Otwórz notatnik systemowy i wklej:
Cytat: CloseProcesses:
Task: {09590F2C-E0F8-4289-8606-87BE786DFB6A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-37082234-313136031-2243966049-1000Core => C:\Users\Sebastian jestem\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-03] (Facebook Inc.)
Task: {433292AF-6C26-4090-B5D3-EF56619FE3A4} - System32\Tasks\Microsoft\Windows\Software\UpdaterSrv => C:\ProgramData\UpdaterSrv\UpdaterSrv.exe <==== UWAGA
Task: {549E00AB-442A-46F8-8D7F-6AD192D53592} - \AdobeFlashPlayerUpdate -> Brak pliku <==== UWAGA
Task: {C5981634-F712-4B62-AC9B-8C1DE5609D42} - System32\Tasks\{303E167F-DB2F-4714-833E-7425B1EF898C} => pcalua.exe -a "C:\Users\Sebastian jestem\Downloads\SoftonicDownloader_for_free-pdf-unlocker.exe" -d "C:\Users\Sebastian jestem\Downloads" <==== UWAGA
HKLM\...\Run: [99] => wscript.exe //B "C:\Users\Sebastian jestem\AppData\Roaming\99.vbs"
HKLM\...\Winlogon: [Userinit] wscript,
HKU\S-1-5-21-37082234-313136031-2243966049-1000\...\Run: [99] => wscript.exe //B "C:\Users\Sebastian jestem\AppData\Roaming\99.vbs"
HKU\S-1-5-21-37082234-313136031-2243966049-1000\...\Run: [msiql] => C:\ProgramData\msiql.exe /RUNNING
HKU\S-1-5-21-37082234-313136031-2243966049-1000\...\Policies\Explorer: []
HKU\S-1-5-21-37082234-313136031-2243966049-1000\...\MountPoints2: {10332163-1773-11e2-a6df-dc0ea12bbbb3} - H:\LaunchU3.exe -a
HKU\S-1-5-21-37082234-313136031-2243966049-1000\...\MountPoints2: {5027c23e-e618-11e1-8325-806e6f6e6963} - F:\DistinguishOS.exe
HKU\S-1-5-21-37082234-313136031-2243966049-1000\...\MountPoints2: {609c238f-fe41-11e1-aec8-dc0ea12bbbb3} - G:\setup.exe
HKU\S-1-5-21-37082234-313136031-2243966049-1002\...\Run: [Facebook Update] => C:\Users\Sebastian jestem\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-02-03] (Facebook Inc.)
HKU\S-1-5-21-37082234-313136031-2243966049-1002\...\MountPoints2: {5027c23e-e618-11e1-8325-806e6f6e6963} - F:\DistinguishOS.exe
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-37082234-313136031-2243966049-1000 -> ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± v˰!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁwľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)xä URL =
FF Homepage: hxxps://www.malwarebytes.org/restorebrowser/
FF Extension: autoreloadyzcom - C:\Users\Sebastian jestem\AppData\Roaming\Mozilla\Firefox\Profiles\p4kfvj8t.default\extensions\autoreload@yz.com [2015-10-15] [Brak podpisu cyfrowego]
FF Extension: keywordsearchkaplycom - C:\Users\Sebastian jestem\AppData\Roaming\Mozilla\Firefox\Profiles\p4kfvj8t.default\extensions\keywordsearch@kaply.com [2015-10-16] [Brak podpisu cyfrowego]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\prefs.js [2015-10-16] <==== UWAGA (Linkuje do pliku *.cfg)
StartMenuInternet: (HKLM) Opera - C:\Program Files (x86)\Opera\Opera.exe hxxp://www.istartsurf.com/?type=sc&ts=1444646952&z=60cbc2e5182a8b951c75fc5g5zcz3z8qbz7q0m1c2g&from=cor&uid=HitachiXHTS547575A9E384_J2540054JVG5TEJVG5TEX
S2 productliednwnload; C:\Users\Sebastian jestem\AppData\Local\Faseway.exe uudateprod productliednwnload [X]
S2 QQRepair1f13; "C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair1f13" [X]
S2 QQRepair270e; "C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair270e" [X]
S2 QQRepairc81; "C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepairc81" [X]
S2 QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepairFixSVC [X]
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [80768 2016-04-25] (Huorong Borui (Beijing) Technology Co., Ltd.)
U3 a6p9dujb; C:\Windows\System32\Drivers\a6p9dujb.sys [0 ] (Advanced Micro Devices) <==== UWAGA (zerobajtowy plik/folder)
S3 ALSysIO; \??\C:\Users\SEBAST~1\AppData\Local\Temp\ALSysIO64.sys [X]
R3 gkernel; \??\C:\Users\SEBAST~1\AppData\Local\Temp\gkernel.sys [X]
S1 softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys [X]
S1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [X]
S2 tsnethlpx64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
2016-05-06 21:54 - 2016-05-06 21:54 - 00000000 ____D C:\Users\Public\Thunder Network
2016-05-06 21:54 - 2016-05-06 21:54 - 00000000 ____D C:\ProgramData\Thunder Network
2016-05-06 21:18 - 2016-05-06 21:18 - 00001535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器.lnk
2016-05-06 21:18 - 2016-05-06 21:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器
2016-05-06 21:18 - 2016-04-25 13:29 - 00080768 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\Windows\system32\Drivers\ucguard.sys
2016-05-07 09:35 - 2013-12-27 14:44 - 00000000 ____D C:\AdwCleaner
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Sebastian jestem\AppData\Roaming\21oUr4gFPUS7aS6PmxetKM
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Sebastian jestem\AppData\Roaming\a6C3QXmwMHj1CEU
2016-05-06 20:58 - 2016-05-06 20:58 - 6494208 _____ () C:\Users\Sebastian jestem\AppData\Roaming\agent.dat
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Sebastian jestem\AppData\Roaming\FsbMq5uTWigbxeR
2016-05-06 20:56 - 2016-05-06 20:56 - 0127488 _____ () C:\Users\Sebastian jestem\AppData\Roaming\Installer.dat
2016-05-06 20:58 - 2016-05-06 20:58 - 0018432 _____ () C:\Users\Sebastian jestem\AppData\Roaming\Main.dat
2016-05-06 20:58 - 2016-05-06 20:58 - 1626777 _____ () C:\Users\Sebastian jestem\AppData\Roaming\Opetough.tst
2016-05-06 20:58 - 2016-05-06 20:58 - 0072717 _____ () C:\Users\Sebastian jestem\AppData\Roaming\Scotity.tst
2016-05-06 20:58 - 2016-05-06 20:58 - 1626777 _____ () C:\Users\Sebastian jestem\AppData\Roaming\Stimtip.tst
2016-05-06 20:58 - 2016-05-06 20:58 - 0072717 _____ () C:\Users\Sebastian jestem\AppData\Roaming\Unasolflex.tst
2016-04-23 17:19 - 2014-07-25 04:39 - 0293320 ____N (深圳市迅雷网络技术有限公司) C:\Users\Sebastian jestem\AppData\Roaming\xldl.dll
C:\ProgramData\a.bat
C:\ProgramData\adb.exe
C:\ProgramData\fastboot.exe
EmptyTemp:
Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
Zapisując Fixlist kodowanie ustaw na UTF-8
Uruchom jako administrator FRST i kliknij w Fix/Napraw.