Odinstaluj Spybot - Search & Destroy.Otwórz notatnik systemowy i wklej: Task: {89FB1AC2-30CD-43BD-B431-F1F19A2185DE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) Task: {D266B96E-5B4D-4775-9CC5-A74F2F1950AC} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.) Task: {E4DF98CB-ED94-4E44-8853-F12743B351DA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.) Hosts: HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) HKU\S-1-5-21-3431712584-4224011876-465977682-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.) HKU\S-1-5-21-3431712584-4224011876-465977682-1000\...\Policies\Explorer: [] BootExecute: autocheck autochk * sdnclean.exe GroupPolicy: Ograniczenia ? <======= UWAGA HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKU\S-1-5-21-3431712584-4224011876-465977682-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA BHO: IE 4.x-6.x BHO for Internet Download Accelerator -> {2A646672-9C3A-4C28-9A7A-1FB0F63F28B6} -> C:\PROGRA~1\IDA\idaiehlp.dll => Brak pliku CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}&z=3ea62c1299fd69aca2b1dccgcz2bab4wamfgbo4z0b&from=icb&uid=KINGSTONXSH103S3240G_50026B7255032C4C&type=sp CHR DefaultSearchKeyword: ChromeDefaultData -> trotux CHR Profile: C:\Users\Maciek\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-06-13] <==== UWAGA CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx U3 catchme; \??\C:\Users\Maciek\AppData\Local\Temp\catchme.sys [X] U3 mbr; \??\C:\ComboFix\mbr.sys [X] 2017-06-13 20:18 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2017-06-13 20:18 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2017-06-13 20:18 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2017-06-13 20:18 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2017-06-13 20:18 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2017-06-13 20:18 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2017-06-13 20:18 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2017-06-13 20:18 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2017-06-13 20:17 - 2017-06-13 20:27 - 00000000 ____D C:\Qoobox 2017-06-13 20:00 - 2017-03-04 00:26 - 00000000 ____D C:\AdwCleaner EmptyTemp: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze. Uruchom jako administrator FRST i kliknij w Fix/Napraw.