Odinstaluj Intel Security True Key
Uzyj:
https://sourceforge.net/projects/adobeflashup...an%20Remover/RemoveMcAfee_silent.exe/download
Wykonaj Fixlist.txt dla FRST:
Task: {432EF320-F06E-4560-B984-9ECC6D876437} - System32\Tasks\{07F4604E-B232-4193-B10F-A00CA4AD44C0} => D:\#GRY\hurtworld\PolskiHurtworld v3.8.1\HurtworldClient.exe
Task: {83E54305-823D-417E-9D4E-166545F05FD6} - System32\Tasks\{1DF853C0-DFE1-4174-8EC3-4215A29B044D} => C:\Windows\system32\pcalua.exe -a "D:\#GRY\Samp\GTA San Andreas\samp.exe" -d "D:\#GRY\Samp\GTA San Andreas"
Task: {ECD65CDE-1A2B-4D6C-99A5-31BF62867AFD} - System32\Tasks\Driver Booster SkipUAC (ToTylkoJa) => C:\Program Files (x86)\IObit\Driver Booster\4.1.0\DriverBooster.exe
Task: {F52B4FD0-E059-41E9-89C0-0480A3854357} - System32\Tasks\{22916F3A-1232-46C4-8CFF-E4D92D771AA7} => D:\#GRY\hurtworld\PolskiHurtworld v3.8.1\HurtworldClient.exe
AlternateDataStreams: C:\ProgramData:NT [40]
AlternateDataStreams: C:\ProgramData:NT2 [432]
AlternateDataStreams: C:\Users\All Users:NT [40]
AlternateDataStreams: C:\Users\All Users:NT2 [432]
AlternateDataStreams: C:\ProgramData\Application Data:NT [40]
AlternateDataStreams: C:\ProgramData\Application Data:NT2 [432]
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT [40]
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2 [432]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [432]
AlternateDataStreams: C:\Users\ToTylkoJa\Dane aplikacji:NT [40]
AlternateDataStreams: C:\Users\ToTylkoJa\Dane aplikacji:NT2 [432]
AlternateDataStreams: C:\Users\ToTylkoJa\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\ToTylkoJa\AppData\Roaming:NT2 [432]
Lsa: [Notification Packages] scecli "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
Startup: C:\Users\ToTylkoJa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WinBrowModule.lnk [2017-10-05]
ShortcutTarget: WinBrowModule.lnk -> C:\Users\ToTylkoJa\AppData\Roaming\WinUpdate\setup.exe (Brak pliku)
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security)
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security)
Toolbar: HKU\S-1-5-21-4137529681-1544360181-1150254902-1000 -> True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
FF Extension: (Activity Stream) - C:\Program Files\Mozilla Firefox\browser\features\activity-stream@mozilla.org.xpi [2017-09-26] [Brak podpisu cyfrowego]
CHR Extension: (WinHandler) - C:\Users\ToTylkoJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dheaknjicnglbojnbjmkofdmpfjajoam [2017-09-03]
C:\Users\ToTylkoJa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dheaknjicnglbojnbjmkofdmpfjajoam
R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [1001920 2017-06-26] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16928 2017-06-26] (McAfee, Inc.)
S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [87760 2017-06-26] (McAfee, Inc.)
S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [X]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== UWAGA (Brak ServiceDLL)
U0 aswVmm; Brak ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CLVirtualBus01; system32\DRIVERS\CLVirtualBus01.sys [X]
2017-10-05 16:05 - 2017-10-05 16:05 - 008250832 _____ (Malwarebytes) C:\Users\ToTylkoJa\Downloads\adwcleaner_7.0.3.1 (1).exe
2017-10-05 16:35 - 2017-09-03 22:22 - 000000000 ____D C:\Users\ToTylkoJa\AppData\Roaming\WinUpdate
2017-10-05 16:12 - 2017-01-19 10:57 - 000000000 ____D C:\AdwCleaner
2017-09-09 02:10 - 2016-12-31 03:38 - 000000000 ____D C:\Program Files (x86)\McAfee
2017-09-08 12:16 - 2016-12-31 03:38 - 000000000 ____D C:\ProgramData\McAfee
2017-08-12 11:38 - 2017-08-12 11:38 - 000000000 ____H () C:\Users\ToTylkoJa\AppData\Local\BITE87A.tmp
EmptyTemp:
Zamiesc screen z:
CrystalDiskInfo:
http://portableapps.com/apps/utilities/crystaldiskinfo_portable
oraz:
Process Explorer:
https://technet.microsoft.com/pl-pl/sysinternals/processexplorer
(cale okna!)