Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Gameorplay.info jak się pozbyć

benefon 18 Mar 2018 11:02 471 2
  • Pomocny post
    #2 18 Mar 2018 11:26
    Kolobos
    Spec od komputerów

    Wykonaj Fixlist.txt dla FRST:
    Task: {29DAA69C-6288-4763-982F-B7A4AB64E71F} - System32\Tasks\Benefon => cmd.exe /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v Benefon /t REG_SZ /d "explorer.exe hxxp://exinariuminix.info" <==== UWAGA
    Task: {8E1CF52C-B71E-4234-BE4B-8F15567EC84B} - System32\Tasks\{DF08D9B7-B4A0-4069-A308-61299191884C} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\Creative Cloud Uninstaller.exe"
    AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
    AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
    HKU\S-1-5-21-3948126379-2371097522-1837809734-1000\...\Run: [Benefon] => explorer.exe hxxp://exinariuminix.info <==== UWAGA
    HKU\S-1-5-21-3948126379-2371097522-1837809734-1000\...\MountPoints2: {443ed810-29c7-11e8-b67b-4ccc6a2ade5b} - K:\AutoRun.exe
    HKU\S-1-5-21-3948126379-2371097522-1837809734-1000\...\MountPoints2: {7f7b230d-21df-11e8-b8d0-4ccc6a2ade5b} - K:\AutoRun.exe
    HKU\S-1-5-21-3948126379-2371097522-1837809734-1000\...\MountPoints2: {a7be0649-41f9-11e7-bd33-4ccc6a2ade5b} - K:\AutoRun.exe
    HKU\S-1-5-18\...\Run: [] => [X]
    GroupPolicy: Ograniczenia <==== UWAGA
    FF HKU\S-1-5-21-3948126379-2371097522-1837809734-1000\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Benefon\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
    FF Extension: (__MSG_extName__) - C:\Users\Benefon\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2018-01-24]
    C:\Users\Benefon\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
    CHR HKU\S-1-5-21-3948126379-2371097522-1837809734-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx
    S0 MBAMSwissArmy; System32\Drivers\mbamswissarmy.sys [X]
    2018-03-06 21:47 - 2018-03-06 21:47 - 000003526 _____ C:\Windows\System32\Tasks\Benefon

    Po wykonaniu usun katalog C:\FRST i to wszystko.

    0
  • #3 18 Mar 2018 11:50
    benefon
    Poziom 2  

    Dziękuję bardzo wszystko wróciło do normy.

    0