
Od dwóch dni za każdym razem, gdy włączam przeglądarkę to uruchamia się strona yoursites123...sprawdzałam ustawienia chroma, w rozszerzeniach brak czegoś podejrzanego, a kompletnie nie znam się na kompach i proszę o jakąkolwiek pomoc

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT&q={searchTerms}
HKU\S-1-5-21-207807329-2220231672-3190657982-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT
HKU\S-1-5-21-207807329-2220231672-3190657982-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-207807329-2220231672-3190657982-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-207807329-2220231672-3190657982-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT&q={searchTerms}
CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT"
CHR Session Restore: Default -> [funkcja włączona]
R2 WdMan; C:\ProgramData\eWdMe\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego]
C:\ProgramData\eWdMe
Task: {050F7609-308B-4F76-878E-B89214B8B0F5} - System32\Tasks\{E2F10FF2-A3E1-44F9-8E80-6B8BD3CE2860} => pcalua.exe -a C:\Users\Monika\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=cor
ShortcutWithArgument: C:\Users\Monika\Desktop\QGIS Desktop 2.12.1.lnk -> D:\qgi\bin\nircmd.exe (NirSoft) -> exec hide D:\qgi\bin\qgis.bat <==== UWAGA
ShortcutWithArgument: C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
ShortcutWithArgument: C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
ShortcutWithArgument: C:\Users\Monika\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
ShortcutWithArgument: C:\Users\Monika\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
ShortcutWithArgument: C:\Users\Monika\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
ShortcutWithArgument: C:\Users\Monika\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449653615&z=a3c2785191cc543fd146017g1z5zdtfq5w7c2q4gcq&from=ient07021&uid=TOSHIBAXMK1656GSY_20MXT3MITXX20MXT3MIT <==== UWAGA
cHR HKLM\...\Chrome\Extension: [efhdjkbfpoohkmfaldijcpbnmbpefpkb] - C:\Program Files\ALLPlayer\AllPlayer.crx <nie znaleziono>
CHR HKU\S-1-5-21-207807329-2220231672-3190657982-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efhdjkbfpoohkmfaldijcpbnmbpefpkb] - C:\Program Files\ALLPlayer\AllPlayer.crx <nie znaleziono>
C:\ProgramData\9WdM9
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 4 gości