Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Spouštění Chrome a stránky po zapnutí PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Spouštění Chrome a stránky po zapnutí PC
Dobrý den,
už delší dobu mě trápí takový problém, notebook je velice zpomalený a při každém spuštění počítače se automaticky spouští chrome s nějakou reklamou (Originalsoftware- larati.net) -netuším co to je Četl jsem zdejší rady a nainstaloval jsem AdwCleaner, ten sice pár souborů našel, ale nevidím sebemenší změnu na rychlosti počítače a reklama se pořád sama spouští. Prosím tedy o kontrolu logu, předem moc děkuji :
už delší dobu mě trápí takový problém, notebook je velice zpomalený a při každém spuštění počítače se automaticky spouští chrome s nějakou reklamou (Originalsoftware- larati.net) -netuším co to je Četl jsem zdejší rady a nainstaloval jsem AdwCleaner, ten sice pár souborů našel, ale nevidím sebemenší změnu na rychlosti počítače a reklama se pořád sama spouští. Prosím tedy o kontrolu logu, předem moc děkuji :
Re: Spouštění Chrome a stránky po zapnutí PC
Ahoj
Poprosim aj log z AdwCleaneru
Poprosim aj log z AdwCleaneru
Absolvent skoly pre novacikov
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Spouštění Chrome a stránky po zapnutí PC
Nejsem si jistý jestli je to to, co potřebujete, ale zkopíroval jsem těch 5 txt souborů z AdwCleaneru, které jsou v programu pod záložkou "Soubory protokolu"
- Přílohy
-
- Logs.rar
- (17.56 KiB) Staženo 70 x
Re: Spouštění Chrome a stránky po zapnutí PC
Ano, je to spravne, Urob este raz sken v AdwCleaneri a ak sa vyskytnu opat nalezy, nechaj ich zmazat a posli log.
Nasledne poprosim o obidva nove logy z FRST.
Nasledne poprosim o obidva nove logy z FRST.
Absolvent skoly pre novacikov
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Spouštění Chrome a stránky po zapnutí PC
Provedl jsem další sken a byly tam další 4 nálezy, smazal jsem je ale problémy stále zůstávají , logy přikládám do přílohy
- Přílohy
-
- Logs-2.rar
- (14.5 KiB) Staženo 60 x
Re: Spouštění Chrome a stránky po zapnutí PC
Tady ještě zasílám nové FRST logy.
- Přílohy
-
- Downloads-2.rar
- (33.88 KiB) Staženo 70 x
Re: Spouštění Chrome a stránky po zapnutí PC
Otvor poznamkovy blok (Win+R -> notepad -> enter)
- Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:
Kód: Vybrat vše
Start CloseProcesses: CreateRestorePoint: PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum CMD: type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat" HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e663-e85a-11e8-83f7-3cf862b27914} - "F:\autorun.exe" HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e6c0-e85a-11e8-83f7-3cf862b27914} - "H:\SETUP.EXE" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat [2018-02-03] () [File not signed] FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION Task: {4F024B93-619B-4003-827E-B64ED081DD2E} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION Task: {684EBD42-4DEC-441B-86BE-FBA11EAF0058} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION Task: {C76C46F6-5370-4323-8E43-EC3D66D822EC} - \Lenovo\ImController\TimeBasedEvents\c1b75653-0b8b-4a1a-8771-52d79afb5f76 -> No File <==== ATTENTION Task: {CA7BEF64-BD61-4B18-9C82-166D21523579} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION Task: {CD626EAE-A681-4F9A-AFE4-50A1CC778A29} - \Lenovo\ImController\TimeBasedEvents\9204f3bc-cf22-4bc2-ba76-7d9251fd6df5 -> No File <==== ATTENTION Task: {F6EE1A82-9EE4-45DA-A633-005BA6A65F59} - \Lenovo\ImController\TimeBasedEvents\6ac67465-d295-4ceb-b8e2-9be7fc214157 -> No File <==== ATTENTION HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com SearchScopes: HKU\S-1-5-21-3779911134-3468200891-374603919-1001 -> DefaultScope {7C931681-ED70-4926-A81D-1861AA9F96A5} URL = S2 CCSDK; "C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe" [X] S2 ImControllerService; "%SystemDrive%\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe" [X] U3 mfeavfk01; no ImagePath 2019-10-29 18:21 - 2019-10-29 18:21 - 000000000 ____D C:\Users\Honza\Downloads\FRST-OlderVersion ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service" Hosts: EmptyTemp: End
- Uloz na plochu s nazvom fixlist.txt
- Spusti znovu FRST a klikni na Fix
- Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
- Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj
Absolvent skoly pre novacikov
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Spouštění Chrome a stránky po zapnutí PC
Hotovo. po restartu se chrome už sám nezapnul, sice potom spouštění chromu bylo dost zpomalené, ale to asi možná kvůli tomu restartu
fixlog je tu:
Fix result of Farbar Recovery Scan Tool (x64) Version: 29-10-2019
Ran by Honza (29-10-2019 21:29:46) Run:1
Running from C:\Users\Honza\Desktop
Loaded Profiles: Honza (Available Profiles: Honza)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
CMD: type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat"
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e663-e85a-11e8-83f7-3cf862b27914} - "F:\autorun.exe"
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e6c0-e85a-11e8-83f7-3cf862b27914} - "H:\SETUP.EXE"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat [2018-02-03] () [File not signed]
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {4F024B93-619B-4003-827E-B64ED081DD2E} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: {684EBD42-4DEC-441B-86BE-FBA11EAF0058} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {C76C46F6-5370-4323-8E43-EC3D66D822EC} - \Lenovo\ImController\TimeBasedEvents\c1b75653-0b8b-4a1a-8771-52d79afb5f76 -> No File <==== ATTENTION
Task: {CA7BEF64-BD61-4B18-9C82-166D21523579} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {CD626EAE-A681-4F9A-AFE4-50A1CC778A29} - \Lenovo\ImController\TimeBasedEvents\9204f3bc-cf22-4bc2-ba76-7d9251fd6df5 -> No File <==== ATTENTION
Task: {F6EE1A82-9EE4-45DA-A633-005BA6A65F59} - \Lenovo\ImController\TimeBasedEvents\6ac67465-d295-4ceb-b8e2-9be7fc214157 -> No File <==== ATTENTION
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
SearchScopes: HKU\S-1-5-21-3779911134-3468200891-374603919-1001 -> DefaultScope {7C931681-ED70-4926-A81D-1861AA9F96A5} URL =
S2 CCSDK; "C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe" [X]
S2 ImControllerService; "%SystemDrive%\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe" [X]
U3 mfeavfk01; no ImagePath
2019-10-29 18:21 - 2019-10-29 18:21 - 000000000 ____D C:\Users\Honza\Downloads\FRST-OlderVersion
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service"
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========
Count : 2991
Average :
Sum : 25612139012
Maximum :
Minimum :
Property : Length
========= End of Powershell: =========
========= type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat" =========
@echo off
TITLE Steam update check..
start "" http://j.gs/9KCw
========= End of CMD: =========
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e663-e85a-11e8-83f7-3cf862b27914} => removed successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e6c0-e85a-11e8-83f7-3cf862b27914} => removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4F024B93-619B-4003-827E-B64ED081DD2E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F024B93-619B-4003-827E-B64ED081DD2E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{684EBD42-4DEC-441B-86BE-FBA11EAF0058}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{684EBD42-4DEC-441B-86BE-FBA11EAF0058}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C76C46F6-5370-4323-8E43-EC3D66D822EC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C76C46F6-5370-4323-8E43-EC3D66D822EC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\c1b75653-0b8b-4a1a-8771-52d79afb5f76" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA7BEF64-BD61-4B18-9C82-166D21523579}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA7BEF64-BD61-4B18-9C82-166D21523579}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Monitor" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD626EAE-A681-4F9A-AFE4-50A1CC778A29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD626EAE-A681-4F9A-AFE4-50A1CC778A29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\9204f3bc-cf22-4bc2-ba76-7d9251fd6df5" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6EE1A82-9EE4-45DA-A633-005BA6A65F59}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6EE1A82-9EE4-45DA-A633-005BA6A65F59}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\6ac67465-d295-4ceb-b8e2-9be7fc214157" => removed successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
"HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages" => removed successfully
"HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKLM\System\CurrentControlSet\Services\CCSDK => removed successfully
CCSDK => service removed successfully
HKLM\System\CurrentControlSet\Services\ImControllerService => removed successfully
ImControllerService => service removed successfully
HKLM\System\CurrentControlSet\Services\mfeavfk01 => removed successfully
mfeavfk01 => service removed successfully
C:\Users\Honza\Downloads\FRST-OlderVersion => moved successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MCODS => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8151040 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 44398075 B
Java, Flash, Steam htmlcache => 105741139 B
Windows/system/drivers => 2100739 B
Edge => 6744534 B
Chrome => 443629264 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 148 B
systemprofile32 => 148 B
LocalService => 19396 B
NetworkService => 34626 B
Honza => 7202664 B
RecycleBin => 0 B
EmptyTemp: => 589.4 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 21:34:01 ====
fixlog je tu:
Fix result of Farbar Recovery Scan Tool (x64) Version: 29-10-2019
Ran by Honza (29-10-2019 21:29:46) Run:1
Running from C:\Users\Honza\Desktop
Loaded Profiles: Honza (Available Profiles: Honza)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
CMD: type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat"
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e663-e85a-11e8-83f7-3cf862b27914} - "F:\autorun.exe"
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e6c0-e85a-11e8-83f7-3cf862b27914} - "H:\SETUP.EXE"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat [2018-02-03] () [File not signed]
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {4F024B93-619B-4003-827E-B64ED081DD2E} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: {684EBD42-4DEC-441B-86BE-FBA11EAF0058} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {C76C46F6-5370-4323-8E43-EC3D66D822EC} - \Lenovo\ImController\TimeBasedEvents\c1b75653-0b8b-4a1a-8771-52d79afb5f76 -> No File <==== ATTENTION
Task: {CA7BEF64-BD61-4B18-9C82-166D21523579} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {CD626EAE-A681-4F9A-AFE4-50A1CC778A29} - \Lenovo\ImController\TimeBasedEvents\9204f3bc-cf22-4bc2-ba76-7d9251fd6df5 -> No File <==== ATTENTION
Task: {F6EE1A82-9EE4-45DA-A633-005BA6A65F59} - \Lenovo\ImController\TimeBasedEvents\6ac67465-d295-4ceb-b8e2-9be7fc214157 -> No File <==== ATTENTION
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
SearchScopes: HKU\S-1-5-21-3779911134-3468200891-374603919-1001 -> DefaultScope {7C931681-ED70-4926-A81D-1861AA9F96A5} URL =
S2 CCSDK; "C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe" [X]
S2 ImControllerService; "%SystemDrive%\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe" [X]
U3 mfeavfk01; no ImagePath
2019-10-29 18:21 - 2019-10-29 18:21 - 000000000 ____D C:\Users\Honza\Downloads\FRST-OlderVersion
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service"
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========
Count : 2991
Average :
Sum : 25612139012
Maximum :
Minimum :
Property : Length
========= End of Powershell: =========
========= type "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat" =========
@echo off
TITLE Steam update check..
start "" http://j.gs/9KCw
========= End of CMD: =========
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e663-e85a-11e8-83f7-3cf862b27914} => removed successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e6c0-e85a-11e8-83f7-3cf862b27914} => removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4F024B93-619B-4003-827E-B64ED081DD2E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F024B93-619B-4003-827E-B64ED081DD2E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{684EBD42-4DEC-441B-86BE-FBA11EAF0058}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{684EBD42-4DEC-441B-86BE-FBA11EAF0058}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C76C46F6-5370-4323-8E43-EC3D66D822EC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C76C46F6-5370-4323-8E43-EC3D66D822EC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\c1b75653-0b8b-4a1a-8771-52d79afb5f76" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA7BEF64-BD61-4B18-9C82-166D21523579}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA7BEF64-BD61-4B18-9C82-166D21523579}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Monitor" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD626EAE-A681-4F9A-AFE4-50A1CC778A29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD626EAE-A681-4F9A-AFE4-50A1CC778A29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\9204f3bc-cf22-4bc2-ba76-7d9251fd6df5" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6EE1A82-9EE4-45DA-A633-005BA6A65F59}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6EE1A82-9EE4-45DA-A633-005BA6A65F59}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\6ac67465-d295-4ceb-b8e2-9be7fc214157" => removed successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
"HKU\S-1-5-21-3779911134-3468200891-374603919-1001\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages" => removed successfully
"HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKLM\System\CurrentControlSet\Services\CCSDK => removed successfully
CCSDK => service removed successfully
HKLM\System\CurrentControlSet\Services\ImControllerService => removed successfully
ImControllerService => service removed successfully
HKLM\System\CurrentControlSet\Services\mfeavfk01 => removed successfully
mfeavfk01 => service removed successfully
C:\Users\Honza\Downloads\FRST-OlderVersion => moved successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MCODS => removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8151040 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 44398075 B
Java, Flash, Steam htmlcache => 105741139 B
Windows/system/drivers => 2100739 B
Edge => 6744534 B
Chrome => 443629264 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 148 B
systemprofile32 => 148 B
LocalService => 19396 B
NetworkService => 34626 B
Honza => 7202664 B
RecycleBin => 0 B
EmptyTemp: => 589.4 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 21:34:01 ====
Re: Spouštění Chrome a stránky po zapnutí PC
Tak moc děkuji za pomoc
Re: Spouštění Chrome a stránky po zapnutí PC
Odporucam este odinstalovat programy "McAfee LiveSafe" a "McAfee WebAdvisor" - su viacmenej zbytocne, kedze v PC je uz Avast.
Nasledne odporucam aj precistit PC cez McAfee odinstalator: http://us.mcafee.com/apps/supporttools/mcpr/mcpr.asp
Staci stiahnut, spustit ako spravca, kliknut na Next, opisat overovaci kod, pockat na dokoncenie a potvrdit restart PC.
Potom poprosim este raz o nove logy z FRST.
Nasledne odporucam aj precistit PC cez McAfee odinstalator: http://us.mcafee.com/apps/supporttools/mcpr/mcpr.asp
Staci stiahnut, spustit ako spravca, kliknut na Next, opisat overovaci kod, pockat na dokoncenie a potvrdit restart PC.
Potom poprosim este raz o nove logy z FRST.
Absolvent skoly pre novacikov
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Spouštění Chrome a stránky po zapnutí PC
Hotovo, tady jsou nové logy:
- Přílohy
-
- Desktop.rar
- (31.75 KiB) Staženo 62 x
Re: Spouštění Chrome a stránky po zapnutí PC
Otvor poznamkovy blok (Win+R -> notepad -> enter)
- Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:
Kód: Vybrat vše
Start CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e663-e85a-11e8-83f7-3cf862b27914} - "F:\autorun.exe" HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e6c0-e85a-11e8-83f7-3cf862b27914} - "H:\SETUP.EXE" S3 McSecDashboardService; C:\Program Files\McAfeeDashboard\McSecDashboardService.exe [1270536 2019-02-26] (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\McAfeeDashboard 2019-10-30 12:33 - 2019-10-30 12:33 - 010642552 _____ (McAfee, LLC.) C:\Users\Honza\Downloads\MCPR.exe 2019-10-22 01:09 - 2019-10-30 12:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee 2019-10-30 12:19 - 2018-01-24 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501} FirewallRules: [{F6C1171F-9346-4164-8D1F-A64A7F005A11}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File FirewallRules: [{6DCDACCB-8AB7-428F-9D6C-37A7EB080341}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File C:\Program Files\Common Files\AV\McAfee VirusScan C:\Program Files\Common Files\McAfee C:\Program Files\McAfee C:\WINDOWS\System32\drivers\cfwids.sys C:\WINDOWS\System32\drivers\HipShieldK.sys C:\WINDOWS\System32\drivers\mfeaack.sys C:\WINDOWS\System32\drivers\mfeavfk.sys C:\WINDOWS\System32\drivers\mfeelamk.sys C:\WINDOWS\System32\drivers\mfefirek.sys C:\WINDOWS\System32\drivers\mfehidk.sys C:\WINDOWS\System32\DRIVERS\mfencbdc.sys C:\WINDOWS\System32\DRIVERS\mfencrk.sys C:\WINDOWS\System32\drivers\mfeplk.sys C:\WINDOWS\System32\drivers\mfewfpk.sys Hosts: EmptyTemp: End
- Uloz na plochu s nazvom fixlist.txt
- Spusti znovu FRST a klikni na Fix
- Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
- Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj
Absolvent skoly pre novacikov
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Spouštění Chrome a stránky po zapnutí PC
Hotovo, tady je fixlog
Fix result of Farbar Recovery Scan Tool (x64) Version: 30-10-2019 01
Ran by Honza (31-10-2019 09:55:43) Run:2
Running from C:\Users\Honza\Desktop
Loaded Profiles: Honza (Available Profiles: Honza)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e663-e85a-11e8-83f7-3cf862b27914} - "F:\autorun.exe"
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e6c0-e85a-11e8-83f7-3cf862b27914} - "H:\SETUP.EXE"
S3 McSecDashboardService; C:\Program Files\McAfeeDashboard\McSecDashboardService.exe [1270536 2019-02-26] (McAfee, Inc. -> McAfee, Inc.)
C:\Program Files\McAfeeDashboard
2019-10-30 12:33 - 2019-10-30 12:33 - 010642552 _____ (McAfee, LLC.) C:\Users\Honza\Downloads\MCPR.exe
2019-10-22 01:09 - 2019-10-30 12:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2019-10-30 12:19 - 2018-01-24 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
FirewallRules: [{F6C1171F-9346-4164-8D1F-A64A7F005A11}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{6DCDACCB-8AB7-428F-9D6C-37A7EB080341}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
C:\Program Files\Common Files\AV\McAfee VirusScan
C:\Program Files\Common Files\McAfee
C:\Program Files\McAfee
C:\WINDOWS\System32\drivers\cfwids.sys
C:\WINDOWS\System32\drivers\HipShieldK.sys
C:\WINDOWS\System32\drivers\mfeaack.sys
C:\WINDOWS\System32\drivers\mfeavfk.sys
C:\WINDOWS\System32\drivers\mfeelamk.sys
C:\WINDOWS\System32\drivers\mfefirek.sys
C:\WINDOWS\System32\drivers\mfehidk.sys
C:\WINDOWS\System32\DRIVERS\mfencbdc.sys
C:\WINDOWS\System32\DRIVERS\mfencrk.sys
C:\WINDOWS\System32\drivers\mfeplk.sys
C:\WINDOWS\System32\drivers\mfewfpk.sys
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e663-e85a-11e8-83f7-3cf862b27914} => removed successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e6c0-e85a-11e8-83f7-3cf862b27914} => removed successfully
HKLM\System\CurrentControlSet\Services\McSecDashboardService => removed successfully
McSecDashboardService => service removed successfully
C:\Program Files\McAfeeDashboard => moved successfully
C:\Users\Honza\Downloads\MCPR.exe => moved successfully
C:\WINDOWS\system32\Tasks\McAfee => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee => moved successfully
"AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F6C1171F-9346-4164-8D1F-A64A7F005A11}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6DCDACCB-8AB7-428F-9D6C-37A7EB080341}" => removed successfully
"C:\Program Files\Common Files\AV\McAfee VirusScan" => not found
"C:\Program Files\Common Files\McAfee" => not found
"C:\Program Files\McAfee" => not found
"C:\WINDOWS\System32\drivers\cfwids.sys" => not found
"C:\WINDOWS\System32\drivers\HipShieldK.sys" => not found
"C:\WINDOWS\System32\drivers\mfeaack.sys" => not found
"C:\WINDOWS\System32\drivers\mfeavfk.sys" => not found
"C:\WINDOWS\System32\drivers\mfeelamk.sys" => not found
"C:\WINDOWS\System32\drivers\mfefirek.sys" => not found
"C:\WINDOWS\System32\drivers\mfehidk.sys" => not found
"C:\WINDOWS\System32\DRIVERS\mfencbdc.sys" => not found
"C:\WINDOWS\System32\DRIVERS\mfencrk.sys" => not found
"C:\WINDOWS\System32\drivers\mfeplk.sys" => not found
"C:\WINDOWS\System32\drivers\mfewfpk.sys" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8151040 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 23258269 B
Java, Flash, Steam htmlcache => 132043 B
Windows/system/drivers => 659661 B
Edge => 2550455 B
Chrome => 386516333 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 22572 B
NetworkService => 22572 B
Honza => 41920748 B
RecycleBin => 257677 B
EmptyTemp: => 442 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 09:58:10 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 30-10-2019 01
Ran by Honza (31-10-2019 09:55:43) Run:2
Running from C:\Users\Honza\Desktop
Loaded Profiles: Honza (Available Profiles: Honza)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e663-e85a-11e8-83f7-3cf862b27914} - "F:\autorun.exe"
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\...\MountPoints2: {2da0e6c0-e85a-11e8-83f7-3cf862b27914} - "H:\SETUP.EXE"
S3 McSecDashboardService; C:\Program Files\McAfeeDashboard\McSecDashboardService.exe [1270536 2019-02-26] (McAfee, Inc. -> McAfee, Inc.)
C:\Program Files\McAfeeDashboard
2019-10-30 12:33 - 2019-10-30 12:33 - 010642552 _____ (McAfee, LLC.) C:\Users\Honza\Downloads\MCPR.exe
2019-10-22 01:09 - 2019-10-30 12:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2019-10-30 12:19 - 2018-01-24 21:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
FirewallRules: [{F6C1171F-9346-4164-8D1F-A64A7F005A11}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{6DCDACCB-8AB7-428F-9D6C-37A7EB080341}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
C:\Program Files\Common Files\AV\McAfee VirusScan
C:\Program Files\Common Files\McAfee
C:\Program Files\McAfee
C:\WINDOWS\System32\drivers\cfwids.sys
C:\WINDOWS\System32\drivers\HipShieldK.sys
C:\WINDOWS\System32\drivers\mfeaack.sys
C:\WINDOWS\System32\drivers\mfeavfk.sys
C:\WINDOWS\System32\drivers\mfeelamk.sys
C:\WINDOWS\System32\drivers\mfefirek.sys
C:\WINDOWS\System32\drivers\mfehidk.sys
C:\WINDOWS\System32\DRIVERS\mfencbdc.sys
C:\WINDOWS\System32\DRIVERS\mfencrk.sys
C:\WINDOWS\System32\drivers\mfeplk.sys
C:\WINDOWS\System32\drivers\mfewfpk.sys
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e663-e85a-11e8-83f7-3cf862b27914} => removed successfully
HKU\S-1-5-21-3779911134-3468200891-374603919-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2da0e6c0-e85a-11e8-83f7-3cf862b27914} => removed successfully
HKLM\System\CurrentControlSet\Services\McSecDashboardService => removed successfully
McSecDashboardService => service removed successfully
C:\Program Files\McAfeeDashboard => moved successfully
C:\Users\Honza\Downloads\MCPR.exe => moved successfully
C:\WINDOWS\system32\Tasks\McAfee => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee => moved successfully
"AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F6C1171F-9346-4164-8D1F-A64A7F005A11}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6DCDACCB-8AB7-428F-9D6C-37A7EB080341}" => removed successfully
"C:\Program Files\Common Files\AV\McAfee VirusScan" => not found
"C:\Program Files\Common Files\McAfee" => not found
"C:\Program Files\McAfee" => not found
"C:\WINDOWS\System32\drivers\cfwids.sys" => not found
"C:\WINDOWS\System32\drivers\HipShieldK.sys" => not found
"C:\WINDOWS\System32\drivers\mfeaack.sys" => not found
"C:\WINDOWS\System32\drivers\mfeavfk.sys" => not found
"C:\WINDOWS\System32\drivers\mfeelamk.sys" => not found
"C:\WINDOWS\System32\drivers\mfefirek.sys" => not found
"C:\WINDOWS\System32\drivers\mfehidk.sys" => not found
"C:\WINDOWS\System32\DRIVERS\mfencbdc.sys" => not found
"C:\WINDOWS\System32\DRIVERS\mfencrk.sys" => not found
"C:\WINDOWS\System32\drivers\mfeplk.sys" => not found
"C:\WINDOWS\System32\drivers\mfewfpk.sys" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8151040 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 23258269 B
Java, Flash, Steam htmlcache => 132043 B
Windows/system/drivers => 659661 B
Edge => 2550455 B
Chrome => 386516333 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 22572 B
NetworkService => 22572 B
Honza => 41920748 B
RecycleBin => 257677 B
EmptyTemp: => 442 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 09:58:10 ====
Re: Spouštění Chrome a stránky po zapnutí PC
Tak McAfee by uz mal byt kompletne odinstalovany. Inak logy uz vyzeraju OK.
Ak uz teda nie su ziadne problemy s PC, tak este upraceme po pouzitych nastrojoch:
Ak uz teda nie su ziadne problemy s PC, tak este upraceme po pouzitych nastrojoch:
- Stiahni DelFix: https://toolslib.net/downloads/finish/2-delfix/
- Uloz na plochu a spusti
- Nechaj oznacenu moznost "Remove disinfection tools"
- Klikni na "Run"
Absolvent skoly pre novacikov
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
E-mail: conder (zavinac) forum.viry.cz
Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).
Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.
V pripade spokojnosti je mozne podporit forum. Dakujeme!
Re: Spouštění Chrome a stránky po zapnutí PC
Tak jsem to udělal, opravdu moc děkuji, jste úžasní