Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Yoursite 123 jak to usunac? -

TipToe 12 Gru 2015 07:39 1104 1
  • CControls
  • Pomocny post
    #2 12 Gru 2015 09:22
    Acorus 20
    Spec od komputerów

    Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {12CE24B1-8DD8-4023-8756-A59E2661B4E8} - System32\Tasks\{9B0A00DE-4666-43BB-8B74-546DB0CE83D2} => pcalua.exe -a C:\Users\Krzychu\AppData\Roaming\istartpageing\UninstallManager.exe -c -ptid=cornl
    Task: {272E8101-66C4-4307-B6EC-B9E80741A93E} - System32\Tasks\Price Fountain => C:\Users\Krzychu\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
    Task: {52518E3E-9459-4AE0-8FFA-2A5BE44038E3} - System32\Tasks\{B63158DC-3478-4B22-81A9-D756F02A7E1C} => pcalua.exe -a C:\Users\Krzychu\AppData\Roaming\yoursearching\UninstallManager.exe -c -ptid=cornl
    Task: C:\Windows\Tasks\Price Fountain.job => C:\Users\Krzychu\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
    ShortcutWithArgument: C:\Users\Krzychu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...t07021&uid=SAMSUNGXHD250HJ_S0URJ90Q214378 <==== UWAGA
    ShortcutWithArgument: C:\Users\Krzychu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...t07021&uid=SAMSUNGXHD250HJ_S0URJ90Q214378 <==== UWAGA
    ShortcutWithArgument: C:\Users\Krzychu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...t07021&uid=SAMSUNGXHD250HJ_S0URJ90Q214378 <==== UWAGA
    HKU\S-1-5-21-1235493860-3996717231-3485183817-1000\...\Run: [ASRockXTU] => [X]
    HKU\S-1-5-21-1235493860-3996717231-3485183817-1000\...\Run: [zASRockInstantBoot] => [X]
    HKU\S-1-5-21-1235493860-3996717231-3485183817-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...t07021&uid=SAMSUNGXHD250HJ_S0URJ90Q214378




    HKU\S-1-5-21-1235493860-3996717231-3485183817-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...t07021&uid=SAMSUNGXHD250HJ_S0URJ90Q214378
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-1235493860-3996717231-3485183817-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...amp;uid=SAMSUNGXHD250HJ_S0URJ90Q214378&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1235493860-3996717231-3485183817-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...amp;uid=SAMSUNGXHD250HJ_S0URJ90Q214378&q={searchTerms}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.yoursearching.com/?type=sc&ts=...=cornl&uid=SAMSUNGXHD250HJ_S0URJ90Q214378
    R2 IhPul; C:\Users\Krzychu\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
    S2 amdacpusrsvc; "C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe" [X]
    2015-12-09 07:49 - 2015-12-09 07:49 - 00000000 ____D C:\Users\Krzychu\AppData\Roaming\TSv
    2015-12-09 07:49 - 2015-12-09 07:49 - 00000000 ____D C:\ProgramData\WWdMW
    2015-12-08 19:54 - 2015-12-08 19:54 - 00002996 _____ C:\Windows\System32\Tasks\{5C1F926B-0B97-468C-98AA-641055267993}
    2015-12-07 15:54 - 2015-12-07 15:54 - 00000000 ____D C:\Users\Krzychu\AppData\Roaming\OpenCandy
    2015-12-07 15:53 - 2015-12-07 15:53 - 00003152 _____ C:\Windows\System32\Tasks\{9B0A00DE-4666-43BB-8B74-546DB0CE83D2}
    2015-12-07 15:52 - 2015-12-09 07:49 - 00000000 ____D C:\ProgramData\Tmp0x0x
    2015-12-07 15:52 - 2015-12-07 15:53 - 00000000 ____D C:\Users\Krzychu\AppData\Roaming\istartpageing
    2015-12-06 10:31 - 2015-12-06 10:31 - 00002996 _____ C:\Windows\System32\Tasks\{29723DA1-155C-4A40-80CB-1C0C27BAAD00}
    2015-12-06 10:30 - 2015-12-06 10:30 - 00002996 _____ C:\Windows\System32\Tasks\{5214D6BB-F14A-473F-A602-CB7B0887BDD6}
    2015-11-26 23:43 - 2015-11-26 23:43 - 00003152 _____ C:\Windows\System32\Tasks\{B63158DC-3478-4B22-81A9-D756F02A7E1C}
    2015-11-26 17:36 - 2015-12-09 07:49 - 00000000 ____D C:\ProgramData\WWMiniProW
    2015-11-26 17:36 - 2015-11-26 23:43 - 00000000 ____D C:\Users\Krzychu\AppData\Roaming\yoursearching
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan i później Cleaning.

    0