Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Złośliwe oprogramowanie - hohosearch

sarcatiel2 17 Maj 2016 11:57 693 3
  • #1 17 Maj 2016 11:57
    sarcatiel2
    Poziom 2  

    Dzień dobry

    Złapałem jakiegoś babola, który przestawia mi domyślne wyszukiwarki na chrome oraz firefox, dodaje banery z reklamami oraz ogólnie spowolnił działanie przeglądarek. Zamieszczam pliki po skanie FRST. Proszę o pomoc

    0 3
  • CControls
  • #2 17 Maj 2016 12:19
    Domino_2
    Pomocny dla użytkowników

    Odinstaluj qksee i YAC(Yet Another Cleaner!).

    Cytat:

    Task: {05999150-0484-488B-B708-390E23B78BDD} - System32\Tasks\{143478CD-5FD9-42E8-ACA8-6EE7AFCB6AAF} => C:\Users\hp\Desktop\mega\SETUP.EXE
    Task: {1FC5064F-8660-4CBE-8FA8-2D467C3BB8DA} - System32\Tasks\{0F47BCC7-BA83-46F0-9DE3-6918F596136E} => Chrome.exe hxxp://www.skype.com/go/downloading?source=li...amp;amp;ver=6.22.81.105&LastError=404
    Task: {AA2760A6-F4D0-4C14-91FA-3197F9EEFD79} - System32\Tasks\Browser Updater Task(Core) => C:\Program Files (x86)\QQBrowser\Update\92F98F289D0EAEDB2BDE5D6123144390\Update\BrowserUpdate.exe [2016-04-25] (Tencent) <==== UWAGA
    Task: {C211889E-1203-4986-8DA4-581DFA861DC7} - System32\Tasks\{007490E9-A4D5-4A2C-BF74-A6A2E2232AC5} => Chrome.exe hxxp://ui.skype.com/ui/0/7.2.0.103/pl/abandoninstall?page=tsBing
    Task: {C86FD570-C188-48E2-B3D5-B526E09979A2} - System32\Tasks\{92EAA194-B358-42D0-8772-F84EB650E018} => pcalua.exe -a C:\Users\hp\Desktop\VCR446Free.exe -d C:\Users\hp\Desktop
    Task: {F0F26CD6-C619-46FC-B899-4644D1EF99D0} - System32\Tasks\Nekatynufoch Configuration => C:\Program Files (x86)\Nekatynufoch\nekatynufochconfigurationtask.exe [2016-05-02] () <==== UWAGA
    Task: {FE6BA95D-0A80-4EF0-897F-63A2BBF0043D} - System32\Tasks\{7F1275E5-E660-4E19-8F04-83ECF18CF706} => Chrome.exe hxxp://www.skype.com/go/downloading?source=li...amp;amp;ver=6.22.81.105&amp;LastError=404
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    HKU\S-1-5-21-1023320188-2119989331-2487285016-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    FF NewTab: hxxp://www.nicesearches.com?type=hp&ts=14...;z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c




    FF DefaultSearchEngine: hohosearch
    FF DefaultSearchEngine.US: data:text/plain,browser.search.defaultenginename.US=hohosearch
    FF Homepage: hxxp://www.nicesearches.com?type=hp&ts=14...;z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c
    FF Keyword.URL: hxxp://www.hohosearch.com/chrome.php?uid=92F9....&v=20160501&mode=ffexttoolbar&q=
    FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
    FF SearchPlugin: C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-05-02]
    FF Extension: xRocket Toolbar - C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\oprhcc43.default\Extensions\arthurj8283@gmail.com [2016-05-09] [Brak podpisu cyfrowego]
    FF Extension: GsearchFinder - C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [2016-05-02]
    FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\oprhcc43.default\extensions\arthurj8283@gmail.com
    CHR HomePage: Profile 1 -> hxxp://www.nicesearches.com?type=hp&ts=14...;z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c
    CHR StartupUrls: Profile 1 -> "hxxp://www.nicesearches.com?type=hp&ts=1462773152&from=87640509&uid=kingstonxsv300s37a120g_50026b77480d71ac&z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c"
    CHR DefaultSearchURL: Profile 1 -> hxxp://www.nicesearches.com/search.php?type=d...a6106da4f198a299efbg6zdq0odm6mac1g6w0c&q={searchTerms}
    CHR DefaultSearchKeyword: Profile 1 -> nice
    CHR Plugin: (Widevine Content Decryption Module) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll => Brak pliku
    R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2016-05-03] (Elex do Brasil Participações Ltda)
    S2 Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [X]
    S2 serveras; C:\Users\hp\AppData\Roaming\ASPackage\ASSrv.exe [X]
    R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [262344 2016-05-03] (Elex do Brasil Participações Ltda)
    S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [55056 2016-05-03] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [110112 2016-05-03] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlMon; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [52440 2016-04-08] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [103904 2016-05-03] (Elex do Brasil Participações Ltda)
    R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [52392 2015-06-30] (Elex do Brasil Participações Ltda)
    S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
    2016-05-17 11:49 - 2016-05-17 11:49 - 00000000 ____D C:\Users\hp\Downloads\FRST-OlderVersion
    2016-05-05 12:50 - 2016-05-03 11:15 - 00055056 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
    2016-05-05 12:50 - 2015-06-30 04:50 - 00052392 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
    2016-05-04 08:42 - 2016-05-13 12:09 - 00000000 ____D C:\ProgramData\MwinpM
    2016-05-04 08:42 - 2016-05-13 11:59 - 00000001 _____ C:\Windows\SysWOW64\pl.html
    2016-05-04 08:42 - 2016-05-05 12:49 - 00000000 ____D C:\Users\hp\AppData\Roaming\WinZiper
    2016-05-04 08:42 - 2016-05-04 08:42 - 00000000 ____D C:\Program Files (x86)\QQBrowser
    EmptyTemp:


    Wklej to do notatnika i zapisz pod nazwą fixlist.txt i umieść w folderze gdzie znajduje się plik FRST.exe/FRST64.exe, odpal go i kliknij Fix/Napraw.

    0
  • CControls
  • #3 17 Maj 2016 12:19
    Kolobos
    Spec od komputerów

    Odinstaluj:
    qksee
    YAC(Yet Another Cleaner!)

    Zainstaluj aktualizacje z https://support.microsoft.com/pl-pl/kb/2545227

    Obok frst.exe utworz plik fixlist.txt z zawartoscia:
    Task: {05999150-0484-488B-B708-390E23B78BDD} - System32\Tasks\{143478CD-5FD9-42E8-ACA8-6EE7AFCB6AAF} => C:\Users\hp\Desktop\mega\SETUP.EXE
    Task: {1FC5064F-8660-4CBE-8FA8-2D467C3BB8DA} - System32\Tasks\{0F47BCC7-BA83-46F0-9DE3-6918F596136E} => Chrome.exe hxxp://www.skype.com/go/downloading?source=li...amp;amp;ver=6.22.81.105&amp;LastError=404
    Task: {AA2760A6-F4D0-4C14-91FA-3197F9EEFD79} - System32\Tasks\Browser Updater Task(Core) => C:\Program Files (x86)\QQBrowser\Update\92F98F289D0EAEDB2BDE5D6123144390\Update\BrowserUpdate.exe [2016-04-25] (Tencent) <==== UWAGA
    Task: {C211889E-1203-4986-8DA4-581DFA861DC7} - System32\Tasks\{007490E9-A4D5-4A2C-BF74-A6A2E2232AC5} => Chrome.exe hxxp://ui.skype.com/ui/0/7.2.0.103/pl/abandoninstall?page=tsBing
    Task: {C86FD570-C188-48E2-B3D5-B526E09979A2} - System32\Tasks\{92EAA194-B358-42D0-8772-F84EB650E018} => pcalua.exe -a C:\Users\hp\Desktop\VCR446Free.exe -d C:\Users\hp\Desktop
    Task: {F0F26CD6-C619-46FC-B899-4644D1EF99D0} - System32\Tasks\Nekatynufoch Configuration => C:\Program Files (x86)\Nekatynufoch\nekatynufochconfigurationtask.exe [2016-05-02] () <==== UWAGA
    Task: {FE6BA95D-0A80-4EF0-897F-63A2BBF0043D} - System32\Tasks\{7F1275E5-E660-4E19-8F04-83ECF18CF706} => Chrome.exe hxxp://www.skype.com/go/downloading?source=li...amp;amp;ver=6.22.81.105&amp;LastError=404
    Shortcut: C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe (Google Inc.)
    Shortcut: C:\Users\hp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe (Google Inc.)
    Shortcut: C:\Users\hp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk -> C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe (Google Inc.)
    Shortcut: C:\Users\hp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe (Google Inc.)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe (Google Inc.)
    2016-05-05 12:50 - 2016-05-05 08:43 - 00303008 _____ () C:\ProgramData\eeaUDOiyy\protect\protect.exe
    2016-05-05 12:50 - 2016-05-03 11:12 - 00065696 _____ () C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll
    2016-05-05 12:50 - 2015-06-30 04:50 - 00176976 _____ () C:\Program Files (x86)\Elex-tech\YAC\tws\unrar.dll
    2016-05-05 12:50 - 2015-06-30 04:50 - 00087744 _____ () C:\Program Files (x86)\Elex-tech\YAC\tws\unacev2.dll
    2016-05-04 08:42 - 2016-02-15 04:21 - 00582144 _____ () C:\Program Files (x86)\qksee\curlpp.dll
    2016-05-04 08:42 - 2016-05-03 04:32 - 00065816 _____ () C:\Program Files (x86)\qksee\zlib1.dll
    2016-05-05 12:50 - 2016-05-03 11:12 - 00179200 _____ () C:\Program Files (x86)\Elex-tech\YAC\libpng.dll
    2016-05-05 12:50 - 2016-05-05 08:43 - 01708448 _____ () C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\libglesv2.dll
    2016-05-05 12:50 - 2016-05-05 08:43 - 00080288 _____ () C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\libegl.dll
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
    (Qksee Pvt Ltd.) C:\Program Files (x86)\qksee\qkseeSvc.exe
    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
    () C:\ProgramData\eeaUDOiyy\protect\protect.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    (Google Inc.) C:\Program Files (x86)\eeaUDOiyy\eeaUDOiyy\chrome.exe
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    HKU\S-1-5-21-1023320188-2119989331-2487285016-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
    FF NewTab: hxxp://www.nicesearches.com?type=hp&ts=14...;z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c
    FF DefaultSearchEngine: hohosearch
    FF DefaultSearchEngine.US: data:text/plain,browser.search.defaultenginename.US=hohosearch
    FF Homepage: hxxp://www.nicesearches.com?type=hp&ts=14...;z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c
    FF Keyword.URL: hxxp://www.hohosearch.com/chrome.php?uid=92F9....&v=20160501&mode=ffexttoolbar&q=
    FF SearchPlugin: C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-05-02]
    FF Extension: xRocket Toolbar - C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\oprhcc43.default\Extensions\arthurj8283@gmail.com [2016-05-09] [Brak podpisu cyfrowego]
    FF Extension: GsearchFinder - C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [2016-05-02]
    FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\oprhcc43.default\extensions\arthurj8283@gmail.com
    CHR HomePage: Profile 1 -> hxxp://www.nicesearches.com?type=hp&ts=14...;z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c
    CHR StartupUrls: Profile 1 -> "hxxp://www.nicesearches.com?type=hp&ts=1462773152&from=87640509&uid=kingstonxsv300s37a120g_50026b77480d71ac&z=6cb5a6106da4f198a299efbg6zdq0odm6mac1g6w0c"
    CHR DefaultSearchURL: Profile 1 -> hxxp://www.nicesearches.com/search.php?type=d...a6106da4f198a299efbg6zdq0odm6mac1g6w0c&q={searchTerms}
    CHR Extension: (Ask Search) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl [2015-07-03]
    CHR Extension: (iLivid) - C:\Users\hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf [2015-07-03]
    R2 eeaUDOiyy_protect; C:\ProgramData\eeaUDOiyy\protect\protect.exe [303008 2016-05-05] ()
    R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2016-05-03] (Elex do Brasil Participações Ltda)
    S2 nekatynufochconfigurationservice; C:\Program Files (x86)\Nekatynufoch\nekatynufochconfigurationservice.exe [299264 2016-05-02] ()
    R2 qkseeService; C:\Program Files (x86)\qksee\qkseeSvc.exe [751384 2016-05-03] (Qksee Pvt Ltd.)
    S2 Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [X]
    S2 serveras; C:\Users\hp\AppData\Roaming\ASPackage\ASSrv.exe [X]
    R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [262344 2016-05-03] (Elex do Brasil Participações Ltda)
    S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [55056 2016-05-03] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [110112 2016-05-03] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlMon; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [52440 2016-04-08] (Elex do Brasil Participações Ltda)
    R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [103904 2016-05-03] (Elex do Brasil Participações Ltda)
    R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [52392 2015-06-30] (Elex do Brasil Participações Ltda)
    S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
    2016-05-17 11:49 - 2016-05-17 11:49 - 00000000 ____D C:\Users\hp\Downloads\FRST-OlderVersion
    2016-05-05 12:51 - 2016-05-05 12:51 - 00000000 ____D C:\ProgramData\eeaUDOiyy
    2016-05-05 12:50 - 2016-05-13 14:01 - 00000000 ____D C:\Program Files (x86)\eeaUDOiyy
    2016-05-05 12:50 - 2016-05-05 12:50 - 00000000 ____D C:\Users\Public\Documents\eeaUDOiyy
    2016-05-05 12:50 - 2016-05-05 12:50 - 00000000 ____D C:\Users\hp\AppData\Roaming\Elex-tech
    2016-05-05 12:50 - 2016-05-05 12:50 - 00000000 ____D C:\Users\hp\AppData\Local\eeaUDOiyy
    2016-05-05 12:50 - 2016-05-05 12:50 - 00000000 ____D C:\Program Files (x86)\Elex-tech
    2016-05-05 12:50 - 2016-05-03 11:15 - 00055056 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
    2016-05-05 12:50 - 2015-06-30 04:50 - 00052392 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
    2016-05-04 08:42 - 2016-05-17 08:54 - 00000000 ____D C:\Program Files (x86)\qksee
    2016-05-04 08:42 - 2016-05-13 12:09 - 00000000 ____D C:\ProgramData\MwinpM
    2016-05-04 08:42 - 2016-05-13 11:59 - 00000001 _____ C:\Windows\SysWOW64\pl.html
    2016-05-04 08:42 - 2016-05-06 12:15 - 00000000 ____D C:\Users\hp\AppData\Roaming\eCyber
    2016-05-04 08:42 - 2016-05-05 12:49 - 00000000 ____D C:\Users\hp\AppData\Roaming\WinZiper
    2016-05-04 08:42 - 2016-05-04 08:42 - 00009426 _____ C:\Windows\System32\Tasks\Browser Updater Task(Core)
    2016-05-04 08:42 - 2016-05-04 08:42 - 00000000 ____D C:\Users\hp\AppData\Roaming\qksee
    2016-05-04 08:42 - 2016-05-04 08:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
    2016-05-04 08:42 - 2016-05-04 08:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qksee
    2016-05-04 08:42 - 2016-05-04 08:42 - 00000000 ____D C:\Program Files (x86)\QQBrowser
    2016-05-02 18:41 - 2016-05-05 08:49 - 00000000 ____D C:\Program Files (x86)\hohobnd
    2016-05-02 18:41 - 2016-05-02 18:42 - 00000000 ____D C:\Users\hp\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
    2016-05-02 18:41 - 2016-05-02 18:41 - 00009084 _____ C:\Windows\System32\Tasks\Nekatynufoch Configuration
    2016-05-02 18:41 - 2016-05-02 18:41 - 00000000 ____D C:\Program Files (x86)\Nekatynufoch
    2016-05-02 18:35 - 2016-05-02 18:35 - 02619605 _____ C:\Windows\chromebrowser.exe
    2016-04-18 13:35 - 2016-04-18 13:35 - 00000000 ____D C:\Users\hp\AppData\Roaming\PeerNetworking
    EmptyTemp:

    W FRST wybierz Napraw.

    Usun katalog C:\FRST.

    Uzyj http://www.bleepingcomputer.com/download/adwcleaner/ opcja Szukaj i Usun.
    Do tego pelny skan przy pomocy http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ i rowniez usun to co wykryje.

    0
  • #4 17 Maj 2016 12:37
    sarcatiel2
    Poziom 2  

    Dziękuję Panowie, pomogło

    0