Odinstaluj AVG PC TuneUp 2015,Java 7 Update 55,Java 7 Update 71,JavaFX 2.1.1,YAC(Yet Another Cleaner!).Otwórz notatnik systemowy i wklej: HKU\S-1-5-21-732684873-2498896525-955034014-1000\...\ChromeHTML: -> "C:\Program Files\Bagsarah\Application\chrome.exe" "%1" <==== UWAGA ContextMenuHandlers1_S-1-5-21-732684873-2498896525-955034014-1000: [SysMenuExt] -> {020B1D4B-5738-4C77-9E19-4F173DD9B486} => -> Brak pliku Task: {1205F0CF-3188-46FB-BF50-43A597B2D566} - \efa86c6d-a3f9-4add-85c7-4ab28d547494-1 -> Brak pliku <==== UWAGA Task: {1D51412A-5AF3-434C-BAF0-F15434CC6B75} - \7633d77e-5a81-4a2b-9a50-349a56f43628-5 -> Brak pliku <==== UWAGA Task: {399489A5-64E6-46D1-AE3A-012AFBCBB854} - \efa86c6d-a3f9-4add-85c7-4ab28d547494-7 -> Brak pliku <==== UWAGA Task: {43CBA1C0-CBEE-4117-B09C-A5AC13ACF53A} - \7633d77e-5a81-4a2b-9a50-349a56f43628-4 -> Brak pliku <==== UWAGA Task: {6881B527-D501-4C1C-82BD-FFFC40E618AE} - \7633d77e-5a81-4a2b-9a50-349a56f43628-1 -> Brak pliku <==== UWAGA Task: {6E68A951-8DAE-401B-B50E-D3F80DF7E304} - \efa86c6d-a3f9-4add-85c7-4ab28d547494-4 -> Brak pliku <==== UWAGA Task: {6EA2574C-DD2F-4383-9DA6-9A1E52B91C7D} - System32\Tasks\{0187C93F-CC5D-4B0C-A2A4-23086699A8AF} => C:\Windows\system32\pcalua.exe -a D:\MaSzyna_15_04\RAINSTED.exe -d D:\MaSzyna_15_04 Task: {823230EC-621D-49D4-B115-C112EA284726} - System32\Tasks\{AF3D7C92-FB4A-4BCD-B7E1-F9571AF6E1EC} => C:\Windows\system32\pcalua.exe -a "N:\pelne\Fable - The Lost Chapters PL\setup.exe" -d "N:\pelne\Fable - The Lost Chapters PL" Task: {83A08418-4719-464A-87CC-9AAA67002940} - \efa86c6d-a3f9-4add-85c7-4ab28d547494-5 -> Brak pliku <==== UWAGA Task: {86069344-9BD2-40EC-BCDB-18971756C581} - System32\Tasks\{21AB4798-A72B-4EDF-BAE2-405978A11A57} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup Task: {9E7E4091-B5FD-4E1F-8F55-9C979B1E1952} - System32\Tasks\MaciekZirconRifledV2 => rundll32.exe PlanetariaCollating.dll,main 7 1 <==== UWAGA Task: {A8D623CA-6298-4DB4-9A7B-26366B439313} - System32\Tasks\{CEE25991-558C-4217-8C33-F162D98D37E1} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\Electronic Arts\The Godfather The Game\GDFTHR_uninst.exe" -d "C:\Program Files\Electronic Arts\The Godfather The Game" Task: {DBF8BBBE-E495-456C-933B-6A666DD1D989} - System32\Tasks\{BD2DA661-0C3B-4148-90E8-E2D12A6887CC} => C:\Windows\system32\pcalua.exe -a F:\GDFTHR_inst.exe -d F:\ Task: {DCB7FFD5-753B-4A0A-B0CB-2CD29577E6E2} - System32\Tasks\{9131BDA3-9AED-4F5B-887E-287E4FF8526E} => C:\Windows\system32\pcalua.exe -a F:\DirectX\DXSETUP.exe -d F:\DirectX Task: {F3042021-58AA-41D0-ADE7-08BEB9A24BD1} - \7633d77e-5a81-4a2b-9a50-349a56f43628-2 -> Brak pliku <==== UWAGA MSCONFIG\startupreg: QHSafeTray => "C:\Program Files\360\Total Security\safemon\QHSafeTray.exe" /start HKU\S-1-5-21-732684873-2498896525-955034014-1000\...\Policies\system: [Shell] explorer.exe,msiexec.exe /i hxxp://point.orangeiloveyou.com/?data=zDlkMj1YFTk1OTM3MjH5MTU3FkF1NWF5FdhLFjk8RUQWNThLRH== /q <==== UWAGA IFEO\DisplaySwitch.exe: [Debugger] IFEO\GoogleUpdate.exe: [Debugger] 324095823984.exe IFEO\GoogleUpdaterService.exe: [Debugger] 8736459873644.exe IFEO\taskmgr.exe: [Debugger] GroupPolicy: Ograniczenia - Chrome <==== UWAGA GroupPolicy\User: Ograniczenia ? <==== UWAGA CHR res: Zainfekowany resources.pak (search_engine). Przeinstaluj Chrome. <==== UWAGA CHR HomePage: Default -> hxxp://www.luckysearch123.com?type=hp&ts=1494513353&from=c8350511&uid=st3500418as_9vm2n7z7xxxx9vm2n7z7&z=51e57ba488d85e9f9f1f9bagbz7t1z7weg0c3c0wem CHR StartupUrls: Default -> "hxxp://www.luckysearch123.com?type=hp&ts=1494513353&from=c8350511&uid=st3500418as_9vm2n7z7xxxx9vm2n7z7&z=51e57ba488d85e9f9f1f9bagbz7t1z7weg0c3c0wem" CHR NewTab: Default -> Not-active:"chrome-extension://llaficoajjainaijghjlofdfmbjpebpa/newtab.html" CHR DefaultSearchURL: Default -> hxxp://www.mystarting123.com/search/index.php?z=c2b25d983511412e4032b0fgaz5t0w9qcc9qao1g4me&q={searchTerms} CHR DefaultSearchKeyword: Default -> mystarting123 CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx R2 iSafeService; C:\Program Files\Elex-tech\YAC\iSafeSvc.exe [131024 2016-12-02] (Elex do Brasil Participações Ltda) <==== UWAGA R1 iSafeKrnl; C:\Program Files\Elex-tech\YAC\iSafeKrnl.sys [227776 2016-05-23] (Elex do Brasil Participações Ltda) <==== UWAGA R1 iSafeKrnlKit; C:\Program Files\Elex-tech\YAC\iSafeKrnlKit.sys [97912 2016-05-23] (Elex do Brasil Participações Ltda) <==== UWAGA R1 iSafeKrnlMon; C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [45032 2016-05-23] (Elex do Brasil Participações Ltda) <==== UWAGA R1 iSafeKrnlR3; C:\Program Files\Elex-tech\YAC\iSafeKrnlR3.sys [73232 2016-05-23] (Elex do Brasil Participações Ltda) <==== UWAGA R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [59152 2016-05-19] (Elex do Brasil Participações Ltda) <==== UWAGA 2017-07-26 21:34 - 2016-05-19 08:42 - 000059152 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys 2017-08-12 10:39 - 2016-08-19 19:17 - 000000398 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2017-07-26 21:27 - 2015-08-18 08:43 - 000000000 ____D C:\AdwCleaner 2014-09-01 10:18 - 2014-09-01 10:18 - 000001248 _____ () C:\Users\Maciek\AppData\Roaming\BQBECKYI 2014-09-01 10:18 - 2014-09-01 10:18 - 000002086 _____ () C:\Users\Maciek\AppData\Roaming\DD 2015-03-31 10:14 - 2015-03-31 10:14 - 000004387 _____ () C:\Users\Maciek\AppData\Roaming\QMOHpy9eGD4q7C4XVzG 2015-03-31 10:14 - 2015-03-31 10:14 - 000005655 _____ () C:\Users\Maciek\AppData\Roaming\qS27NKSUtxJ2N9t EmptyTemp: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze. Uruchom jako administrator FRST i kliknij w Fix/Napraw. Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan(Skanuj) i później Cleaning(Oczyść). Pokaż nowy raport z FRST bez Addition i Shortcut.