Skocz do zawartości

Reklamy w przeglądarce,wolno działający komputer


Rekomendowane odpowiedzi

Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

1) Odinstaluj te programy:
 

  Cytat

AnyProtect (HKLM\...\AnyProtect) (Version: 1.0.0.4 - CMI Limited) <==== UWAGA
AnySend (HKLM\...\ASPackage) (Version:  - CMI Limited) <==== UWAGA

CinemaP-1.9cV19.08 (HKLM\...\CinemaP-1.9cV19.08) (Version: 1.36.01.22 - Cinema PlusV19.08) <==== UWAGA
CinemaPlus-3.2cV19.08 (HKLM\...\CinemaPlus-3.2cV19.08) (Version: 1.36.01.22 - Cinema PlusV19.08) <==== UWAGA
Coupon Time (HKLM\...\Coupon Time) (Version: 2015.08.19.110543 - Coupon Time) <==== UWAGA
Crossbrowse (HKLM\...\Crossbrowse) (Version: 39.6.2171.95 - The Crossbrowse Authors) <==== UWAGA

GamesDesktop 008.005010064 (HKLM\...\gmsd_pl_005010064_is1) (Version:  - GAMESDESKTOP) <==== UWAGA
GamesDesktop 008.005010065 (HKLM\...\gmsd_pl_005010065_is1) (Version:  - GAMESDESKTOP) <==== UWAGA

MyBestOffersToday 008.014010064 (HKLM\...\mbot_pl_014010064_is1) (Version:  - MYBESTOFFERSTODAY) <==== UWAGA
mystartsearch uninstall (HKLM\...\mystartsearch uninstall) (Version:  - mystartsearch) <==== UWAGA

Object Browser (HKLM\...\Object Browser) (Version: 1.36.01.22 - ObjectB) <==== UWAGA

PhraseProfessor 1.10.0.22 (HKLM\...\PhraseProfessor_1.10.0.22) (Version: 1.10.0.22 - PhraseProfessor) <==== UWAGA
Plus.HD_3.5V18.08 (HKLM\...\Plus.HD_3.5V18.08) (Version: 1.36.01.22 - HD CinemaV18.08)

PriceFountain (remove only) (HKU\S-1-5-21-892523515-1518344882-2423736544-1000\...\PriceFountain) (Version: 1.1.6.5 - DHTUHNIVQBA) <==== UWAGA
RapidMediaConverter (HKU\S-1-5-21-892523515-1518344882-2423736544-1000\...\RapidMediaConverter) (Version: 1.1.0.34 - RapidMediaConverter) <==== UWAGA
RegClean-Pro (HKLM\...\RegClean-Pro_is1) (Version: 6.21 - systweak.com) <==== UWAGA

Shopper-Pro (HKLM\...\ShopperPro) (Version:  - ) <==== UWAGA
SmartWeb (HKLM\...\SmartWeb) (Version: 8.0.9 - SoftBrain Technologies Ltd.) <==== UWAGA
SnapDo (HKLM\...\{8D47CCFD-30B4-44B9-A2DD-ADF1DBB5F737}) (Version: 1.0.0.0 - Resoft)

Update for PriceFountain (HKU\S-1-5-21-892523515-1518344882-2423736544-1000\...\Price Fountain) (Version:  - Update for PriceFountain) <==== UWAGA

WordSurfer 1.10.0.19 (HKLM\...\WordSurfer_1.10.0.19) (Version: 1.10.0.19 - WordSurfer)
爱奇艺万能播放器 (HKLM\...\GeePlayer) (Version: 1.5.12.1411 - 爱奇艺)
爱奇艺影音 (HKLM\...\IQIYI Video) (Version:  - 爱奇艺)

 

 

2) Otwórz Notatnik i wklej w nim:

 

  Cytat
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\baidu\baidu.lnk -> C:\Program Files\baid
C:\Program Files\baidu
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\avgua32.exe" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\globalUpdatem" /f
C:\Users\Alan\Documents\Ola\The Sims™ 3.lnk
C:\Users\Alan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenFM.lnk
C:\Users\Alan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape\PhotoScape.lnk
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape\Uninstall PhotoScape.lnk
ShortcutWithArgument: C:\Users\Alan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1440086688&z=abc25203a1fa6250d0573f5g6z8z8e6e7b8q4w9bew&from=cmi&uid=ST9500325AS_5VE650SBXXXX5VE650SB
ShortcutWithArgument: C:\Users\Alan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files\Opera\launcher.exe (Opera Software) -> hxxp://www.mystartsearch.com/?type=sc&ts=1440086688&z=abc25203a1fa6250d0573f5g6z8z8e6e7b8q4w9bew&from=cmi&uid=ST9500325AS_5VE650SBXXXX5VE650SB
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files\Opera\launcher.exe (Opera Software) -> hxxp://www.mystartsearch.com/?type=sc&ts=1440086688&z=abc25203a1fa6250d0573f5g6z8z8e6e7b8q4w9bew&from=cmi&uid=ST9500325AS_5VE650SBXXXX5VE650SB
ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files\Opera\launcher.exe (Opera Software) -> hxxp://www.mystartsearch.com/?type=sc&ts=1440086688&z=abc25203a1fa6250d0573f5g6z8z8e6e7b8q4w9bew&from=cmi&uid=ST9500325AS_5VE650SBXXXX5VE650SB
ShortcutWithArgument: C:\Users\Alan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\爱奇艺万能播放器.lnk -> C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe (爱奇艺) -> -runfrom startmenurun
C:\IQIYI Video
ShortcutWithArgument: C:\Users\Alan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\爱奇艺万能播放器.lnk -> C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe (爱奇艺) -> -runfrom quicklaunchrun
C:\Users\Alan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\爱奇艺万能播放器.lnk
C:\Users\Alan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\爱奇艺万能播放器.lnk
GoHD (HKLM\...\GoHD) (Version: 1.36.01.22 - InstallMoon) <==== UWAGA
istartsurf uninstall (HKLM\...\istartsurf uninstall) (Version:  - istartsurf) <==== UWAGA
iWebar (HKLM\...\iWebar) (Version: 1.36.01.22 - Webby) <==== UWAGA
customCLSID: HKU\S-1-5-21-892523515-1518344882-2423736544-1000_Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}\InprocServer32 -> C:\IQIYI Video\LStyle\npWebPlayer.dll (爱奇艺公司)
CustomCLSID: HKU\S-1-5-21-892523515-1518344882-2423736544-1000_Classes\CLSID\{61CED8F3-2CB2-4C3C-9484-7530E1127A58}\InprocServer32 -> C:\IQIYI Video\LStyle\npWebPlayer.dll (爱奇艺公司)
CustomCLSID: HKU\S-1-5-21-892523515-1518344882-2423736544-1000_Classes\CLSID\{D96C1D26-5CDF-4506-9244-57233C3984DF}\InprocServer32 -> C:\IQIYI Video\LStyle\npWebPlayer.dll (爱奇艺公司)
CustomCLSID: HKU\S-1-5-21-892523515-1518344882-2423736544-1000_Classes\CLSID\{F3D0D36F-23F8-4682-A195-74C92B03D4AF-NOT}\InprocServer32 -> C:\IQIYI Video\LStyle\npWebPlayer.dll (爱奇艺公司)
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST.exe
Uruchom FRST i kliknij przycisk Fix (NAPRAW).
Powstanie plik fixlog.txt.
Daj ten log.

 

3) Użyj >Adw-cleaner
najpierw kliknij na SZUKAJ (SCAN), a dopiero po zakończeniu skanowania, gdy uaktywni się przycisk USUŃ (CLEANING), to kliknij na niego.
Pokaż raport z niego

 

4) Zrób nowe logi FRST.

 

jesi

Odnośnik do komentarza

1.
Usunięte wszystko oprócz chińskich znaczków i 'mystartsearch'

edit; zapomialem dopisać,pokazuje się deinstaltor programu,program się niby usuwa,lecz nadal jest na pc. restart pc nie pomógł

 

2. wykonane

3. wykonane

4. wykonane

Sporadycznie reklamy pokazują się dalej.


Pozdrawiam


 

Fixlog.txtPobieranie informacji ...

AdwCleanerC1.txtPobieranie informacji ...

FRST.txtPobieranie informacji ...

Shortcut.txtPobieranie informacji ...

Addition.txtPobieranie informacji ...

Odnośnik do komentarza

1) Do Notatnika wklej:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A3DC987B-88C2-4507-9CE2-F5295253B7C9}]
"NameServer"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A3DC987B-88C2-4507-9CE2-F5295253B7C9}]
"NameServer"="8.8.8.8"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DB671C29-D791-4356-8584-9D90A66A95C2}]
"NameServer"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DB671C29-D791-4356-8584-9D90A66A95C2}]
"NameServer"="8.8.8.8"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e29ac6c2-7037-11de-816d-806e6f6e6963}]
"NameServer"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e29ac6c2-7037-11de-816d-806e6f6e6963}]
"NameServer"="8.8.8.8"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E40E1801-DAD3-4CBB-A6BC-1CBE9A290732}]
"NameServer"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E40E1801-DAD3-4CBB-A6BC-1CBE9A290732}]
"NameServer"="8.8.8.8"
Z Menu Notatnika >> Plik >> Zapisz jako >> Ustaw rozszerzenie na Wszystkie pliki >> Zapisz jako> FIX.REG >>
plik uruchom (dwuklik i OK).

 

2) Otwórz Notatnik i wklej w nim:

 

  Cytat
C:\Users\Alan\AppData\Local\Bamtechno.exe
C:\Program Files\4C4C4544-1439987158-4210-8053-C3C04F4B334A\jnstF8B2.tmp
C:\Program Files\4C4C4544-1439987158-4210-8053-C3C04F4B334A\hnsy3269.tmp
C:\Program Files\4C4C4544-1439987158-4210-8053-C3C04F4B334A
AppInit_DLLs: C:\ProgramData\Saophase\K-tax.dll => Brak pliku
GroupPolicy: Zasady grupy  Chrome wykryto <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Zasada ograniczeń <======= UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Zasada ograniczeń <======= UWAGA
HKU\S-1-5-21-892523515-1518344882-2423736544-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Zasada ograniczeń <======= UWAGA
HKU\S-1-5-21-892523515-1518344882-2423736544-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTwkzwGbNf0bwS2LsRZodLJgnzUh1WD6fKZOhiGvTk0DnfcTB-WXhHzRY0AFvX2dAKu41gWzuvUazIGUVMtLFTuHIWyqWT3-H-rpQ4XDkonbQGJzQCw-vXfb0eKX5PCrH5aIeX5XLFz_fRkQl-KJ2GOplCfq5jm6rOobFdA,,&q={searchTerms}
HKU\S-1-5-21-892523515-1518344882-2423736544-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTwkzwGbNf0bwS2LsRZodLJgnzUh1WD6fKZOhiGvTk0DnfcTB-WXhHzRY0AFvX2dAKu41gWzuvUazIGUVMtLFTuHIWyqWT3-H-rpQ4XDkonbQGJzQCw-vXfb0eKX5PCrH5aIeX5XLFz_fRkQl-KJ2GOplCfq5jm6rOobFdA,,&q={searchTerms}
HKU\S-1-5-21-892523515-1518344882-2423736544-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTwkzwGbNf0bwS2LsRZodLJgnzUh1WD6fKZOhiGvTk0DnfcTB-WXhHzRY0AFvX2dAKu41gWzuvUazIGUVMtLFTuHIWyqWT3-H-rpQ4XDkonbQGJzQCw-vXfb0eKX5PCrH5aIeX5XLFz_fRkQl-KJ2GOplCfq5jm6rOobFdA,,&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {ielnksrch} URL =
SearchScopes: HKU\S-1-5-21-892523515-1518344882-2423736544-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR Extension: (Coupon Time) - C:\Users\Alan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flamddjkhfinbcdfnbnajdpbibpekcje [2015-08-19]
CHR Extension: (hokofmgcicpnjchllaccgedmmmbbnbmf) - C:\Users\Alan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2015-08-25]
CHR Extension: (ppmoihbfiilgkkgcogbblhhanjjaocil) - C:\Users\Alan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppmoihbfiilgkkgcogbblhhanjjaocil [2015-08-25]
OPR Extension: (GoHD) - C:\Users\Alan\AppData\Roaming\Opera Software\Opera Stable\Extensions\fijhlnmmmgflacagjecncpmpnhjieggk [2015-08-19]
OPR Extension: (Coupon Time) - C:\Users\Alan\AppData\Roaming\Opera Software\Opera Stable\Extensions\flamddjkhfinbcdfnbnajdpbibpekcje [2015-08-19]
OPR Extension: (iWebar) - C:\Users\Alan\AppData\Roaming\Opera Software\Opera Stable\Extensions\hdhmofnopkgkpgnpggloijpbnaonhplc [2015-08-19]
OPR Extension: (hokofmgcicpnjchllaccgedmmmbbnbmf) - C:\Users\Alan\AppData\Roaming\Opera Software\Opera Stable\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2015-08-25]
OPR Extension: (ppmoihbfiilgkkgcogbblhhanjjaocil) - C:\Users\Alan\AppData\Roaming\Opera Software\Opera Stable\Extensions\ppmoihbfiilgkkgcogbblhhanjjaocil [2015-08-25]
R2 eupdateddw; C:\Users\Alan\AppData\Local\Bamtechno.exe [50688 2015-08-19] () [brak podpisu cyfrowego]
R2 hyverumu; C:\Program Files\4C4C4544-1439987158-4210-8053-C3C04F4B334A\jnstF8B2.tmp [209920 2015-08-19] () [brak podpisu cyfrowego]
R2 jybiqyqo; C:\Program Files\4C4C4544-1439987158-4210-8053-C3C04F4B334A\hnsy3269.tmp [137728 2015-08-19] () [brak podpisu cyfrowego]
S2 gopibeko; C:\Users\Alan\AppData\Local\4C4C4544-1439994510-4210-8053-C3C04F4B334A\snsoE756.tmp [X]
S2 qurycyhy; C:\Program Files\4C4C4544-1439987158-4210-8053-C3C04F4B334A\knsdB7B6.tmpfs [X]
S2 Saophase; C:\ProgramData\Saophase\Saophase.exe [X]
C:\Users\Alan\AppData\Local\Bamtechno.exe
S1 {24720a6a-1c0d-497f-a74e-2030c479b761}Gw; system32\drivers\{24720a6a-1c0d-497f-a74e-2030c479b761}Gw.sys [X]
S1 {70a16b63-7ec8-4c35-a1de-12751e3d9375}Gw; system32\drivers\{70a16b63-7ec8-4c35-a1de-12751e3d9375}Gw.sys [X]
S1 {857b30e2-58a8-4390-9fe4-040508fe0dcc}Gw; system32\drivers\{857b30e2-58a8-4390-9fe4-040508fe0dcc}Gw.sys [X]
S1 {9f2ac096-af5a-4c47-ab9d-0efd1379eed3}Gw; system32\drivers\{9f2ac096-af5a-4c47-ab9d-0efd1379eed3}Gw.sys [X]
S1 {db97384e-1f00-468a-bbb9-c073b671999e}Gw; system32\drivers\{db97384e-1f00-468a-bbb9-c073b671999e}Gw.sys [X]
C:\Program Files\Common Files\pbt3dgj5.exe
C:\Program Files\Common Files\h2a3toho
C:\Users\Alan\Downloads\Audacity-11826-dp.exe
C:\Users\Alan\AppData\Local\nsiFBD3.tmp
C:\ProgramData\MWinManProM
C:\ProgramData\Saophases
C:\ProgramData\lWinManProl
C:\Users\Alan\AppData\Local\nsmC42E.tmp
C:\ProgramData\caMyciloP
C:\ProgramData\caMyciloPs
C:\Users\Alan\AppData\Local\nsm11C1.tmp
C:\Program Files\95bcdca6-1da1-4084-80d4-fa4187a693c1
C:\ProgramData\nWinManPron
C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
C:\Program Files\e38c4288-8b74-461b-ad54-73c6dc0f4631
C:\Program Files\4C4C4544-1439987158-4210-8053-C3C04F4B334A
C:\Windows\system32\findit.xml
C:\ProgramData\Sublights
C:\Users\Alan\AppData\Local\Bamtechno.exe
C:\Users\Public\QiYi
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\baidu
Task: {F59A0CEF-7B51-4F29-A858-F99D4A4E6AEA} - System32\Tasks\PFExe => C:\Users\Alan\AppData\Local\PriceFountain\pricefountain.exe
C:\Users\Alan\AppData\Local\PriceFountain
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GeePlayer" /f
FirewallRules: [{1F926EA8-C220-4D34-B60A-8ABD9BC16E81}] => (Allow) C:\Users\Alan\AppData\Roaming\IQIYI Video\LStyle\GpUpdate.exe
FirewallRules: [{CA4C718C-476C-4F43-BCB1-888F2E0030C0}] => (Allow) C:\IQIYI Video\GeePlayer\GeePlayer.exe
FirewallRules: [{F19DD154-908B-47A2-99B2-A7F7A529DCEF}] => (Allow) C:\Users\Alan\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe
FirewallRules: [{AB6144A6-0D64-41E4-91EF-B0DA8E7A2E94}] => (Allow) C:\IQIYI Video\LStyle\QyClient.exe
FirewallRules: [{51030637-39D7-4858-BC4A-E7BEC5748653}] => (Allow) C:\IQIYI Video\LStyle\QyWebPlayer.exe
FirewallRules: [{0D4C84BA-E820-4F0A-BD2C-4B04CAA2FA9D}] => (Allow) C:\IQIYI Video\Common\QyKernel.exe
FirewallRules: [{391B9A1F-C242-4BCC-B8E6-62AAC0EE1A43}] => (Allow) C:\IQIYI Video\LStyle\QyPlayer.exe
FirewallRules: [{EE9CA6C3-D727-4149-9BA7-10D55ED77718}] => (Allow) C:\Users\Alan\AppData\Roaming\IQIYI Video\GeePlayer\GpUpdate.exe
FirewallRules: [{21375D4A-5599-41E8-A647-0A8AEC39C535}] => (Allow) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe
FirewallRules: [{7F2ADEFB-340D-4C9A-B5EB-CDA4B9A0CE81}] => (Allow) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe
FirewallRules: [{8EEED36E-8E0D-49F4-B664-904EC50963BA}] => (Allow) C:\IQIYI Video\GeePlayer\GeePlayer\GeePlayer.exe
FirewallRules: [{10429BC3-342A-4C0D-A1C1-D85164EADAE4}] => (Allow) C:\Users\Alan\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe
FirewallRules: [{9B52BC67-956B-48FD-826D-15C65D55FA5B}] => (Allow) C:\IQIYI Video\LStyle\QyClient.exe
FirewallRules: [{4FABBCE1-7C53-45FB-BCD5-A42EFA251000}] => (Allow) C:\IQIYI Video\LStyle\QyWebPlayer.exe
FirewallRules: [{077913D9-D093-416A-AF1C-57EFBE3ACAD2}] => (Allow) C:\IQIYI Video\Common\QyKernel.exe
FirewallRules: [{4013A2E4-F047-4AE0-9602-31181A85A253}] => (Allow) C:\IQIYI Video\LStyle\QyPlayer.exe
C:\Users\Alan\AppData\Roaming\IQIYI Video
C:\Users\Alan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\爱奇艺万能播放器.lnk
C:\IQIYI Video
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape\Uninstall PhotoScape.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\baidu\baidu.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\baidu
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST.exe
Uruchom FRST i kliknij przycisk Fix (NAPRAW).
Powstanie plik fixlog.txt.
Daj ten log.

 

3) Zrób nowe logi FRST.

 

jessi

Odnośnik do komentarza
  Cytat
Dlaczego w Logu FRST na samym początku są pokazane przeglądarki firefox i chrome,skoro używam tylko opery,a pozostałe przeglądarki zostały odinstalowane?

Google Chrome jest na liście zainstalowanych Twoich programów:

  Cytat
Google Chrome (HKLM\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)

więc w logu FRST.txt też ją widać.

 

Natomiast Firefox - pewnie zostały po nim resztki, więc FRST pokazał i tę przeglądarkę, choć jej nie ma liście Twoich programów.

 

Kończymy:

Otwórz Notatnik i wklej w nim:

 

 

  Cytat
DeleteQuarantine:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST. Uruchom FRST i kliknij w Fix (NAPRAW).

przez SHIFT+DEL usuń pozostały folder C:\FRST.

 

W Adw-Cleaner kliknij na przycisk Odinstaluj (UNINSTALL).

 

Zainstaluj nowszą wersję Javy, wg https://www.fixitpc.pl/topic/5-dezynfekcja-kroki-finalizuj%C4%85ce-temat/?do=findComment&comment=43590

 

jessi

Odnośnik do komentarza
Gość
Ten temat został zamknięty. Brak możliwości dodania odpowiedzi.
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...