
Mam serdeczną prośbę podobną do innych pytających mianowicie Strong Singal. W załączniku logi z FRST(logi z tego programu musiałem przekopiować do nowego pliku txt, nie bo mogłem zapisać) oraz OLT. Z góry dziękuję za pomoc i pozdrawiam serdecznie
Error - 2015-05-19 12:02:13 | Computer Name = MrMarch | Source = WinMgmt | ID = 10
Description =
Check "winmgmt" service or repair WMI.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Winmgmt]
"DisplayName"="@%Systemroot%\\system32\\wbem\\wmisvc.dll,-205"
"ImagePath"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,\
74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"Description"="@%Systemroot%\\system32\\wbem\\wmisvc.dll,-204"
"ObjectName"="localSystem"
"ErrorControl"=dword:00000000
"Start"=dword:00000002
"Type"=dword:00000020
"DependOnService"=hex(7):52,00,50,00,43,00,53,00,53,00,00,00,00,00
"ServiceSidType"=dword:00000001
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Winmgmt\Parameters]
"ServiceDllUnloadOnStop"=dword:00000001
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
77,00,62,00,65,00,6d,00,5c,00,57,00,4d,00,49,00,73,00,76,00,63,00,2e,00,64,\
00,6c,00,6c,00,00,00
"ServiceMain"="ServiceMain"
Task: {CB9BC319-090A-4361-88ED-3489E8B5D97B} - \Microsoft\Windows\Offline Files\Logon Synchronization No Task File <==== ATTENTION
Task: {E1091988-7065-4B7B-8AC1-3859C6C3CF22} - \Microsoft\Windows\Offline Files\Background Synchronization No Task File <==== ATTENTION
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://q.search-simple.com/?affID=bl_f354b450-a8ac-4c3c-bc9a-4403d9802300
S4 CscService; %SystemRoot%\System32\cscsvc.dll [X]
S3 PeerDistSvc; %SystemRoot%\system32\peerdistsvc.dll [X]
S4 CSC; system32\drivers\csc.sys [X]
S4 RDPDR; System32\drivers\rdpdr.sys [X]
S3 s3cap; \SystemRoot\system32\DRIVERS\vms3cap.sys [X]
S4 storflt; system32\DRIVERS\vmstorfl.sys [X]
S3 storvsc; \SystemRoot\system32\DRIVERS\storvsc.sys [X]
S1 VBoxSF; system32\drivers\VBoxSF.sys [X]
S3 vmbus; \SystemRoot\system32\DRIVERS\vmbus.sys [X]
S3 VMBusHID; \SystemRoot\system32\DRIVERS\VMBusHID.sys [X]
C:\Windows\Minidump\*.dmp
C:\Program Files\Strong Signal
C:\Users\Mr. March\AppData\Roaming\key-find
EmptyTemp:
==================== Accounts: =============================
Administrator (S-1-5-21-1384433103-774265942-2269624152-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-1384433103-774265942-2269624152-501 - Limited - Disabled)
user (S-1-5-21-1384433103-774265942-2269624152-1000 - Administrator - Enabled) => C:\Users\user
Administrator (S-1-5-21-2970542215-3170522797-3596620580-500 - Administrator - Disabled)
Gość (S-1-5-21-2970542215-3170522797-3596620580-501 - Limited - Disabled)
Mr. March (S-1-5-21-2970542215-3170522797-3596620580-1000 - Administrator - Enabled) => C:\Users\Mr. March
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
BHO: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File
C:\Program Files\Strong Signal
FF Extension: Strong Signal - C:\Users\Mr. March\AppData\Roaming\Mozilla\Firefox\Profiles\992uwsnv.default\Extensions\{1c00b031-52f0-4616-bdcf-2e1a2c46eb7a}.xpi [2015-02-27]
CHR RestoreOnStartup: Default -> "hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bg_616_bl-is-16__alt__ddc_dsssyc_bd_com"
CHR StartupUrls: Default -> "hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bg_616_bl-is-16__alt__ddc_dsssyc_bd_com"
CHR DefaultSearchKeyword: Default -> yahoo.com
CHR DefaultNewTabURL: Default -> http://search.yahoo.com/?fr=hp-ddc-bd-tabs&type=bg_616_bl-is-16__alt__ddc_dsssyctabs_bd_com
CHR Extension: (Strong Signal) - C:\Users\Mr. March\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcdmgnpdjibgflhdpdiadieiellikmge [2015-03-11]
EmptyTemp:
DeleteQuarantine:
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 1 gość