Elektroda.pl
Elektroda.pl
X
CControls
Prosz, dodaj wyj徠ek www.elektroda.pl do Adblock.
Dzi瘯i temu, 瞠 ogl康asz reklamy, wspierasz portal i u篡tkownik闚.

Jak usun望 Yoursites 123?

martynka008 11 Gru 2015 13:45 2709 2
  • CControls
  • #2 11 Gru 2015 14:21
    Domino_2
    Pomocny dla u篡tkownik闚

    Zdecyduj si na jednego antywirusa i tego zostaw, drugiego odinstaluj.

    Odinstaluj Click Caption 1.10.0.2, ConvertAd, Optimizer Pro v3.2, Remote Desktop Access, sweet-page uninstall i WindowsMangerProtect20.0.0.1277.

    Cytat:

    ShortcutWithArgument: C:\Users\Rybki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    ShortcutWithArgument: C:\Users\Rybki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    ShortcutWithArgument: C:\Users\Rybki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    ShortcutWithArgument: C:\Users\Rybki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    ShortcutWithArgument: C:\Users\Rybki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA




    ShortcutWithArgument: C:\Users\Rybki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX <==== UWAGA
    (TODO: <公司名>) C:\Program Files (x86)\SFK\SSFK.exe
    (TFuns LIMITED) C:\ProgramData\vWdMv\WdMan.exe
    (TODO: <公司名>) C:\Program Files (x86)\SFK\SSFK.exe
    HKLM-x32\...\Run: [gmsd_pl_2] => [X]
    ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Brak pliku
    ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Brak pliku
    ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Brak pliku
    ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Brak pliku
    ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Brak pliku
    ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Brak pliku
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    HKU\S-1-5-21-58270921-3454604265-467642762-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    HKU\S-1-5-21-58270921-3454604265-467642762-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    HKU\S-1-5-21-58270921-3454604265-467642762-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    HKU\S-1-5-21-58270921-3454604265-467642762-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-58270921-3454604265-467642762-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-58270921-3454604265-467642762-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    BHO-x32: Sale Charger -> {7a38e53c-e000-41e4-9b5a-47447db81c2b} -> C:\Program Files (x86)\Sale Charger\Extensions\7a38e53c-e000-41e4-9b5a-47447db81c2b.dll => Brak pliku
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=144...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    FF DefaultSearchEngine: yoursites123
    FF SearchEngineOrder.3: Bing
    FF SelectedSearchEngine: yoursites123
    FF Homepage: hxxp://searchinterneat-a.akamaihd.net/h?eq=U0...aBAwXFwcFIk0FA18DB0VXfWFoKB8fHGZCLFx7CVgDRlBR
    FF Keyword.URL: hxxp://search.tb.ask.com/search/GGmain.jhtml?...EDD&n=780cebc2&ind=2014112706&p2=^BA5^xdm007^YYA^pl&si=CPbEjfehm8ICFQrLtAod5nwAQQ&searchfor=
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml [2014-11-27]
    FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\faststartff@gmail.com
    FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\deskCutv2@gmail.com => nie znaleziono
    FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\default_newtabff@gmail.com
    FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\yahooprotected@gmail.com
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1449667092&z=cd9d9991133c271ad8f4fc8g6z5z3t6qfq9mae7tdg&from=ient07021&uid=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX"
    CHR DefaultSearchURL: Default -> hxxp://www.yoursites123.com/web/?type=ds&...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> yoursites123
    CHR Extension: (Sale Charger) - C:\Users\Rybki\AppData\Local\Google\Chrome\User Data\Default\Extensions\npgfkibkmennbfadphcpjejdpfaeaenh [2015-05-21] [UpdateUrl: hxxp://cdn.salecharger.net/update] <==== UWAGA
    CHR HKU\S-1-5-21-58270921-3454604265-467642762-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
    OPR Extension: (Sale Charger) - C:\Users\Rybki\AppData\Roaming\Opera Software\Opera Stable\Extensions\npgfkibkmennbfadphcpjejdpfaeaenh [2015-05-21]
    R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: <公司名>)
    R2 WdMan; C:\ProgramData\vWdMv\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    2015-12-09 14:20 - 2015-12-11 12:09 - 00000000 ____D C:\Program Files (x86)\SFK
    2015-12-09 14:19 - 2015-12-09 14:19 - 00000000 ____D C:\Users\Rybki\AppData\Roaming\TSv
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    EmptyTemp:


    Wklej to do notatnika i zapisz pod nazw fixlist.txt i umie嗆 w folderze gdzie znajduje si plik FRST.exe/FRST64.exe, odpal go i kliknij Fix/Napraw.

    Przeskanuj komputer programem ADWCleaner i usu wszystko co znalaz.

    0
  • CControls
  • #3 11 Gru 2015 14:58
    Kolobos
    Spec od komputer闚

    @Domino_2 a co z tym wszystkim:
    (tsvr.com) C:\Users\Rybki\AppData\Roaming\TSv\TSvr.exe
    (© 2015 Microsoft Corporation) C:\Users\Rybki\AppData\Local\Microsoft\BingSvc\BingSvc.exe
    HKU\S-1-5-21-58270921-3454604265-467642762-1001\...\Run: [BingSvc] => C:\Users\Rybki\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-14] (© 2015 Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Brak pliku
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-11-22]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.226\SSScheduler.exe (McAfee, Inc.)
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    Hosts: 0.0.0.1 mssplus.mcafee.com
    BHO: ClickCaption -> {A18EA34C-6D33-4298-8A54-7F16499904C0} -> C:\Program Files\ClickCaption_1.10.0.2\IE\ClickCaptionClientIE.dll [2014-10-30] (ClickCaption)
    BHO-x32: Sale Charger -> {7a38e53c-e000-41e4-9b5a-47447db81c2b} -> C:\Program Files (x86)\Sale Charger\Extensions\7a38e53c-e000-41e4-9b5a-47447db81c2b.dll => Brak pliku
    BHO-x32: ClickCaption -> {A18EA34C-6D33-4298-8A54-7F16499904C0} -> C:\Program Files (x86)\ClickCaption_1.10.0.2\IE\ClickCaptionClientIE.dll [2014-10-30] (ClickCaption)
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=144...id=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX
    FF NewTab: chrome://quick_start/content/index.html
    FF DefaultSearchEngine: yoursites123
    FF Extension: Default NewTab - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\default_newtabff@gmail.com [2015-12-09] [Brak podpisu cyfrowego]
    FF Extension: YahooToolsProtected - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\yahooprotected@gmail.com [2015-12-09] [Brak podpisu cyfrowego]
    FF Extension: YahooToolsProtected - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\yahooprotected@gmail.com [2015-12-09] [Brak podpisu cyfrowego]
    FF Extension: Fast Start - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\Extensions\faststartff@gmail.com [2014-11-27] [Brak podpisu cyfrowego]
    FF Extension: Sale Charger - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\Extensions\{999dfb75-830f-4be2-adf1-8e98cb386aa5}.xpi [2015-05-21] [Brak podpisu cyfrowego]
    FF HKLM-x32\...\Firefox\Extensions: [{190bc294-c8e5-471c-9466-3eb945b09542}] - C:\Program Files (x86)\Mozilla Firefox\extensions\{190bc294-c8e5-471c-9466-3eb945b09542}
    FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\faststartff@gmail.com
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
    FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\deskCutv2@gmail.com => nie znaleziono
    FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\default_newtabff@gmail.com
    FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Rybki\AppData\Roaming\Mozilla\Firefox\Profiles\04wkpkaf.default-1417107447324\extensions\yahooprotected@gmail.com
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-07-14] [Brak podpisu cyfrowego]
    FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\!vitruvian-csp.js [2014-11-27]
    CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1449667092&z=cd9d9991133c271ad8f4fc8g6z5z3t6qfq9mae7tdg&from=ient07021&uid=HGSTXHTS545050A7E680_TMA55C3J11YA5M11YA5MX"
    CHR DefaultSearchURL: Default -> hxxp://www.yoursites123.com/web/?type=ds&...XHTS545050A7E680_TMA55C3J11YA5M11YA5MX&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> yoursites123
    CHR Extension: (Sale Charger) - C:\Users\Rybki\AppData\Local\Google\Chrome\User Data\Default\Extensions\npgfkibkmennbfadphcpjejdpfaeaenh [2015-05-21] [UpdateUrl: hxxp://cdn.salecharger.net/update] <==== UWAGA
    CHR HKLM\...\Chrome\Extension: [jdiejbegdjikmehflknhkbieocmnogcf] - C:\Users\Rybki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdiejbegdjikmehflknhkbieocmnogcf.crx [2015-11-07]
    CHR HKU\S-1-5-21-58270921-3454604265-467642762-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-12-05]
    CHR HKLM-x32\...\Chrome\Extension: [jdiejbegdjikmehflknhkbieocmnogcf] - C:\Users\Rybki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdiejbegdjikmehflknhkbieocmnogcf.crx [2015-11-07]
    OPR Extension: (Sale Charger) - C:\Users\Rybki\AppData\Roaming\Opera Software\Opera Stable\Extensions\npgfkibkmennbfadphcpjejdpfaeaenh [2015-05-21]
    S2 51cdb72; c:\Program Files (x86)\Optimizer Pro 3.11\OptProCrash.dll [3105792 2014-11-27] () [Brak podpisu cyfrowego]
    R2 IhPul; C:\Users\Rybki\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
    R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: <公司名>)
    R2 WdMan; C:\ProgramData\vWdMv\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    R1 ccnfd_1_10_0_2; C:\Windows\System32\drivers\ccnfd_1_10_0_2.sys [58232 2014-10-30] (ClickCaption)
    2015-12-09 14:20 - 2015-12-11 12:09 - 00000000 ____D C:\Program Files (x86)\SFK
    2015-12-09 14:19 - 2015-12-09 14:21 - 00000000 ____D C:\ProgramData\vWdMv
    2015-12-09 14:19 - 2015-12-09 14:19 - 00000000 ____D C:\Users\Rybki\AppData\Roaming\TSv
    2015-12-09 14:17 - 2015-12-09 14:18 - 00000000 ____D C:\ProgramData\rWdMr
    2015-11-22 12:50 - 2015-11-22 12:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
    2015-11-22 12:50 - 2015-11-22 12:50 - 00000000 ____D C:\Program Files\McAfee Security Scan
    2015-12-11 11:17 - 2014-09-20 10:17 - 00003886 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1411204629
    2015-12-09 14:17 - 2015-10-30 20:05 - 00000000 ____D C:\ProgramData\3WMiniPro3

    @martynka008 utworz nowy fixlist.txt z tym co podalem.

    Po wykonaniu wszystkiego zamiesc nowe logi z FRST, ze skanowania.

    1