Odinstaluj WiseEnhance.Otwórz notatnik systemowy i wklej: CloseProcesses: Task: {56F3BAFD-65F0-47CC-ABDA-55A2A790D348} - System32\Tasks\DllKitPRO => C:\Program Files (x86)\DllKitPRO\dllkitpro.exe ShortcutWithArgument: C:\Users\p-brodowska\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxps://launchpage.org/?uid=oTlKBGjcgxocXesqx8HhaKyP2ZdHBNdEksLk7PIa61Me2rxjPRoWaLPOFFaa1lfBr5M%3D ShortcutWithArgument: C:\Users\p-brodowska\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxps://launchpage.org/?uid=oTlKBGjcgxocXesqx8HhaKyP2ZdHBNdEksLk7PIa61Me2rxjPRoWaLPOFFaa1lfBr5M%3D ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxps://launchpage.org/?uid=oTlKBGjcgxocXesqx8HhaKyP2ZdHBNdEksLk7PIa61Me2rxjPRoWaLPOFFaa1lfBr5M%3D AlternateDataStreams: C:\Windows:CM_0cd0516c121d264328094cbc136815fbe30680b9e9453d21fa79277b8c116d8e [74] AlternateDataStreams: C:\Windows:CM_c4a554a382517fa5a0078f23a3964f7ac7c90af8b43349fdaafcafec8f1e8a9c [74] AlternateDataStreams: C:\ProgramData\Temp:A1EDB939 [286] HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-04-28] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-09-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\Run: [BingSvc] => C:\Users\p-brodowska\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2016-01-25] (© 2015 Microsoft Corporation) HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\RunOnce: [Uninstall C:\Users\p-brodowska\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\p-brodowska\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\Policies\Explorer: [] HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {350d0fb0-bcdc-11e4-82a6-fcf8ae163370} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {3f54fa57-e1b4-11e4-82b9-28d24442bcef} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {487b2fbb-11a1-11e4-8265-28d24442bcef} - "H:\DT4000_Launcher.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {909dce69-d082-11e3-8251-fcf8ae163370} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {909dcec8-d082-11e3-8251-fcf8ae163370} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {909dd022-d082-11e3-8251-28d24442bcef} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {ae0586a3-fd3b-11e3-8262-28d24442bcef} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {ae05885b-fd3b-11e3-8262-28d24442bcef} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {c74f4c27-6601-11e5-82d6-28d24442bcef} - "F:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {cb716c05-d162-11e5-82f3-28d24442bcef} - "F:\DT4000G2_Launcher.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {db06e700-b355-11e4-82a2-28d24442bcef} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {db06e738-b355-11e4-82a2-28d24442bcef} - "F:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {e2784df9-aea2-11e4-829c-28d24442bcef} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {e8ce76e0-32e6-11e4-826b-28d24442bcef} - "G:\Windows/AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {e9c15f1b-2c7b-11e6-830b-28d24442bcef} - "G:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {ef4eac32-6ad6-11e5-82d8-28d24442bcef} - "F:\AutoRun.exe" HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\...\MountPoints2: {fa242fa6-05ac-11e4-8263-28d24442bcef} - "G:\AutoRun.exe" AutoConfigURL: [S-1-5-21-2956326098-1236834922-3697426559-1001] => hxxp://webunstop.com/wpad.dat?5b39248f335389456cb722dea88fce4230956241 ManualProxies: 0hxxp://webunstop.com/wpad.dat?5b39248f335389456cb722dea88fce4230956241 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSVVVGI134_QT8oBc4Bx48F_MKDlC6h-Ez_hl_Q-_ofvC_uq1SLXMPEzs-BMU_WDcMaAbDPutgQbEyITgOb1AXY7G5TP8KFqQ-B15FvxH0EQ4ErqeOTYZ8tJlErtj9DUIx1gWw_qjX0QA,,&q={searchTerms} HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.live.com/1rewlive4startup/home HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSVVVGI134_QT8oBc4Bx48F_MKDlC6h-Ez_hl_Q-_ofvC_uq1SLXMPEzs-BMU_WDcMaAbDPutgQbEyITgOb1AXY7G5TP8KFqQ-B15FvxH0EQ4ErqeOTYZ8tJlErtj9DUIx1gWw_qjX0QA,,&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} SearchScopes: HKU\S-1-5-21-2956326098-1236834922-3697426559-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} SearchScopes: HKU\S-1-5-21-2956326098-1236834922-3697426559-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSVVVGI134_QT8oBc4Bx48F_MKDlC6h-Ez_hl_Q-_ofvC_uq1SLXMPEzs-BMU_WDcMaAbDPutgQbEyITgOb1AXY7G5TP8KFqQ-B15FvxH0EQ4ErqeOTYZ8tJlErtj9DUIx1gWw_qjX0QA,,&q={searchTerms} CHR NewTab: Default -> Not-active:"chrome-extension://doibabjiapabnfibohiinbmjjblnlioi/stubby.html" CHR DefaultSearchURL: Default -> hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421356113&from=cor&uid=ST1000LM014-SSHD-8GB_W380Y5Y4XXXXW380Y5Y4&q={searchTerms} CHR DefaultSearchKeyword: Default -> omiga-plus CHR HKU\S-1-5-21-2956326098-1236834922-3697426559-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx S2 ERDAS Licensing Service; C:\Program Files (x86)\ERDAS\Shared\licensing\bin\Win32Release\lmgrd.exe [X] S2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S2 RHDISK_AMD64; \??\C:\Program Files (x86)\Rohos\RHDISK_AMD64.SYS [X] RemoveProxy: EmptyTemp: Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze. Uruchom jako administrator FRST i kliknij w Fix/Napraw. Pobierz i uruchom jako administrator AdwCleaner https://toolslib.net/downloads/finish/1/ Kliknij Scan(Skanuj) i później Cleaning(Oczyść).