension: Default NewTab - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\e4bud3cx.default\extensions\default_newtabff@gmail.com [2015-12-09] [Brak podpisu cyfrowego]
    FF Extension: YahooToolsProtected - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\e4bud3cx.default\extensions\yahooprotected@gmail.com [2015-12-09] [Brak podpisu cyfrowego]
    FF Extension: YahooToolsProtected - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\e4bud3cx.default\extensions\yahooprotected@gmail.com [2015-12-09] [Brak podpisu cyfrowego]
    FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\e4bud3cx.default\extensions\defsearchp@gmail.com => nie znaleziono
    CHR DefaultSearchURL: Default -> hxxp://www.yoursites123.com/web/?type=ds&...p;uid=ST9320423AS_5VH5BYQ6XXXX5VH5BYQ6&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> yoursites123
    OPR Extension: (Treasure Track) - C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Extensions\niboabacfgmdbjkomgmjknihaiamhmij [2015-10-28]
    2015-12-09 20:32 - 2015-12-09 20:32 - 00000000 ____D C:\Users\Admin\Desktop\FRST-OlderVersion
    2015-12-09 13:10 - 2015-12-09 13:11 - 00000000 ____D C:\ProgramData\1WdM1
    2015-12-09 13:10 - 2015-12-09 13:10 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TSv
    2015-12-09 13:08 - 2015-12-09 13:09 - 00000000 ____D C:\ProgramData\vWdMv
    2015-12-09 13:08 - 2015-10-28 18:05 - 00000000 ____D C:\ProgramData\rWMiniPror
    2015-11-23 11:43 - 2015-10-28 11:06 - 00001934 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
    EmptyTemp:

    W FRST wybierz Napraw.

    Usun katalog C:\FRST i to wszystko.

    0
  • #3 09 Gru 2015 21:53
    kubas2131
    Poziom 2  

    Super udało sie WIELKIE DZIĘKI !!!! :D

    0