Elektroda.pl
Elektroda.pl
X
Please add exception to AdBlock for elektroda.pl.
If you watch the ads, you support portal and users.

Wiersz poleceń windows uruchamia się na kilka sekund.

Paidy 24 Nov 2019 23:51 516 8
Texa Poland
  • Texa Poland
  • #2
    krzychupar
    Level 43  
    Otwórz notatnik i wklej :

    CloseProcesses:
    AlternateDataStreams: C:\ProgramData\TEMP:E8956AB5 [756]
    AlternateDataStreams: C:\ProgramData\TEMP:EFB09287 [206]
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
    HKU\S-1-5-21-1658502691-500409222-3740802431-1001\...\MountPoints2: {d2d52e5d-d7ab-11e9-ac21-485f9991e2a2} - "E:\HiSuiteDownLoader.exe"
    AlternateShell:
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
    HKU\S-1-5-21-1658502691-500409222-3740802431-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-1658502691-500409222-3740802431-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
    SearchScopes: HKLM -> {7D4E683D-3FF3-4470-B4E1-B38501944928} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {7D4E683D-3FF3-4470-B4E1-B38501944928} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKU\S-1-5-21-1658502691-500409222-3740802431-1001 -> {7D4E683D-3FF3-4470-B4E1-B38501944928} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    S2 0010601571080176mcinstcleanup; C:\Users\paidy\AppData\Local\Temp\001060~1.EXE -cleanup -nolog [X] <==== UWAGA

    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść w folderze gdzie masz FRST.exe.
    Uruchom FRST i kliknij w Fix/Napraw.
  • Texa Poland
  • #4
    User removed account
    Level 1  
  • #6
    Kolobos
    IT specialist
    Wykonaj taki Fixlist.txt:
    AlternateDataStreams: C:\windows\system32\Drivers\wyjujvzr.sys:changelist [244]
    S1 wyjujvzr; C:\windows\system32\drivers\wyjujvzr.sys [72816 2019-11-25] (Microsoft Corporation -> Microsoft Corporation)
    S3 H2OFFT; \SystemRoot\System32\drivers\H2OFFT64.sys [X]
    2019-11-25 00:39 - 2019-11-25 00:39 - 000072816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wyjujvzr.sys
    2019-11-24 23:41 - 2019-11-24 23:41 - 000000000 ____D C:\Users\paidy\Downloads\FRST-OlderVersion

    Zrob skan przy pomocy mbam oraz cureit i usun to co wykryja.
  • #8
    User removed account
    Level 1  
  • #9
    Kolobos
    IT specialist
    Wykonaj czysty rozruch i sprawdz czy nadal bedzie sie sam otwieral, jezeli nie to wlaczaj po trochu az trafisz na wpis, ktory powoduje problem. Jak juz trafisz to podaj.