Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Yoursite 123 - Log i pomoc co usunąć

darecki777 29 Gru 2015 21:54 852 2
  • CControls
  • #2 30 Gru 2015 02:00
    krzychupar
    Poziom 41  

    Otwórz notatnik systemowy i wklej:

    Code:
    Task: {BD2FA008-B0EA-4FBB-B0E8-71C289088878} - System32\Tasks\{1C622627-8861-4496-8CA3-C23E62C8E12B} => pcalua.exe -a "C:\Program Files\ODEON\JAF\pkey driver\Driver_setup_English.exe" -d "C:\Program Files\ODEON\JAF\pkey driver"
    
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\...\Run: [Gadu-Gadu] => "F:\Program Files\Gadu-Gadu\gg.exe" /tray
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\...\MountPoints2: {04982f27-5204-11e3-a29d-582c80139263} - G:\KODAK_Software_Downloader.exe
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\...\MountPoints2: {ab8f74c0-46c2-11e3-a5c4-93732b9060af} - G:\AutoRun.exe
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\...\MountPoints2: {f40a9190-51e4-11e4-95d4-582c80139263} - H:\LGAutoRun.exe
    AppInit_DLLs: c:\progra~2\bitguard\271832~1.68\{c16c1~1\bitguard.dll => Brak pliku
    BootExecute: autocheck autochk * sdnclean.exe
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1451387698&z=f0b2487e7f436c823d9b788gcz4w9g4c8b3m0q1t1q&from=wpm12253&uid=ST9250320AS_5SW1M36R
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts=1439844786&z=445dd322d780d6e96b4d4a1gdzbc2tab4z8z1qbb4t&from=cornl&uid=ST9250320AS_5SW1M36R&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1451387698&z=f0b2487e7f436c823d9b788gcz4w9g4c8b3m0q1t1q&from=wpm12253&uid=ST9250320AS_5SW1M36R
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1439844786&z=445dd322d780d6e96b4d4a1gdzbc2tab4z8z1qbb4t&from=cornl&uid=ST9250320AS_5SW1M36R&q={searchTerms}
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.key-find.com/web/?type=dspp&ts=1423235534&from=cor&uid=ST9250320AS_5SW1M36R&q={searchTerms}
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1451387698&z=f0b2487e7f436c823d9b788gcz4w9g4c8b3m0q1t1q&from=wpm12253&uid=ST9250320AS_5SW1M36R
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss_Btisdt7&mntrId=407422242B31B509&affID=123621&tt=280813_ts&tsp=4991
    HKU\S-1-5-21-1734542124-1900964956-491971444-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1451387698&z=f0b2487e7f436c823d9b788gcz4w9g4c8b3m0q1t1q&from=wpm12253&uid=ST9250320AS_5SW1M36R




    HKU\S-1-5-21-1734542124-1900964956-491971444-500\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.key-find.com/web/?type=dspp&ts=1423235534&from=cor&uid=ST9250320AS_5SW1M36R&q={searchTerms}
    SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
    SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
    SearchScopes: HKU\S-1-5-21-1734542124-1900964956-491971444-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9250320AS_5SW1M36R&ts=1423235576&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1734542124-1900964956-491971444-500 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
    SearchScopes: HKU\S-1-5-21-1734542124-1900964956-491971444-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9250320AS_5SW1M36R&ts=1423235576&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1734542124-1900964956-491971444-500 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9250320AS_5SW1M36R&ts=1423235576&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1734542124-1900964956-491971444-500 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9250320AS_5SW1M36R&ts=1423235576&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1734542124-1900964956-491971444-500 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9250320AS_5SW1M36R&ts=1423235576&type=default&q={searchTerms}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.delta-homes.com/?type=sc&ts=1444459532&z=cb5f343eed712412ecf17dag6zfzaz1z4w2t6wfoez&from=wpm07163&uid=ST9250320AS_5SW1M36R
    FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\3x3mrwx5.default-1423385382600
    FF NewTab: hxxp://www.yoursites123.com/newtab/?type=nt&ts=1451387698&z=f0b2487e7f436c823d9b788gcz4w9g4c8b3m0q1t1q&from=wpm12253&uid=ST9250320AS_5SW1M36R
    FF DefaultSearchEngine: yoursites123
    FF SelectedSearchEngine: delta-homes
    FF Homepage: hxxp://www.yoursites123.com/?type=hp&ts=1451387698&z=f0b2487e7f436c823d9b788gcz4w9g4c8b3m0q1t1q&from=wpm12253&uid=ST9250320AS_5SW1M36R
    FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [Brak pliku]
    FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF HKLM\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\x2kxik4v.default\extensions\fftoolbar2014@etech.com => nie znaleziono
    FF HKLM\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\3x3mrwx5.default-1423385382600\extensions\defsearchp@gmail.com => nie znaleziono
    StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1451387698&z=f0b2487e7f436c823d9b788gcz4w9g4c8b3m0q1t1q&from=wpm12253&uid=ST9250320AS_5SW1M36R
    CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-21]
    R2 IhPul; C:\Users\Administrator\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
    R2 SSFK; C:\Program Files\SFK\SSFK.exe [302240 2015-12-28] (TODO: <公司名>)
    R2 WdMan; C:\ProgramData\SWdMS\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    R3 vsbus; C:\Windows\System32\DRIVERS\vsb.sys [15264 2008-07-23] () [Brak podpisu cyfrowego]
    S3 vserial; C:\Windows\System32\DRIVERS\vserial.sys [47744 2008-07-23] () [Brak podpisu cyfrowego]
    S2 Mobile Broadband HL Service; "C:\ProgramData\MobileBrServ\mbbservice.exe" -service [X]
    R2 IhPul; C:\Users\Administrator\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
    R2 SSFK; C:\Program Files\SFK\SSFK.exe [302240 2015-12-28] (TODO: <公司名>)
    R2 WdMan; C:\ProgramData\SWdMS\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
    2015-12-29 12:15 - 2015-12-29 12:16 - 00000000 ____D C:\ProgramData\SWdMS
    2015-12-29 12:14 - 2015-12-29 12:14 - 02454636 _____ C:\Program Files\SSFK.exe
    2015-12-29 20:50 - 2015-10-10 07:46 - 00000000 ____D C:\Program Files\SFK
    2015-12-29 12:14 - 2015-12-29 12:14 - 2454636 _____ () C:\Program Files\SSFK.exeC:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    EmptyTemp:



    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom FRST i kliknij w Fix/Napraw.

    0
  • CControls