Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

jak usunąć yoursites123

pales1987 10 Gru 2015 10:17 1197 2
  • CControls
  • #2 10 Gru 2015 10:36
    Acorus 20
    Spec od komputerów

    Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {10E149B6-8BD7-4ADF-96A6-8DAC050439A7} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {4876DBC8-7732-4585-A9AF-CC9F733ABCFF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {63025B52-D1F9-41CA-B27C-BDF5DF9FF058} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {6638134E-AF47-4E2F-9C40-085898A3876F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {683004BF-1A14-451F-A650-AA905CC43BE6} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {761E1E56-2242-4A6D-A6B1-77B62704C4FA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {85ABDC70-7C23-42F4-AD28-819DCD968D74} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {98B35E8F-A94D-4236-93C3-2C567D04864B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {A0F80650-58D0-4A6F-96AA-C3672DC39BF6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {D56473A4-BAF1-47BA-AF5D-0A82F986B39A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {DD16999D-15B7-476D-830C-E25A2EA5BF68} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0\WSE on the Web.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION




    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    HKLM-x32\...\Run: [] => [X]
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-3523528934-3853582799-1656031237-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-3523528934-3853582799-1656031237-1001 -> {9F77576B-AEB0-44FB-ADB5-B9310ACCA03C} URL =
    R2 WdMan; C:\ProgramData\8WdM8\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [File not signed]
    2015-12-10 09:10 - 2015-12-10 09:19 - 00000000 ____D C:\AdwCleaner
    2015-12-09 12:07 - 2015-12-09 12:09 - 00000000 ____D C:\ProgramData\8WdM8
    2015-12-09 12:06 - 2015-12-09 12:07 - 00000000 ____D C:\ProgramData\FWdMF
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    0
  • CControls
  • #3 10 Gru 2015 10:38
    Kolobos
    Spec od komputerów

    Obok frst.exe utworz plik fixlist.txt z zawartoscia:
    Task: {10E149B6-8BD7-4ADF-96A6-8DAC050439A7} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {4876DBC8-7732-4585-A9AF-CC9F733ABCFF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {63025B52-D1F9-41CA-B27C-BDF5DF9FF058} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {6638134E-AF47-4E2F-9C40-085898A3876F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {683004BF-1A14-451F-A650-AA905CC43BE6} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {761E1E56-2242-4A6D-A6B1-77B62704C4FA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {85ABDC70-7C23-42F4-AD28-819DCD968D74} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {98B35E8F-A94D-4236-93C3-2C567D04864B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {A0F80650-58D0-4A6F-96AA-C3672DC39BF6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {D56473A4-BAF1-47BA-AF5D-0A82F986B39A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {DD16999D-15B7-476D-830C-E25A2EA5BF68} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0\WSE on the Web.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    AlternateDataStreams: C:\Program Files\ATI Technologies:Win32App_1
    AlternateDataStreams: C:\Program Files\Microsoft SQL Server:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\ATI Technologies:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Business Objects:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\HP:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Microsoft Office:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Microsoft Visual Studio 8:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Mozilla Firefox:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\MSBuild:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\SQLXML 3.0:Win32App_1
    AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App_1
    (TFuns LIMITED) C:\ProgramData\8WdM8\WdMan.exe
    HKLM-x32\...\Run: [] => [X]
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.pl
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.pl
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://mystart.toshiba.com
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.toshiba.com
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    R2 WdMan; C:\ProgramData\8WdM8\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [File not signed]
    2015-12-10 09:10 - 2015-12-10 09:19 - 00000000 ____D C:\AdwCleaner
    2015-12-09 12:07 - 2015-12-09 12:09 - 00000000 ____D C:\ProgramData\8WdM8
    2015-12-09 12:07 - 2015-12-09 12:08 - 00000001 _____ C:\WINDOWS\SysWOW64\pl.html
    2015-12-09 12:06 - 2015-12-09 12:07 - 00000000 ____D C:\ProgramData\FWdMF
    2015-12-09 12:06 - 2015-12-09 12:06 - 00000386 _____ C:\WINDOWS\SysWOW64\data.bin
    EmptyTemp:

    W FRST wybierz Napraw.

    Usun katalog C:\FRST i to wszystko.

    0