Kód: Vybrat vše
Bing Bar
Aplikuj fixlist pro FRST:
Na Ploše (musí na ní být umístěn FRST) vytvoř textový soubor s názvem fixlist, do něj zkopíruj následujcí skript a ulož.
Kód: Vybrat vše
Start
CloseProcesses:
CreateRestorePoint:
Task: {0609A369-59E8-473F-B4E0-4313FAEA6E28} - System32\Tasks\{1C0D0B1F-C5F2-4558-94F6-30D9E42B7A8D} => pcalua.exe -a C:\Users\IA\Desktop\ytd-1.45.exe -d C:\Users\IA\AppData\Roaming\IDM
Task: {1DC8EC8F-54FB-4274-84DF-481C276B21A1} - System32\Tasks\PCDRScheduledMaintenance => C:\Program Files\PC-Doctor for Windows\pcdrcui.exe [2009-09-18] (PC-Doctor, Inc.)
C:\Program Files\PC-Doctor for Windows
Task: {1E95C9E9-8BCC-4368-B634-DCA451F49E00} - System32\Tasks\{6FA328F5-EC7B-4EC5-8F9B-B2890498185A} => pcalua.exe -a C:\Windows\IsUninst.exe -c -fC:\Windows\system32\NVSYS\Uninst.isu -cC:\Windows\system32\NVSYS\NVINST32.DLL
Task: {2493E2D9-7E0E-4376-8929-6B46E28F116E} - System32\Tasks\{53C342B5-51F4-48E0-BE1F-B9706C66CD17} => pcalua.exe -a C:\Users\IA\AppData\Local\Temp\RarSFX0\install.exe -d C:\Users\IA\AppData\Local\Temp\RarSFX0
Task: {49A0B414-2F8D-4558-8B8C-7AF00C1A9BE0} - System32\Tasks\{05B98E25-8B60-4A4F-A690-32485F40A08E} => pcalua.exe -a C:\Downloads\mw9791enu.exe -d C:\Downloads
Task: {4E74C041-59C8-459D-A6EA-559ECF643C4E} - \avastBCLRestartS-1-5-21-4087050500-3545783654-1483765477-1001 No Task File <==== ATTENTION
Task: {61E52853-08D9-420F-824E-B06EF7083C47} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.43\SymErr.exe
Task: {AF3C8D5E-EC5B-4167-BBB7-21DB094D0BAD} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.43\SymErr.exe
Task: {C3328217-4209-4D46-9DC8-78A56B2C7BAA} - System32\Tasks\{5FC5FE30-A9C8-4D23-BEF4-27A6A08CBFCA} => pcalua.exe -a C:\Downloads\Msvbvm50.exe -d C:\Downloads
AlternateDataStreams: C:\ProgramData\Temp:A1EDB939
AlternateDataStreams: C:\ProgramData\Temp:D3A96964
C:\ProgramData\Temp
HKLM\...\Run: [PC-Doctor for Windows localizer] => C:\Program Files\PC-Doctor for Windows\localizer.exe [95728 2009-09-17] (PC-Doctor, Inc.)
HKU\S-1-5-21-4087050500-3545783654-1483765477-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-4087050500-3545783654-1483765477-1001: @hola.org/vlc,version=1.7.5 -> C:\Users\IA\AppData\Local\Hola\firefox\app\vlc No File
U3 ak053bbt; C:\Windows\System32\Drivers\ak053bbt.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
C:\Windows\System32\Drivers\ak053bbt.sys
U2 ccEvtMgr; No ImagePath
U2 ccSetMgr; No ImagePath
U3 navapsvc; No ImagePath
S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0; \??\c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [X]
U3 SAVRT; No ImagePath
U1 SAVRTPEL; No ImagePath
U3 TlntSvr; No ImagePath
C:\Users\IA\{58C482E3-0C46-43EC-8EE5-C7230FFBC3D6}.dat
C:\Windows\Tasks\*.job
C:\ProgramData\RogueKiller
CMD: bitsadmin /reset /allusers
CMD: dir C:\PROGRA~1
CMD: dir C:\PROGRA~2
CMD: dir %appdata%
CMD: dir %localappdata%
CMD: dir %programdata%
RemoveProxy:
EmptyTemp:
End
Poté otevři FRST jako správce a klikni na tlačítko >Fix<. Po restartu PC se na Ploše objeví fixlog, jeho obsah prosím vlož do dalšího příspěvku.