Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Jak usunąć wirusa przekierowującego na stronę Yoursites123?

Sztaka 12 Gru 2015 10:01 747 5
  • CControls
  • #2 12 Gru 2015 10:19
    Acorus 20
    Spec od komputerów

    Odinstaluj Akamai NetSession Interface, ASUS WebStorage Sync Agent. Otwórz notatnik systemowy i wklej:

    Cytat:
    ShortcutWithArgument: C:\Users\Olga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.omniboxes.com/?type=sc&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\Users\Olga\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\Users\Olga\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.omniboxes.com/?type=sc&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\Users\Olga\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\Users\Olga\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.omniboxes.com/?type=sc&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.omniboxes.com/?type=sc&ts=1448...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.omniboxes.com/?type=sc&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.omniboxes.com/?type=sc&ts=1448...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.omniboxes.com/?type=sc&ts=1448...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.omniboxes.com/?type=sc&ts=1448...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.omniboxes.com/?type=sc&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX <==== UWAGA
    HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [3423104 2012-08-31] (ASUS Cloud Corporation)
    HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
    HKU\S-1-5-21-1377750558-1742932284-389706579-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Olga\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
    HKU\S-1-5-21-1377750558-1742932284-389706579-1002\...\CurrentVersion\Windows: [Load] C:\ProgramData\msbfmvie.exe <===== UWAGA
    HKU\S-1-5-21-1377750558-1742932284-389706579-1002\...\Policies\Explorer: []
    ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Brak pliku
    ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Brak pliku
    ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Brak pliku
    ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Brak pliku
    ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Brak pliku
    ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Brak pliku
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.omniboxes.com/?type=hp&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.omniboxes.com/?type=hp&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.omniboxes.com/?type=hp&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.omniboxes.com/?type=hp&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    HKU\S-1-5-21-1377750558-1742932284-389706579-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    HKU\S-1-5-21-1377750558-1742932284-389706579-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.omniboxes.com/?type=hp&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    HKU\S-1-5-21-1377750558-1742932284-389706579-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.omniboxes.com/?type=hp&ts=1447...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    HKU\S-1-5-21-1377750558-1742932284-389706579-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1377750558-1742932284-389706579-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-1377750558-1742932284-389706579-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=...XHTS545050A7E380_TE8513491D92WC1D92WCX&q={searchTerms}
    StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    FF NewTab: hxxp://www.yoursites123.com/newtab/?type=nt&a...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    FF DefaultSearchEngine: webssearches
    FF SelectedSearchEngine: webssearches
    FF Homepage: hxxp://www.yoursites123.com/?type=hp&ts=1...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    FF SearchPlugin: C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\searchplugins\webssearches.xml [2015-12-07]
    FF Extension: Default SearchProtected - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\extensions\defsearchp@gmail.com.xpi [2015-10-22] [Brak podpisu cyfrowego]
    FF Extension: Default NewTab - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\extensions\default_newtabff@gmail.com [2015-11-26] [Brak podpisu cyfrowego]
    FF Extension: YahooToolsProtected - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\extensions\yahooprotected@gmail.com [2015-11-26] [Brak podpisu cyfrowego]
    FF Extension: Brak nazwy - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\Extensions\defsearchp@gmail.com [2015-12-07] [Brak podpisu cyfrowego]
    FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\extensions\defsearchp@gmail.com
    FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\extensions\deskCutv2@gmail.com => nie znaleziono
    FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\extensions\default_newtabff@gmail.com
    FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Olga\AppData\Roaming\Mozilla\Firefox\Profiles\3k5mrfap.default\extensions\yahooprotected@gmail.com
    StartMenuInternet: FIREFOX.EXE - c:\program files (x86)\mozilla firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1449652297&z=fba6ef51cfc8a928e55e035g2z4z6t8q3w9o7c3e1e&from=ient07021&uid=HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX"
    StartMenuInternet: Google Chrome - c:\program files (x86)\google\chrome\application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    StartMenuInternet: (HKLM) OperaStable - c:\program files (x86)\opera\launcher.exe hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS545050A7E380_TE8513491D92WC1D92WCX
    R2 IhPul; C:\Users\Olga\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
    R2 VSSS; C:\Users\Olga\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [106589824 2015-06-26] (Microsoft Corporation) [Brak podpisu cyfrowego] <==== UWAGA
    R2 WdMan; C:\ProgramData\tWdMt\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    S1 iSafeKrnlMon; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [X]
    R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X]
    U0 msahci; Brak ImagePath
    2015-12-09 10:12 - 2015-12-09 10:13 - 00000000 ____D C:\ProgramData\tWdMt
    2015-12-09 10:11 - 2015-12-09 10:11 - 00000000 ____D C:\ProgramData\iWdMi
    2015-12-08 19:53 - 2015-12-08 19:53 - 01415680 _____ (wj32) C:\Program Files\CLCLLULL.exe
    2015-12-08 19:52 - 2015-12-08 19:52 - 01415680 _____ (wj32) C:\Program Files\XXOX6FOF.exe
    2015-12-08 19:52 - 2015-12-08 19:52 - 01415680 _____ (wj32) C:\Program Files\JS1AS1AA.exe
    2015-12-08 19:52 - 2015-12-08 19:52 - 01415680 _____ (wj32) C:\Program Files\J3N3F73F.exe
    2015-12-08 19:52 - 2015-12-08 19:52 - 01415680 _____ (wj32) C:\Program Files\GGGG7PPY.exe
    2015-12-08 19:52 - 2015-12-08 19:52 - 01415680 _____ (wj32) C:\Program Files\0R09R09I.exe
    2015-12-07 11:12 - 2015-12-07 11:12 - 00000000 ____D C:\Users\Olga\AppData\Roaming\eCyber
    2015-12-03 08:11 - 2015-12-03 08:11 - 01415680 _____ (wj32) C:\Program Files\3J7N3N7V.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\XXOXFO6O.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\X6FF6XFX.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\VDDV4MVM.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\OOXOXXX6.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\M4MVDDVV.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\M4MMDMVD.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\6FX66O6F.exe
    2015-12-01 15:02 - 2015-12-01 15:02 - 01415680 _____ (wj32) C:\Program Files\4VV4MD4V.exe
    2015-12-01 15:01 - 2015-12-01 15:01 - 01415680 _____ (wj32) C:\Program Files\YAM6KYEM.exe
    2015-12-01 15:01 - 2015-12-01 15:01 - 01415680 _____ (wj32) C:\Program Files\R990IRR0.exe
    2015-12-01 15:01 - 2015-12-01 15:01 - 01415680 _____ (wj32) C:\Program Files\0R0RRRR9.exe
    2015-12-01 15:01 - 2015-12-01 15:01 - 01415680 _____ (wj32) C:\Program Files\09II9II9.exe
    2015-12-01 14:59 - 2015-12-01 14:59 - 01415680 _____ (wj32) C:\Program Files\EWWNWWEN.exe
    2015-12-01 14:59 - 2015-12-01 14:59 - 01415680 _____ (wj32) C:\Program Files\E5WE5E5E.exe
    2015-12-01 10:33 - 2015-12-01 10:33 - 01415680 _____ (wj32) C:\Program Files\ZF3VNRRB.exe
    2015-11-30 11:23 - 2015-11-30 11:23 - 01415680 _____ (wj32) C:\Program Files\XP5PDTD1.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\YAMEKKAM.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\MEEK22MM.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\KSK0O44C.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\E2I2MUI2.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\COGGSCO4.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\6M2K6MEI.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\4SGKC4WS.exe
    2015-11-27 20:06 - 2015-11-27 20:06 - 01415680 _____ (wj32) C:\Program Files\2IUY22YM.exe
    2015-11-27 20:05 - 2015-11-27 20:05 - 01415680 _____ (wj32) C:\Program Files\SWG8SCOK.exe
    2015-11-27 20:05 - 2015-11-27 20:05 - 01415680 _____ (wj32) C:\Program Files\I6AEU6AA.exe
    2015-11-27 20:05 - 2015-11-27 20:05 - 01415680 _____ (wj32) C:\Program Files\GWO80SGS.exe
    2015-11-27 20:05 - 2015-11-27 20:05 - 01415680 _____ (wj32) C:\Program Files\EEU2KYAU.exe
    2015-11-27 20:05 - 2015-11-27 20:05 - 01415680 _____ (wj32) C:\Program Files\6IAIYIU6.exe
    2015-11-27 20:05 - 2015-11-27 20:05 - 01415680 _____ (wj32) C:\Program Files\62UKYM26.exe
    2015-11-27 20:05 - 2015-11-27 20:05 - 01415680 _____ (wj32) C:\Program Files\0OKWOG84.exe
    2015-11-27 20:03 - 2015-11-27 20:03 - 01415680 _____ (wj32) C:\Program Files\KH8Z8888.exe
    2015-11-27 20:02 - 2015-11-27 20:02 - 01415680 _____ (wj32) C:\Program Files\AAY6AEEE.exe
    2015-11-27 09:30 - 2015-11-27 09:30 - 01415680 _____ (wj32) C:\Program Files\EYAK6M6Y.exe
    2015-11-26 12:10 - 2015-11-26 12:10 - 01415680 _____ (wj32) C:\Program Files\SW8KG0SK.exe
    2015-11-26 10:45 - 2015-12-09 10:11 - 00000000 ____D C:\ProgramData\9WMiniPro9
    2015-11-26 10:34 - 2015-11-26 10:34 - 01415680 _____ (wj32) C:\Program Files\AM6A6YMI.exe
    2015-11-26 10:34 - 2015-11-26 10:34 - 01415680 _____ (wj32) C:\Program Files\2BKT2TB2.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\YEE6Y66U.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\VVJJB7Z3.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\TDP9T5TH.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\T2TTBKBT.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\G77PG7PG.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\BTKBK22T.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\BTKB2TBB.exe
    2015-11-25 22:04 - 2015-11-25 22:04 - 01415680 _____ (wj32) C:\Program Files\2T2BBTT2.exe
    2015-11-25 10:02 - 2015-11-25 10:02 - 01415680 _____ (wj32) C:\Program Files\9R099RII.exe
    2015-11-25 09:52 - 2015-11-25 09:52 - 01415680 _____ (wj32) C:\Program Files\T1P5LD1P.exe
    2015-11-24 15:07 - 2015-11-24 15:07 - 01415680 _____ (wj32) C:\Program Files\XHTD1L9X.exe
    2015-11-24 15:07 - 2015-11-24 15:07 - 01415680 _____ (wj32) C:\Program Files\C0G0S8SK.exe
    2015-11-24 13:02 - 2015-11-24 13:02 - 01415680 _____ (wj32) C:\Program Files\UUL3C3LU.exe
    2015-11-24 09:06 - 2015-11-24 09:06 - 01415680 _____ (wj32) C:\Program Files\L91TDX55.exe
    2015-11-24 08:54 - 2015-11-24 08:54 - 01415680 _____ (wj32) C:\Program Files\S008CCGO.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\X15PXDPP.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\WO00K44G.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\WGGK08OW.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\SK0KW4K4.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\K888GWC0.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\G8WK848C.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\EYK6K6IA.exe
    2015-11-23 20:04 - 2015-11-23 20:04 - 01415680 _____ (wj32) C:\Program Files\EAYKKYYI.exe
    2015-11-23 20:03 - 2015-11-23 20:03 - 01415680 _____ (wj32) C:\Program Files\G84G0SC4.exe
    2015-11-23 20:03 - 2015-11-23 20:03 - 01415680 _____ (wj32) C:\Program Files\B3RN3RFV.exe
    2015-11-23 20:03 - 2015-11-23 20:03 - 01415680 _____ (wj32) C:\Program Files\3LCUUCU3.exe
    2015-11-23 20:03 - 2015-11-23 20:03 - 01415680 _____ (wj32) C:\Program Files\2Y2MEMKK.exe
    2015-11-23 20:03 - 2015-11-23 20:03 - 01415680 _____ (wj32) C:\Program Files\2MI2UKEK.exe
    2015-11-23 20:02 - 2015-11-23 20:02 - 01415680 _____ (wj32) C:\Program Files\YY7PYGP7.exe
    2015-11-23 20:02 - 2015-11-23 20:02 - 01415680 _____ (wj32) C:\Program Files\5W5NNW55.exe
    2015-11-23 20:02 - 2015-11-23 20:02 - 01415680 _____ (wj32) C:\Program Files\1S1JJSSA.exe
    2015-11-23 20:01 - 2015-11-23 20:01 - 01415680 _____ (wj32) C:\Program Files\ZHHK8HKK.exe
    2015-11-23 20:01 - 2015-11-23 20:01 - 01415680 _____ (wj32) C:\Program Files\UCU3CU3C.exe
    2015-11-23 20:01 - 2015-11-23 20:01 - 01415680 _____ (wj32) C:\Program Files\O6F6OOFF.exe
    2015-11-23 20:01 - 2015-11-23 20:01 - 01415680 _____ (wj32) C:\Program Files\JASJAJ11.exe
    2015-11-23 20:01 - 2015-11-23 20:01 - 01415680 _____ (wj32) C:\Program Files\J1JSSA1J.exe
    2015-11-23 20:01 - 2015-11-23 20:01 - 01415680 _____ (wj32) C:\Program Files\9IRR999I.exe
    2015-11-23 20:00 - 2015-11-23 20:00 - 01415680 _____ (wj32) C:\Program Files\7PGP7GG7.exe
    2015-11-23 10:44 - 2015-11-23 10:44 - 01415680 _____ (wj32) C:\Program Files\LTXHDHDD.exe
    2015-11-23 10:44 - 2015-11-23 10:44 - 01415680 _____ (wj32) C:\Program Files\FFR3F3BJ.exe
    2015-11-23 10:44 - 2015-11-23 10:44 - 01415680 _____ (wj32) C:\Program Files\8KHHKHHZ.exe
    2015-11-23 10:44 - 2015-11-23 10:44 - 01415680 _____ (wj32) C:\Program Files\4DVDM4DV.exe
    2015-11-23 10:44 - 2015-11-23 10:44 - 01415680 _____ (wj32) C:\Program Files\3LU3ULC3.exe
    2015-11-23 10:44 - 2015-11-23 10:44 - 01415680 _____ (wj32) C:\Program Files\1TXL5HDP.exe
    2015-11-23 10:44 - 2015-11-23 10:44 - 01415680 _____ (wj32) C:\Program Files\11HPXD55.exe
    2015-11-23 10:43 - 2015-11-23 10:43 - 01415680 _____ (wj32) C:\Program Files\Y62KMM2M.exe
    2015-11-23 10:43 - 2015-11-23 10:43 - 01415680 _____ (wj32) C:\Program Files\RVFJ37R7.exe
    2015-11-23 10:43 - 2015-11-23 10:43 - 01415680 _____ (wj32) C:\Program Files\NN3Z7VZZ.exe
    2015-11-23 10:43 - 2015-11-23 10:43 - 01415680 _____ (wj32) C:\Program Files\KUEYA2IK.exe
    2015-11-23 10:43 - 2015-11-23 10:43 - 01415680 _____ (wj32) C:\Program Files\E26IEAE2.exe
    2015-11-23 10:43 - 2015-11-23 10:43 - 01415680 _____ (wj32) C:\Program Files\33FVN7FV.exe
    2015-11-23 10:43 - 2015-11-23 10:43 - 01415680 _____ (wj32) C:\Program Files\0IR9IIR0.exe
    2015-11-23 10:40 - 2015-11-23 10:40 - 01415680 _____ (wj32) C:\Program Files\7GP7PP7P.exe
    2015-11-23 07:55 - 2015-11-23 07:55 - 01415680 _____ (wj32) C:\Program Files\1AJAJSSS.exe
    2015-11-22 13:51 - 2015-11-22 13:52 - 01415680 _____ (wj32) C:\Program Files\TT2BTK2T.exe
    2015-11-21 18:10 - 2015-11-21 18:10 - 01415680 _____ (wj32) C:\Program Files\SO04KW8C.exe
    2015-11-19 08:29 - 2015-11-19 08:29 - 01415680 _____ (wj32) C:\Program Files\88HZZK88.exe
    2015-11-18 10:16 - 2015-11-18 10:16 - 00000000 ____D C:\Program Files (x86)\Elex-tech
    2015-11-12 09:12 - 2015-11-12 09:12 - 01415680 _____ (wj32) C:\Program Files\WSWSS00O.exe
    2015-11-12 09:12 - 2015-11-12 09:12 - 01415680 _____ (wj32) C:\Program Files\RR0I09I0.exe
    2015-11-12 09:12 - 2015-11-12 09:12 - 01415680 _____ (wj32) C:\Program Files\PT51DHX1.exe
    2015-11-12 09:12 - 2015-11-12 09:12 - 01415680 _____ (wj32) C:\Program Files\22BKKKTT.exe
    2015-11-10 10:07 - 2015-12-12 09:34 - 00000000 ____D C:\Program Files (x86)\WinZipper
    2015-11-10 10:07 - 2015-12-11 22:56 - 00000000 ____D C:\Program Files (x86)\SFK
    2015-11-10 10:07 - 2015-11-18 10:13 - 00000000 ____D C:\Users\Olga\AppData\Roaming\WinZipper
    2015-11-10 10:07 - 2015-11-10 10:08 - 00000000 ____D C:\ProgramData\gWMiniProg
    2015-11-10 10:06 - 2015-12-09 10:12 - 00000000 ____D C:\Users\Olga\AppData\Roaming\TSv
    2015-11-07 16:38 - 2015-11-07 16:38 - 01415680 _____ (wj32) C:\Program Files\K2TKKTBT.exe
    2015-10-23 16:29 - 2015-10-23 16:29 - 01415680 _____ (wj32) C:\Program Files\6Y2EIME6.exe
    2015-10-20 21:37 - 2015-12-07 11:04 - 00000000 ____D C:\Users\Olga\AppData\Roaming\istartsurf
    2015-10-20 21:37 - 2015-10-20 21:38 - 00000000 ____D C:\ProgramData\vWdsManProv
    2015-10-13 18:07 - 2015-10-13 18:07 - 01415680 _____ (wj32) C:\Program Files\UI2KAMM6.exe
    2015-10-13 18:07 - 2015-10-13 18:07 - 01415680 _____ (wj32) C:\Program Files\O8WC4KGO.exe
    2015-10-07 20:11 - 2015-10-07 20:11 - 01415680 _____ (wj32) C:\Program Files\G080K4O8.exe
    2015-10-07 20:11 - 2015-10-07 20:11 - 01415680 _____ (wj32) C:\Program Files\1L9PDX5T.exe
    2015-09-29 20:47 - 2015-09-29 20:47 - 01415680 _____ (wj32) C:\Program Files\MVV4DVV4.exe
    2015-09-29 20:46 - 2015-09-29 20:46 - 01415680 _____ (wj32) C:\Program Files\LCUUCL3U.exe
    2015-09-28 20:45 - 2015-09-28 20:45 - 01415680 _____ (wj32) C:\Program Files\KAUAI6KE.exe
    2015-09-14 19:42 - 2015-09-14 19:42 - 01415680 _____ (wj32) C:\Program Files\HK8Z8KHZ.exe
    C:\ProgramData\msbfmvie.exe
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    C:\Users\Olga\AC18-3006-POL.exe
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan i później Cleaning.

    0
  • CControls
  • Pomocny post
    #3 12 Gru 2015 10:35
    Kolobos
    Spec od komputerów

    @Acorus 20 tak jest szybciej:
    C:\Program Files\*.exe

    0
  • Pomocny post
    #4 12 Gru 2015 11:38
    Acorus 20
    Spec od komputerów

    Faktycznie. Na drugi raz. Dzięki.

    0
  • #5 12 Gru 2015 12:10
    Sztaka
    Poziom 2  

    Pomogło. Dziękuję bardzo. ;)

    0
  • #6 12 Gru 2015 12:11
    Acorus 20
    Spec od komputerów

    Skasuj folder C:\FRST.
    W AdwCleaner użyj opcji Uninstall.
    Jak usunąć wirusa przekierowującego na stronę Yoursites123?

    0