Strong signal adv


(Martin Dziedzic) #1

frst:  http://www.wklej.org/id/1703396/

additional: http://wklej.org/id/1703405/


(Acorus) #2

Otwórz notatnik systemowy i wklej:

HKLM\...\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7636696 2014-09-03] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] = C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1396592 2014-09-02] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3224527454-2074643379-1976806520-1002\...\Run: [ALLUpdate] = C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2765256 2015-01-24] (ALLPlayer Group Ltd.)
GroupPolicy: Group Policy on Chrome detected ======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction ======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 - {D6D46D65-BF52-40EB-96DC-0347D90F8B65} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8tag=hp-uk3-vsb-21link%5Fcode=qsindex=apsfield-keywords={searchTerms}
SearchScopes: HKU\.DEFAULT - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3224527454-2074643379-1976806520-1002 - {0786B925-D7DA-4E85-A2EA-B366A5168769} URL = https://uk.search.yahoo.com/search?fr=chr-greentree_ieei=utf-8ilc=12type=0p={searchTerms}
SearchScopes: HKU\S-1-5-21-3224527454-2074643379-1976806520-1002 - {D6D46D65-BF52-40EB-96DC-0347D90F8B65} URL = http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8tag=hp-uk3-vsb-21link%5Fcode=qsindex=apsfield-keywords={searchTerms}
BHO-x32: No Name - {c723a437-2eaf-466d-a95b-3fa0966bf88c} - No File
CHR Extension: (Strong Signal) - C:\Users\Marcin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdmekppnalhnpenpglkipoppjmiidke [2015-05-02]
OPR Extension: (Strong Signal) - C:\Users\Marcin\AppData\Roaming\Opera Software\Opera Stable\Extensions\ecdmekppnalhnpenpglkipoppjmiidke [2015-05-01]
2015-05-04 18:34 - 2015-05-04 18:38 - 00000000 ____ D () C:\AdwCleaner
2015-05-02 11:02 - 2015-05-02 11:02 - 00000000 _____ () C:\autoexec.bat
2015-05-02 11:01 - 2015-05-02 11:01 - 00000000 ____ D () C:\sh4ldr
2015-05-02 11:00 - 2015-05-03 19:12 - 00000000 ____ D () C:\Program Files\Enigma Software Group
2015-05-02 11:00 - 2015-05-02 11:00 - 00022704 _____ () C:\Windows\system32\Drivers\EsgScanner.sys
EmptyTemp:

Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.


(Martin Dziedzic) #3

dzieki :wink: problem solved


(Acorus) #4

Skasuj folder C:\FRST