Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Usunięcie search so-v - Usunięcie search so-v

mth11 19 Mar 2016 09:28 438 3
  • #1 19 Mar 2016 09:28
    mth11
    Poziom 2  

    Cześć,
    prośba o pomoc z so-v (widzę wysyp tego tematu...)

    z góry dzięki
    M.

    0 3
  • CControls
  • Pomocny post
    #2 19 Mar 2016 09:43
    Acorus 20
    Spec od komputerów

    Odinstaluj McAfee Security Scan Plus. Otwórz notatnik systemowy i wklej:

    Cytat:
    Task: {D2E305AE-F2C7-448C-896A-37C56F6F5805} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-50942161-3838418200-964783870-1001UA => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-09-18] (Facebook Inc.)
    Task: {EB3FDC5C-F215-4448-9D99-042FF5C06DE1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-50942161-3838418200-964783870-1001Core => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-09-18] (Facebook Inc.)
    Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-50942161-3838418200-964783870-1001Core.job => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-50942161-3838418200-964783870-1001UA.job => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe
    ShortcutWithArgument: C:\Users\Marta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=def4e238-0bd6-4f5e-9b57-84d03272b19e
    ShortcutWithArgument: C:\Users\Marta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.so-v.com/?type=ll&uid=def4e238-0bd6-4f5e-9b57-84d03272b19e
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=def4e238-0bd6-4f5e-9b57-84d03272b19e
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.so-v.com/?type=ll&uid=def4e238-0bd6-4f5e-9b57-84d03272b19e
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
    HKU\S-1-5-21-50942161-3838418200-964783870-1001\...\Run: [Facebook Update] => C:\Users\Marta\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-09-18] (Facebook Inc.)




    HKU\S-1-5-21-50942161-3838418200-964783870-1001\...\Policies\Explorer: []
    HKU\S-1-5-21-50942161-3838418200-964783870-1001\...\MountPoints2: {2378bc93-5711-11e5-beb3-c8f733122a7c} - "D:\LGAutoRun.exe"
    HKU\S-1-5-21-50942161-3838418200-964783870-1001\...\MountPoints2: {a1b86f6a-a5c7-11e5-bebb-c8f733122a7c} - "E:\Autorun.exe"
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-02-21]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe (McAfee, Inc.)
    GroupPolicy: Restriction - Chrome <======= ATTENTION
    SearchScopes: HKU\S-1-5-21-50942161-3838418200-964783870-1001 -> DefaultScope {420C9501-7DBF-468E-B8D1-5736DEEE76DE} URL =
    SearchScopes: HKU\S-1-5-21-50942161-3838418200-964783870-1001 -> {420C9501-7DBF-468E-B8D1-5736DEEE76DE} URL =
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.so-v.com/?type=ll&uid=def4e238-0bd6-4f5e-9b57-84d03272b19e
    StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.so-v.com/?type=ll&uid=def4e238-0bd6-4f5e-9b57-84d03272b19e
    CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.so-v.com/?type=ll&uid=def4e238-0bd6-4f5e-9b57-84d03272b19e
    2016-03-17 18:22 - 2016-03-17 18:22 - 01006592 _____ C:\WINDOWS\SysWOW64\pl1.exe
    2016-03-17 18:22 - 2016-03-17 18:22 - 00000258 __RSH C:\ProgramData\ntuser.pol
    2016-03-17 18:22 - 2016-03-17 18:22 - 00000000 ____D C:\ProgramData\desktopfind
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    0
  • CControls
  • #3 19 Mar 2016 10:13
    mth11
    Poziom 2  

    Pomogło, bardzo dziękuję!

    0