MyStartSerch - jak to usunąć?


(Ala Rejowska) #1

Podczas pobierania jakiegos programu zainstalował mi sie nieszczęsny MyStartSerch, nie chcę tego mieć. Korzystajac z FRST wykonałam skan - tu są jego wyniki:

ADDITION: http://www.wklej.org/id/1582480/

SHORTCUT: http://www.wklej.org/id/1582482/

 

Co dalej wykonac? pomóżcie


(Acorus) #2

Otwórz notatnik systemowy i wklej:

Task: {7ED3B458-8417-45E8-A8E7-AC2027CDCA65} - System32\Tasks\AVG_SYS_TASK_1214av = C:\ProgramData\Avg_Update_1214av\AVG-Secure-Search-Update_1214av.exe [2014-10-26] ()
Task: {AD8057B8-6C05-40B1-BCD3-C3D87A957B40} - System32\Tasks\AVG_SYS_TASK_1214av_DELETE = C:\ProgramData\Avg_Update_1214av\AVG-Secure-Search-Update_1214av.exe [2014-10-26] ()
Task: {F229D643-A133-456C-8402-954E998A86DA} - System32\Tasks\{D5558DBC-D6C2-4810-AEAC-673BF6763834} = pcalua.exe -a C:\Users\Alicja\AppData\Local\PriceMeter\uninst.exe -c /uninstall
Task: C:\WINDOWS\Tasks\AVG_SYS_TASK_1214av.job = C:\ProgramData\Avg_Update_1214av\AVG-Secure-Search-Update_1214av.exe
Task: C:\WINDOWS\Tasks\AVG_SYS_TASK_1214av_DELETE.job = C:\ProgramData\Avg_Update_1214av\AVG-Secure-Search-Update_1214av.exe
HKLM-x32\...\Run: [GrooveMonitor] = C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [PWRISOVM.EXE] = C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2014-06-27] (Power Software Ltd)
HKLM-x32\...\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKU\S-1-5-21-3082375001-2371701637-1367753548-1002\...\Run: [AVG-Secure-Search-Update_1214av] = C:\Users\Alicja\AppData\Roaming\Avg_Update_1214av\AVG-Secure-Search-Update_1214av.exe [2778648 2014-10-26] ()
HKU\S-1-5-21-3082375001-2371701637-1367753548-1002\...\MountPoints2: {842e0d7d-77e3-11e4-bec8-a4db3084715c} - "G:\Startme.exe"
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: youtubeadblocker - {7e5bc8b0-629e-4152-8167-b42ec4fb0469} - C:\Program Files (x86)\youtubeadblocker\IfLbBDGKke9hx1.x64.dll No File
BHO: unisalees - {b926615f-6a7a-4dfc-a46f-bf7b7dcceb7e} - C:\Program Files (x86)\unisalees\qgEBo8e6cGzdio.x64.dll No File
2015-01-01 22:07 - 2015-01-01 22:11 - 00000000 ____ D () C:\Program Files (x86)\PanicButton
2015-01-01 22:06 - 2015-01-01 22:11 - 00000000 ____ D () C:\Program Files (x86)\uniSSaleoS
2015-01-01 22:06 - 2015-01-01 22:11 - 00000000 ____ D () C:\Program Files (x86)\unisalees
2015-01-01 22:06 - 2015-01-01 22:06 - 00000000 ____ D () C:\ProgramData\7294946175141542645
2014-12-19 16:05 - 2014-12-19 16:05 - 00000000 __SHD () C:\found.001
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.