Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

YAC-Wirus - Niemożliwa deinstalacja

filipos94 03 Mar 2016 19:21 639 6
  • #1 03 Mar 2016 19:21
    filipos94
    Poziom 2  

    Witam, mam problem z programem YAC - YET ANOTHER CLEANER. Nie jestem w stanie odinstalować tego pliku z panelu sterowania. Jestem zielony w tym temacie ale doczytałem się, że będzie mi potrzebny program FRST który pobrałem.

    0 6
  • CControls
  • #2 03 Mar 2016 19:24
    Kolobos
    Spec od komputerów

    Szkoda, ze nie doczytales, ze nalezy zamiesic logi, a nie tylko pobrac program.

    Zamiesc logi ze skanowania w zalaczniku, frst.txt oraz addition.txt.

    0
  • CControls
  • Pomocny post
    #4 03 Mar 2016 20:11
    Acorus 20
    Spec od komputerów

    Odinstaluj Delta toolbar, WinZipper. Otwórz notatnik systemowy i wklej:

    Cytat:
    CloseProcesses:
    Task: {07D90CE4-C81D-48F8-84B2-921A995CDA86} - \{4BEB919D-6AAD-41F4-BAB0-DE625448EDBA} -> Brak pliku <==== UWAGA
    Task: {0A82CF78-62F4-4267-B515-152ED131B859} - \{B67FB6FA-6081-4BD8-A790-57345C417D92} -> Brak pliku <==== UWAGA
    Task: {2034C318-F2C9-4390-8B0C-074EB2B4514A} - \{A48AE77C-2B68-46AB-AFC7-AFE7D3D306D9} -> Brak pliku <==== UWAGA
    Task: {307C11B4-9BC0-4E8A-8349-C0D4CBB4D4FB} - \PC Performer_UPDATES -> Brak pliku <==== UWAGA
    Task: {362044D0-7804-4C5E-9DD2-FB762A4811D8} - \PC Performer_DEFAULT -> Brak pliku <==== UWAGA
    Task: {3AFC1751-4D46-4D50-BDA7-FD3541B1F02A} - \{D52A03B3-594F-44B7-B2A1-19F9EEB5B420} -> Brak pliku <==== UWAGA
    Task: {5724EDAD-9156-4EC3-93C2-79ED69B38184} - \{E8448117-8D5C-4279-B65D-9BCE18AACDBC} -> Brak pliku <==== UWAGA
    Task: {5C0E6064-1E6E-4339-BB5E-359F437BB6CD} - \{F58DD5CE-22BC-4DDD-9052-A86FF254AC08} -> Brak pliku <==== UWAGA
    Task: {656CD842-0033-4716-8371-C0EDFC0E44FF} - \{708CF56F-5509-4094-B309-A7448B71B8FA} -> Brak pliku <==== UWAGA
    Task: {69FAC473-4185-4F5A-AC70-A0A008C097B0} - \{100E44F1-9371-43E7-9993-18D6C3558217} -> Brak pliku <==== UWAGA
    Task: {7021BB60-1203-4D36-AC45-9EADCCDDD9CF} - \{1D2CCDDB-434A-4C3E-8747-9EB0E565E81A} -> Brak pliku <==== UWAGA
    Task: {8D74C511-D0CB-4148-9BB8-FB4DB7763987} - \{4AE7BB8D-4BDB-4FC6-86BE-2639887BFA1E} -> Brak pliku <==== UWAGA
    Task: {A501C764-9C89-4B40-A0E3-E801623AC36B} - \{C3388A64-0FE4-442C-AA89-F4CFF4D9C669} -> Brak pliku <==== UWAGA
    Task: {C9B3A2BA-6B3B-4898-80D8-79FF889E1438} - \{DB08141F-6E6B-4438-B3FC-882C9CCF0779} -> Brak pliku <==== UWAGA
    Task: {D267B182-E657-474F-9D16-DF461197B62B} - \{8253711C-C3A3-416B-B90D-5D39B1F7B015} -> Brak pliku <==== UWAGA
    Task: {D6FDF8F1-9CBE-4D3B-B114-4917BB7ED93C} - \{4CA8B28D-F6C6-4B90-AE8E-F0BD047AA75B} -> Brak pliku <==== UWAGA
    Task: {D82310D4-DB01-44AC-98E2-DAE63B7797BA} - System32\Tasks\ext_coupons_notification_service => C:\Program Files\ext coupons\ext_coupons_notification_service.exe <==== UWAGA
    Task: {DB70531A-D3D1-4775-9159-A73124F4C01D} - \{B9D420B8-DC9D-421E-A447-C40EEA98D3B2} -> Brak pliku <==== UWAGA
    Task: {E85CA818-7B06-4DB5-AE3E-B3D6D97AEF8C} - \{6001F657-7EE7-44AA-9C9C-6BCE988EECDA} -> Brak pliku <==== UWAGA
    Task: {FDFF5E46-DC84-432B-8AEA-731A0711B7B0} - \{906D7CCA-B470-488D-9891-716FCD0C5D37} -> Brak pliku <==== UWAGA
    Task: C:\Windows\Tasks\c9d77c59-0ff5-4036-8806-71115fd01f45-11.job => C:\Program Files\HDPlus-V1.9\c9d77c59-0ff5-4036-8806-71115fd01f45-11.exe <==== UWAGA
    Task: C:\Windows\Tasks\ext_coupons_notification_service.job => C:\Program Files\ext coupons\ext_coupons_notification_service.exeǧ/url='hxxp:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='ext coupons' /appid='73143' /srcid='2913' /bic='cbc8ef55c5ef8f19e20e3188f5ed6398' /verifier='96415b0dfb83c6d2769b4b198eaba965' /installerversion='1.50.3.10' /statsdomain='hxxp:/stats.buildomserv.com/data.gif?' /errorsdomain='hxxp:/stats.buildomserv.com/data.gif?' /monetizationdomain='hxxp:/logs.buildomserv.com/monetization.gif <==== UWAGA




    HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1684360 2015-04-28] (APN)
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku
    BootExecute: autocheck autochk * aswBoot.exe /M:419acd37 /dir:"C:\Program Files\AVAST Software\Avast"
    GroupPolicyScripts: Ograniczenia <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450271537&f...;z=247af13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450271537&f...;z=247af13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b
    HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450271537&f...;z=247af13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b
    HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450271537&f...;z=247af13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b
    HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com?type=hp&ts=1450271537&f...;z=247af13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b
    HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com?type=hp&ts=1450271537&f...;z=247af13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b
    HKU\S-1-5-21-2585433557-831808428-2591370862-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.delta-homes.com/web/?type=ds&am...p;uid=ST3500418AS_6VMBCLLKXXXX6VMBCLLK&q={searchTerms}
    HKU\S-1-5-21-2585433557-831808428-2591370862-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
    HKU\S-1-5-21-2585433557-831808428-2591370862-1001\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.babylon.com/?affID=119649&babsrc=HP_ss_din2g&mntrId=A41A00B08C010E51
    HKU\S-1-5-21-2585433557-831808428-2591370862-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
    HKU\S-1-5-21-2585433557-831808428-2591370862-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
    HKU\S-1-5-21-2585433557-831808428-2591370862-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
    HKU\S-1-5-21-2585433557-831808428-2591370862-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
    HKU\S-1-5-21-2585433557-831808428-2591370862-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
    URLSearchHook: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.)
    URLSearchHook: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 - (Brak nazwy) - {687578b9-7132-4a7a-80e4-30ee31099e03} - Brak pliku
    SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450271537&a...f13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b&q={searchTerms}
    SearchScopes: HKLM -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450271537&a...f13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b&q={searchTerms}
    SearchScopes: HKLM -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
    SearchScopes: HKU\.DEFAULT -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450271537&a...f13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b&q={searchTerms}
    SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
    SearchScopes: HKU\.DEFAULT -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450271537&a...f13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b&q={searchTerms}
    SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450271537&a...f13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=119649&babsrc=SP_ss_din2g&mntrId=A41A00B08C010E51
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {393254E7-1850-4706-8905-B74CBCA82731} URL = hxxp://isearch.avg.com/search?cid={3ADBAD69-9719-44BF-8538-1AD396534CDD}&mid=3222d0c8be684c24aab2ec3174d624f4-6f315cf79a6d2d6e43f70b4b94f819d2db4f9f8c&lang=pl&ds=ik011&pr=&d=2012-11-07 15:09:31&v=14.2.0.1&pid=avg&sg=&sap=dsp&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://pandasecurityr.mystart.com/?source=5b9...amp;u=B280EFE21081EDCED9C31F5229C35255&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450271537&a...f13bf88e8623fda01f3g8z1w7e4o2mdg1wdc1b&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = hxxp://badoo.com/startpage/?source=bsb&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={3ADBAD69-9719-44BF-8538-1AD396534CDD}&mid=3222d0c8be684c24aab2ec3174d624f4-6f315cf79a6d2d6e43f70b4b94f819d2db4f9f8c&lang=pl&ds=ik011&pr=&d=2012-11-07 15:09:31&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> {D273F75E-4918-47DC-8D55-3C9AFEA0148C} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10401&src=kw&q={searchTerms}&locale=en_PL&apn_ptnrs=^ABZ&apn_dtid=^YYYYYY^YY^PL&apn_uid=b2a7f045-0b64-4cb1-86d1-76fe09028383&apn_sauid=CFBB9993-AE5F-4F73-945D-151716B78E1A
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1003 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
    SearchScopes: HKU\S-1-5-21-2585433557-831808428-2591370862-1003 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
    BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-00A7-7A786E7484D7} -> C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll [2015-04-22] (APN LLC.)
    BHO: Brak nazwy -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> Brak pliku
    BHO: delta Helper Object -> {C1AF5FA5-852C-4C90-812E-A7F75E011D87} -> C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll [2013-05-20] (Delta-search.com)
    Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll [2013-05-20] (Delta-search.com)
    Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll [2015-04-22] (APN LLC.)
    Toolbar: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> Brak nazwy - {687578B9-7132-4A7A-80E4-30EE31099E03} - Brak pliku
    Toolbar: HKU\S-1-5-21-2585433557-831808428-2591370862-1001 -> Brak nazwy - {D4027C7F-154A-4066-A1AD-4243D8127440} - Brak pliku
    FF DefaultSearchEngine: V9
    FF SearchEngineOrder.1: V9
    FF SelectedSearchEngine: V9
    FF SearchPlugin: C:\Users\Konto\AppData\Roaming\Mozilla\Firefox\Profiles\l4axpnsr.default\searchplugins\V9.xml [2015-12-24]
    FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2014-08-26]
    FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml [2014-12-17]
    FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\my-prefs.js [2015-03-25] <==== UWAGA (Linkuje do pliku *.cfg)
    FF ExtraCheck: C:\Program Files\mozilla firefox\my.cfg [2015-03-25] <==== UWAGA
    CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2015-06-05]
    CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [mocblcnaofikinigmceddfghppkkjbog] - C:\Users\Filip\AppData\Roaming\PlusWinks\PlusWinks.crx [2013-06-11]
    CHR HKLM\...\Chrome\Extension: [noajmlkipclmeolfcnflkjhijkigpfjh] - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx [2014-10-30]
    CHR HKLM\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\Filip\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-07-15]
    CHR HKU\S-1-5-21-2585433557-831808428-2591370862-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\Filip\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [2012-07-15]
    R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [178568 2015-04-22] (APN LLC.)
    R2 iSafeService; C:\Program Files\Elex-tech\YAC\iSafeSvc.exe [118048 2015-05-04] (Elex do Brasil Participações Ltda)
    R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [426160 2015-05-04] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== UWAGA
    R1 iSafeKrnl; C:\Program Files\Elex-tech\YAC\iSafeKrnl.sys [226024 2015-05-04] (Elex do Brasil Participações Ltda)
    S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [48784 2015-05-04] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlKit; C:\Program Files\Elex-tech\YAC\iSafeKrnlKit.sys [96424 2015-05-04] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlMon; C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [43536 2015-05-04] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlR3; C:\Program Files\Elex-tech\YAC\iSafeKrnlR3.sys [71744 2015-05-04] (Elex do Brasil Participações Ltda)
    R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [44712 2015-04-17] (Elex do Brasil Participações Ltda)
    S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
    S3 VGPU; System32\drivers\rdvgkmd.sys [X]
    2016-03-03 19:24 - 2016-03-03 19:24 - 00000000 ____D C:\AdwCleaner
    2016-03-03 15:13 - 2014-12-17 15:16 - 00000000 ____D C:\Program Files\WinZipper
    2013-06-26 21:53 - 2014-06-22 23:57 - 0003728 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
    EmptyTemp:


    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Przeskanuj progr. Malwarebytes Anti-Malware https://data-cdn.mbamupdates.com/web/mbam-setup-2.1.8.1057.exe
    Podczas instalacji usuń zaznaczenie przy Uruchom okres testowy Malwarebytes Anti-Malware Premium.

    0
  • #5 03 Mar 2016 21:09
    filipos94
    Poziom 2  

    Zrobiłem według instrukcji powyżej po restarcie komputera przeskanowałem system Malwarebytes Anti-Malware ponad 21 tysięcy obiektów zostało zamkniętych w kwarantannie aczkolwiek ten program nadal jest w panelu sterowania oraz folder z zawartością. tutaj świerze logi. Antyvirus avira wariuje non stop wyskakują mi powiadomienia o istnieniu wirusa w tym folderze

    0
  • Pomocny post
    #6 03 Mar 2016 21:30
    Kolobos
    Spec od komputerów

    Odinstaluj: YAC(Yet Another Cleaner!)
    To tylko pusty wpis.

    Nowy Fixlist.txt dla FRST:
    HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1684360 2015-04-28] (APN)
    HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [panda4_1dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda4_1dn" /f
    HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [panda4_1dn_XP] => reg.exe delete "HKCU\Software\panda4_1dn" /f
    HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [panda4_1dn_DATA_FOLDER] => cmd.exe /c rmdir "C:\ProgramData\Panda Security URL Filtering" /s /q
    HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [panda4_1dn_INSTALL_FOLDER] => cmd.exe /c rmdir "C:\Windows\system32\config\systemprofile\AppData\Local\panda4_1dn" /s /q
    HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
    HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
    HKU\S-1-5-21-2585433557-831808428-2591370862-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Application Restart #1] => C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe [741704 2015-12-11] (Google Inc.)
    HKU\S-1-5-18\...\RunOnce: [panda4_1dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda4_1dn" /f
    HKU\S-1-5-18\...\RunOnce: [panda4_1dn_XP] => reg.exe delete "HKCU\Software\panda4_1dn" /f
    HKU\S-1-5-18\...\RunOnce: [panda4_1dn_DATA_FOLDER] => cmd.exe /c rmdir "C:\ProgramData\Panda Security URL Filtering" /s /q
    HKU\S-1-5-18\...\RunOnce: [panda4_1dn_INSTALL_FOLDER] => cmd.exe /c rmdir "C:\Windows\system32\config\systemprofile\AppData\Local\panda4_1dn" /s /q
    HKU\S-1-5-18\...\RunOnce: [panda] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda" /f
    HKU\S-1-5-18\...\RunOnce: [panda_XP] => reg.exe delete "HKCU\Software\panda" /f
    Hosts: 0.0.0.1 mssplus.mcafee.com
    FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [Brak pliku]
    FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [Brak pliku]
    FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\xgu8utr8.default\extensions\faststartff@gmail.com => nie znaleziono
    2016-03-03 21:06 - 2016-03-03 21:06 - 00000000 ____D C:\AdwCleaner
    2016-02-23 18:54 - 2015-12-30 14:44 - 00000000 ____D C:\Users\Konto\AppData\Roaming\WinZipper

    Usun katalog C:\FRST.

    0
  • #7 03 Mar 2016 21:34
    filipos94
    Poziom 2  

    Działa! Dziękuje jestem wam ogromnie wdzięczny!

    0