Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Yoursites123 - usuwanie - logi.

ppiotrpp 19 Gru 2015 17:53 588 1
  • CControls
  • #2 19 Gru 2015 18:11
    Acorus 20
    Spec od komputerów

    Odinstaluj McAfee Security Scan Plus, SafeFinder. Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {111C034E-639E-4CE1-9DB4-DA655DF907EC} - System32\Tasks\psv_S-core => cmd.exe /c regedit.exe /s "C:\ProgramData\Danlax\Overranis.reg" &amp; del "C:\ProgramData\Danlax\Overranis.reg" &amp; SCHTASKS /Delete /TN "psv_S-core" /F <==== UWAGA
    Task: {2459B3C4-6C34-428D-873F-9D0FAF9B2163} - System32\Tasks\psv_Zun-Lux => cmd.exe /c regedit.exe /s "C:\ProgramData\Danlax\Quofix.reg" &amp; del "C:\ProgramData\Danlax\Quofix.reg" &amp; SCHTASKS /Delete /TN "psv_Zun-Lux" /F <==== UWAGA
    Task: {37838048-CE00-412D-B4E8-EAFDE43DED22} - System32\Tasks\psv_Donit => cmd.exe /c regedit.exe /s "C:\ProgramData\Danlax\InTraxtone.reg" &amp; del "C:\ProgramData\Danlax\InTraxtone.reg" &amp; SCHTASKS /Delete /TN "psv_Donit" /F <==== UWAGA
    AppInit_DLLs: C:\ProgramData\Danlax\Holdlex.dll => C:\ProgramData\Danlax\Holdlex.dll [1172480 2015-09-21] ()
    AppInit_DLLs-x32: C:\ProgramData\Danlax\Triooteco.dll => C:\ProgramData\Danlax\Triooteco.dll [384512 2015-09-21] ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-12-13]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (McAfee, Inc.)
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    AutoConfigURL: [S-1-5-21-403033949-2693121034-3414106736-1001] => hxxp://stopblock.me/wpad.dat?d4cdc58a2323227fbb8bef1a006a0740446121
    Hosts:
    HKU\S-1-5-21-403033949-2693121034-3414106736-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...lcq1A_LDNpXqQ7c9KXXIk4kAQtwP3zzRvO9A,,&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0...QTSEcFME0FCFwEURNNfW1KBFgCVEdGFEtZAlI=&q={searchTerms}
    SearchScopes: HKLM -> OldSearch URL = hxxp://www.oursurfing.com/web/?type=ds&ts...=st1000lm024xhn-m101mbb_s30yj9hfc06146&q={searchTerms}




    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0...QTSEcFME0FCFwEURNNfW1KBFgCVEdGFEtZAlI=&q={searchTerms}
    CHR RestoreOnStartup: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggaJgoBUAhCGBgXJAEKTA1CE1QOIg8LUxQTR1Ybc1sOA19GFwIFIk0FA1oDB0VXfV5bFElXTwh3MlxZEkwDRGFRIVpT"
    CHR Extension: (Treasure Track) - C:\Users\Lukasz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakjfioapmlckdpmcnijbpidkbdlmklb [2015-11-07] [UpdateUrl: hxxp://cdn.treasuretrack.net/update] <==== UWAGA
    OPR Extension: (Treasure Track) - C:\Users\Lukasz\AppData\Roaming\Opera Software\Opera Stable\Extensions\hakjfioapmlckdpmcnijbpidkbdlmklb [2015-11-07]
    OPR Extension: (Discover Treasure) - C:\Users\Lukasz\AppData\Roaming\Opera Software\Opera Stable\Extensions\hmphmnjjhbjlckhfhiaomidadhpdnjgl [2015-10-03]
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [289256 2015-12-02] (McAfee, Inc.)
    R2 WdMan; C:\ProgramData\8WdM8\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    S2 McNaiAnn; "C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
    S3 McODS; "C:\ProgramData\McAfee\Update\Installs\pkg_default\Download_Files\default\vso\vso_li_cat\%VSINSTALL_DIR64%\mcods.exe" [X]
    2015-12-19 16:32 - 2015-12-19 17:27 - 00000000 ____D C:\AdwCleaner
    2015-12-14 16:04 - 2015-12-14 16:06 - 00000000 ____D C:\ProgramData\8WdM8
    2015-12-14 16:02 - 2015-12-14 16:02 - 00000000 ____D C:\ProgramData\nWdMn
    2015-12-13 17:36 - 2015-12-13 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    0