Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

czarny ekran i brak skryptu vbs

RTC 05 Cze 2016 20:31 588 4
  • Pomocny post
    #2 05 Cze 2016 21:13
    krzychupar
    Poziom 40  

    Odinstaluj:
    groover
    hohosearch - Uninstall

    Otwórz notatnik i wklej:
    Task: {2B7BB7B4-03DF-49F5-A8D1-CF20FB084537} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
    Task: {63C6B538-6388-4496-80B3-4B40DEED8120} - System32\Tasks\Doroghtshejas Module => C:\Program Files (x86)\Doroghtshejas\doroghtshejasmoduletask.exe [2016-06-03] () <==== UWAGA
    Task: {705EB138-949E-4800-85EA-0DFB4ECD0D28} - System32\Tasks\{C1598AAD-0C0E-4059-A850-7241F4F5257D} => pcalua.exe -a "C:\Users\lekcje itp\Downloads\wlsetup-web(1).exe" -d "C:\Users\lekcje itp\Downloads"
    Task: {71DEC9FD-4C59-4D5D-8081-E885E60A720A} - \lekcje itpDecompensateRetractionV2 -> Brak pliku <==== UWAGA
    Task: {B1E89551-E6F8-402D-B4B4-2CDD7D5C6236} - System32\Tasks\{12F0C191-35E4-413E-AF1E-6D6FD9867266} => pcalua.exe -a "H:\PLAY ONLINE\Setup.exe" -d "H:\PLAY ONLINE"
    Task: {CF56712E-F380-4D33-A4F0-DEEEEB0A69BA} - System32\Tasks\{7000B8BF-0C5E-41B4-8EC6-CE95191B6541} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe"
    Task: {F4A87748-4346-4B1F-B7B5-E1CA6941BD4C} - System32\Tasks\Opera scheduled Autoupdate 1436639474 => C:\Program Files (x86)\Opera\launcher.exe
    Hosts:
    HKLM\...\RunOnce: [WEPRODUCT@5Be7] => C:\Users\lekcje itp\AppData\Local\Temp\HUQI7U42TA.exe [20992 2016-06-03] () <===== UWAGA
    HKLM-x32\...\RunOnce: [GrpConv] => grpconv -o
    HKLM-x32\...\RunOnce: [DeleteOnReboot] => C:\Users\aaa\AppData\Local\Temp\DeleteOnReboot.bat [139 2016-06-04] () <===== UWAGA
    HKLM\...\Winlogon: [Userinit] wscript C:\Windows\run.vbs,
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\...\MountPoints2: G - G:\AutoRun.exe
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\...\MountPoints2: {14144877-29c0-11e6-99a1-806e6f6e6963} - F:\autorun.exe
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\...\MountPoints2: {6426b938-5fb3-11e5-a669-1c7508130c5c} - G:\AutoRun.exe
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\...\MountPoints2: {8ee28c55-5c76-11e5-9031-1c7508130c5c} - G:\AutoRun.exe
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\...\MountPoints2: {a53f92f3-5bd0-11e5-92a7-1c7508130c5c} - G:\AutoRun.exe
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\...\MountPoints2: {a53f9300-5bd0-11e5-92a7-1c7508130c5c} - H:\AutoRun.exe
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\Control Panel\Desktop\\SCRNSAVE.EXE ->
    AppInit_DLLs: C:\ProgramData\Quotenamron\KonCore.dll => Brak pliku
    AppInit_DLLs-x32: C:\ProgramData\Quotenamron\Subdex.dll => Brak pliku
    GroupPolicy: Ograniczenia - Chrome <======= UWAGA
    CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}




    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki1&a...n=instalki1&iwa_source=installer_instalki
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms}
    HKU\S-1-5-21-3400122002-629171188-2149167339-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.bing.com/search?q={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope - brak wartości
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3400122002-629171188-2149167339-1001 -> {ielnksrch} URL = hxxp://www.bing.com/search?q={searchTerms}
    BHO-x32: Brak nazwy -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> Brak pliku
    FF NewTab:
    FF DefaultSearchEngine: Google
    FF Homepage: hxxp://www.interia.pl/#utm_source=instalki1&a...n=instalki1&iwa_source=installer_instalki
    FF Keyword.URL:
    CHR HomePage: ChromeDefaultData2 -> hxxp://d2ucfwpxlh3zh3.cloudfront.net/?ts=AHEq...8B3D011B15ADCA3F2&ptid=bwp&mode=loadm
    CHR StartupUrls: ChromeDefaultData2 -> "hxxp://d2ucfwpxlh3zh3.cloudfront.net/?ts=AHEqB3YsB30sAU..&v=20160603&uid=DCA84CAD013B7288B3D011B15ADCA3F2&ptid=bwp&mode=loadm"
    CHR DefaultSearchURL: ChromeDefaultData2 -> hxxp://d2ucfwpxlh3zh3.cloudfront.net/chrome.php?q={searchTerms}&ts=AHEqB3YsB30sAU..&v=20160603&uid=DCA84CAD013B7288B3D011B15ADCA3F2&ptid=bwp&mode=loadm
    CHR DefaultSearchKeyword: ChromeDefaultData2 -> hohosearch
    CHR HKLM-x32\...\Chrome\Extension: [jidkebcigjgheaahopdnlfaohgnocfai] - hxxps://clients2.google.com/service/update2/crx
    R2 MPCProtectService; C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe [350688 2016-06-03] (DotC United Inc)
    S2 DigitalWave.Update.Service; Brak ImagePath
    S2 doroghtshejasmoduleservice; "C:\Program Files (x86)\Doroghtshejas\doroghtshejasmoduleservice.html5" {79740E79-A383-47A7-B513-3DF6563D007F} {8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83} [X]
    S3 cpuz137; Brak ImagePath
    S3 EagleX64; Brak ImagePath
    R1 MPCKpt; C:\Windows\System32\DRIVERS\MPCKpt.sys [60136 2016-06-03] (DotC United Inc)
    S3 WinRing0_1_2_0; Brak ImagePath
    S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
    2016-06-04 10:46 - 2016-06-04 10:51 - 00000000 ____D C:\AdwCleaner
    2016-06-03 22:01 - 2016-06-03 22:01 - 00000000 ____D C:\Program Files (x86)\Doroghtshejas
    2016-06-03 22:01 - 2016-06-03 22:01 - 00000000 ____D C:\Program Files (x86)\Decoing
    2016-06-03 22:00 - 2016-06-03 22:01 - 00008998 _____ C:\Windows\System32\Tasks\Doroghtshejas Module
    2016-06-03 21:59 - 2016-06-04 10:34 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner
    2016-06-03 21:59 - 2016-06-03 21:59 - 00060136 ____N (DotC United Inc) C:\Windows\system32\Drivers\MPCKpt.sys
    2016-06-03 21:56 - 2016-06-04 11:53 - 00000000 ____D C:\Program Files (x86)\mpck
    2016-06-04 11:56 - 2015-01-17 12:13 - 00000266 __RSH C:\ProgramData\ntuser.pol
    2016-06-04 10:47 - 2016-02-04 19:43 - 00000000 ____D C:\ProgramData\Avg
    2016-04-04 15:52 - 2016-04-04 15:52 - 6504960 _____ () C:\Users\lekcje itp\AppData\Roaming\agent.dat
    2016-06-03 21:59 - 2016-05-19 16:54 - 1443152 _____ ( ) C:\Users\lekcje itp\AppData\Roaming\AutoTime_51490.jpg
    2016-04-04 15:52 - 2016-04-04 15:52 - 0065232 _____ () C:\Users\lekcje itp\AppData\Roaming\Config.xml
    2015-06-22 16:05 - 2015-06-22 16:05 - 0568240 _____ () C:\Users\lekcje itp\AppData\Roaming\gameboxsetup.exe
    2016-04-04 15:52 - 2016-04-04 15:52 - 1170432 _____ () C:\Users\lekcje itp\AppData\Roaming\Greening.exe
    2016-04-04 15:52 - 2016-04-04 15:52 - 1626339 _____ () C:\Users\lekcje itp\AppData\Roaming\Greening.tst
    2016-04-04 15:52 - 2016-04-04 15:52 - 0271516 _____ () C:\Users\lekcje itp\AppData\Roaming\inst.lat
    2016-04-04 15:52 - 2016-04-04 15:52 - 0014208 _____ () C:\Users\lekcje itp\AppData\Roaming\InstallationConfiguration.xml
    2016-04-04 15:52 - 2016-04-04 15:52 - 0127488 _____ () C:\Users\lekcje itp\AppData\Roaming\Installer.dat
    2016-04-04 15:52 - 2016-04-04 15:52 - 0402905 _____ () C:\Users\lekcje itp\AppData\Roaming\Konsillight.bin
    2016-04-04 15:52 - 2016-04-04 15:52 - 0018432 _____ () C:\Users\lekcje itp\AppData\Roaming\Main.dat
    2016-04-04 15:52 - 2016-04-04 15:52 - 0005568 _____ () C:\Users\lekcje itp\AppData\Roaming\md.xml
    2016-04-04 15:52 - 2016-04-04 15:52 - 0126464 _____ () C:\Users\lekcje itp\AppData\Roaming\noah.dat
    2016-06-03 21:57 - 2016-06-02 03:47 - 1936896 _____ () C:\Users\lekcje itp\AppData\Roaming\service72564.exe
    2016-06-03 21:57 - 2016-06-02 03:47 - 1936896 _____ () C:\Users\lekcje itp\AppData\Roaming\service90132.exe
    2016-04-04 15:54 - 2016-04-04 15:54 - 0032038 _____ () C:\Users\lekcje itp\AppData\Roaming\uninstall_temp.ico
    2016-01-21 22:24 - 2016-01-23 12:24 - 0000071 _____ () C:\Users\lekcje itp\AppData\Roaming\WB.CFG
    C:\Users\lekcje itp\AppData\Local\Temp\HUQI7U42TA.exe
    C:\Users\aaa\AppData\Local\Temp\DeleteOnReboot.bat
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść w folderze gdzie znajduje się FRST.exe
    Uruchom FRST i kliknij w Fix/Napraw.

    0
  • #3 09 Cze 2016 20:08
    RTC
    Uczeń

    gdy zapisuje w pierwszym folderze frst to niby zapisuje ale gdy otwieram i daje napraw to pisze,że nie odnaleziono...

    0
  • Pomocny post
    #4 09 Cze 2016 20:12
    Kolobos
    Spec od komputerów

    FRST masz pobranych, gdzie SAM go zapisales, wiec dlaczego zapisujesz Fixlistst w "pierwszym folderze frst"?

    0
  • Pomocny post
    #5 09 Cze 2016 20:13
    Acorus 20
    Spec od komputerów

    Masz umieścić skrypt tam gdzie masz FRST czyli C:\Users\lekcje itp\Downloads

    0