Elektroda.pl
Elektroda.pl
X

Search our partners

Find the latest content on electronic components. Datasheets.com
Elektroda.pl
Please add exception to AdBlock for elektroda.pl.
If you watch the ads, you support portal and users.

Reklamy Price Fountain - jak usunąć?

Lukarek1988 21 May 2016 21:52 705 2
  • #1
    Lukarek1988
    Level 2  
    Hej.
    Mój siostrzeniec dorwał się do komputera i zainstalował mnóstwo dziwnych rzeczy i od tamtej pory nie działa mi Allegro na żadnej przeglądarce (Chrome, FF, IE). Czy ktoś może mi pomóc?:)
    Poprawiłem. swiercm.
  • Helpful post
    #2
    Kolobos
    IT specialist
    Odinstaluj: Java(TM) 6 Update 20
    Zainstaluj http://ninite.com/java/

    Wykonaj Fixlist.txt dla FRST:
    Task: {01EE7DCB-60FF-4DDA-B191-CC9C954D3507} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-16] ()
    Task: {0CBE1AA8-B8AB-47B7-87A7-763F5A671454} - System32\Tasks\WandaNonpayingInstantsV2 => Rundll32.exe OtologistDocumenter.dll,main 7 1 <==== UWAGA
    Task: {10121743-CACF-4660-8E99-61BF989063FD} - System32\Tasks\{B8C020F0-2156-4E79-847D-10B9939466DB} => Firefox.exe
    Task: {6BAEF420-64CC-4E2A-9DCA-5B24D0E9637F} - System32\Tasks\{5BCE752B-80AF-4AC9-98C9-EF046DEE19A3} => Firefox.exe
    Task: {B27F34E0-6A46-4A5A-8565-00574EC5F2BC} - System32\Tasks\{9E6D2D65-F6E1-4AAC-9999-42920CB3EDFA} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{5E6F6CF3-BACC-4144-868C-E14622C658F3}\setup.exe" -c -runfromtemp -l0x0015 -removeonly
    Task: {B4FF9A1B-828F-41F4-A8F4-0C03F6391A3F} - System32\Tasks\{1AE72FF6-99CC-4CC6-9E2F-839AEC166DE2} => Firefox.exe hxxp://ui.skype.com/ui/0/6.1.59.129/pl/abandoninstall?page=tsProgressBar
    Task: {E0E3D11E-E089-4B8F-B780-CDC3FE4BBC57} - System32\Tasks\{AD3BBA9F-54CF-4772-8898-1DBFF206076E} => Firefox.exe hxxp://ui.skype.com/ui/0/5.5.0.124.259/pl/aba...cluded,google-chrome:notoffered;disabled
    Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
    HKLM-x32\...\Run: [] => [X]
    SearchScopes: HKU\S-1-5-21-1532088769-3263117296-3807043853-1000 -> {0EED3774-6293-4C1C-8269-E4E74D386CE3} URL = hxxp://rover.ebay.com/rover/1/4908-44618-9400-8/4?satitle={searchTerms}
    SearchScopes: HKU\S-1-5-21-1532088769-3263117296-3807043853-1000 -> {9BD116D0-2F16-4515-BFA8-BB9CB31BF8A3} URL = hxxp://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Brak pliku
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\findit.xml [2016-03-09]
    FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2014-10-07]
    CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx
    S3 dump_wmimmc; \??\C:\AeriaGames\WolfTeam-PL\GameGuard\dump_wmimmc.sys [X]
    2016-05-10 19:27 - 2016-05-10 19:27 - 00002968 _____ C:\Windows\System32\Tasks\{5BCE752B-80AF-4AC9-98C9-EF046DEE19A3}
    2016-05-10 19:22 - 2016-05-10 19:22 - 00002968 _____ C:\Windows\System32\Tasks\{B8C020F0-2156-4E79-847D-10B9939466DB}
    2016-03-06 17:38 - 2016-03-06 17:38 - 8037888 _____ () C:\Users\Wanda\AppData\Roaming\agent.dat
    2016-03-06 17:38 - 2016-03-06 17:38 - 0065040 _____ () C:\Users\Wanda\AppData\Roaming\Config.xml
    2016-03-06 17:38 - 2016-03-06 17:38 - 0011424 _____ () C:\Users\Wanda\AppData\Roaming\InstallationConfiguration.xml
    2016-03-06 17:38 - 2016-03-06 17:38 - 0127488 _____ () C:\Users\Wanda\AppData\Roaming\Installer.dat
    2016-03-06 17:38 - 2016-03-06 17:37 - 0769024 _____ () C:\Users\Wanda\AppData\Roaming\K-ron.exe
    2016-03-06 17:38 - 2016-03-06 17:38 - 1901977 _____ () C:\Users\Wanda\AppData\Roaming\K-ron.tst
    2016-03-06 17:38 - 2016-03-06 17:38 - 0018432 _____ () C:\Users\Wanda\AppData\Roaming\Main.dat
    2016-03-06 17:38 - 2016-03-06 17:38 - 0005568 _____ () C:\Users\Wanda\AppData\Roaming\md.xml
    2016-03-06 17:38 - 2016-03-06 17:38 - 0126464 _____ () C:\Users\Wanda\AppData\Roaming\noah.dat
    2016-03-06 17:38 - 2016-03-06 17:38 - 0032038 _____ () C:\Users\Wanda\AppData\Roaming\uninstall_temp.ico
    EmptyTemp:

    Po wykonaniu usun katalog C:\FRST.

    Zrob pelny skan przy pomocy Mbam i usun to co wykryje:
    http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/
  • #3
    Lukarek1988
    Level 2  
    Super, już wszystko działa bez problemu :) Bardzo dziękuję za pomoc :)