logo elektroda
logo elektroda
X
logo elektroda
REKLAMA
REKLAMA
Adblock/uBlockOrigin/AdGuard mogą powodować znikanie niektórych postów z powodu nowej reguły.

Jak usunąć przekierowanie na yoursites123 przy włączaniu przeglądarki?

pales1987 10 Gru 2015 10:17 1488 2
REKLAMA
  • #1 15227119
    pales1987
    Poziom 1  
    Posty: 1
    Przy włączaniu strony przekierowuje mnie na "yoursites123", jak to usunąć?
    Proszę bardzo o pomoc.
    Załączniki:
    • Addition.txt (34.77 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • FRST.txt (76.55 KB) Musisz być zalogowany, aby pobrać ten załącznik.
  • REKLAMA
  • #2 15227148
    Acorus 20
    Poziom 43  
    Posty: 10541
    Pomógł: 3247
    Ocena: 1063
    Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {10E149B6-8BD7-4ADF-96A6-8DAC050439A7} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {4876DBC8-7732-4585-A9AF-CC9F733ABCFF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {63025B52-D1F9-41CA-B27C-BDF5DF9FF058} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {6638134E-AF47-4E2F-9C40-085898A3876F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {683004BF-1A14-451F-A650-AA905CC43BE6} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {761E1E56-2242-4A6D-A6B1-77B62704C4FA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {85ABDC70-7C23-42F4-AD28-819DCD968D74} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {98B35E8F-A94D-4236-93C3-2C567D04864B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {A0F80650-58D0-4A6F-96AA-C3672DC39BF6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {D56473A4-BAF1-47BA-AF5D-0A82F986B39A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {DD16999D-15B7-476D-830C-E25A2EA5BF68} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0\WSE on the Web.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    HKLM-x32\...\Run: [] => [X]
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-3523528934-3853582799-1656031237-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-3523528934-3853582799-1656031237-1001 -> {9F77576B-AEB0-44FB-ADB5-B9310ACCA03C} URL =
    R2 WdMan; C:\ProgramData\8WdM8\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [File not signed]
    2015-12-10 09:10 - 2015-12-10 09:19 - 00000000 ____D C:\AdwCleaner
    2015-12-09 12:07 - 2015-12-09 12:09 - 00000000 ____D C:\ProgramData\8WdM8
    2015-12-09 12:06 - 2015-12-09 12:07 - 00000000 ____D C:\ProgramData\FWdMF
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
  • #3 15227154
    Kolobos
    Spec od komputerów
    Posty: 85152
    Pomógł: 17160
    Ocena: 10422
    Obok frst.exe utworz plik fixlist.txt z zawartoscia:
    Task: {10E149B6-8BD7-4ADF-96A6-8DAC050439A7} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {4876DBC8-7732-4585-A9AF-CC9F733ABCFF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {63025B52-D1F9-41CA-B27C-BDF5DF9FF058} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {6638134E-AF47-4E2F-9C40-085898A3876F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {683004BF-1A14-451F-A650-AA905CC43BE6} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {761E1E56-2242-4A6D-A6B1-77B62704C4FA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {85ABDC70-7C23-42F4-AD28-819DCD968D74} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {98B35E8F-A94D-4236-93C3-2C567D04864B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {A0F80650-58D0-4A6F-96AA-C3672DC39BF6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {D56473A4-BAF1-47BA-AF5D-0A82F986B39A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {DD16999D-15B7-476D-830C-E25A2EA5BF68} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0\WSE on the Web.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\PAWEŁ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX <==== ATTENTION
    AlternateDataStreams: C:\Program Files\ATI Technologies:Win32App_1
    AlternateDataStreams: C:\Program Files\Microsoft SQL Server:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\ATI Technologies:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Business Objects:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\HP:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Microsoft Office:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Microsoft Visual Studio 8:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\Mozilla Firefox:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\MSBuild:Win32App_1
    AlternateDataStreams: C:\Program Files (x86)\SQLXML 3.0:Win32App_1
    AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App_1
    (TFuns LIMITED) C:\ProgramData\8WdM8\WdMan.exe
    HKLM-x32\...\Run: [] => [X]
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.pl
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.pl
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://mystart.toshiba.com
    HKU\S-1-5-21-3523528934-3853582799-1656031237-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.toshiba.com
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659206&z=7365ddfb468016a00e1e579gfz2z0t7q7w2t9o9e2w&from=ient07021&uid=HGSTXHTS541075A9E680_140523JD130A1B0J6XVKX&q={searchTerms}
    R2 WdMan; C:\ProgramData\8WdM8\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [File not signed]
    2015-12-10 09:10 - 2015-12-10 09:19 - 00000000 ____D C:\AdwCleaner
    2015-12-09 12:07 - 2015-12-09 12:09 - 00000000 ____D C:\ProgramData\8WdM8
    2015-12-09 12:07 - 2015-12-09 12:08 - 00000001 _____ C:\WINDOWS\SysWOW64\pl.html
    2015-12-09 12:06 - 2015-12-09 12:07 - 00000000 ____D C:\ProgramData\FWdMF
    2015-12-09 12:06 - 2015-12-09 12:06 - 00000386 _____ C:\WINDOWS\SysWOW64\data.bin
    EmptyTemp:

    W FRST wybierz Napraw.

    Usun katalog C:\FRST i to wszystko.
REKLAMA