Odinstaluj McAfee Security Scan Plus.Otwórz notatnik systemowy i wklej: ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku Task: {0CD22093-A01A-406E-B569-28DF743F0739} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe ShortcutWithArgument: C:\Users\wnucz\Desktop\Поиcк в Интeрнете.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> " <==== Cyrillic AlternateDataStreams: C:\ProgramData:482EE99B1E21CE8C [217] AlternateDataStreams: C:\ProgramData:A4EC501E2FCB9F84 [1] AlternateDataStreams: C:\Users\All Users:482EE99B1E21CE8C [217] AlternateDataStreams: C:\Users\All Users:A4EC501E2FCB9F84 [1] AlternateDataStreams: C:\ProgramData\Dane aplikacji:482EE99B1E21CE8C [217] AlternateDataStreams: C:\ProgramData\Dane aplikacji:A4EC501E2FCB9F84 [1] HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-04-28] (Adobe Systems Incorporated) HKLM\...\Run: [iTunesHelper] => D:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc.) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM\...\Command Processor: cd C:\Users\wnucz\Desktop <==== UWAGA HKU\S-1-5-21-874860623-626904812-4115847722-1001\...\Run: [MyComGames] => C:\Users\wnucz\AppData\Local\MyComGames\MyComGames.exe [5753040 2017-10-12] (MY.COM B.V.) HKU\S-1-5-21-874860623-626904812-4115847722-1001\...\MountPoints2: {1757f0a3-e980-11e6-8122-708bcda1f16a} - "F:\AutoRun.exe" HKU\S-1-5-21-874860623-626904812-4115847722-1001\...\MountPoints2: {7e751436-9a71-11e6-80fc-806e6f6e6963} - "E:\cda_menu.exe" HKU\S-1-5-21-874860623-626904812-4115847722-1001\...\MountPoints2: {a583165f-5dc1-11e7-813a-708bcda1f16a} - "F:\AutoRun.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-09-26] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe (McAfee, Inc.) GroupPolicy: Ograniczenia - Chrome <==== UWAGA GroupPolicy\User: Ograniczenia <==== UWAGA HKU\S-1-5-21-874860623-626904812-4115847722-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://mail.ru/cnt/10445?gp=811013 SearchScopes: HKU\S-1-5-21-874860623-626904812-4115847722-1001 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = FF DefaultSearchEngine: Mozilla\Firefox\Profiles\y6jmbzqk.default -> Поиск@Mail.Ru FF SelectedSearchEngine: Mozilla\Firefox\Profiles\y6jmbzqk.default -> Поиск@Mail.Ru FF Homepage: Mozilla\Firefox\Profiles\y6jmbzqk.default -> hxxp://mail.ru/cnt/10445?gp=811013 CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=MB3521BF7-ACF1-4B0E-95AE-AD96B19BE2A0&SearchSource=55&CUI=&UM=8&UP=SP1B7D16B7-20F4-4A8D-BC03-201B47126D31&SSPV= CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=MB3521BF7-ACF1-4B0E-95AE-AD96B19BE2A0&SearchSource=55&CUI=&UM=8&UP=SP1B7D16B7-20F4-4A8D-BC03-201B47126D31&SSPV=","hxxp://google.pl/","hxxp://start.mysearchdial.com/?f=1&a=irmsd1202&cd=2XzuyEtN2Y1L1Qzu0Fzz0DtCtCtCtD0BtDyEzz0A0CtDtAtAtN0D0Tzu0SyBtCyEtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1892460537&ir=","","hxxp://www.google.pl/","hxxp://www.google.com/","hxxp://mysearch.avg.com/?cid={B3E793B5-D8E5-4B02-A909-9E3CCD2800C4}&mid=2af42fbd8fb247d2affb016ecebf87aa-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-20%2023:30:21&v=17.3.1.91&pid=safeguard&sg=&sap=hp","hxxp://mail.ru/cnt/10445?gp=811009" CHR HKLM-x32\...\Chrome\Extension: [lhemechcanjmilllmccjbjldonmnnjjj] - hxxps://clients2.google.com/service/update2/crx S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [X] 2017-10-05 22:54 - 2017-10-05 23:29 - 000000000 ____D C:\Program Files\Reimage 2017-10-05 22:53 - 2017-10-05 23:17 - 000000000 ____D C:\rei 2017-10-04 22:45 - 2017-10-05 23:18 - 000001580 _____ C:\Users\wnucz\Desktop\Поиcк в Интeрнете.lnk 2017-10-04 22:45 - 2017-10-04 22:45 - 000000000 ____D C:\Users\wnucz\AppData\Local\Поиcк в Интeрнете 2017-10-04 22:41 - 2017-10-04 23:30 - 000000000 ____D C:\Users\wnucz\AppData\Local\Mail.Ru 2017-10-04 22:41 - 2017-10-04 22:42 - 000000191 _____ C:\Users\wnucz\Desktop\Искать в Интернете.url 2017-10-04 22:41 - 2017-10-04 22:42 - 000000000 ____D C:\ProgramData\Mail.Ru EmptyTemp: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze. Uruchom jako administrator FRST i kliknij w Fix/Napraw. Zapisując Fixlist kodowanie ustaw na UTF-8 Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan(Skanuj) i później Cleaning(Oczyść).