Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

jak usunac yoursites123

sv5n 14 Gru 2015 12:22 981 2
  • Pomocny post
    #2 14 Gru 2015 12:52
    Acorus 20
    Spec od komputerów

    Odinstaluj McAfee Security Scan Plus, WordFly 1.10.0.28. Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {B82399F1-F7EA-4FF1-ADA9-943899084FAD} - System32\Tasks\WordFly Auto Updater 1.10.0.28 Core => C:\Program Files (x86)\WordFly_1.10.0.28\Update\WordflyAutoUpdateClient.exe [2015-10-30] (WF) <==== UWAGA
    Task: {EAA0A963-9D4B-4EEB-9A81-D4900C745A1A} - System32\Tasks\WordFly Auto Updater 1.10.0.28 Pending Update => C:\Program Files (x86)\WordFly_1.10.0.28\Update\WordflyAutoUpdateClient.exe [2015-10-30] (WF) <==== UWAGA
    ShortcutWithArgument: C:\Users\darek\Desktop\Symulator Jazdy 2.lnk -> E:\Program Files (x86)\Symulator Jazdy 2\Release\Launcher.exe () -> hxxp://www.istartpageing.com/?type=sc&ts=...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    ShortcutWithArgument: C:\Users\darek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    ShortcutWithArgument: C:\Users\darek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    ShortcutWithArgument: C:\Users\darek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    ShortcutWithArgument: C:\Users\darek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA




    ShortcutWithArgument: C:\Users\darek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    ShortcutWithArgument: C:\Users\darek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T <==== UWAGA
    AlternateDataStreams: C:\ProgramData:NT
    AlternateDataStreams: C:\ProgramData:NT2
    AlternateDataStreams: C:\Users\All Users:NT
    AlternateDataStreams: C:\Users\All Users:NT2
    AlternateDataStreams: C:\ProgramData\Application Data:NT
    AlternateDataStreams: C:\ProgramData\Application Data:NT2
    AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT
    AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2
    AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT
    AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2
    AlternateDataStreams: C:\Users\darek\Dane aplikacji:NT
    AlternateDataStreams: C:\Users\darek\Dane aplikacji:NT2
    AlternateDataStreams: C:\Users\darek\AppData\Roaming:NT
    AlternateDataStreams: C:\Users\darek\AppData\Roaming:NT2
    HKLM-x32\...\Run: [] => [X]
    HKU\S-1-5-21-3308304905-4290484103-3662009915-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T
    HKU\S-1-5-21-3308304905-4290484103-3662009915-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3308304905-4290484103-3662009915-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&...T1000DL002-9TT153_W1V0116TXXXXW1V0116T&q={searchTerms}
    FF SearchPlugin: C:\Users\darek\AppData\Roaming\Mozilla\Firefox\Profiles\n1aewljq.default\searchplugins\webssearches.xml [2015-12-14]
    FF Extension: Web Protector - C:\Users\darek\AppData\Roaming\Mozilla\Firefox\Profiles\n1aewljq.default\extensions\{8a167a0d-2593-78be-dffa-baa301a8d989} [2015-05-27] [Brak podpisu cyfrowego]
    FF Extension: YahooToolsProtected - C:\Users\darek\AppData\Roaming\Mozilla\Firefox\Profiles\n1aewljq.default\extensions\yahooprotected@gmail.com [2015-12-04] [Brak podpisu cyfrowego]
    FF Extension: Default NewTab - C:\Users\darek\AppData\Roaming\Mozilla\Firefox\Profiles\n1aewljq.default\extensions\default_newtabff@gmail.com [2015-12-14] [Brak podpisu cyfrowego]
    CHR HomePage: Default -> hxxp://www.yoursites123.com/?type=hp&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T
    CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1450087887&z=85e58167862e191f9643559gczbwbe4e0b3m0b1b1t&from=wpm07173&uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T"
    CHR DefaultSearchURL: Default -> hxxp://www.yoursites123.com/web/?type=ds&...T1000DL002-9TT153_W1V0116TXXXXW1V0116T&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> yoursites123
    CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1...p;uid=ST1000DL002-9TT153_W1V0116TXXXXW1V0116T
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [289256 2015-07-31] (McAfee, Inc.)
    S2 Update Nano Surfer; "C:\Program Files (x86)\Nano Surfer\updateNanoSurfer.exe" [X]
    S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
    S4 NVHDA; system32\drivers\nvhda64v.sys [X]
    S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
    2015-12-14 11:13 - 2015-12-14 11:20 - 00000000 ____D C:\Program Files (x86)\WinZipper
    2015-12-14 11:13 - 2015-12-14 11:13 - 00000000 ____D C:\Users\darek\AppData\Roaming\WinZipper
    2015-12-14 11:12 - 2015-12-14 12:04 - 00000000 ____D C:\Program Files (x86)\SFK
    2015-12-14 11:12 - 2015-12-14 11:12 - 00000000 ____D C:\Users\darek\AppData\Roaming\TSv
    2015-12-14 11:11 - 2015-12-14 11:11 - 00000000 ____D C:\ProgramData\vWdMv
    2015-12-04 10:30 - 2015-12-14 11:11 - 00000000 ____D C:\ProgramData\gWMiniProg
    2015-12-04 10:30 - 2015-12-07 17:17 - 00000000 ____D C:\Users\darek\AppData\Roaming\istartpageing
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan i później Cleaning.

    0
  • #3 14 Gru 2015 13:13
    sv5n
    Poziom 2  

    dzięki wielkie:)

    0