logo elektroda
logo elektroda
X
logo elektroda
REKLAMA
REKLAMA
Adblock/uBlockOrigin/AdGuard mogą powodować znikanie niektórych postów z powodu nowej reguły.

Jak usunąć Yoursites123 z mojego komputera?

George44 11 Gru 2015 11:30 792 4
REKLAMA
  • #1 15230266
    George44
    Poziom 10  
    Posty: 5
    I ja złapałem to dziadostwo i bardzo proszę o pomoc.
    Załączniki:
    • FRST.txt (48.04 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • Addition.txt (34.86 KB) Musisz być zalogowany, aby pobrać ten załącznik.
  • REKLAMA
  • #2 15230289
    Kolobos
    Spec od komputerów
    Posty: 85152
    Pomógł: 17160
    Ocena: 10422
    Fixlist.txt dla FRST:
    CustomCLSID: HKU\S-1-5-21-1122998355-271559669-1889142247-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\uzytkownik\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Brak pliku
    CustomCLSID: HKU\S-1-5-21-1122998355-271559669-1889142247-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\uzytkownik\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Brak pliku
    CustomCLSID: HKU\S-1-5-21-1122998355-271559669-1889142247-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\uzytkownik\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Brak pliku
    CustomCLSID: HKU\S-1-5-21-1122998355-271559669-1889142247-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\uzytkownik\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Brak pliku
    CustomCLSID: HKU\S-1-5-21-1122998355-271559669-1889142247-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\uzytkownik\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-1122998355-271559669-1889142247-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\uzytkownik\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Brak pliku
    CustomCLSID: HKU\S-1-5-21-1122998355-271559669-1889142247-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\uzytkownik\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => Brak pliku
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    (TFuns LIMITED) C:\ProgramData\4WdM4\WdMan.exe
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    ProxyServer: [S-1-5-21-1122998355-271559669-1889142247-1001] => http=127.0.0.1:13910;https=127.0.0.1:13910
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    HKU\S-1-5-21-1122998355-271559669-1889142247-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wp.pl/
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1122998355-271559669-1889142247-1001 -> {BBD2A17E-7D35-4B8C-8ED4-6B98FC608E7E} URL =
    BHO-x32: Brak nazwy -> {C34EB3A4-510D-37C1-5DA5-06FF30D5DCB1} -> Brak pliku
    FF HKU\S-1-5-21-1122998355-271559669-1889142247-1001\...\Firefox\Extensions: [{A76D49C8-C5FA-0A3F-D2BE-619DD822712B}] - C:\Program Files (x86)\BlockAndSurf-soft\171.xpi => nie znaleziono
    R2 WdMan; C:\ProgramData\4WdM4\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    S1 {6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64; system32\drivers\{6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64.sys [X]
    2015-12-09 08:43 - 2015-12-09 08:45 - 00000000 ____D C:\ProgramData\4WdM4
    2015-12-09 08:43 - 2015-12-09 08:43 - 00000000 ____D C:\ProgramData\MWdMM
    2015-12-11 09:30 - 2014-06-05 09:52 - 00000000 ____D C:\AdwCleaner
    2014-06-05 11:08 - 2014-06-05 11:08 - 0830792 _____ (Click Me In Limited) C:\Users\uzytkownik\AppData\Local\nsr4EB4.tmp
    2014-06-05 11:15 - 2014-06-05 11:15 - 0301608 _____ (VuuPC Limited) C:\Users\uzytkownik\AppData\Local\nst48A.tmp
    EmptyTemp:

    W FRST wybierz Napraw.

    Usun katalog C:\FRST i to wszystko.
  • REKLAMA
  • #3 15230300
    Acorus 20
    Poziom 43  
    Posty: 10541
    Pomógł: 3247
    Ocena: 1063
    Otwórz notatnik systemowy i wklej:

    Cytat:
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\Users\uzytkownik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635 <==== UWAGA
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    Winlogon\Notify\igfxcui: igfxdev.dll [X]
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    ProxyServer: [S-1-5-21-1122998355-271559669-1889142247-1001] => http=127.0.0.1:13910;https=127.0.0.1:13910
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449647018&z=374a7753220aeb11a2153b3g8zdz7t6qaz8mbedg7w&from=ient07021&uid=WDCXWD5000AAKX-22ERMA0_WD-WCC2EJD5063550635&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1122998355-271559669-1889142247-1001 -> {BBD2A17E-7D35-4B8C-8ED4-6B98FC608E7E} URL =
    BHO-x32: Brak nazwy -> {C34EB3A4-510D-37C1-5DA5-06FF30D5DCB1} -> Brak pliku
    R2 WdMan; C:\ProgramData\4WdM4\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    S1 {6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64; system32\drivers\{6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64.sys [X]
    2015-12-11 08:31 - 2015-12-11 08:44 - 00000000 ____D C:\Users\uzytkownik\Doctor Web
    2015-12-09 08:43 - 2015-12-09 08:45 - 00000000 ____D C:\ProgramData\4WdM4
    2015-12-09 08:43 - 2015-12-09 08:43 - 00000000 ____D C:\ProgramData\MWdMM
    2015-12-11 09:30 - 2014-06-05 09:52 - 00000000 ____D C:\AdwCleaner
    2014-06-05 11:08 - 2014-06-05 11:08 - 0830792 _____ (Click Me In Limited) C:\Users\uzytkownik\AppData\Local\nsr4EB4.tmp
    2014-06-05 11:15 - 2014-06-05 11:15 - 0301608 _____ (VuuPC Limited) C:\Users\uzytkownik\AppData\Local\nst48A.tmp
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
  • REKLAMA
  • #4 15230329
    George44
    Poziom 10  
    Posty: 5
    Jesteś wielki! - pomogło! - baaardzo dziękuję.:-)
  • #5 15231335
    swiercm
    Moderator na urlopie...
    Posty: 18308
    Pomógł: 1216
    Ocena: 550
    Kolobos napisał:
    Usun katalog C:\FRST i to wszystko.

    Temat zamykam.
    Jak usunąć Yoursites123 z mojego komputera?
REKLAMA