Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

S.piesearch.com - Nie mogę usunąć tego z Chrome.

marchelmx 27 Kwi 2016 13:25 876 3
  • #1 27 Kwi 2016 13:25
    marchelmx
    Poziom 2  

    Witam, jak w temacie, nie mogę tego usunąć. Dotychczas zrobiłem:
    - skanowanie Malwarebyte
    - skanowanie ADWCleaner
    - skanowanie zainstalowanym Avastem

    Wszystkie znalezione przez w/w programy zagrożenia usunąłem. W załączniku przesyłam pliki z FRST.

    0 3
  • Pomocny post
    #2 27 Kwi 2016 14:00
    krzychupar
    Poziom 40  

    Otwórz notatnik i wklej:
    HKLM-x32\...\Run: [RFX_auto_upgrade] => [X]
    HKLM-x32\...\Run: [] => [X]
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd)
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {010de942-d340-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {010de96a-d340-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {010de996-d340-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {010dedd9-d340-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {0ce6117b-84ed-11e3-be99-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {11af2cdd-ad55-11e5-807b-c0143dd40a43} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {11af2d42-ad55-11e5-807b-c0143dd40a43} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {11af2d79-ad55-11e5-807b-c0143dd40a43} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {11af2e0e-ad55-11e5-807b-c0143dd40a43} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {11af2e38-ad55-11e5-807b-c0143dd40a43} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {11af2f4f-ad55-11e5-807b-abd93caeaeed} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {13b9cfc9-a654-11e5-8077-85fae25c786b} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {13b9d008-a654-11e5-8077-85fae25c786b} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {1e4fab53-a9f9-11e5-807a-99b14d162989} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {1e4faccc-a9f9-11e5-807a-99b14d162989} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {1e4fbe33-a9f9-11e5-807a-99b14d162989} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {1e4fbe5c-a9f9-11e5-807a-99b14d162989} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {257e9072-9bb7-11e2-be77-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {4a4beeb6-81cd-11e3-be99-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7161bc54-efb9-11e5-808c-bec547d1712b} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7161ce40-efb9-11e5-808c-bec547d1712b} - "F:\AutoRun.exe"




    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {73d43f5c-7b95-11e3-be95-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {73d43f93-7b95-11e3-be95-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7b0beb05-d2e7-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7b0beb51-d2e7-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7b0beb71-d2e7-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7b0bec3d-d2e7-11e5-8087-a9fc206e5e7f} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7f063d98-b6d6-11e2-be79-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7f063dca-b6d6-11e2-be79-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {7f064ecf-b6d6-11e2-be79-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {a8b78354-8799-11e2-be74-c0143dd40a44} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {b0cc994a-abdb-11e5-807a-99b14d162989} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {b0ccbc1d-abdb-11e5-807a-99b14d162989} - "F:\AutoRun.exe"
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\...\MountPoints2: {d06d234a-c7e8-11e5-8083-e8bc1c0f8cf6} - "F:\AutoRun.exe"
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
    HKU\S-1-5-21-1538701862-1188691642-2677981732-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
    SearchScopes: HKU\S-1-5-21-1538701862-1188691642-2677981732-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
    SearchScopes: HKU\S-1-5-21-1538701862-1188691642-2677981732-1001 -> {CBE94256-006C-42BC-8A10-263D2901BD3B} URL = hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox
    Toolbar: HKLM - Brak nazwy - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Brak pliku
    Toolbar: HKLM - Brak nazwy - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Brak pliku
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => nie znaleziono
    2016-04-26 15:56 - 2016-04-27 11:27 - 00000000 ____D C:\AdwCleaner
    2016-04-24 16:58 - 2016-04-24 16:58 - 00000266 __RSH C:\ProgramData\ntuser.pol
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść w folderze gdzie znajduje się FRST.exe
    Uruchom FRST i kliknij w Fix/Napraw.

    0
  • #3 27 Kwi 2016 14:16
    marchelmx
    Poziom 2  

    Działa. Dziękuję za pomoc.

    Temat do zamknięcia.

    0
  • #4 27 Kwi 2016 15:11
    RADU23
    Moderator - Komputery Serwis

    Usuń folder C:\FRST i to wszystko.
    S.piesearch.com - Nie mogę usunąć tego z Chrome.

    0