Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

usuwanie real time z chrome

rabaj2 08 Mar 2016 22:05 474 1
  • #2 08 Mar 2016 23:19
    Kolobos
    Spec od komputerów

    Obok frst.exe utworz plik fixlist.txt z zawartoscia:
    Task: {6866CDAC-3842-464C-9006-07286D21A9E3} - System32\Tasks\Microsoft_Hardware_Launch_rundll32_exe => Rundll32.exe url.dll,OpenURL hxxp://go.microsoft.com/fwlink/?LinkId=116866
    Task: {88D20664-FB5D-4EB7-A88C-742B6D1C402E} - System32\Tasks\{58D3028D-4BCC-4864-B16B-BC9F0340FE1B} => Chrome.exe hxxp://www.skype.com/go/downloading?source=li...amp;amp;ver=7.2.0.103&LastError=12007
    Task: C:\Windows\Tasks\AlBU7rn.job => C:\Users\Rafa�\AppData\Roaming\AlBU7rn.exe <==== UWAGA
    ShortcutWithArgument: C:\Users\Rafał\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> www.aqovd.com?oem=sunadplv3&uid=50026B724800078A_KINGSTONSH103S3120G&tm=1447999662
    ShortcutWithArgument: C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> www.aqovd.com?oem=sunadplv3&uid=50026B724800078A_KINGSTONSH103S3120G&tm=1447999662
    ShortcutWithArgument: C:\Users\Rafał\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> www.aqovd.com?oem=sunadplv3&uid=50026B724800078A_KINGSTONSH103S3120G&tm=1447999662
    ShortcutWithArgument: C:\Users\Rafał\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> www.aqovd.com?oem=sunadplv3&uid=50026B724800078A_KINGSTONSH103S3120G&tm=1447999662
    AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
    HKLM\...\Run: [SpaceSoundPro] => "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe"
    HKU\S-1-5-21-3758712363-3073578704-783211916-1001\...\MountPoints2: {1f5c0fd0-12bf-11e5-82c7-5cac4cc2e1f6} - "D:\Lenovo_Suite.exe"
    HKU\S-1-5-21-3758712363-3073578704-783211916-1001\...\MountPoints2: {47fec834-5709-11e5-82e5-5cac4cc2e1f6} - "D:\Lenovo_Suite.exe"
    HKU\S-1-5-21-3758712363-3073578704-783211916-1001\...\MountPoints2: {a6cb2241-cda9-11e5-833c-00a0c6000000} - "D:\Lenovo_Suite.exe"
    HKU\S-1-5-21-3758712363-3073578704-783211916-1001\...\MountPoints2: {b0519095-426f-11e4-8251-5cac4cc2e1f6} - "E:\_AUTORUN\AUTORUN.EXE"
    HKU\S-1-5-21-3758712363-3073578704-783211916-1001\...\MountPoints2: {ff71feee-b3d0-11e5-832e-00a0c6000000} - "F:\AutoRun.exe"
    Startup: C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\u.lnk [2015-05-28]
    ShortcutTarget: u.lnk -> C:\Users\Rafał\AppData\Roaming\obsfzlfdyj.exe (Brak pliku)
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    CHR Extension: (Real-time) - C:\Users\Rafał\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\epiigdnioginncdapahfgjfcckgabdod [2015-11-20]
    S2 ginoquci; C:\Users\RAFA~1\AppData\Local\Temp\nst60F9.tmp [X]
    2016-01-13 15:02 - 2016-01-13 18:09 - 08388608 _____ C:\Users\Rafał\Downloads\GenoPro-37794-dp.vhdx
    2016-03-07 20:00 - 2015-11-15 14:10 - 00000000 ____D C:\AdwCleaner
    2015-04-19 13:20 - 2015-11-22 09:29 - 0000626 _____ () C:\Users\Rafał\AppData\Roaming\AlBU7rn
    2015-04-20 15:05 - 2015-04-20 15:05 - 1579520 _____ () C:\Users\Rafał\AppData\Roaming\AlBU7rn.exe
    2014-10-03 11:04 - 2014-12-07 19:35 - 0000025 _____ () C:\Users\Rafał\AppData\Roaming\Opusbext.dat
    EmptyTemp:

    W FRST wybierz Napraw.

    0