Odinstaluj Spybot - Search & Destroy.Otwórz notatnik systemowy i wklej: CustomCLSID: HKU\S-1-5-21-2794799345-1553271875-783634000-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-87963CEFC348}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => Brak pliku ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.) ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.) ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.) ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.) Task: {673DB270-8BA1-46BA-939D-6F8112C007FB} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2017-05-23] (Safer-Networking Ltd.) Task: {9E18F923-AB16-45A0-B45F-631A5CA569EC} - \{7E7E0C47-080B-087F-7A11-09050E091108} -> Brak pliku <==== UWAGA Task: {B20CB66B-5F4F-4538-8202-9DBC56590D7F} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2017-05-23] (Safer-Networking Ltd.) Task: {C78694B5-F204-411B-94B2-7F63DBA3034B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2017-05-23] (Safer-Networking Ltd.) HKLM-x32\...\Run: [WinLogon] => C:\ProgramData\CheckTime\WinLogon.exe [3920384 2017-10-12] () <==== UWAGA HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4174464 2017-05-23] (Safer-Networking Ltd.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA HKU\S-1-5-21-2794799345-1553271875-783634000-1001\...\Run: [6890751] => "C:\Users\Dudas\AppData\Roaming\15hkwmotdj0\ngi0offae1t.exe" /VERYSILENT HKU\S-1-5-21-2794799345-1553271875-783634000-1001\...\Run: [1HXNSNCTHNB6UU8] => "C:\Program Files\P4ZDTWFEMH\P4ZDTWFEM.exe" HKU\S-1-5-21-2794799345-1553271875-783634000-1001\...\Run: [727475] => "C:\Users\Dudas\AppData\Roaming\fycjzvx2tpl\xtkqdh4d0tq.exe" /VERYSILENT HKU\S-1-5-21-2794799345-1553271875-783634000-1001\...\Run: [2214220] => "C:\Users\Dudas\AppData\Roaming\5zcjd5x1ywi\uolnrsnaxr5.exe" /VERYSILENT HKU\S-1-5-21-2794799345-1553271875-783634000-1001\...\Run: [7606442] => "C:\Users\Dudas\AppData\Roaming\yc0vk2vhqd2\5uc1cydx2e4.exe" /VERYSILENT HKU\S-1-5-21-2794799345-1553271875-783634000-1001\...\Run: [W4D8JW9P8LA89KF] => "C:\Program Files\5X9NT4FVOM\5X9NT4FVO.exe" HKU\S-1-5-21-2794799345-1553271875-783634000-1001\...\Run: [JUOHIMHIUNXGUYO] => "C:\Program Files\VSKTBVE2ZL\FKEVIYGNS.exe" ShellExecuteHooks: Brak nazwy - {5F51FFFE-7463-4220-B711-E5B9ACB8EDFE} - C:\Users\Dudas\AppData\Roaming\tmp546.dat -> Brak pliku BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Ograniczenia - Chrome <==== UWAGA CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx S1 wfcre; system32\drivers\wfcre.sys [X] S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X] 2017-10-13 02:43 - 2017-10-13 11:51 - 000000000 ____D C:\AdwCleaner 2017-10-12 21:22 - 2017-10-12 22:31 - 000000000 ____D C:\Program Files\3IYHUUYGT8 2017-10-12 21:20 - 2017-10-12 22:32 - 000000000 ____D C:\Program Files\VSKTBVE2ZL 2017-10-12 21:20 - 2017-10-12 22:32 - 000000000 ____D C:\Program Files\P4ZDTWFEMH 2017-10-12 21:20 - 2017-10-12 22:31 - 000000000 ____D C:\Program Files\5X9NT4FVOM 2017-10-12 21:20 - 2017-10-12 21:44 - 000000000 ____D C:\Users\Dudas\AppData\Roaming\yc0vk2vhqd2 2017-10-12 21:20 - 2017-10-12 21:44 - 000000000 ____D C:\Users\Dudas\AppData\Roaming\fycjzvx2tpl 2017-10-12 21:20 - 2017-10-12 21:44 - 000000000 ____D C:\Users\Dudas\AppData\Roaming\5zcjd5x1ywi 2017-10-12 21:20 - 2017-10-12 21:44 - 000000000 ____D C:\Users\Dudas\AppData\Roaming\15hkwmotdj0 2017-10-12 21:16 - 2017-10-12 21:16 - 000140800 _____ () C:\Users\Dudas\AppData\Local\installer.dat C:\ProgramData\CheckTime\WinLogon.exe EmptyTemp: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze. Uruchom jako administrator FRST i kliknij w Fix/Napraw.