po zrobieniu FIXA wywaliło BSODa
W logu widzę, ze BSOD'y miałeś juz tez wczesniej, wiec to nie ma zadnego zwiazku z usuwaniem, (to sprawa sterowników/sprzetowa).
Te wszystkie błędy, jakie teraz będą się pojawiać są spowodowane przez infekcję (albo blokada, albo zmiana uprawnień).
Ciężko to będzie naprawić, ale trzeba przynajmniej spróbować.
1) Otwórz Notatnik i wklej w nim:
Reg: reg add HKLM\SYSTEM\CurrentControlSet\Services\Schedule /v Start /t REG_DWORD /d 0x2 /f
Reg: reg delete "HKCU\Software\Microsoft\Windows Script Host" /f
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamgui.exe
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbampt.exe
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamscheduler.exe
Unlock: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamservice.exe
Task: {41AFF5ED-283F-4915-8211-9DDDCB014C2B} - \SaveSenseLiveUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {44DF30EB-FD6D-4D4C-A227-9B2FF89F4F55} - \bench-Updater removing No Task File <==== ATTENTION
Task: {5AE3026C-2FF8-4886-BA71-1D5174A6F098} - \SaveSenseLiveUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {6588ACC4-25B7-40DC-8A6A-6D3BE6A5F886} - \bench-sys No Task File <==== ATTENTION
Task: {C08EAEC9-484D-4157-BF70-166893E1CA8D} - \SaveSense No Task File <==== ATTENTION
Task: {EBB0E7FC-784E-425B-BD1E-044FDCCDCD7A} - \AmiUpdXp No Task File <==== ATTENTION
HKU\S-1-5-21-2652757564-2263176674-1634755116-1000\...\Winlogon: [Shell] explorer.exe,"C:\Windows\SysWOW64\Windows Services\win32.exe" <==== ATTENTION
IFEO\avcenter.exe: [Debugger] nqij.exe
IFEO\avconfig.exe: [Debugger] nqij.exe
IFEO\avgcsrvx.exe: [Debugger] nqij.exe
IFEO\avgidsagent.exe: [Debugger] nqij.exe
IFEO\avgnt.exe: [Debugger] nqij.exe
IFEO\avgrsx.exe: [Debugger] nqij.exe
IFEO\avguard.exe: [Debugger] nqij.exe
IFEO\avgui.exe: [Debugger] nqij.exe
IFEO\avgwdsvc.exe: [Debugger] nqij.exe
IFEO\avp.exe: [Debugger] nqij.exe
IFEO\avscan.exe: [Debugger] nqij.exe
IFEO\bdagent.exe: [Debugger] nqij.exe
IFEO\blindman.exe: [Debugger] nqij.exe
IFEO\ccuac.exe: [Debugger] nqij.exe
IFEO\ComboFix.exe: [Debugger] nqij.exe
IFEO\egui.exe: [Debugger] nqij.exe
IFEO\hijackthis.exe: [Debugger] nqij.exe
IFEO\keyscrambler.exe: [Debugger] nqij.exe
IFEO\mbam.exe: [Debugger] nqij.exe
IFEO\mbamgui.exe: [Debugger] nqij.exe
IFEO\mbampt.exe: [Debugger] nqij.exe
IFEO\mbamscheduler.exe: [Debugger] nqij.exe
IFEO\mbamservice.exe: [Debugger] nqij.exe
IFEO\MpCmdRun.exe: [Debugger] nqij.exe
IFEO\MSASCui.exe: [Debugger] nqij.exe
IFEO\MsMpEng.exe: [Debugger] nqij.exe
IFEO\msseces.exe: [Debugger] nqij.exe
IFEO\rstrui.exe: [Debugger] nqij.exe
IFEO\SDFiles.exe: [Debugger] nqij.exe
IFEO\SDMain.exe: [Debugger] nqij.exe
IFEO\SDWinSec.exe: [Debugger] nqij.exe
IFEO\spybotsd.exe: [Debugger] nqij.exe
IFEO\wireshark.exe: [Debugger] nqij.exe
IFEO\zlclient.exe: [Debugger] nqij.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S4 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S4 LMIInfo; \??\D:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [X]
S4 VGPU; System32\drivers\rdvgkmd.sys [X]
C:\Windows\SysWOW64\AI_RecycleBin
Reboot:
Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. Powstanie plik fixlog.txt. Daj ten log.
2) Zrób nowe logi z FRST.
3) Uruchom
Dostępne tylko dla zarejestrowanych użytkowników i w oknie wklej:
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\rules.ref
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware
Zastosuj opcję
Unlock.
4) Sprawdź, co jeszcze nie działa.
F.