Elektroda.pl
Elektroda.pl
X
CControls
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Booking.com i allegro.pl-jak to usunąć?

Valdemarus83 12 Sie 2016 17:15 1794 2
  • CControls
  • Pomocny post
    #2 12 Sie 2016 17:40
    Kolobos
    Spec od komputerów

    Nie pobieraj programow z dobrychprogramow przy pomocy ich menadzera pobierania, ktory instaluje szkodliwe dodatki. Pobieraj tylko z bezposrednich linkow.

    Uzyj AdwCleaner, opcja Scan i Clean/Szukaj i Usun: http://www.bleepingcomputer.com/download/adwcleaner/

    Odinstaluj:
    PriceFountain
    TuneUp Utilities 2012
    Update for PriceFountain

    Obok frst.exe utworz plik Fixlist.txt z zawartoscia:
    Task: {176CD269-CDD5-4AF5-8C76-081EF0091F98} - System32\Tasks\Valdemarus999AmberySpineV2 => Rundll32.exe TopographicMyocardial.dll,main 7 1 <==== UWAGA
    Task: {80C4812D-4A5C-48FA-8AAE-BE1B8A74F85D} - System32\Tasks\LuckyBrowse => C:\Program Files (x86)\LuckyBrowse\app\luckybrowse.exe <==== UWAGA
    Task: {8AB1C60B-2F8E-4A4F-A5BC-6594BEBC2293} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2012-05-29] (TuneUp Software)
    Task: {8DC672B1-F080-41C7-B91E-CACDFD45211D} - System32\Tasks\Opera scheduled Autoupdate 1459025195 => C:\Program Files (x86)\Opera\launcher.exe [2016-08-03] (Opera Software)
    Task: {D51E47BF-A71A-426E-A3EC-3EA78BB0B3EC} - \Program aktualizacji online firmy Adobe. -> Brak pliku <==== UWAGA
    ShortcutWithArgument: C:\Users\Valdemarus999\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://esurf.biz/?ssid=1452983228&a=1024132&src=sh&uuid=23b46654-af06-43cb-b5d9-f7fb2af336d5"
    ShortcutWithArgument: C:\Users\Valdemarus999\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk -> C:\Users\Valdemarus999\AppData\Roaming\WarThunder\wt.ico () -> hxxp://mmotraffic.com/catalog/goplay/1000932/MTE3NjYvLy8xMDAwOTMy/
    ShortcutWithArgument: C:\Users\Valdemarus999\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://esurf.biz/?ssid=1452983228&a=1024132&src=sh&uuid=23b46654-af06-43cb-b5d9-f7fb2af336d5"
    ShortcutWithArgument: C:\Users\Valdemarus999\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://esurf.biz/?ssid=1452983228&a=1024132&src=sh&uuid=23b46654-af06-43cb-b5d9-f7fb2af336d5"
    ShortcutWithArgument: C:\Users\Valdemarus999\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Users\Valdemarus999\AppData\Roaming\WarThunder\wt.ico () -> hxxp://mmotraffic.com/catalog/goplay/1000932/MTE3NjYvLy8xMDAwOTMy/




    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {0137a91a-862e-11e4-855c-80eb35773521} - J:\setup.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {2483a53e-9586-11e4-b637-448a5ba29304} - E:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {2b409990-8635-11e4-a4bf-448a5ba29304} - E:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {36a73b14-a0a3-11e4-9322-448a5ba29304} - E:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {3b473d16-f391-11e5-908f-448a5ba29304} - E:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {3b473d24-f391-11e5-908f-448a5ba29304} - F:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {431bbddb-00aa-11e5-b1f5-448a5ba29304} - F:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {616fcad9-a22a-11e4-8d14-448a5ba29304} - F:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {8dd5aedd-b2df-11e4-aa97-448a5ba29304} - E:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {9766d179-8624-11e4-8771-9bb75c0f6652} - H:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {9766d1b2-8624-11e4-8771-9bb75c0f6652} - H:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {9bfcc164-b15f-11e4-98fb-448a5ba29304} - F:\AutoRun.exe
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\...\MountPoints2: {db2d43f3-8960-11e4-b7ac-448a5ba29304} - E:\AutoRun.exe
    HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-12-23] (Microsoft Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk [2014-12-17]
    ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe ()
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    AutoConfigURL: [S-1-5-21-3374997123-4250737858-3742662734-1000] => hxxp://unstopp.me/wpad.dat?f4ce55290e8942c1d76c52461b6a5bc94422440
    ManualProxies: 0hxxp://unstopp.me/wpad.dat?f4ce55290e8942c1d76c52461b6a5bc94422440
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hp&ts=143...rnl&uid=SanDiskXSDSSDHII120G_143635403992
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hp&ts=143...rnl&uid=SanDiskXSDSSDHII120G_143635403992
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hp&ts=143...rnl&uid=SanDiskXSDSSDHII120G_143635403992
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hp&ts=143...rnl&uid=SanDiskXSDSSDHII120G_143635403992
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE07&ocid=UE07DHP
    HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hp&ts=143...rnl&uid=SanDiskXSDSSDHII120G_143635403992
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3374997123-4250737858-3742662734-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://isearch.omiga-plus.com/web/?utm_source...992&ts=1422549437&type=default&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3374997123-4250737858-3742662734-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts...;uid=SanDiskXSDSSDHII120G_143635403992&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3374997123-4250737858-3742662734-1000 -> {cf34d395-9ff1-49a0-98a5-8db1636431b1} URL = hxxp://houmpage.com/search/?src=ds&q={searchTerms}&ssid=1450732751&a=1004256&uuid=1ca6be13-8786-449d-a39f-3f44a4d4dbca
    SearchScopes: HKU\S-1-5-21-3374997123-4250737858-3742662734-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://isearch.omiga-plus.com/web/?utm_source...992&ts=1422549437&type=default&q={searchTerms}
    Handler: WSAMVCUchrome - Brak wartości CLSID
    FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Valdemarus999\AppData\Roaming\Mozilla\Firefox\Profiles\07akfx0b.default\extensions\defsearchp@gmail.com => nie znaleziono
    FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Valdemarus999\AppData\Roaming\Mozilla\Firefox\Profiles\07akfx0b.default\extensions\deskCutv2@gmail.com => nie znaleziono
    CHR HKU\S-1-5-21-3374997123-4250737858-3742662734-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efhdjkbfpoohkmfaldijcpbnmbpefpkb] - C:\Program Files (x86)\ALLPlayer\AllPlayer.crx <nie znaleziono>
    CHR HKLM-x32\...\Chrome\Extension: [efhdjkbfpoohkmfaldijcpbnmbpefpkb] - C:\Program Files (x86)\ALLPlayer\AllPlayer.crx <nie znaleziono>
    OPR Extension: (Discover Treasure) - C:\Users\Valdemarus999\AppData\Roaming\Opera Software\Opera Stable\Extensions\gdonjefppfjocdidacpemibdhbfaolhe [2015-12-21]
    OPR Extension: (Adblock Fast) - C:\Users\Valdemarus999\AppData\Roaming\Opera Software\Opera Stable\Extensions\klhobddcbiabdfjmomildokiglpmdicc [2016-05-07]
    OPR Extension: (Adblock Plus) - C:\Users\Valdemarus999\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-06-30]
    OPR Extension: (Bookmarks Import & Export) - C:\Users\Valdemarus999\AppData\Roaming\Opera Software\Opera Stable\Extensions\omhcddilnfoiiplehpjihipcocdplljn [2016-03-25]
    S2 2df638ba; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\LibraryApps\LibraryApps.dll",serv
    S2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [X]
    S2 Update ace race; "C:\Program Files (x86)\ace race\updateacerace.exe" [X]
    S2 Util ace race; "C:\Program Files (x86)\ace race\bin\utilacerace.exe" [X]
    S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-03-09] ()
    S3 MSICDSetup; \??\D:\CDriver64.sys [X]
    S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
    S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
    S3 VGPU; System32\drivers\rdvgkmd.sys [X]
    2016-08-12 15:43 - 2016-08-12 15:42 - 00975904 _____ (Cutelecod ) C:\Users\Valdemarus999\Downloads\Free-Audio-CD-to-MP3-Converter-48820-dp.exe
    2016-08-05 15:35 - 2016-03-26 22:46 - 00003900 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1459025195
    EmptyTemp:

    W FRST wybierz Napraw.

    Skroty do booking.com i allegro! usun, nie widac ich w logu.

    0
  • CControls
  • #3 12 Sie 2016 18:02
    Valdemarus83
    Poziom 3  

    Dzięki Ci wielkie. ;)
    Booking.com i allegro.pl-jak to usunąć?

    0