Otwórz notatnik systemowy i wklej: ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> Brak pliku Task: {95E04AE4-16E5-4FE5-90DD-9D0DB8FB4282} - System32\Tasks\GoogleUpdateTaskMachineUA => [Argument = /ua /installsource scheduler] <==== UWAGA Task: {E344A4E9-1CD8-4D09-A28A-002F9FB7F445} - System32\Tasks\GoogleUpdateTaskMachineCore => [Argument = /c] <==== UWAGA HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\MountPoints2: {84cbcb27-f42e-11e6-b9f8-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1000\...\MountPoints2: {db59c090-502f-11e6-a050-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {84cbcb27-f42e-11e6-b9f8-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {db59c090-502f-11e6-a050-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {84cbcb27-f42e-11e6-b9f8-3c970e408dd5} - autorun.exe HKU\S-1-5-21-2413066759-4021284835-616923704-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {db59c090-502f-11e6-a050-3c970e408dd5} - autorun.exe BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy\User: Ograniczenia <==== UWAGA GroupPolicyUsers\S-1-5-21-2413066759-4021284835-616923704-1004\User: Ograniczenia <==== UWAGA URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-2413066759-4021284835-616923704-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-02-21] [Brak podpisu cyfrowego] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-02-21] U3 BcmSqlStartupSvc; Brak ImagePath U2 CLKMSVC10_3A60B698; Brak ImagePath U2 CLKMSVC10_C3B3B687; Brak ImagePath U2 DriverService; Brak ImagePath U2 IAStorDataMgrSvc; Brak ImagePath U2 iATAgentService; Brak ImagePath U2 idealife Update Service; Brak ImagePath U3 IGRS; Brak ImagePath U2 IviRegMgr; Brak ImagePath U2 nvUpdatusService; Brak ImagePath U2 Oasis2Service; Brak ImagePath U2 PCCarerService; Brak ImagePath U2 ReadyComm.DirectRouter; Brak ImagePath U2 RichVideo; Brak ImagePath U2 RtLedService; Brak ImagePath U2 SeaPort; Brak ImagePath U2 SoftwareService; Brak ImagePath S1 ZAM; \??\C:\windows\System32\drivers\zam64.sys [X] S1 ZAM_Guard; \??\C:\windows\System32\drivers\zamguard64.sys [X] 2017-09-28 14:39 - 2017-09-28 14:39 - 000000000 ____D C:\windows\System32\Tasks\Safer-Networking 2017-09-28 14:38 - 2017-09-29 12:55 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 EmptyTemp: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze. Uruchom jako administrator FRST i kliknij w Fix/Napraw. Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan(Skanuj) i później Cleaning(Oczyść).