Przestań pobierać za pomocą asystenta pobierania. SpyHunter to jest szkodliwy program.
-
Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Tcpip…\Interfaces{6F90A1E7-DB08-4194-976E-B2878B7BDB71}: [DhcpNameServer] 5.152.219.50 31.3.252.71
CMD: ipconfig /flushdns
Uruchom FRST i kliknij Fix. Później skasuj folder C:\FRST
- Odinstaluj McAfee Security Scan Plus.
Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
FF SearchEngineOrder.1: v9
FF SelectedSearchEngine: Ask Web Search
SearchScopes: HKU\S-1-5-21-1097719403-401819125-2768112302-1000 -> {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://pl.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
FF Keyword.URL: hxxp://pl.search.yahoo.com/search?fr=ytff-comodo&p=
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S1 wafd_vt_1_10_0_20; system32\drivers\wafd_vt_1_10_0_20.sys [X]
2015-08-25 18:57 - 2015-08-25 18:57 - 00865000 _____ (Application Installer generic ) C:\Users\Laptop\Downloads\CCleaner-13061-dp.exe
2015-08-25 18:36 - 2015-08-25 18:36 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Laptop\Downloads\SpyHunter-Installer.exe
2012-09-09 18:06 - 2012-09-09 18:06 - 0000000 _____ () C:\Users\Laptop\AppData\Local\AtStart.txt
2012-09-09 18:06 - 2012-09-09 18:06 - 0000000 _____ () C:\Users\Laptop\AppData\Local\DSwitch.txt
2012-09-09 18:06 - 2012-09-09 18:06 - 0000000 _____ () C:\Users\Laptop\AppData\Local\QSwitch.txt
Task: {11A8792B-AF7D-48A6-A594-27845D05F6D1} - System32\Tasks\{760F9AB4-E3BE-4CD3-B065-B9344914DA62} => pcalua.exe -a G:\hp\sp45131.exe -d G:\hp
Task: {229C5CD0-82C7-4B0C-94E3-1F55326D28F8} - System32\Tasks\{32A9D673-E912-45B5-9A9B-E9747DFD2175} => pcalua.exe -a E:\setup.exe -d E:\
CMD: ipconfig /flushdns
Uruchom FRST i kliknij Fix. Skasuj folder C:\FRST
-
Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :
2015-08-25 21:23 - 2015-08-25 23:25 - 00000000 ____ D C:\AdwCleaner
2015-08-25 18:38 - 2015-08-25 18:36 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Dell\Downloads\SpyHunter-Installer.exe
CMD: ipconfig /flushdns
Uruchom FRST i kliknij Fix. Skasuj folder C:\FRST