Masz mało ramu.
Zamiesc screen z CrystalDiskInfo:
http://portableapps.com/apps/utilities/crystaldiskinfo_portable
Odinstaluj:
Contextual Tool Extrafind (HKLM\...\1e9c15d8) (Version: - ) <==== UWAGA
istartsurf uninstall (HKLM\...\istartsurf uninstall) (Version: - istartsurf) <==== UWAGA
omiga-plus uninstall (HKLM\...\omiga-plus uninstall) (Version: - omiga-plus) <==== UWAGA
WPM17.8.0.3297 (HKLM\...\WPM) (Version: 17.8.0.3297 - Cherished Technololgy LIMITED) <==== UWAGA
AVG Web TuneUp
Uzyj AdwCleaner, opcja Scan i Clean/Szukaj i Usun:
https://toolslib.net/downloads/viewdownload/1-adwcleaner/
Obok frst.exe utworz plik fixlist.txt z zawartoscia:
(© 2015 Microsoft Corporation) C:\Users\Sylwia\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.1.8\ToolbarUpdater.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.1.8\loggingserver.exe
(DTools LIMITED) C:\ProgramData\lWdsManProl\WdsManPro.exe
HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe
HKLM\...\Run: [vProt] => C:\Program Files\AVG Web TuneUp\vprot.exe [3177360 2015-10-04] ()
HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\...\Run: [Badoo Desktop] => C:\ProgramData\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe
HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\...\Run: [BingSvc] => C:\Users\Sylwia\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)
GroupPolicyScripts: Ograniczenia <======= UWAGA
GroupPolicyScripts\User: Ograniczenia <======= UWAGA
ProxyEnable: [S-1-5-21-2149846570-3116261561-3701264130-1001] => Proxy [funkcja włączona]
ProxyServer: [S-1-5-21-2149846570-3116261561-3701264130-1001] => 127.0.0.1:8118
AutoConfigURL: [S-1-5-21-2149846570-3116261561-3701264130-1001] => 127.0.0.1:8118
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki&utm_medium=installer&utm_campaign=instalki
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792&q={searchTerms}
HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=SL5M&ocid=SL5MDHP&osmkt=pl-pl
HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792
HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://mysearch.avg.com/?cid={907A8E03-FF4F-43A5-B35A-CB8BB34CC7B9}&mid=b258d80cf9af47d0a383d152ba7c9429-0339af823c62af038391b60339ed2ca6588ebe58&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-06%2017:34:03&v=4.1.6.294&pid=wtu&sg=&sap=hp
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792&q={searchTerms}
SearchScopes: HKLM -> {004FDA13-238B-4326-AF76-CD11B8A85100} URL = hxxp://startsear.ch/?aff=1&src=sp&cf=3414268f-1e10-11e2-856f-001bfc987dda&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2149846570-3116261561-3701264130-1001 -> DefaultScope {004FDA13-238B-4326-AF76-CD11B8A85100} URL = hxxp://startsear.ch/?aff=1&src=sp&cf=3414268f-1e10-11e2-856f-001bfc987dda&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2149846570-3116261561-3701264130-1001 -> {004FDA13-238B-4326-AF76-CD11B8A85100} URL = hxxp://startsear.ch/?aff=1&src=sp&cf=3414268f-1e10-11e2-856f-001bfc987dda&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2149846570-3116261561-3701264130-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2149846570-3116261561-3701264130-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2149846570-3116261561-3701264130-1001 -> {9557EB5A-D3A0-47F9-903D-330697F424B2} URL = hxxp://www.bing.com/search?FORM=SL5MDF&PC=SL5M&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2149846570-3116261561-3701264130-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={907A8E03-FF4F-43A5-B35A-CB8BB34CC7B9}&mid=b258d80cf9af47d0a383d152ba7c9429-0339af823c62af038391b60339ed2ca6588ebe58&lang=pl&ds=AVG&coid=avgtbavg&cmpid=0915tb&pr=fr&d=2014-11-06 17:34:03&v=4.1.6.294&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: Internet Panel -> {CE7C3CF0-4B15-11D1-ABED-709549C10000} -> C:\Program Files\NetPanel\IEHelper.dll [2013-06-11] (Gemius)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792&ts=1383861341
CHR StartupUrls: Default -> "hxxp://isearch.omiga-plus.com/?type=hp&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792"
CHR DefaultSearchURL: Default -> hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1421778646&from=cor&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792&q={searchTerms}
CHR DefaultSearchKeyword: Default -> omiga-plus
CHR Extension: (Badanie Megapanel PBI/Gemius) - C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmlmanpnnbnpabnonijjmnmplnbfcgbf [2014-06-13]
CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Sylwia\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx <nie znaleziono>
CHR HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2149846570-3116261561-3701264130-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [jmlmanpnnbnpabnonijjmnmplnbfcgbf] - C:\Program Files\NetPanel\chromegem.crx [2014-01-03]
StartMenuInternet: (HKLM) Opera - C:\Program Files\Opera\Opera.exe hxxp://www.delta-homes.com/?type=sc&ts=1388693882&from=wpm0102&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792
StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe hxxp://www.istartsurf.com/?type=sc&ts=1445811767&z=55c8ca3c30a260984d316a0g3zfz5w9beg4gaw4g5z&from=cornl&uid=WDCXWD2500BEKT-75PVMT0_WD-WXC1A81J3792J3792
R2 PrivoxyService; C:\Program Files\Alfasistem Memory\privoxy.exe [371200 2015-10-23] (The Privoxy team - www.privoxy.org) [Brak podpisu cyfrowego] <==== UWAGA
R2 vToolbarUpdater40.1.8; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.1.8\ToolbarUpdater.exe [1875856 2015-10-04] (AVG Secure Search)
R2 WdsManPro; C:\ProgramData\lWdsManProl\WdsManPro.exe [442504 2015-10-25] (DTools LIMITED)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
2015-10-25 23:23 - 2015-10-25 23:24 - 00000000 ____D C:\ProgramData\lWdsManProl
2015-10-25 23:23 - 2015-10-25 23:23 - 00000102 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-10-25 23:22 - 2015-10-25 23:23 - 00000000 ____D C:\Users\Sylwia\AppData\Roaming\istartsurf
2015-10-25 23:08 - 2015-10-25 23:08 - 00967296 _____ (Software ) C:\Users\Sylwia\Downloads\Everest-Home-Edition-11558-dp.exe
2015-10-25 19:49 - 2015-10-25 19:49 - 00724424 _____ (Opera Software) C:\Users\Sylwia\Downloads\Opera_NI_stable (1).exe
Task: {2C500373-EF32-4408-A748-B0467099BD62} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
EmptyTemp:
W FRST wybierz Napraw.