Jak usunąć Mystartsearch


(JAMIEST) #1

już chyba wszyscy wiedza o co chodzi, przeczytałem parę tematów i chyba wiem o co chodzi, wiec proszę o pomoc:

 

 

FRST: http://www.wklej.org/id/1566840/

Additional: http://wklej.org/id/1566841/


(Acorus) #2

Pobierz i uruchom AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Szukaj i później Usuń.

Pokaż nowe logi z FRST.


(JAMIEST) #3

FRST:http://www.wklej.org/id/1566852/

Additional: http://www.wklej.org/id/1566853/


(Acorus) #4

Odinstaluj Spybot - Search & Destroy.Otwórz notatnik systemowy i wklej:

HKU\S-1-5-21-117609710-57989841-725345543-1003\Software\Classes\.exe: exefile = ===== ATTENTION!
HKU\S-1-5-21-117609710-57989841-725345543-1003\Software\Classes\exefile: ===== ATTENTION!
Hosts:
HKLM\...\Run: [RTHDCPL] = C:\WINDOWS\RTHDCPL.EXE [16857600 2008-02-13] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Alcmtr] = C:\WINDOWS\ALCMTR.EXE [69632 2005-05-03] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NvCplDaemon] = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [Adobe ARM] = C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\TPSvc: TPSvc.dll [X]
HKU\S-1-5-21-117609710-57989841-725345543-1003\...\Run: [Google Update] = C:\Documents and Settings\Halinka\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [107912 2014-10-24] (Google Inc.)
HKU\S-1-5-21-117609710-57989841-725345543-1003\...\MountPoints2: {23b459d2-db58-11df-a105-001d7dca250c} - I:\Toshiba\Launcher\start.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKU\S-1-5-21-117609710-57989841-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
URLSearchHook: [S-1-5-21-117609710-57989841-725345543-1189] ATTENTION == Default URLSearchHook is missing.
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-117609710-57989841-725345543-1189 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Spybot-SD IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search Destroy\SDHelper.dll (Safer Networking Limited)
BHO: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
S3 Cardex; \\C:\WINDOWS\system32\drivers\TBPANEL.SYS [X]
S3 gfiark; system32\drivers\gfiark.sys [X]
S4 IntelIde; No ImagePath
S1 sbaphd; system32\drivers\sbaphd.sys [X]
S2 sbapifs; system32\drivers\sbapifs.sys [X]
U1 WS2IFSL; No ImagePath
U3 aju2xonn; No ImagePath
2014-12-25 12:58 - 2014-12-25 13:03 - 00000000 ____ D () C:\AdwCleaner
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(JAMIEST) #5

mam nadzieje, ze wszystko juz bedzie w porzadku:) mam rozumiecm, ze FRST juz jest do usuniecia?


(Acorus) #6

Jak wszystko gra to skasuj folder C:\FRST