logo elektroda
logo elektroda
X
logo elektroda
REKLAMA
REKLAMA
Adblock/uBlockOrigin/AdGuard mogą powodować znikanie niektórych postów z powodu nowej reguły.

Jak usunąć wirusa yoursites123 z przeglądarki?

tynncia 12 Gru 2015 10:25 1482 11
REKLAMA
  • #1 15232889
    tynncia
    Poziom 2  
    Posty: 4
    Problem z wirusem i proszę o pomoc w jego usunięciu.:)
    Załączniki:
    • FRST.txt (51.2 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • Addition.txt (39.77 KB) Musisz być zalogowany, aby pobrać ten załącznik.
  • REKLAMA
  • #2 15232932
    krzychupar
    Poziom 43  
    Posty: 6807
    Pomógł: 1490
    Ocena: 633
    Otwórz notatnik systemowy i wklej:

    Task: {179E2B7E-965F-487F-87BD-7C945F15E360} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA
    Task: {27092A88-5FC2-4996-8680-58D91F48B778} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA
    Task: {2DBDF756-E95D-4A4C-8591-09EA1059E13E} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA
    Task: {42512625-9704-4662-B791-2D5746124054} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAG
    Inc.)
    Task: {56D53C01-A9B3-4BFF-9E60-13AA92C1DBE0} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA
    Task: {58291B7B-2B2C-4D4D-9A27-02F12CDE3255} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA
    Task: {7579539D-4548-4BD0-8B40-FB00E66D2387} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA
    Task: {B9CFE055-2932-4F7B-9EC2-AFCD5AC5D607} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGATask: {CE39AADC-B74F-4362-8BC6-455517E429BD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGATask: {EB4A1A3C-E41A-4A62-9BA2-1059C824059E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA
    hortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Martyna - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    FF Extension: Brak nazwy - C:\Users\pelu\AppData\Roaming\Mozilla\Firefox\Profiles\b0mnqrtz.default\extensions\quick_searchff@gmail.com [nie znaleziono]
    FF Extension: Brak nazwy - C:\Users\pelu\AppData\Roaming\Mozilla\Firefox\Profiles\b0mnqrtz.default\extensions\sweetsearch@gmail.com [nie znaleziono]
    StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
    2015-12-11 19:49 - 2015-12-11 19:50 - 00000000 ____D C:\ProgramData\HWdMH
    C:\Users\pelu\AppData\Local\Temp\SkypeSetup.exe
    C:\Windows\SysWOW64\pl2.exe
    10:39 2015-12-12
    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
  • REKLAMA
  • Pomocny post
    #3 15232935
    Acorus 20
    Poziom 43  
    Posty: 10541
    Pomógł: 3247
    Ocena: 1063
    Otwórz notatnik systemowy i wklej:

    Cytat:
    CustomCLSID: HKU\S-1-5-21-3835159084-1933550233-79305402-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-469477DCC869}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => Brak pliku
    Task: {179E2B7E-965F-487F-87BD-7C945F15E360} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA
    Task: {27092A88-5FC2-4996-8680-58D91F48B778} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA
    Task: {2DBDF756-E95D-4A4C-8591-09EA1059E13E} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA
    Task: {42512625-9704-4662-B791-2D5746124054} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA
    Task: {56D53C01-A9B3-4BFF-9E60-13AA92C1DBE0} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA
    Task: {58291B7B-2B2C-4D4D-9A27-02F12CDE3255} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA
    Task: {7579539D-4548-4BD0-8B40-FB00E66D2387} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA
    Task: {833B4969-F1D9-4E3E-BAAF-67576E3E4BAD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA
    Task: {B9CFE055-2932-4F7B-9EC2-AFCD5AC5D607} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA
    Task: {CE39AADC-B74F-4362-8BC6-455517E429BD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA
    Task: {EB4A1A3C-E41A-4A62-9BA2-1059C824059E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Martyna - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    Edge HomeButtonPage: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> hxxp://www.delta-homes.com/?type=hp&ts=1444315510&z=90c67323614e21a78f8a4bcgczezfz9c7g2w2wageg&from=ient07031&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    R2 WdMan; C:\ProgramData\HWdMH\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
    2015-12-11 19:49 - 2015-12-11 19:50 - 00000000 ____D C:\ProgramData\HWdMH
    2015-12-11 20:29 - 2014-12-21 21:07 - 00000000 ____D C:\AdwCleaner
    C:\Windows\SysWOW64\pl2.exe
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
  • Pomocny post
    #4 15232940
    Kolobos
    Spec od komputerów
    Posty: 85164
    Pomógł: 17165
    Ocena: 10439
    Odinstaluj: McAfee Security Scan Plus

    Fixlist.txt dla FRST:
    CustomCLSID: HKU\S-1-5-21-3835159084-1933550233-79305402-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-469477DCC869}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => Brak pliku
    Task: {179E2B7E-965F-487F-87BD-7C945F15E360} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA
    Task: {27092A88-5FC2-4996-8680-58D91F48B778} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA
    Task: {2DBDF756-E95D-4A4C-8591-09EA1059E13E} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA
    Task: {42512625-9704-4662-B791-2D5746124054} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA
    Task: {56D53C01-A9B3-4BFF-9E60-13AA92C1DBE0} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA
    Task: {58291B7B-2B2C-4D4D-9A27-02F12CDE3255} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA
    Task: {7579539D-4548-4BD0-8B40-FB00E66D2387} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA
    Task: {833B4969-F1D9-4E3E-BAAF-67576E3E4BAD} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA
    Task: {B9CFE055-2932-4F7B-9EC2-AFCD5AC5D607} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA
    Task: {CE39AADC-B74F-4362-8BC6-455517E429BD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA
    Task: {EB4A1A3C-E41A-4A62-9BA2-1059C824059E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\pelu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Martyna - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP <==== UWAGA
    (Filefacts.net) C:\Program Files (x86)\Smart File Advisor\SFAUpdater.exe
    HKLM-x32\...\Run: [Smart File Advisor] => C:\Program Files (x86)\Smart File Advisor\sfa.exe [282384 2015-03-22] (Filefacts.net)
    HKLM-x32\...\Run: [SFAUpdater] => C:\Program Files (x86)\Smart File Advisor\SFAUpdater.exe [656144 2015-03-18] (Filefacts.net)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-11-10]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.226\SSScheduler.exe (McAfee, Inc.)
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    Hosts: 0.0.0.1 mssplus.mcafee.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    HKU\S-1-5-21-3835159084-1933550233-79305402-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP&q={searchTerms}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    Edge HomeButtonPage: HKU\S-1-5-21-3835159084-1933550233-79305402-1001 -> hxxp://www.delta-homes.com/?type=hp&ts=1444315510&z=90c67323614e21a78f8a4bcgczezfz9c7g2w2wageg&from=ient07031&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    FF Extension: Brak nazwy - C:\Users\pelu\AppData\Roaming\Mozilla\Firefox\Profiles\b0mnqrtz.default\extensions\quick_searchff@gmail.com [nie znaleziono]
    FF Extension: Brak nazwy - C:\Users\pelu\AppData\Roaming\Mozilla\Firefox\Profiles\b0mnqrtz.default\extensions\sweetsearch@gmail.com [nie znaleziono]
    FF Extension: Firefox Certificate Store Hotfix - C:\Users\pelu\AppData\Roaming\Mozilla\Firefox\Profiles\b0mnqrtz.default\Extensions\firefox-hotfix@mozilla.org.xpi [2015-04-13] [Brak podpisu cyfrowego]
    StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449859696&z=7ce6a45f689471d572f3c3eg7z4z8tab5w4t0q7tdo&from=ient07021&uid=ST500LT012-1DG142_W3P8P5PPXXXXW3P8P5PP
    S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
    2015-12-11 20:28 - 2015-12-11 20:28 - 01738240 _____ C:\Users\pelu\Downloads\adwcleaner_5.024 (2).exe
    2015-12-11 20:26 - 2015-12-11 20:26 - 01738240 _____ C:\Users\pelu\Downloads\adwcleaner_5.024 (1).exe
    2015-12-11 19:49 - 2015-12-11 19:50 - 00000000 ____D C:\ProgramData\HWdMH
    2015-12-11 19:49 - 2015-12-11 19:49 - 00000001 _____ C:\WINDOWS\SysWOW64\pl.html
    2015-12-02 19:36 - 2015-12-02 19:36 - 00000000 _____ C:\WINDOWS\SysWOW64\pl2.exe
    2015-12-11 20:29 - 2014-12-21 21:07 - 00000000 ____D C:\AdwCleaner
    EmptyTemp:

    Po wykonaniu usun katalog C:\FRST i to wszystko.
  • #5 15233082
    tynncia
    Poziom 2  
    Posty: 4
    Ok, zrobiłam, tylko jak uruchomić jako administrator, skoro nie mam takiej opcji?:/
  • REKLAMA
  • #6 15233083
    safbot1st
    Poziom 43  
    Posty: 21951
    Pomógł: 2719
    Ocena: 1583
    Pod prawym klikiem myszy na ikonie FRST "Uruchom jako..."?
  • REKLAMA
  • #7 15233084
    Kolobos
    Spec od komputerów
    Posty: 85164
    Pomógł: 17165
    Ocena: 10439
    Uruchom normalnie.
  • #8 15233099
    tynncia
    Poziom 2  
    Posty: 4
    Jeśli coś źle robię, to proszę się nie denerwować, ale ja się kompletnie na tym nie znam, a chcę spróbować to sama naprawić.:D

    Jak usunąć wirusa yoursites123 z przeglądarki?
  • Pomocny post
    #9 15233101
    Kolobos
    Spec od komputerów
    Posty: 85164
    Pomógł: 17165
    Ocena: 10439
    Co Ty robisz?

    Masz uruchomic frst.exe, a nie plik txt...
    Fixlist.txt musi znajdowac sie w katalogu w ktorym masz frst.exe (C:\Users\pelu\Downloads), a nie logi.
  • Pomocny post
    #10 15233104
    safbot1st
    Poziom 43  
    Posty: 21951
    Pomógł: 2719
    Ocena: 1583
    Masz FRST.EXE ! uruchomić "jako", nie TXT.
    FIXLIST.TXT umieszczasz w katalogu w którym masz FRST.EXE.
    Uruchamiasz FRST.EXE "jako adm." i naciskasz guzik "Napraw".
  • #11 15233137
    tynncia
    Poziom 2  
    Posty: 4
    Przepraszam za problem i dzięki za naprawienie mojego!:)
  • #12 15233263
    swiercm
    Moderator na urlopie...
    Posty: 18308
    Pomógł: 1216
    Ocena: 550
    tynncia napisał:
    Przepraszam za problem i dzięki za naprawienie mojego!

    Usuń folder C:\FRST i to wszystko.
    Wątek warto zamknąć samemu.
    Tym razem zrobię to sam.
    Jak usunąć wirusa yoursites123 z przeglądarki?

Podsumowanie tematu

✨ Użytkownik zgłosił problem z wirusem yoursites123 w przeglądarce i prosił o pomoc w jego usunięciu. W odpowiedziach zasugerowano użycie narzędzia FRST (Farbar Recovery Scan Tool) oraz dostarczenie pliku Fixlist.txt, który powinien znajdować się w tym samym katalogu co FRST.exe. Użytkownik został poinstruowany, jak uruchomić FRST jako administrator oraz jak poprawnie umieścić plik Fixlist.txt. Po wykonaniu kroków, użytkownik został poinformowany o konieczności usunięcia folderu C:FRST jako ostatniego kroku w procesie usuwania wirusa.
Wygenerowane przez model językowy.
REKLAMA