Odinstaluj: Adobe Reader 9, zmien na najnowsza wersje AR lub na Foxit:
http://ninite.com/foxit/
W Chrome zmien AdBlock na uBlock Origin.
Nowy Fixlist.txt dla FRST:
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
ShortcutWithArgument: C:\Users\'lfgg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\'lfgg\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk"
HKLM\...\Providers\5ydp3vr3: C:\Program Files (x86)\Fevuphmervly Launcher\local64spl.dll
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\żěŃą\X64\KZipShell.dll -> Brak pliku
CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
2017-02-16 10:15 - 2017-02-16 10:15 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-15 20:29 - 2017-02-15 20:29 - 05659775 _____ (Swearware) C:\Users\'lfgg\Downloads\ComboFix.exe
2017-02-15 19:39 - 2017-02-15 19:39 - 00000000 ____D C:\Users\'lfgg\AppData\Local\CEF
2017-02-15 19:34 - 2017-02-15 19:34 - 00000000 __SHD C:\Users\'lfgg\AppData\Local\svchost
2017-02-15 19:33 - 2017-02-16 09:19 - 00000000 ____D C:\Users\'lfgg\AppData\Roaming\{7b1-bc-9b-8e458-9fa7e-cc81-14fad}
2017-02-15 19:31 - 2017-02-16 09:26 - 00000000 ____D C:\Program Files (x86)\Fevuphmervly Launcher
2017-02-15 19:31 - 2017-02-15 20:22 - 00000000 ____D C:\Users\'lfgg\AppData\Roaming\Shogersh
2017-02-15 19:31 - 2017-02-15 19:40 - 00000000 ____D C:\Users\'lfgg\AppData\Local\Rozaph
2016-08-09 19:11 - 2016-08-09 19:11 - 0000036 _____ () C:\Program Files\smaple.txt
2017-01-08 11:09 - 2011-07-19 03:37 - 0003262 _____ () C:\Program Files (x86)\Falco.ico
2017-01-08 11:09 - 2011-07-19 04:05 - 0000046 _____ () C:\Program Files (x86)\Falco.url
Po wykonaniu usun katalog C:\FRST i to wszystko.