Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

Błąd podczas uruchamiania systemu - C:\WINDOWS\run.vbs.

koller91 20 Mar 2016 15:32 636 2
  • Pomocny post
    #2 20 Mar 2016 16:12
    Acorus 20
    Spec od komputerów

    Odinstaluj WebStorage.Otwórz notatnik systemowy i wklej:

    Cytat:
    CloseProcesses:
    Shortcut: C:\Users\Public\Desktop\iTNC530 (340494).lnk -> C:\Programme\iTNC530\340494\itncstart.bat ()
    ShortcutWithArgument: C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458480570&a=1003813&src=sh&uuid=da60ccdd-2825-4883-bb6c-cbba50a2d1ac"
    ShortcutWithArgument: C:\Users\Paweł\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458480570&a=1003813&src=sh&uuid=da60ccdd-2825-4883-bb6c-cbba50a2d1ac"
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1458480570&a=1003813&src=sh&uuid=da60ccdd-2825-4883-bb6c-cbba50a2d1ac"
    ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1458480570&a=1003813&src=sh&uuid=da60ccdd-2825-4883-bb6c-cbba50a2d1ac"
    Hosts:
    HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\ASUSWSLoader.exe [63296 2014-02-25] ()
    HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM\...\Winlogon: [Userinit] wscript C:\Windows\run.vbs,
    HKLM-x32\...\Winlogon: [Userinit] wscript C:\Windows\run.vbs, [X]
    HKU\S-1-5-21-1502461472-2632271880-3566253967-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Paweł\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
    AutoConfigURL: [S-1-5-21-1502461472-2632271880-3566253967-1001] => hxxp://un-stop.net/wpad.dat?bf112180ec10c05ce018473fb44768f07869438
    ManualProxies: 0hxxp://un-stop.net/wpad.dat?bf112180ec10c05ce018473fb44768f07869438
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKU\S-1-5-21-1502461472-2632271880-3566253967-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-1502461472-2632271880-3566253967-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =




    R2 Service Mgr CashKitten; C:\ProgramData\d8986107-dff3-4565-a17b-637d7c3968d3\plugincontainer.exe [1407208 2016-03-20] () <==== UWAGA
    R2 Update Mgr CashKitten; C:\Program Files (x86)\Common Files\d8986107-dff3-4565-a17b-637d7c3968d3\updater.exe [1277160 2016-03-20] () <==== UWAGA
    U0 msahci; system32\drivers\msahci.sys [X]
    2016-03-20 14:30 - 2016-03-20 14:30 - 00848437 _____ C:\Users\Paweł\AppData\Roaming\Hayity.bin
    2016-03-20 14:30 - 2016-03-20 14:30 - 00127488 _____ C:\Users\Paweł\AppData\Roaming\Installer.dat
    2016-03-20 14:30 - 2016-03-20 14:30 - 00023200 _____ C:\Windows\System32\Tasks\{7A0F0847-050B-0E0D-0C11-7E09057A110F}
    2016-03-20 14:30 - 2016-03-20 14:30 - 00015840 _____ C:\Users\Paweł\AppData\Roaming\InstallationConfiguration.xml
    2016-03-20 14:30 - 2016-03-20 14:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\LuckyBrowse
    2016-03-20 14:30 - 2016-03-20 14:30 - 00000000 ____D C:\ProgramData\690a8075-3aa1-0
    2016-03-20 14:30 - 2016-03-20 14:30 - 00000000 ____D C:\ProgramData\690a8075-01d5-1
    2016-03-20 14:30 - 2016-03-20 14:30 - 00000000 ____D C:\Program Files (x86)\Cash Kitten
    2016-03-20 08:27 - 2016-03-20 08:27 - 00001561 _____ C:\Users\Public\Desktop\iTNC530 (340494).lnk
    2016-03-20 08:27 - 2016-03-20 08:27 - 00000000 ____D C:\Programme
    2016-03-20 08:27 - 2016-03-20 08:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HEIDENHAIN
    2016-03-20 14:52 - 2015-11-15 17:18 - 00000000 ____D C:\AdwCleaner
    2016-03-20 14:30 - 2016-03-20 14:30 - 0848437 _____ () C:\Users\Paweł\AppData\Roaming\Hayity.bin
    2016-03-20 14:30 - 2016-03-20 14:30 - 0015840 _____ () C:\Users\Paweł\AppData\Roaming\InstallationConfiguration.xml
    2016-03-20 14:30 - 2016-03-20 14:30 - 0127488 _____ () C:\Users\Paweł\AppData\Roaming\Installer.dat
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
    Uruchom jako administrator FRST i kliknij w Fix/Napraw.

    1
  • #3 20 Mar 2016 19:14
    koller91
    Poziom 2  

    Pomogło! Ogromnie dziękuję Ci za pomoc! Pozdrawiam.
    Błąd podczas uruchamiania systemu - C:\WINDOWS\run.vbs.

    0