W panelu sterowania odinstaluj Ask Toolbar, YoutubeAdblocker, Lollipop.
Pobierz i uruchom AdwCleaner Kliknij Szukaj i później Usuń.
Do okna Własne opcje skanowania / skrypt wklej:
:OTL
SRV - File not found [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014-03-26 23:06:53 | 000,166,352 | ---- | M] (APN LLC.) [Auto | Running] -- C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe -- (APNMCP)
SRV - [2014-01-16 23:54:24 | 000,208,896 | ---- | M] () [Auto | Running] -- C:\Windows\System32\winaps.exe -- (winapiserv)
SRV - [2014-01-08 22:52:19 | 000,216,064 | ---- | M] () [Auto | Running] -- C:\Windows\System32\winevents.exe -- (winevent)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | Boot | Stopped] -- -- (aswVmm)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\aswStm.sys -- (aswStm)
DRV - File not found [File_System | System | Stopped] -- C:\Windows\system32\drivers\aswSP.sys -- (aswSP)
DRV - File not found [File_System | System | Stopped] -- C:\Windows\system32\drivers\aswSnx.sys -- (aswSnx)
DRV - File not found [Kernel | Boot | Stopped] -- -- (aswRvrt)
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\aswRdr2.sys -- (aswRdr)
DRV - File not found [File_System | Auto | Stopped] -- C:\Windows\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
O4 - HKLM..\Run: [csrss] "C:\Users\Aneta\Videos\csrss\chp.exe" csrss.exe -poolip=176.34.128.129 -poolport=1337 -pooluser=AZqgLXarpu4iKYXUwCSx1TitDtRM8Pv2SJ -poolpassword=PASSWORD -genproclimit=2 File not found
O4 - HKLM..\Run: [Driver] C:\Windows\Web\driver.exe ()
O4 - HKLM..\Run: [Regedit32] C:\Windows\system32\regedit.exe File not found
O4 - HKLM..\Run: [Regedit32] C:\Windows\system32\regedit.exe File not found
O4 - HKLM..\Run: [System Configuration] C:\Windows\System32\{$1284-9213-2940-1289$}\appsvc.exe -rundll32 /SYSTEM32 "C:\Windows\System32\taskmgr.exe" "C:\Program Files\Microsoft\Windows" File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [0000710a] C:\ProgramData\System\0000710a.exe ()
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [002f1767] C:\ProgramData\System\002f1767.exe File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [Google Services Updater] C:\ProgramData\Google Services\ulotmhvct.exe ()
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [juhisfeajagm] C:\Users\Aneta\juhisfeajagm.exe File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [lollipop] c:\users\aneta\appdata\local\lollipop\lollipop.exe ()
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [pymydoncatbi] C:\Users\Aneta\pymydoncatbi.exe File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [rymmytgocagn] C:\Users\Aneta\rymmytgocagn.exe File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [vabfidytnubg] C:\Users\Aneta\vabfidytnubg.exe File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [xanqykycolym] C:\Users\Aneta\xanqykycolym.exe File not found
O4 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000..\Run: [xeadeasuzdip] C:\Users\Aneta\xeadeasuzdip.exe File not foundO4 - Startup: C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.ini.url ()
O4 - Startup: C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HpM3Util.exe ()
O4 - Startup: C:\Users\Aneta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft .NET.vbs ()
O4 - Startup: C:\Users\Gość\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Update.Microsoft.com.url ()
F3 - HKU\S-1-5-21-2138566727-3381751025-2574945166-1000 WinNT: Load - (C:\Windows\System32\{$1284-9213-2940-1289$}\appsvc.exe) - C:\Windows\System32\{$1284-9213-2940-1289$}\appsvc.exe ()
O27 - HKLM IFEO\avcenter.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\avguard.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\avp.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\bdagent.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\ccuac.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\ComboFix.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\egui.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\hijackthis.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\keyscrambler.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\mbam.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\MpCmdRun.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\MSASCui.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\MsMpEng.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\msseces.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\spybotsd.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\wireshark.exe: Debugger - nsjw.exe File not found
O27 - HKLM IFEO\zlclient.exe: Debugger - nsjw.exe File not found
O32 - AutoRun File - [2011-08-04 18:13:52 | 000,000,110 | -H-- | M] () - F:\autorun.inf -- [FAT32]
[2014-04-16 00:30:09 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014-03-20 20:04:03 | 000,000,000 | -HSD | C] -- C:\ProgramData\qwtetgasg
[2014-03-20 20:03:44 | 000,000,000 | -HSD | C] -- C:\ProgramData\bbtmp
[2014-02-26 19:48:51 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\Ugogk
[2014-02-26 19:48:36 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\Gyem
[2014-02-26 19:48:30 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\Baut
[2014-03-20 20:04:10 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\Qyhyde
[2014-03-20 20:04:10 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\Oxehk
[2014-03-20 20:04:10 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\Haheax
:Files
C:\ProgramData\*.exe
C:\Windows\Web\libcurl-4.dll
C:\Windows\Web\minerd.exe
C:\Windows\Web\zlib1.dll
C:\Windows\Web\drive.exe
C:\Windows\System32\{$1284-9213-2940-1289$}
:Reg
[HKEY_USERS\S-1-5-21-2138566727-3381751025-2574945166-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"accckbt"=-
"eesveief"=-
:Commands
[resethosts]
[emptytemp]
Kliknij Wykonaj skrypt i zatwierdź restart.
Pokaż raport z usuwania i nowy log Skanuj.
Pobierz Farbar Recovery Scan Tool 32-Bit Version
Uruchom FRST i kliknij Scan. Pokaż raport FRST i Addition.