Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

DNS Unlocker Safefinder - Wyskakujace reklamy

karmelloss 06 Mar 2016 11:34 453 5
  • #1 06 Mar 2016 11:34
    karmelloss
    Poziom 2  

    Witam. Mam problem z przeglądarkami i kompem, znalazłem tego safefinder ale usunąć się nie da. Wyskakuje tez DNS Unlocker. Jestem totalnie zielony co po kolei mam zrobić. Proszę o pomoc z góry dziękuje

    0 5
  • Pomocny post
    #4 06 Mar 2016 12:18
    Acorus 20
    Spec od komputerów

    Odinstaluj PriceFountain. Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {1F8266C5-5CF2-42A9-9AAF-4A3686FF3ABA} - System32\Tasks\{7D61908C-962D-8E16-24D2-E5E771AFD617} => C:\Windows\system32\regsvr32.exe [2014-10-29] (Microsoft Corporation)
    Task: {90623F2E-D5B4-450F-B42A-2B63167F1EB1} - System32\Tasks\PriceFountainUpdateVer => C:\Users\Komputer\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
    Task: {A49F8810-2706-44EB-9344-1471B234FF17} - System32\Tasks\KomputerInterdictionsPaunchiestV2 => Rundll32.exe ReincarnationistsHybridize.dll,main 7 1 <==== UWAGA
    Task: C:\Windows\Tasks\PriceFountainUpdateVer.job => C:\Users\Komputer\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== UWAGA
    HKU\S-1-5-21-1428417011-3637687758-2974101222-1002\...\RunOnce: [PriceFountainUpdateVer] => [X]
    HKU\S-1-5-21-1428417011-3637687758-2974101222-1002\...\MountPoints2: {6a372c9a-8f01-11e5-8278-ace01098df61} - "G:\Startme.exe"
    HKU\S-1-5-21-1428417011-3637687758-2974101222-1002\...\MountPoints2: {7b71cf03-5d41-11e5-826b-0c5b8f279a64} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1428417011-3637687758-2974101222-1002\...\MountPoints2: {ab560489-31fb-11e5-825e-ace01098df61} - "F:\AutoRun.exe"
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    Tcpip\Parameters: [NameServer] 82.163.142.7 95.211.158.134
    Tcpip\..\Interfaces\{42D2CACE-0E27-4F11-89AB-9BB87EAE512A}: [DhcpNameServer] 82.163.142.7
    Tcpip\..\Interfaces\{5FFC6956-F257-4CC3-9C9C-4E20773CEDCF}: [DhcpNameServer] 82.163.142.7
    Tcpip\..\Interfaces\{928548A8-2996-4506-9723-367322679CF4}: [DhcpNameServer] 82.163.142.7
    Tcpip\..\Interfaces\{F8982F73-36E0-4459-B89F-2D158D98B526}: [DhcpNameServer] 82.163.142.7
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-1428417011-3637687758-2974101222-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...EWo-LuuBa1550kitxUlbcsLSKjUNQJYx3tcw,,&q={searchTerms}




    HKU\S-1-5-21-1428417011-3637687758-2974101222-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...EWo-LuuBa1550kitxUlbcsLSKjUNQJYx3tcw,,&q={searchTerms}
    HKU\S-1-5-21-1428417011-3637687758-2974101222-1002\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...EWo-LuuBa1550kitxUlbcsLSKjUNQJYx3tcw,,&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope - brak wartości
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> DefaultScope - brak wartości
    SearchScopes: HKLM-x32 -> {A22BE487-8A68-41F4-9F19-16127585600B} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?i...k%5Fcode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKU\S-1-5-21-1428417011-3637687758-2974101222-1002 -> {A22BE487-8A68-41F4-9F19-16127585600B} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?i...k%5Fcode=qs&index=aps&field-keywords={searchTerms}
    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll => Brak pliku
    BHO-x32: Middle Rush -> {d00ab4cc-662c-40b6-a85f-d53086f4bb16} -> C:\Program Files (x86)\Middle Rush\Extensions\d00ab4cc-662c-40b6-a85f-d53086f4bb16.dll => Brak pliku
    FF Extension: Discovery App - C:\Users\Komputer\AppData\Roaming\Mozilla\Firefox\Profiles\lquzrn98.default\Extensions\{1e3cded4-09a1-4be5-8b7a-b07d46bfaee0}.xpi [2015-12-15] [Brak podpisu cyfrowego]
    S2 Tristip; C:\ProgramData\Tristip\Tristip [X]
    2016-03-06 09:38 - 2016-03-06 09:38 - 00000000 ____D C:\ProgramData\e7e5d225-6d03-0
    2016-03-06 09:38 - 2016-03-06 09:38 - 00000000 ____D C:\ProgramData\e7e5d225-4781-1
    2016-03-05 21:38 - 2016-03-05 21:38 - 00000000 ____D C:\ProgramData\e7e5d225-34c3-0
    2016-03-05 21:38 - 2016-03-05 21:38 - 00000000 ____D C:\ProgramData\e7e5d225-2935-1
    2016-03-05 10:34 - 2016-03-05 10:34 - 00003444 _____ C:\Windows\System32\Tasks\booking.com Sat2
    2016-03-05 10:34 - 2016-03-05 10:34 - 00003444 _____ C:\Windows\System32\Tasks\booking.com Sat1
    2016-03-05 10:34 - 2016-03-05 10:34 - 00002608 _____ C:\Windows\System32\Tasks\Booking_helper
    2016-03-05 10:34 - 2016-03-05 10:34 - 00000000 ___HD C:\Users\Komputer\AppData\Roaming\GoldenGate
    2016-03-05 10:34 - 2016-03-05 10:34 - 00000000 ___HD C:\Users\Komputer\AppData\Roaming\Booking_helper
    2016-03-05 10:34 - 2016-03-05 10:34 - 00000000 ____D C:\Users\Komputer\AppData\Local\ExcommunicatorsWindsor
    2016-03-05 10:05 - 2016-03-06 10:11 - 00000000 ____D C:\Users\Komputer\AppData\Roaming\PriceFountainUpdateVer
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.
    Przeskanuj progr. Malwarebytes Anti-Malware https://data-cdn.mbamupdates.com/web/mbam-setup-2.1.8.1057.exe
    Podczas instalacji usuń zaznaczenie przy Uruchom okres testowy Malwarebytes Anti-Malware Premium.

    0
  • #5 07 Mar 2016 09:18
    karmelloss
    Poziom 2  

    Dziekuje za pomoc, wszystko działa jak trzeba :)

    0