Odinstaluj:
AVG Web TuneUp
AVG Zen
StormFall
UpdateChecker
Otwórz notatnik systemowy i wklej:
Task: {3611BA85-1F04-46C6-A952-AFC1BEEA7399} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA
Task: {3655DAF4-1498-49A2-9BF6-8111C5A030F9} - System32\Tasks\{6E9CB322-D27D-4771-9C70-D15FF70E5627} => pcalua.exe -a C:\Users\Rafael\Desktop\PandoraMT2\PandoraMT2.exe -d C:\Users\Rafael\Desktop\PandoraMT2
Task: {491E8F89-3AF4-4780-ADBD-8A281ABFBAF0} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA
Task: {5C805C10-47BD-4A1E-9266-CACB28CF913D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA
Task: {632DD340-A287-4D0B-951F-24F37E772E14} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA
Task: {7ABE7B3E-E885-4CB9-9F44-CA539DB65A0D} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA
Task: {94D87539-0CFF-4189-B7A6-6827DF641F67} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA
Task: {CCDA1553-8D64-4683-8B17-4AE74E127EF6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA
Task: {D295A86D-DC73-48D3-9625-7D243090CB9F} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA
Task: {DC33D824-CA7A-4AD5-B6A9-93EFFACF3D30} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA
Task: {EEB6E4B6-4949-4B01-8927-86A3A5F53677} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA
Task: {F5B9D16C-8D0F-4AA0-8009-A221518C8F7D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2923876251-4096457698-3730816502-1002Core.job => C:\Users\Rafael\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2923876251-4096457698-3730816502-1002UA.job => C:\Users\Rafael\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\Open Chrome.job => c:\program files (x86)\Google\Chrome\Application\chrome.exeF--new-window hxxp:/toolbar.avg.com/
ShortcutWithArgument: C:\Users\Rafael\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\Users\Rafael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\Users\Rafael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall\StormFall.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\Users\Rafael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\Users\Rafael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\StormFall.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\Users\Rafael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\Users\Rafael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.so-v.com/?type=ll&uid=76cc2b19-987e-4812-b124-c81ec64d36eb
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2923876251-4096457698-3730816502-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://flux-cf.com/
SearchScopes: HKU\.DEFAULT -> {9E9CF7A0-3C73-4F9A-BB06-7630401A3F53} URL =
SearchScopes: HKU\S-1-5-21-2923876251-4096457698-3730816502-1001 -> {9E9CF7A0-3C73-4F9A-BB06-7630401A3F53} URL =
SearchScopes: HKU\S-1-5-21-2923876251-4096457698-3730816502-1002 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={3DCF132F-1F06-4B2D-A3BA-D1B3DD387720}&mid=0457443d50a747d39d29f121db340661-e9b2c3f38b4dd4ee9069d88606db39e314971a91&lang=pl&ds=AVG&coid=avgtbavg&cmpid=0915tb&pr=fr&d=2014-12-24 22:22:04&v=4.1.6.294&pid=wtu&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2923876251-4096457698-3730816502-1002 -> {9E9CF7A0-3C73-4F9A-BB06-7630401A3F53} URL =
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.2.4.155\AVG Web TuneUp.dll [2015-12-16] (AVG)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.2.4.155\AVG Web TuneUp.dll [2016-02-03] (AVG)
FF NewTab: hxxp://www.yoursearching.com/newtab/?type=nt&ts=1451734925&z=3d0af1b6b6ce7ad67a1775cgdz3w4g6m0c6zbtco7w&from=cornl&uid=st1000lm024xhn-m101mbb_s2u5j9bcb02309
FF DefaultSearchEngine: so-v
FF Homepage: hxxp://www.yoursearching.com/?type=hp&ts=1451734925&z=3d0af1b6b6ce7ad67a1775cgdz3w4g6m0c6zbtco7w&from=cornl&uid=st1000lm024xhn-m101mbb_s2u5j9bcb02309
FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Rafael\AppData\Roaming\Mozilla\Firefox\Profiles\g3fpacwk.default\extensions\defsearchp@gmail.com => nie znaleziono
CHR HomePage: Profile 1 -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=pl-pl
CHR DefaultSearchURL: Profile 1 -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> bing.com
CHR HKU\S-1-5-21-2923876251-4096457698-3730816502-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1215560 2016-02-22] ()
S3 X6va062; \??\C:\WINDOWS\SysWOW64\Drivers\X6va062 [X]
2016-02-22 17:58 - 2014-12-24 22:21 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-02-22 17:58 - 2014-12-24 22:21 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-02-21 11:42 - 2013-08-11 21:55 - 00000000 ____D C:\Users\Rafael\AppData\Roaming\TS3Client
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
EmptyTemp:
Plik zapisz pod nazwą fixlist.txt i umieść w folderze C:\Users\Rafael\Downloads\FRST64.exe
Uruchom FRST i kliknij w Fix/Napraw.