Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Yoursites 123 - jak usunąć spywere

ziemek27 11 Gru 2015 20:05 855 3
  • CControls
  • #2 11 Gru 2015 20:19
    Acorus 20
    Spec od komputerów

    Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {8F5592A3-B4B4-4E11-B9D2-4FB2EA70C4EE} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-213544534-1241525733-4023974878-1001Core => C:\Users\ziemek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-20] (Facebook Inc.)
    Task: {DBDC3EC6-63AA-4250-9FDF-BBEE37B2CA9B} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-213544534-1241525733-4023974878-1001UA => C:\Users\ziemek\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-20] (Facebook Inc.)
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-213544534-1241525733-4023974878-1001Core.job => C:\Users\ziemek\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-213544534-1241525733-4023974878-1001UA.job => C:\Users\ziemek\AppData\Local\Facebook\Update\FacebookUpdate.exe
    ShortcutWithArgument: C:\Users\ziemek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY <==== UWAGA
    ShortcutWithArgument: C:\Users\ziemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY <==== UWAGA
    ShortcutWithArgument: C:\Users\ziemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY <==== UWAGA
    ShortcutWithArgument: C:\Users\ziemek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY <==== UWAGA




    HKLM-x32\...\Run: [RestartNeroSetup] => "C:\Users\ziemek\AppData\Local\Temp\Nero Web\SetupXu.exe" MODE="update" STARTMODE="2" USERSEL="3" FAMILYNAME="Nero 7" RUNSETUPXU="1" UPGRADE="1" <===== UWAGA
    HKU\S-1-5-21-213544534-1241525733-4023974878-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\ziemek\AppData\Local\Akamai\netsession_win.exe"
    HKU\S-1-5-21-213544534-1241525733-4023974878-1001\...\Run: [Facebook Update] => C:\Users\ziemek\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-01-20] (Facebook Inc.)
    AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL => Brak pliku
    AppInit_DLLs-x32: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll => Brak pliku
    HKU\S-1-5-21-213544534-1241525733-4023974878-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&...p;uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY&q={searchTerms}
    HKU\S-1-5-21-213544534-1241525733-4023974878-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...7021&uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY
    HKU\S-1-5-21-213544534-1241525733-4023974878-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...7021&uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY
    HKU\S-1-5-21-213544534-1241525733-4023974878-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&...p;uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
    SearchScopes: HKU\S-1-5-21-213544534-1241525733-4023974878-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Brak pliku
    Toolbar: HKLM - Brak nazwy - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Brak pliku
    StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1...7021&uid=ST9500325AS_S2W7J8SYXXXXS2W7J8SY
    S3 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
    2015-12-11 16:59 - 2015-12-11 17:00 - 00000000 ____D C:\ProgramData\4WdM4
    2015-12-11 18:34 - 2015-10-08 15:22 - 00000000 ____D C:\AdwCleaner
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    0
  • CControls
  • #3 11 Gru 2015 20:45
    ziemek27
    Poziom 2  

    dzięki wielkie za pomoc :P

    0
  • #4 11 Gru 2015 20:55
    Acorus 20
    Spec od komputerów

    Skasuj folder C:\FRST.

    0