Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

SONY VAIO - Znowu mnie dopadł yoursites123

m_niebieski 14 Sty 2016 20:19 603 2
  • Pomocny post
    #2 15 Sty 2016 01:04
    krzychupar
    Poziom 40  

    Uaktualnij Jave
    Odinstaluj
    Picexa
    OdOtwórz notatnik systemowy i wklej:
    Task: {41B7EF2A-F09A-46F2-9966-DE29B6BB8608} - System32\Tasks\{4FBC9D39-4CF5-4847-9CA8-BFB11DD5E5B5} => pcalua.exe -a "C:\Program Files (x86)\PDFCreator\unins000.exe"
    ShortcutWithArgument: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS541075A9E680_130105J8110076JK941KX
    ShortcutWithArgument: C:\Users\Marek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS541075A9E680_130105J8110076JK941KX
    ShortcutWithArgument: C:\Users\Marek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS541075A9E680_130105J8110076JK941KX
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS541075A9E680_130105J8110076JK941KX
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    (TU-Funs LIMITED) C:\ProgramData\3WdM3\WdMan.exe
    (tsvr.com) C:\Users\Marek\AppData\Roaming\TSv\TSvr.exe
    (TODO: <公司名>) C:\Program Files (x86)\SFK\SSFK.exe
    (BEIJING MUXING TECHNOLOGY CO. LTD) C:\Program Files (x86)\Picexa\picexasvc.exe
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)




    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\Run: [] => [X]
    2016-01-14 16:28 - 2015-12-15 09:56 - 00582144 _____ () C:\Program Files (x86)\Picexa\curlpp.dll
    2016-01-14 16:28 - 2015-12-15 09:56 - 00065688 _____ () C:\Program Files (x86)\Picexa\zlib1.dll
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: E - "E:\AutoRun.exe"
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: {6432abb5-7d4d-11e4-82c7-a41731e77a70} - "E:\Startme.exe"
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: {75a32286-f047-11e4-82e7-a41731e77a70} - "E:\AutoRun.exe"
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: {b953e537-4fb5-11e4-82b3-a41731e77a70} - "E:\AutoRun.exe"
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: {c0825816-f493-11e3-8291-a41731e77a70} - "E:\AutoRun.exe"
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: {c0825951-f493-11e3-8291-a41731e77a70} - "E:\AutoRun.exe"
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: {c9ea38f6-bb6a-11e3-8276-a41731e77a70} - "E:\AutoRun.exe"
    HKU\S-1-5-21-3241976038-2156822688-677630913-1001\...\MountPoints2: {c9ea3984-bb6a-11e3-8276-a41731e77a70} - "E:\AutoRun.exe"
    BootExecute: autocheck autochk * sdnclean64.exe
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    SearchScopes: HKLM -> DefaultScope - brak wartości
    SearchScopes: HKLM-x32 -> DefaultScope - brak wartości
    BHO: BaeStSaveForYoU -> {1D85B87A-D964-2343-9F40-007C1ECB33C6} -> Brak pliku
    Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2015-10-19] (pdfforge GmbH)
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS541075A9E680_130105J8110076JK941KX
    FF ProfilePath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\za98i1ik.default-1414794180827
    FF NewTab: hxxp://www.yoursites123.com/newtab/?type=nt&a...HitachiXHTS541075A9E680_130105J8110076JK941KX
    FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => nie znaleziono
    StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1...HitachiXHTS541075A9E680_130105J8110076JK941KX
    R2 IhPul; C:\Users\Marek\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com)
    R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [183488 2016-01-14] (TODO: <公司名>)
    U4 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
    2016-01-14 16:28 - 2016-01-14 20:06 - 00000000 ____D C:\Program Files (x86)\Picexa
    2016-01-14 16:28 - 2016-01-14 16:28 - 00001801 _____ C:\Users\Public\Desktop\Picexa.lnk
    2016-01-14 16:28 - 2016-01-14 16:28 - 00000000 ____D C:\Users\Marek\AppData\Roaming\Picexa Viewer
    2016-01-14 16:28 - 2016-01-14 16:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picexa
    2016-01-14 16:27 - 2016-01-14 18:37 - 00000000 ____D C:\Program Files (x86)\SFK
    2016-01-14 16:25 - 2016-01-14 16:26 - 00000000 ____D C:\Users\Marek\AppData\Roaming\TSv
    2016-01-14 16:19 - 2016-01-14 16:20 - 00000000 ____D C:\ProgramData\3WdM3
    2015-12-15 16:36 - 2014-08-01 19:30 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    0
  • #3 15 Sty 2016 08:21
    m_niebieski
    Poziom 3  

    Serdeczne dzięki. Działa.
    Już wczoraj odinstalowałem Picexa który jakoś młodemu podszedł pod myszkę. Java nie da się uaktualnić - bo system nie chce i koniec.
    Wczoraj też przeleciałem kompa ADWCleanerem, ale tak połowicznie zadziałał.
    Jeszcze raz dziękuję

    0