Nie działają strony internetowe, dużo reklam

Witam serdecznie,

mam problem z laptopem. 

System windows 8.1

W jakiś sposób komputer został zarażony.

Nie działają strony internetowe na żadnej przeglądarce(mozilla, edge), wyskakiwały dziwne reklamy, część była po chińsku, kilka usunąłem - odinstaluj program.

Został jakiś:

  • safefinder

Przy próbie połączenia się z internetem wyskakuje komunikat nieznany protokół, do tego przy odpalaniu FRST również informacja że nie można się połączyć z internetem (internet oczywiście działa)

Odpalałem ADware coś tak wykrył ale przy usuwaniu wyskakuje błąd i program się wyłącza.

Anti Malware bytes nic nie wykyrwa. 

Skan FRST 

http://www.wklej.org/id/2284104/ Addition

http://www.wklej.org/id/2284105/ FRST

http://www.wklej.org/id/2284107/ Shorcut

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

CloseProcesses:
HKLM\...\Run: [IDSCCOM23W] = "C:\Program Files (x86)\Hostify\idsccom_23W.exe"
HKLM-x32\...\Run: [ic-0.95026ae8ca21e.exe -start] = C:\Users\Catering\AppData\Local\Temp\358450875\ic-0.95026ae8ca21e.exe [2289664 2016-04-11] (Microsoft Corporation) ===== UWAGA
HKLM-x32\...\Run: [mpck_en_005030294] = [X]
HKLM-x32\...\Run: [rec_pl_251] = [X]
HKLM-x32\...\Run: [sun21] = [X]
HKLM\...\Winlogon: [Userinit] wscript C:\Windows\run.vbs,
HKLM-x32\...\Winlogon: [Userinit] , [X]
HKU\S-1-5-21-1212541044-1667248246-77305449-1001\...\Run: [svchost0] = C:\Program Files (x86)\UCBrowser\Application\UUC0789.exe
AppInit_DLLs: C:\ProgramData\Quoteex\Strongzundax.dll = C:\ProgramData\Quoteex\Strongzundax.dll [363520 2016-04-13] ()
AppInit_DLLs-x32: C:\ProgramData\Quoteex\Medlab.dll = C:\ProgramData\Quoteex\Medlab.dll [257536 2016-04-13] ()
Winsock: Catalog5 01 C:\Windows\SysWOW64\napinsp.dll [55296 2014-10-29] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 02 C:\Windows\SysWOW64\pnrpnsp.dll [70144 2014-10-29] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [70144 2014-10-29] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\Windows\SysWOW64\NLAapi.dll [65536 2014-10-29] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [286208 2014-10-29] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [23040 2014-10-29] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\System32\winrnr.dll"
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKU\S-1-5-21-1212541044-1667248246-77305449-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUT3FUuencSlQ3pQ-1yrFvJ2ZWXZxhMxlTyskjtmKKvDXm4hGKtsfYdO72NA9B33_1R5qbPe6fjDKPbrpkMk9Mr9qlzWIKoX6v4nXV_PfM6P9xLwquFCGQr5TO-qbPui-dHAaugBKIMZo9tgu_HCIq0ViEaqx1uw,,q={searchTerms}
HKU\S-1-5-21-1212541044-1667248246-77305449-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUT3FUuencSlQ3pQ-1yrFvJ2ZWXZxhMxlTyskjtmKKvDXm4hGKtsfYdO72NA9B33_1R5qbPe6fjDKPbrpkMk9Mr9qlzWIKoX6v4nXV_PfM6P9xLwquFCGQr5TO-qbPui-dHAaugBKIMZo9tgu_HCIq0ViEaqx1uw,,q={searchTerms}
HKU\S-1-5-21-1212541044-1667248246-77305449-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUT3FUuencSlQ3pQ-1yrFvJ2ZWXZxhMxlTyskjtmKKvDXm4hGKtsfYdO72NA9B33_1R5qbPe6fjDKPbrpkMk9Mr9qlzWIKoX6v4nXV_PfM6P9xLwquFCGQr5TO-qbPui-dHAaugBKIMZo9tgu_HCIq0ViEaqx1uw,,q={searchTerms}
HKU\S-1-5-21-1212541044-1667248246-77305449-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUT3FUuencSlQ3pQ-1yrFvJ2ZWXZxhMxlTyskjtmKKvDXm4hGKtsfYdO72NA9B33_1SxYNEZ_cPgS_YbV8kwPIR3Mu2-p6qxVECswtGXnTNO7IPrpp9ZB1FkVTrpjxDafl4yA3fDa7seokFBv-dIvklMrM2wJ8vQ,,
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 - ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUT3FUuencSlQ3pQ-1yrFvJ2ZWXZxhMxlTyskjtmKKvDXm4hGKtsfYdO72NA9B33_1R5qbPe6fjDKPbrpkMk9Mr9qlzWIKoX6v4nXV_PfM6P9xLwquFCGQr5TO-qbPui-dHAaugBKIMZo9tgu_HCIq0ViEaqx1uw,,q={searchTerms}
SearchScopes: HKLM-x32 - {9E48D1AE-11AA-47CC-9275-BAEF921966D2} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8tag=hp-uk3-vsb-21link%5Fcode=qsindex=apsfield-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1212541044-1667248246-77305449-1001 - {9E48D1AE-11AA-47CC-9275-BAEF921966D2} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8tag=hp-uk3-vsb-21link%5Fcode=qsindex=apsfield-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-1212541044-1667248246-77305449-1001 - {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYSttY34mamef947lyuPOB2E6QjqkhGUT3FUuencSlQ3pQ-1yrFvJ2ZWXZxhMxlTyskjtmKKvDXm4hGKtsfYdO72NA9B33_1R5qbPe6fjDKPbrpkMk9Mr9qlzWIKoX6v4nXV_PfM6P9xLwquFCGQr5TO-qbPui-dHAaugBKIMZo9tgu_HCIq0ViEaqx1uw,,q={searchTerms}
FF NewTab: C:\\ProgramData\\Quoteex\\ff.NT
FF DefaultSearchEngine.US: data:text/plain,browser.search.defaultenginename.US=hohosearch
FF Keyword.URL: undefined://undefined/
FF Extension: thirteen degrees 1.0.1 - C:\Users\Catering\AppData\Roaming\Mozilla\Firefox\Profiles\ohoyga5h.default\Extensions\{0a99cfb9-e762-4cf9-92f5-4afe1e03c36a}.xpi [2016-04-08] [Brak podpisu cyfrowego]
FF Extension: GsearchFinder - C:\Users\Catering\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [2016-04-09]
R2 AppecivreSpA; C:\ProgramData\\AppecivreSpA\\AppecivreSpA.exe [692736 2016-04-12] () [Brak podpisu cyfrowego]
R2 Bahju; C:\Users\Catering\AppData\Roaming\AnumohOlepek\Jaoylri.exe [125776 2016-04-11] ()
R2 Cajudigmud; C:\Users\Catering\AppData\Roaming\Luroser\Luroser.exe [174416 2016-04-11] ()
R2 DCHP; C:\ProgramData\\DCHP\\DCHP.exe [400384 2016-04-12] () [Brak podpisu cyfrowego]
R2 Lispo; C:\Users\Catering\AppData\Roaming\Jaufl\Jaufl.exe [174408 2016-04-10] ()
R2 Quoteex; C:\ProgramData\\Quoteex\\Quoteex.exe [1222656 2016-04-11] () [Brak podpisu cyfrowego]
S2 Laelnew; "C:\Users\Catering\AppData\Roaming\RubmZexdaa\Meameyrh.exe" -cms [X]
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [80768 2016-03-28] (Huorong Borui (Beijing) Technology Co., Ltd.)
2016-04-13 18:07 - 2016-04-13 18:07 - 00000000 ____ D C:\Windows\system32\geu
2016-04-12 18:11 - 2016-04-15 15:11 - 00000000 ____ D C:\ProgramData\AppecivreSpA
2016-04-12 18:11 - 2016-04-12 18:11 - 00000000 ____ D C:\ProgramData\AppecivreSpAs
2016-04-12 18:01 - 2016-04-12 18:11 - 00000000 ____ D C:\ProgramData\DCHP
2016-04-12 10:48 - 2016-04-12 10:48 - 00000000 ____ D C:\Windows\system32\irov
2016-04-11 18:16 - 2016-04-11 18:17 - 05660031 _____ (Swearware) C:\Users\Catering\Downloads\ComboFix.exe
2016-04-11 18:03 - 2016-04-11 18:03 - 00000000 ____ D C:\Windows\system32\lici
2016-04-11 17:39 - 2016-04-15 12:53 - 00000000 ____ D C:\AdwCleaner
2016-04-11 17:35 - 2016-04-11 17:35 - 00000000 ____ D C:\Users\Catering\AppData\Roaming\MCorp
2016-04-11 13:26 - 2016-04-11 15:41 - 00001563 _____ C:\Users\Catering\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器.lnk
2016-04-11 13:26 - 2016-04-11 15:41 - 00000000 ____ D C:\Users\Catering\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
2016-04-11 13:24 - 2016-04-11 13:24 - 00000000 ____ D C:\Users\Catering\AppData\Local\UCBrowser
2016-04-11 13:24 - 2016-03-28 14:28 - 00080768 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\Windows\system32\Drivers\ucguard.sys
2016-04-11 13:15 - 2016-04-11 17:55 - 00000000 ____ D C:\Users\Catering\AppData\Local\app
2016-04-11 13:13 - 2016-04-11 13:13 - 00000000 ____ D C:\Users\Catering\AppData\Roaming\Luroser
2016-04-11 13:13 - 2016-04-11 13:13 - 00000000 ____ D C:\Users\Catering\AppData\Roaming\AnumohOlepek
2016-04-11 13:12 - 2016-04-11 13:13 - 00000000 ____ D C:\Users\Catering\AppData\Local\Tempfolder
2016-04-11 13:12 - 2016-04-11 13:12 - 00000000 ____ D C:\Users\Catering\AppData\Roaming\Jaufl
2016-04-11 12:59 - 2016-04-11 13:00 - 00000000 ____ D C:\Users\Public\Thunder Network
2016-04-11 12:59 - 2016-04-11 12:59 - 00000000 ____ D C:\ProgramData\Thunder Network
2016-04-11 12:53 - 2016-04-11 12:53 - 00000000 ____ D C:\ProgramData\Quoteexs
2016-04-11 12:52 - 2016-04-15 15:11 - 00000000 ____ D C:\ProgramData\Quoteex
2016-04-11 12:52 - 2016-04-11 12:52 - 06504960 _____ C:\Users\Catering\AppData\Roaming\agent.dat
2016-04-11 12:52 - 2016-04-11 12:52 - 01626416 _____ C:\Users\Catering\AppData\Roaming\Ancore.tst
2016-04-11 12:52 - 2016-04-11 12:52 - 00126464 _____ C:\Users\Catering\AppData\Roaming\noah.dat
2016-04-11 12:52 - 2016-04-11 12:52 - 00126464 _____ C:\Users\Catering\AppData\Roaming\lobby.dat
2016-04-11 12:52 - 2016-04-11 12:52 - 00072699 _____ C:\Users\Catering\AppData\Roaming\DanTough.tst
2016-04-11 12:52 - 2016-04-11 12:52 - 00065424 _____ C:\Users\Catering\AppData\Roaming\Config.xml
2016-04-11 12:52 - 2016-04-11 12:52 - 00054272 _____ C:\Users\Catering\AppData\Roaming\ApplicationHosting.dat
2016-04-11 12:52 - 2016-04-11 12:52 - 00018432 _____ C:\Users\Catering\AppData\Roaming\Main.dat
2016-04-11 12:52 - 2016-04-11 12:52 - 00005568 _____ C:\Users\Catering\AppData\Roaming\md.xml
2016-04-11 12:52 - 2016-04-11 12:51 - 01222656 _____ C:\Users\Catering\AppData\Roaming\DanTough.exe
2016-04-11 12:52 - 2016-04-11 12:51 - 01222656 _____ C:\Users\Catering\AppData\Roaming\Ancore.exe
2016-04-11 12:51 - 2016-04-11 12:51 - 00289312 _____ C:\Users\Catering\AppData\Roaming\inst.lat
2016-04-11 12:51 - 2016-04-11 12:51 - 00127488 _____ C:\Users\Catering\AppData\Roaming\Installer.dat
2016-04-11 12:51 - 2016-04-11 12:51 - 00015840 _____ C:\Users\Catering\AppData\Roaming\InstallationConfiguration.xml
2016-04-11 12:50 - 2016-04-11 12:50 - 02516840 _____ C:\Windows\chromebrowser.exe
2016-04-12 10:49 - 2014-12-24 00:43 - 00000000 ____ D C:\ProgramData\McAfee
2016-04-11 12:52 - 2016-04-11 12:52 - 0032038 _____ () C:\Users\Catering\AppData\Roaming\uninstall_temp.ico
Task: {00317592-46A0-450F-BBC2-A0BC813132ED} - System32\Tasks\psv_Nimbam = /c regedit.exe /s "C:\ProgramData\Quoteex\Zamhome.reg" amp; del "C:\ProgramData\Quoteex\Zamhome.reg" amp; SCHTASKS /Delete /TN "psv_Nimbam" /F ==== UWAGA
Task: {0771879F-8A33-40E2-9097-F8C5DCC0A390} - System32\Tasks\psv_Newing = /c regedit.exe /s "C:\ProgramData\Quoteex\Kan-Ron.reg" amp; del "C:\ProgramData\Quoteex\Kan-Ron.reg" amp; SCHTASKS /Delete /TN "psv_Newing" /F ==== UWAGA
Task: {1A0BA252-0566-45F1-8A25-C2386A786A24} - System32\Tasks\psv_CofNimzap = /c regedit.exe /s "C:\ProgramData\AppecivreSpA\Temptech.reg" amp; del "C:\ProgramData\AppecivreSpA\Temptech.reg" amp; SCHTASKS /Delete /TN "psv_CofNimzap" /F ==== UWAGA
Task: {33BD39CA-7476-4B29-9100-430B53EED062} - System32\Tasks\snp = C:\ProgramData\Quoteex\Quoteex.exe [2016-04-11] () ==== UWAGA
Task: {58B90696-9430-4F1F-A16F-25958978C79F} - System32\Tasks\psv_Touch-Dom = /c regedit.exe /s "C:\ProgramData\Quoteex\SilTip.reg" amp; del "C:\ProgramData\Quoteex\SilTip.reg" amp; SCHTASKS /Delete /TN "psv_Touch-Dom" /F ==== UWAGA
Task: {6700F08B-5548-46C3-961D-875F3E78BA0A} - System32\Tasks\{08970864-6043-4333-B1F9-79B65F403D0F} = pcalua.exe -a "C:\Program Files (x86)\Common Files\Ecosing\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\Ecosing\uninstall.dat" -a uninstallme 8E262AB9-8DE1-4007-89AC-5C7A56EBEBD1 DeviceId=728ca844-7b20-8f09-d233-77399b311b43 BarcodeId=51198003 ChannelId=3 DistributerName=APSFWakeNet
Task: {6A04B9E3-A731-420C-8399-2E846824A826} - System32\Tasks\psv_Stansoltam = /c regedit.exe /s "C:\ProgramData\Quoteex\Rankflex.reg" amp; del "C:\ProgramData\Quoteex\Rankflex.reg" amp; SCHTASKS /Delete /TN "psv_Stansoltam" /F ==== UWAGA
Task: {A08B3F56-9062-42C8-A775-B3DDB37DDDCE} - System32\Tasks\UCBrowserUpdater = C:\Program Files (x86)\UCBrowser\Application\update_task.exe
Task: {A0D618EE-82C7-4747-9F87-0847AFE192E5} - System32\Tasks\psv_Nimwarm = /c regedit.exe /s "C:\ProgramData\AppecivreSpA\Quote-Touch.reg" amp; del "C:\ProgramData\AppecivreSpA\Quote-Touch.reg" amp; SCHTASKS /Delete /TN "psv_Nimwarm" /F ==== UWAGA
Task: {A3E2DCC8-60B1-415F-8B17-6F1A01E31656} - System32\Tasks\psv_Tripplenix = /c regedit.exe /s "C:\ProgramData\Quoteex\Strong-Tip.reg" amp; del "C:\ProgramData\Quoteex\Strong-Tip.reg" amp; SCHTASKS /Delete /TN "psv_Tripplenix" /F ==== UWAGA
Task: {D1BCE6CD-FFD1-4C99-AD94-433690FD973C} - System32\Tasks\psv_Ranit = /c regedit.exe /s "C:\ProgramData\Quoteex\FlexTom.reg" amp; del "C:\ProgramData\Quoteex\FlexTom.reg" amp; SCHTASKS /Delete /TN "psv_Ranit" /F ==== UWAGA
Task: {DFFFF7A4-E298-4740-8962-70CA4D4C92AE} - System32\Tasks\{7D797947-7D7E-0E7A-0C11-7A0E7D781105} = powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand OwA7ADsAOwAgACAAIAA7ACAAIAA7ADsAOwAgADsAJABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQA9ACIAcwB0AG8AcAAiADsAJABzAGMAPQAiAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAIgA7ACQAVwBhAHIAbgBpAG4AZwBQAHIAZQBmAGUA (dane wartości zawierają 9368 znaków więcej).
Task: {EEF3934E-AAF2-4E2B-953E-ADF2E7B719FA} - System32\Tasks\psv_Funlatsing = /c regedit.exe /s "C:\ProgramData\Quoteex\Jayphase.reg" amp; del "C:\ProgramData\Quoteex\Jayphase.reg" amp; SCHTASKS /Delete /TN "psv_Funlatsing" /F ==== UWAGA
Task: C:\Windows\Tasks\UCBrowserUpdater.job = C:\Program Files (x86)\UCBrowser\Application\update_task.exe
ShortcutWithArgument: C:\Users\Catering\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) - %SNP%
ShortcutWithArgument: C:\Users\Catering\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) - %SNP%
ShortcutWithArgument: C:\Users\Catering\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) - %SNP%
ShortcutWithArgument: C:\Users\Catering\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) - %SNF%
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) - %SNF%
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) - %SNF%
Hosts:
CMD: netsh winsock reset
CMD: sfc /scanfile=C:\Windows\SysWOW64\dnsapi.dll
EmptyTemp:

Uruchom FRST i kliknij Napraw (Fix). Pokaż raport z usuwania Fixlog.

 

dziękuję za zainteresowanie

http://www.wklej.org/id/2284663/ fixlog

http://www.wklej.org/id/2284677/ FRST

http://www.wklej.org/id/2284678/ Addition

Wklej do systemowego notatnika i zapisz jako plik tekstowy o nazwie fixlist :

SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
C:\Users\Catering\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
2016-04-05 17:21 - 2016-04-12 09:26 - 00000000 ____ D C:\Windows\System32\Tasks\McAfee
DeleteQuarantine:

Uruchom FRST i kliknij Napraw (Fix). Skasuj folder C:\FRST

ok zrobione wszystko, tylko że internet dalej nie działa i nie da się przeskanować systemu

W logach nie widać przyczyny tego problemu.

Ok wyłączyłem opcję Smartscreen i zaczął działać. Dziwne?

Skanuje właśnie