Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

safe finder, delta homes -

Thaiphoon 15 Gru 2015 19:08 561 3
  • #2 15 Gru 2015 19:20
    Acorus 20
    Spec od komputerów

    Odinstaluj SpyHunter 4. Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {1DE2AAE7-C5EC-4436-A846-F4757B403C33} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-12-15] (Enigma Software Group USA, LLC.)
    Task: {5FDB3F6E-759E-4880-8F26-6F08B85EA2A2} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2418958778-1799597219-1879622347-1000Core => C:\Users\Kacper\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-13] (Facebook Inc.)
    Task: {9F20016E-41F3-4193-8674-DCA629FFC493} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2418958778-1799597219-1879622347-1000UA => C:\Users\Kacper\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-13] (Facebook Inc.)
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2418958778-1799597219-1879622347-1000Core.job => C:\Users\Kacper\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2418958778-1799597219-1879622347-1000UA.job => C:\Users\Kacper\AppData\Local\Facebook\Update\FacebookUpdate.exe
    ShortcutWithArgument: C:\Users\Kacper\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?utm_source=b&...SUNGXSP2504C_S09QJ1HLC21734&ts=1377328424 <==== UWAGA
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1001\...\Run: [Facebook Update] => C:\Users\Kacper\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-09-13] (Facebook Inc.)
    AppInit_DLLs: C:\ProgramData\Lightzap\Strongdex.dll => C:\ProgramData\Lightzap\Strongdex.dll [518656 2015-12-15] ()
    AppInit_DLLs-x32: C:\ProgramData\Lightzap\K-Sailnix.dll => C:\ProgramData\Lightzap\K-Sailnix.dll [320512 2015-12-15] ()
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}




    HKU\S-1-5-21-2418958778-1799597219-1879622347-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F...Fd__nsmCgk4lY_EuvWtUMaUjhiZOsZTgyeGHSfNMo7A,,,,
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F...Fd__nsmCgk4lY_EuvWtUMaUjhiZOsZTgyeGHSfNMo7A,,,,
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    HKU\S-1-5-21-2418958778-1799597219-1879622347-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
    SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2418958778-1799597219-1879622347-1000 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2418958778-1799597219-1879622347-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2418958778-1799597219-1879622347-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2418958778-1799597219-1879622347-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...jJie06u28ia4CSOgLxQ-S8pnuZtzpiTbwHTA,,&q={searchTerms}
    FF Homepage: C:\ProgramData\Lightzaps\ff.HP");user_pref("browser.newtab.url", "C:\ProgramData\Lightzaps\ff.NT
    FF NewTab: user_pref("browser.startup.homepage", "C:\ProgramData\Lightzaps\ff.HP");C:\ProgramData\Lightzaps\ff.NT
    FF SearchPlugin: C:\Users\Kacper\AppData\Roaming\Mozilla\Firefox\Profiles\jAibHnOj.default\searchplugins\findit.xml [2015-12-15]
    CHR StartupUrls: Default -> "hxxp://www.interia.pl/#utm_source=sft&utm_medium=installer&utm_campaign=sft","hxxp://googlepl/"
    CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - <Brak Path/update_url>
    R2 Lightzap; C:\ProgramData\\Lightzap\\Lightzap.exe [431104 2015-12-15] () [Brak podpisu cyfrowego]
    S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1045376 2015-12-15] (Enigma Software Group USA, LLC.)
    S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-15] ()
    2015-12-15 19:01 - 2015-12-15 19:01 - 00000000 _____ C:\autoexec.bat
    2015-12-15 19:00 - 2015-12-15 19:00 - 00003334 _____ C:\Windows\System32\Tasks\SpyHunter4Startup
    2015-12-15 19:00 - 2015-12-15 19:00 - 00001047 _____ C:\Users\Kacper\Desktop\SpyHunter.lnk
    2015-12-15 19:00 - 2015-12-15 19:00 - 00000000 ____D C:\Users\Kacper\AppData\Roaming\Enigma Software Group
    2015-12-15 19:00 - 2015-12-15 19:00 - 00000000 ____D C:\sh4ldr
    2015-12-15 18:59 - 2015-12-15 18:59 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
    2015-12-15 18:59 - 2015-12-15 18:59 - 00000000 ____D C:\Program Files\Enigma Software Group
    2015-12-15 17:30 - 2015-12-15 18:20 - 00000000 ____D C:\ProgramData\Lightzap
    2015-12-15 17:30 - 2015-12-15 17:30 - 00002377 _____ C:\Windows\SysWOW64\findit.xml
    2015-12-15 17:30 - 2015-12-15 17:30 - 00000000 ____D C:\ProgramData\Lightzaps
    2015-12-15 17:30 - 2015-12-15 17:30 - 00000000 ____D C:\Program Files (x86)\Wise
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan i później Cleaning.

    0
  • #3 15 Gru 2015 19:54
    Thaiphoon
    Poziom 6  

    Chyba się udało. Ja i mój młodszy kuzyn dziękujemy.;)

    0
  • #4 15 Gru 2015 19:57
    Acorus 20
    Spec od komputerów

    Skasuj folder C:\FRST.
    W AdwCleaner użyj opcji Uninstall.
    safe finder, delta homes -

    0