Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Jak usunąć so-v.com? Prośba o fixlistę.

maxiorm 30 Mar 2016 12:03 498 6
  • #1 30 Mar 2016 12:03
    maxiorm
    Poziom 3  

    Witam.
    W moich przeglądarkach pojawiło się so-v.com, czytałem podobne tematy, ale myślę, że te logi to z każdego komputera są inne.
    Z góry dziękuję za pomoc.
    Pierwszy raz to będę robił.
    W internecie znalazłem jak wydobyć i wkleić te logi tutaj.
    Proszę o pomoc. Pozdrawiam.

    0 6
  • CControls
  • #2 30 Mar 2016 12:19
    Domino_2
    Pomocny dla użytkowników

    Odinstaluj ASUS WebStorage i Java 8 Update 73.

    Cytat:

    Task: {019CB4D3-5B4A-4969-B0A3-43F36C8C334D} - System32\Tasks\{2D4AF470-E418-4F1E-B9A0-8BCB8995AA34} => Chrome.exe hxxp://ui.skype.com/ui/0/7.4.0.102/pl/abandoninstall?page=tsProgressBar
    Task: {0B48E543-2CB1-4663-AD7B-650762E8EE9F} - System32\Tasks\{19F3F18C-97F1-49FD-8BF4-8967933FDFB2} => Chrome.exe hxxp://ui.skype.com/ui/0/7.4.0.102/pl/abandoninstall?page=tsProgressBar
    Task: {0D2CBDD6-1FE6-4550-B3DC-3050748EC69B} - System32\Tasks\{F1CB22C7-5154-4C23-9A5F-F0DA673CA02C} => pcalua.exe -a "D:\gry\GTA\Gta Sa v2.00+ PATCH ZMIENIAJACY WERSJE\CD2(polonizacja)\Setup.exe" -d "D:\gry\GTA\Gta Sa v2.00+ PATCH ZMIENIAJACY WERSJE\CD2(polonizacja)"
    Task: {1D9C8BE6-1A1D-4F48-9FFF-36F6E649E824} - System32\Tasks\{2688F357-6915-41FD-B21B-87DB9D6FBFEE} => pcalua.exe -a C:\Users\Maks\Downloads\MinecraftZyczu.exe -d C:\Users\Maks\Downloads
    Task: {23588385-7D3C-4823-BC44-4B8835CCD90C} - \ReclaimerUpdateXML_Maks -> Brak pliku <==== UWAGA
    Task: {28B22590-0237-4F8E-BD64-CBC825CFF6BD} - System32\Tasks\{210A8391-4849-4F07-8180-2D31C66A0FB2} => pcalua.exe -a "C:\Users\Maks\Downloads\Schwertransport Simulator 2011.exe" -d C:\Users\Maks\Downloads
    Task: {31A3882C-454A-424D-970A-61EBA70BA2FB} - System32\Tasks\Driver Booster SkipUAC (Maks) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
    Task: {3F64F8F3-A281-49AD-AE18-1534772ABCA7} - System32\Tasks\{B3C2358F-D4AF-4A92-B39E-A361FEE44325} => pcalua.exe -a "C:\Users\Maks\Downloads\FIFA 2002_SETUP.exe" -d C:\Users\Maks\Downloads
    Task: {45EBCED8-84D2-49D7-818C-48107DB643DD} - \FacebookUpdateTaskUserS-1-5-21-3911633335-2632447348-1901586541-1001Core -> Brak pliku <==== UWAGA
    Task: {4B53A8E0-39EF-4ACE-8C00-03340C24C4D4} - \pricemeterdownloader -> Brak pliku <==== UWAGA
    Task: {4BC54DEE-B75B-4914-91A9-340D88D75483} - \GoogleUpdateTaskMachineUA -> Brak pliku <==== UWAGA
    Task: {579E9844-C7D8-4B9D-8735-5363D4E8AE16} - \ReclaimerUpdateFiles_Maks -> Brak pliku <==== UWAGA
    Task: {58CFEFE8-C292-4F5B-9205-D976045C1144} - \WPD\SqmUpload_S-1-5-21-3911633335-2632447348-1901586541-1001 -> Brak pliku <==== UWAGA
    Task: {98AB93A4-AA3D-40CA-8D33-9ECFF835DAFC} - \FacebookUpdateTaskUserS-1-5-21-3911633335-2632447348-1901586541-1001UA -> Brak pliku <==== UWAGA
    Task: {9BC9F707-9726-4723-8A9F-EE67C824CC5A} - \RNUpgradeHelperResumePrompt_Maks -> Brak pliku <==== UWAGA
    Task: {B910CB3C-46B1-4387-83C2-804B15B110E5} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe [2016-03-21] ()




    Task: {ED42CCE4-0A38-40F6-9FCD-31B334A1A13A} - System32\Tasks\{3ADB3229-6093-4B07-A896-875B7EC3766F} => Chrome.exe hxxp://ui.skype.com/ui/0/7.8.80.102/pl/abandoninstall?page=tsProgressBar
    ShortcutWithArgument: C:\Users\Maks\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> D:\Program Files (x86)\firefox.exe (Mozilla Corporation) -> hxxp://www.so-v.com/?type=ll&uid=b63a5fae-7400-4c81-aca0-4ab4ed43991a
    () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
    HKLM\...\Run: [ASUS WebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] ()
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: G - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {029cb126-debc-11e3-9d72-bcaec5a49644} - G:\LGAutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac840-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac84e-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac85b-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac894-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {0905b8b6-52a8-11e3-bbf6-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {0905b8c4-52a8-11e3-bbf6-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {21b3f502-b223-11e3-97cf-d3c5f08223f2} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {23bbc363-7ba9-11e3-adde-af91774e8539} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {23bbc377-7ba9-11e3-adde-af91774e8539} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {2bf5c841-6389-11e3-883e-a6f19f93dcb3} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {2fb47e5f-278e-11e3-8c2e-bcaec5a49644} - G:\start.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {31856f5d-1018-11e5-8899-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {35534ccd-a90c-11e3-b82e-9f22a82bbedc} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {35bf615d-75f9-11e3-9d7b-b8ab673e99f2} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {3680fc5a-382f-11e3-af81-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {3680fc89-382f-11e3-af81-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {3680fc95-382f-11e3-af81-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {429d2b7d-447d-11e3-bca8-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {435ef81d-4e59-11e3-a3a8-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {4d64fcd8-aa23-11e3-b244-e633a20f85bb} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {59dcbddb-55d0-11e3-9e68-cbbca386b4c1} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {732fb928-4e12-11e3-aef5-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {732fb934-4e12-11e3-aef5-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {7864ef21-6a97-11e4-ae06-bcaec5a49644} - I:\LGAutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {8eb3299e-1ca3-11e3-8f5b-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {8eb329ac-1ca3-11e3-8f5b-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {90d8f824-a882-11e3-84c7-e150d015f8b9} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a15d2697-b3f5-11e2-9411-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a15d26a4-b3f5-11e2-9411-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a21d367a-7c42-11e3-b962-fbdcac1091cf} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a3185da7-a8a5-11e3-b3e3-b1c19be5b8ca} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a3185dcf-a8a5-11e3-b3e3-b1c19be5b8ca} - I:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a3185ddb-a8a5-11e3-b3e3-b1c19be5b8ca} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b4bea8d2-82b9-11e4-be40-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b6e4fcd6-682e-11e5-a43c-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b99e19c0-381d-11e3-b784-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b99e19d5-381d-11e3-b784-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {ccf8560a-1ca4-11e3-bbcc-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {d3a8841f-a9d4-11e3-b4b0-b828e8e513f5} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {d3a8842d-a9d4-11e3-b4b0-b828e8e513f5} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {d3a88438-a9d4-11e3-b4b0-b828e8e513f5} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {e051851f-679e-11e5-91f3-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {e36d1b5d-5464-11e3-95e9-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {e5f3de28-48c0-11e3-977b-74f06dc56225} - G:\AutoRun.exe
    ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll [2009-11-26] (eCareme Technologies, Inc.)
    ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll [2009-11-26] (eCareme Technologies, Inc.)
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...c4yetVNkkiZltsN_LPrWlbqb_QIYQBz3WqfQ,,&q={searchTerms}
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...c4yetVNkkiZltsN_LPrWlbqb_QIYQBz3WqfQ,,&q={searchTerms}
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...c4yetVNkkiZltsN_LPrWlbqb_QIYQBz3WqfQ,,&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
    SearchScopes: HKU\S-1-5-21-3911633335-2632447348-1901586541-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-3911633335-2632447348-1901586541-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3911633335-2632447348-1901586541-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe
    FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-08-03] [Brak podpisu cyfrowego]
    FF HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => nie znaleziono
    StartMenuInternet: FIREFOX.EXE - D:\Program Files (x86)\firefox.exe hxxp://www.so-v.com/?type=ll&uid=b63a5fae-7400-4c81-aca0-4ab4ed43991a
    CHR HomePage: Default -> hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1458810963&z=723d543194645e308a0e064g5zdw0b5bfg4g6geq4m&from=wpm0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA"
    CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <nie znaleziono>
    R2 Everything; C:\Program Files (x86)\Everything\Everything.exe [1048576 2014-08-06] () [Brak podpisu cyfrowego] <==== UWAGA
    S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
    S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
    S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
    S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
    S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
    S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
    S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [X]
    S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
    S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
    S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
    S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
    S1 lnzrpmiu; \??\C:\Windows\system32\drivers\lnzrpmiu.sys [X]
    U3 tmlwf; Brak ImagePath
    U3 tmwfp; Brak ImagePath
    2016-03-30 11:31 - 2016-03-30 11:31 - 00000001 _____ C:\Windows\SysWOW64\pl.html
    2016-03-29 17:56 - 2016-03-29 17:56 - 00000518 _____ C:\so-v.xml
    2016-03-24 11:16 - 2016-03-24 11:16 - 00000633 _____ C:\yoursites123.xml
    EmptyTemp:


    Wklej to do notatnika i zapisz pod nazwą fixlist.txt i umieść w folderze gdzie znajduje się plik FRST.exe/FRST64.exe, odpal go i kliknij Fix/Napraw.

    0
  • CControls
  • #3 30 Mar 2016 12:21
    krzychupar
    Poziom 40  

    Otwórz notatnik systemowy i wklej:
    Task: {0D2CBDD6-1FE6-4550-B3DC-3050748EC69B} - System32\Tasks\{F1CB22C7-5154-4C23-9A5F-F0DA673CA02C} => pcalua.exe -a "D:\gry\GTA\Gta Sa v2.00+ PATCH ZMIENIAJACY WERSJE\CD2(polonizacja)\Setup.exe" -d "D:\gry\GTA\Gta Sa v2.00+ PATCH ZMIENIAJACY WERSJE\CD2(polonizacja)"
    Task: {1D9C8BE6-1A1D-4F48-9FFF-36F6E649E824} - System32\Tasks\{2688F357-6915-41FD-B21B-87DB9D6FBFEE} => pcalua.exe -a C:\Users\Maks\Downloads\MinecraftZyczu.exe -d C:\Users\Maks\Downloads
    Task: {23588385-7D3C-4823-BC44-4B8835CCD90C} - \ReclaimerUpdateXML_Maks -> Brak pliku <==== UWAGA
    Task: {28B22590-0237-4F8E-BD64-CBC825CFF6BD} - System32\Tasks\{210A8391-4849-4F07-8180-2D31C66A0FB2} => pcalua.exe -a "C:\Users\Maks\Downloads\Schwertransport Simulator 2011.exe" -d C:\Users\Maks\Downloads
    Task: {45EBCED8-84D2-49D7-818C-48107DB643DD} - \FacebookUpdateTaskUserS-1-5-21-3911633335-2632447348-1901586541-1001Core -> Brak pliku <==== UWAGA
    Task: {4B53A8E0-39EF-4ACE-8C00-03340C24C4D4} - \pricemeterdownloader -> Brak pliku <==== UWAGA
    Task: {4BC54DEE-B75B-4914-91A9-340D88D75483} - \GoogleUpdateTaskMachineUA -> Brak pliku <==== UWAGA
    Task: {579E9844-C7D8-4B9D-8735-5363D4E8AE16} - \ReclaimerUpdateFiles_Maks -> Brak pliku <==== UWAGA
    Task: {58CFEFE8-C292-4F5B-9205-D976045C1144} - \WPD\SqmUpload_S-1-5-21-3911633335-2632447348-1901586541-1001 -> Brak pliku <==== UWAGA
    Task: {98AB93A4-AA3D-40CA-8D33-9ECFF835DAFC} - \FacebookUpdateTaskUserS-1-5-21-3911633335-2632447348-1901586541-1001UA -> Brak pliku <==== UWAGA
    Task: {9BC9F707-9726-4723-8A9F-EE67C824CC5A} - \RNUpgradeHelperResumePrompt_Maks -> Brak pliku <==== UWAGA
    ShortcutWithArgument: C:\Users\Maks\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk -> D:\Program Files (x86)\firefox.exe (Mozilla Corporation) -> hxxp://www.so-v.com/?type=ll&uid=b63a5fae-7400-4c81-aca0-4ab4ed43991a
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: G - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {029cb126-debc-11e3-9d72-bcaec5a49644} - G:\LGAutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac840-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac84e-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac85b-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {031ac894-7859-11e3-a91b-e0628126bff7} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {0905b8b6-52a8-11e3-bbf6-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {0905b8c4-52a8-11e3-bbf6-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {21b3f502-b223-11e3-97cf-d3c5f08223f2} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {23bbc363-7ba9-11e3-adde-af91774e8539} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {23bbc377-7ba9-11e3-adde-af91774e8539} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {2bf5c841-6389-11e3-883e-a6f19f93dcb3} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {2fb47e5f-278e-11e3-8c2e-bcaec5a49644} - G:\start.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {31856f5d-1018-11e5-8899-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {35534ccd-a90c-11e3-b82e-9f22a82bbedc} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {35bf615d-75f9-11e3-9d7b-b8ab673e99f2} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {3680fc5a-382f-11e3-af81-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {3680fc89-382f-11e3-af81-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {3680fc95-382f-11e3-af81-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {429d2b7d-447d-11e3-bca8-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {435ef81d-4e59-11e3-a3a8-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {4d64fcd8-aa23-11e3-b244-e633a20f85bb} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {59dcbddb-55d0-11e3-9e68-cbbca386b4c1} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {732fb928-4e12-11e3-aef5-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {732fb934-4e12-11e3-aef5-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {7864ef21-6a97-11e4-ae06-bcaec5a49644} - I:\LGAutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {8eb3299e-1ca3-11e3-8f5b-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {8eb329ac-1ca3-11e3-8f5b-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {90d8f824-a882-11e3-84c7-e150d015f8b9} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a15d2697-b3f5-11e2-9411-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a15d26a4-b3f5-11e2-9411-74f06dc56225} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a21d367a-7c42-11e3-b962-fbdcac1091cf} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a3185da7-a8a5-11e3-b3e3-b1c19be5b8ca} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a3185dcf-a8a5-11e3-b3e3-b1c19be5b8ca} - I:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {a3185ddb-a8a5-11e3-b3e3-b1c19be5b8ca} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b4bea8d2-82b9-11e4-be40-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b6e4fcd6-682e-11e5-a43c-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b99e19c0-381d-11e3-b784-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {b99e19d5-381d-11e3-b784-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {ccf8560a-1ca4-11e3-bbcc-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {d3a8841f-a9d4-11e3-b4b0-b828e8e513f5} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {d3a8842d-a9d4-11e3-b4b0-b828e8e513f5} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {d3a88438-a9d4-11e3-b4b0-b828e8e513f5} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {e051851f-679e-11e5-91f3-bcaec5a49644} - G:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {e36d1b5d-5464-11e3-95e9-bcaec5a49644} - F:\AutoRun.exe
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\MountPoints2: {e5f3de28-48c0-11e3-977b-74f06dc56225} - G:\AutoRun.exe
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=14...p;uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA&q={searchTerms}
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...c4yetVNkkiZltsN_LPrWlbqb_QIYQBz3WqfQ,,&q={searchTerms}
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...c4yetVNkkiZltsN_LPrWlbqb_QIYQBz3WqfQ,,&q={searchTerms}
    HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61...c4yetVNkkiZltsN_LPrWlbqb_QIYQBz3WqfQ,,&q={searchTerms}
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
    SearchScopes: HKU\S-1-5-21-3911633335-2632447348-1901586541-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-3911633335-2632447348-1901586541-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3911633335-2632447348-1901586541-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
    FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF HKU\S-1-5-21-3911633335-2632447348-1901586541-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => nie znaleziono
    StartMenuInternet: FIREFOX.EXE - D:\Program Files (x86)\firefox.exe hxxp://www.so-v.com/?type=ll&uid=b63a5fae-7400-4c81-aca0-4ab4ed43991a
    CHR HomePage: Default -> hxxp://www.yoursites123.com/?type=hp&ts=1...0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA
    CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1458810963&z=723d543194645e308a0e064g5zdw0b5bfg4g6geq4m&from=wpm0314&uid=ST9320325AS_6VD9J5FAXXXX6VD9J5FA"
    CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <nie znaleziono>
    S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
    S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X]
    S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
    S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
    S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
    S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
    S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [X]
    S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
    S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
    S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
    S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
    S1 lnzrpmiu; \??\C:\Windows\system32\drivers\lnzrpmiu.sys [X]
    U3 tmlwf; Brak ImagePath
    U3 tmwfp; Brak ImagePath
    2016-03-29 17:56 - 2016-03-29 17:56 - 00000518 _____ C:\so-v.xml
    2016-03-24 11:16 - 2016-03-24 11:16 - 00000633 _____ C:\yoursites123.xml

    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść w folderze C:\Users\Maks\Downloads\
    Uruchom FRST i kliknij w Fix/Napraw.

    1
  • #4 30 Mar 2016 12:22
    Kolobos
    Spec od komputerów

    Tego nie usuwaj:
    R2 Everything; C:\Program Files (x86)\Everything\Everything.exe [1048576 2014-08-06] () [Brak podpisu cyfrowego] <==== UWAGA
    To tez zbedne w fixlist:
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe

    2
  • #5 30 Mar 2016 12:57
    maxiorm
    Poziom 3  

    Serdecznie dziękuję za pomoc.
    Pomogło.
    Wielki dzięki.:)

    Pozdrawiam.

    0
  • #6 30 Mar 2016 13:23
    Domino_2
    Pomocny dla użytkowników

    Możesz skasować folder C:\FRST.

    0
  • #7 30 Mar 2016 13:32
    maxiorm
    Poziom 3  

    Zrobione. Jeszcze raz wielkie dzięki!:)
    Jak usunąć so-v.com? Prośba o fixlistę.

    0