Otwórz notatnik systemowy i wklej: Task: {B4265FE2-4998-49A4-A2E4-9F9043D8A811} - System32\Tasks\{5B876A67-445E-4320-8D05-C27FD53F92CE} => C:\Windows\system32\pcalua.exe -a C:\Users\Lenovo\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=cor Task: {DB5E0C19-2803-4CEF-8C5A-42CA1C21868F} - System32\Tasks\WordFly Auto Updater 1.10.0.25 Pending Update => C:\Program Files\WordFly_1.10.0.25\Update\WordflyAutoUpdateClient.exe <==== UWAGA Task: {F2D7A291-7309-49C2-96FE-6244B4E596F0} - System32\Tasks\Opera N Sunday => C:\Program Files\Opera\launcher.exe Task: {F932F1FE-9423-472A-9CAA-CE4784F7392C} - System32\Tasks\WordFly Auto Updater 1.10.0.25 Core => C:\Program Files\WordFly_1.10.0.25\Update\WordflyAutoUpdateClient.exe <==== UWAGA Task: {FA3B40E4-E999-4F9D-BF37-09566B96646F} - System32\Tasks\Opera N Saturday => C:\Program Files\Opera\launcher.exe ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.omniboxes.com/?type=sc&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.omniboxes.com/?type=sc&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.omniboxes.com/?type=sc&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-988529653-4191510744-129551502-1000\...\MountPoints2: D - D:\SETUP.EXE HKU\S-1-5-21-988529653-4191510744-129551502-1000\...\MountPoints2: {21884aef-07d8-11e7-ae6b-001c25d5a7d1} - G:\Setup.exe HKU\S-1-5-21-988529653-4191510744-129551502-1000\...\MountPoints2: {610d0a71-b022-11e6-812f-001c25d5a7d1} - D:\SETUP.EXE GroupPolicy: Ograniczenia ? <==== UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.omniboxes.com/?type=hp&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.omniboxes.com/?type=hp&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ&q={searchTerms} HKU\S-1-5-21-988529653-4191510744-129551502-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.omniboxes.com/web/?type=ds&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ&q={searchTerms} HKU\S-1-5-21-988529653-4191510744-129551502-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.omniboxes.com/?type=hp&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ HKU\S-1-5-21-988529653-4191510744-129551502-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ&q={searchTerms} SearchScopes: HKLM -> DefaultScope - brak wartości SearchScopes: HKU\S-1-5-21-988529653-4191510744-129551502-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.omniboxes.com/web/?type=ds&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1443550579&z=63a8a96625cf9aad8954ba1g3z3zfc1w2w8ebccbfq&from=cor&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ FF NewTab: Mozilla\Firefox\Profiles\f1n0rgjr.default -> hxxp://www.omniboxes.com/newtab/?type=nt&ts=1448355757&z=011933a90a2e131e3c31807g3z6zfb9c2wbw8mfw2t&from=ient07031&uid=ST3160815AS_6RAE0DCJXXXX6RAE0DCJ FF DefaultSearchEngine: Mozilla\Firefox\Profiles\f1n0rgjr.default -> omniboxes FF SelectedSearchEngine: Mozilla\Firefox\Profiles\f1n0rgjr.default -> omniboxes C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze. Uruchom jako administrator FRST i kliknij w Fix/Napraw. Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan(Skanuj) i później Cleaning(Oczyść).