Odinstaluj:
Adobe Reader 8 - Polish (HKLM\...\{AC76BA86-7AD7-1045-7B44-A81200000003}) (Version: 8.1.2 - Adobe Systems Incorporated)
Adobe Reader 8.1.2 Security Update 1 (KB403742) (HKLM\...\{AC76BA86-7AD7-1045-7B44-A81200000003}_Adobe Reader 8 - Polish) (Version: - )
Image Editor Packages (HKCU\...\Image Editor Packages) (Version: - ) <==== ATTENTION
Tango (HKLM\...\{CC0F8C80-825E-4DE5-B892-07A8615EA467}) (Version: - ) <==== ATTENTION
Video Converter Packages (HKCU\...\Video Converter Packages) (Version: - ) <==== ATTENTION
HDD Regenerator
Obok frst.exe utworz plik fixlist.txt z zawartoscia:
Task: {30A6BA3C-71C8-4A4B-9172-F66046AA9B73} - System32\Tasks\Yahoo! Search Updater => C:\Users\krzysiek\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrsetup.exe <==== ATTENTION
Task: {44185A34-913A-42B5-8474-EF0A7AFF88FB} - System32\Tasks\Opera D6 => C:\Program Files\Opera\launcher.exe [2014-10-29] (Opera Software)
Task: {86103C2A-5A79-4DEC-BAA6-7A5E4C486CD6} - System32\Tasks\Opera D4 => C:\Program Files\Opera\launcher.exe [2014-10-29] (Opera Software)
Task: {8DBB20B0-E787-4C21-9DD0-1134E705C296} - System32\Tasks\Opera D7 => C:\Program Files\Opera\launcher.exe [2014-10-29] (Opera Software)
Task: {A09E1579-0404-4724-B5D7-A0DDA38E1243} - System32\Tasks\Opera D2 => C:\Program Files\Opera\launcher.exe [2014-10-29] (Opera Software)
Task: {C913B3F4-8691-4094-AF9C-94B3E5A30137} - System32\Tasks\Opera D5 => C:\Program Files\Opera\launcher.exe [2014-10-29] (Opera Software)
() C:\ProgramData\0fd8dc4b-3fdb-4d7c-a6d4-ff64cff56cc4\maintainer.exe
HKLM\...\Run: [HDD Regenerator] => "C:\Program Files\HDD Regenerator\Shell.exe" /1
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
FF DefaultSearchEngine: Yahoo! Search
FF SelectedSearchEngine: Yahoo! Search
CHR HomePage: Default -> hxxp://rts.dsrlte.com?affID=na
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
2014-11-02 22:17 - 2014-11-02 22:18 - 00006199 _____ () C:\hijackthis.log
2014-11-01 21:10 - 2014-11-01 21:10 - 00415232 _____ (Farbar) C:\Users\Gosia\Downloads\FSS.exe
2014-11-01 21:10 - 2014-11-01 21:10 - 00002366 _____ () C:\Users\Gosia\Downloads\FSS.txt
2014-10-29 18:29 - 2014-11-01 21:17 - 00000000 ____D () C:\ProgramData\0fd8dc4b-3fdb-4d7c-a6d4-ff64cff56cc4
2014-10-23 18:59 - 2014-10-23 18:59 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (9).lnk
2014-10-23 18:59 - 2014-10-23 18:59 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (8).lnk
2014-10-23 18:56 - 2014-10-23 18:56 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (7).lnk
2014-10-23 18:56 - 2014-10-23 18:56 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (6).lnk
2014-10-23 18:56 - 2014-10-23 18:56 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (5).lnk
2014-10-23 18:56 - 2014-10-23 18:56 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (4).lnk
2014-10-23 18:56 - 2014-10-23 18:56 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (3).lnk
2014-10-23 18:56 - 2014-10-23 18:56 - 00000104 _____ () C:\Users\Maja\Desktop\Komputer — skrót (2).lnk
EmptyTemp:
W FRST wybierz Fix.
Zainstaluj
http://ninite.com/foxit/
Usun katalog C:\FRST i to wszystko.