Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Znów wyświetla mi się reklama co jakiś czas, dokładnie z opisem kasyna.

CzaSzkA1234 13 Maj 2017 19:29 411 1
  • Pomocny post
    #2 13 Maj 2017 20:02
    Kolobos
    Spec od komputerów

    Obok frst.exe utworz plik Fixlist.txt z zawartoscia:
    Task: {0CF30404-EAFA-47CC-9646-1078451A802E} - System32\Tasks\{13D7ABFE-050B-4E4A-96BC-12AB8B3273C7} => pcalua.exe -a K:\setup.exe -d K:\
    Task: {2E1FC857-B67F-436E-B9E5-D2E6B4BBC61C} - System32\Tasks\{B5924547-7ACB-4E0C-A5C5-8BE8C652AF0F} => pcalua.exe -a "D:\call of duty\Call of Duty - Black Ops\Redist\vcredist_x86.exe" -d "D:\call of duty\Call of Duty - Black Ops\Redist"
    Task: {63C8A518-CEEE-4466-9B3C-AB7FCA6B77A2} - System32\Tasks\{42F6C9C4-8296-41EE-919D-98FEFB34F3CB} => pcalua.exe -a H:\Support\VCRedist\vcredist_x86.exe -d H:\Support\VCRedist
    Task: {82A9A2D1-E827-43D7-9F8E-333F2BE64E92} - System32\Tasks\{7CE9466C-1AB0-4A1A-A6F7-0DBF70D10C3A} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{C40C3C3D-97CF-44B5-836C-766E374464B3}\setup.exe" -c -runfromtemp -l0x0009 -removeonly
    Task: {8753B5D9-6BC6-4873-B645-B1E7A3EDD84E} - System32\Tasks\free1newsnetxzxcsm => Firefox.exe free1news.net/xzxcsm <==== UWAGA
    Task: {B1441220-358B-49EE-AC29-12D22BB948C1} - System32\Tasks\{82829BE0-78D3-4558-BF79-924225ADFD82} => pcalua.exe -a "E:\SteamLibrary\SteamApps\common\Assassin's Creed 2\redist\GameLauncher\UbisoftGameLauncherInstaller.exe" -d "E:\SteamLibrary\SteamApps\common\Assassin's Creed 2\redist\GameLauncher"
    ShortcutWithArgument: C:\Users\Hania Karol\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> url,FileProtocolHandler "hxxp://www.mail.ru/cnt/20775012?gp=811035"
    (© 2015 Microsoft Corporation) C:\Users\Hania Karol\AppData\Local\Microsoft\BingSvc\BingSvc.exe
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\Run: [BingSvc] => C:\Users\Hania Karol\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-12] (© 2015 Microsoft Corporation)
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: H - H:\LaunchU3.exe -a
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: J - J:\autorun.exe
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: K - K:\setup\rsrc\Autorun.exe
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {349771f9-94c4-11e3-a3c5-001a4d9eb045} - H:\LaunchU3.exe -a
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {36daeca3-08fb-11e4-a43d-001a4d9eb045} - H:\Startme.exe
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {36daeca9-08fb-11e4-a43d-001a4d9eb045} - I:\Startme.exe
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {a5da29da-3d7c-11e3-8125-001a4d9eb045} - K:\setup.exe
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {a5da29de-3d7c-11e3-8125-001a4d9eb045} - I:\Setup.exe "1, NecroVisioN, 1C Publishing EU"
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {a5da29e2-3d7c-11e3-8125-001a4d9eb045} - L:\setup.exe
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {a5da29e6-3d7c-11e3-8125-001a4d9eb045} - 0
    HKU\S-1-5-21-3634597872-1468280441-2304974095-1000\...\MountPoints2: {a5da29ea-3d7c-11e3-8125-001a4d9eb045} - 0
    GroupPolicyScripts: Ograniczenia <======= UWAGA
    GroupPolicyScripts\User: Ograniczenia <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    FF Extension: (Bing Search) - C:\Users\Hania Karol\AppData\Roaming\Mozilla\Firefox\Profiles\2ifi4fqv.default\Extensions\bingsearch.full@microsoft.com [2015-04-25] [Brak podpisu cyfrowego]CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
    2017-05-09 00:14 - 2017-05-09 00:14 - 00003618 _____ C:\Windows\System32\Tasks\free1newsnetxzxcsm
    2017-05-13 09:45 - 2015-04-25 20:22 - 00000000 ____D C:\AdwCleaner

    W FRST wybierz Napraw.

    Po wykonaniu usun katalog C:\FRST i to wszystko.

    0