Komputer 1:
Wklej do notatnika:
DeleteQuarantine:
Plik zapisujesz pod nazwą
fixlist.txt i umieszczasz obok FRST. Uruchom FRST i kliknij w nim
FixPrzeczyść dysk oraz rejestr
CCleaner (zakładka
Cleaner i
Rejestr)
Zainstaluj
https://www.instalki.pl/download/programy/windows/bezpieczenstwo/zabezpieczajace/unchecky/---------------------------------
Komputer mamy:
W AdwCleaner

Uninstall
Odinstaluj
Steel Cut. Następnie:
Wklej do notatnika:
- Kod: Zaznacz wszystko
HKLM-x32\...\Run: [mbot_pl_014010053] => [X]
HKLM-x32\...\Run: [gmsd_pl_005010053] => [X]
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1438877736&z=5cacc40c7980fe21e5f2782gcz1c2bbbam6m7q6q9c&from=cmi&uid=ST3250620AS_5QE00LJTXXXX5QE00LJT&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1438877736&z=5cacc40c7980fe21e5f2782gcz1c2bbbam6m7q6q9c&from=cmi&uid=ST3250620AS_5QE00LJTXXXX5QE00LJT&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1438877736&z=5cacc40c7980fe21e5f2782gcz1c2bbbam6m7q6q9c&from=cmi&uid=ST3250620AS_5QE00LJTXXXX5QE00LJT&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1438877736&z=5cacc40c7980fe21e5f2782gcz1c2bbbam6m7q6q9c&from=cmi&uid=ST3250620AS_5QE00LJTXXXX5QE00LJT&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2112974569-3588844033-3721115501-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=ST3250620AS_5QE00LJTXXXX5QE00LJT&ts=1438877835&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2112974569-3588844033-3721115501-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cmi&utm_campaign=install_ie&utm_content=ds&from=cmi&uid=ST3250620AS_5QE00LJTXXXX5QE00LJT&ts=1438877835&type=default&q={searchTerms}
FF DefaultSearchUrl: hxxps://search.yahoo.com/yhs/search
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Keyword.URL: hxxps://search.yahoo.com/yhs/search
HKU\S-1-5-21-2112974569-3588844033-3721115501-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.yahoo.com/?fr=hp-avast&type=agc511
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
FF SearchPlugin: C:\Users\Danka\AppData\Roaming\Mozilla\Firefox\Profiles\cgb318bt.default\searchplugins\yahoo-avast.xml [2015-07-18]
FF Extension: Search Enginer - C:\Users\Danka\AppData\Roaming\Mozilla\Firefox\Profiles\cgb318bt.default\Extensions\ffsearch_toolbar [2015-08-06]
FF HKLM-x32\...\Firefox\Extensions: [ffsearch_toolbar] - C:\Users\Danka\AppData\Roaming\Mozilla\Firefox\Profiles\cgb318bt.default\extensions\ffsearch_toolbar
FF Extension: No Name - C:\Users\Danka\AppData\Roaming\Mozilla\Firefox\Profiles\cgb318bt.default\extensions\[email protected] [not found]
FF Extension: No Name - C:\Users\Danka\AppData\Roaming\Mozilla\Firefox\Profiles\cgb318bt.default\extensions\[email protected] [not found]
FF Extension: No Name - C:\Users\Danka\AppData\Roaming\Mozilla\Firefox\Profiles\cgb318bt.default\extensions\[email protected] [not found]
R2 Update Steel Cut; C:\Program Files (x86)\Steel Cut\updateSteelCut.exe [472816 2015-08-23] ()
R2 Util Steel Cut; C:\Program Files (x86)\Steel Cut\bin\utilSteelCut.exe [472816 2015-08-23] ()
C:\Program Files (x86)\Steel Cut
S2 Update Swift Record; "C:\Program Files (x86)\Swift Record\updateSwiftRecord.exe" [X]
R1 {4892723d-a7bd-44aa-848e-1a2264b27545}Gw64; C:\Windows\System32\drivers\{4892723d-a7bd-44aa-848e-1a2264b27545}Gw64.sys [48776 2015-08-21] (StdLib)
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 X6va029; \??\C:\Windows\SysWOW64\Drivers\X6va029 [X]
2015-08-22 04:36 - 2015-08-21 13:58 - 00048776 _____ (StdLib) C:\Windows\system32\Drivers\{4892723d-a7bd-44aa-848e-1a2264b27545}Gw64.sys
2015-08-15 20:25 - 2015-08-15 07:31 - 00048776 _____ (StdLib) C:\Windows\system32\Drivers\{c0367639-9649-487c-b7bb-588e14f2a875}Gw64.sys
EmptyTemp:
Plik zapisujesz pod nazwą
fixlist.txt i umieszczasz obok FRST. Uruchom FRST i kliknij w nim
Fix. Powstanie plik
fixlog.txt, który podajesz na forum.
Następnie podaj nowe logi z FRST.