Witam, mam problem, gdyż po uruchomieniu wiersza poleceń ( nawet jako administrator okienko tylko mignie i nie uruchamia się). Wiem, że da się to załatwić plikiem do FRST ale nie wiem jak go stworzyć.
CloseProcesses:
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19645800 2019-02-06] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\MountPoints2: {96ab7f48-d38b-11e7-9604-bc5ff4653052} - "G:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\Winlogon: [Shell] %comspec% <==== UWAGA
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\Run: [Gaijin.Net Agent] => C:\Users\Domel_PC\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe [2268232 2017-12-09] (Gaijin Network LTD -> Gaijin Entertainment)
GroupPolicy: Ograniczenia ? <==== UWAGA
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [2513000 2017-10-29] (Lavasoft Software Canada -> Lavasoft)
GroupPolicy\User: Ograniczenia ? <==== UWAGA
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist "C:\Users\Domel_PC\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" ( start /MIN "" "C:\Users\Domel_PC\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== UWAGA
SearchScopes: HKU\S-1-5-21-2429865692-3756273716-32309595-1001 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL =
SearchScopes: HKU\S-1-5-21-2429865692-3756273716-32309595-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://pl.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10438__171029__yaie&p={searchTerms}
CHR HomePage: Default -> inline.go.mail.ru
Toolbar: HKLM-x32 - PDFescape Desktop Toolbar - {A6D4ADF0-4C82-4712-B9B8-69EE9CF06462} - C:\Program Files (x86)\PDFescape Desktop\creator-ie-plugin.dll [2017-07-13] (PDFescape -> Red Software)
Toolbar: HKLM-x32 - PDF Architect 5 Toolbar - {84F23192-A475-4038-B5C0-8584777F2DF4} - C:\Program Files (x86)\PDF Architect 5\creator\plugins\IEAddin\creator-ie-plugin.dll [2017-11-29] (pdfforge GmbH -> pdfforge GmbH)
S2 Framework; C:\ProgramData\WindowsSQL\System.exe [8192 2016-02-17] () [Brak podpisu cyfrowego] <==== UWAGA
S3 XXLHASP; c:\windows\system32\drivers\XXLHASP.sys [288768 2019-01-04] (NGO -> ) [Brak podpisu cyfrowego]
CustomCLSID: HKU\S-1-5-21-2429865692-3756273716-32309595-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> Brak pliku
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Brak pliku
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> Brak pliku
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> Brak pliku
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Brak pliku
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> Brak pliku
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku
Task: {07CECA15-3744-45DA-855E-B2D9201A96EB} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
Task: {09529888-4903-46A3-9036-27183CEBFAA1} - System32\Tasks\DB Xmas Task (One-Time) => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\xmas.exe
Task: {A7F704C3-53BA-4610-9B9C-CB3684F11FCF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe (Piriform Software Ltd -> Piriform Software Ltd)
IE trusted site: HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\webcompanion.com -> hxxp://webcompanion.com
0.0.0.0 telemetry.malwarebytes.com
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2429865692-3756273716-32309595-1001\...\StartupApproved\Run: => "Gaijin.Net Agent"
EmptyTemp: