Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

prośba o sprawdzenie logów FRST

kazo.m 07 Kwi 2018 22:23 477 6
  • #1 07 Kwi 2018 22:23
    kazo.m
    Poziom 15  

    Witam.
    Znów mam jakieś badziewie na komputerze.
    Użyłem Malwerbytes w trybie awaryjnym i usunąłem wszystko, co znalazł.
    Jednak jeszcze coś zostało.
    Bardzo proszę o sprawdzenie logów.

    0 6
  • Pomocny post
    #2 08 Kwi 2018 07:25
    krzychupar
    Poziom 41  

    Odinstaluj:

    McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.183 - McAfee, Inc.)

    Otwórz notatnik systemowy i wklej:
    ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    ContextMenuHandlers4-x32: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\kazo\AppData\Local\MEGAsync\ShellExtX64.dll -> Brak pliku
    Task: {0323E4B4-766A-42D4-A9F0-535269689A6A} - \Notepad -> Brak pliku <==== UWAGA
    Task: {09DE298F-94C5-4284-99FE-C6EC1ECF0C3C} - System32\Tasks\Origin => C:\Users\kazo\AppData\Roaming\Origin\update.vbe <==== UWAGA
    Task: {2BCCCD85-C8E7-4AAF-A04C-5DA6FF2A1CDC} - \KlgKDPyHEeVbjwqnEgK2 -> Brak pliku <==== UWAGA
    Task: {2F69A71E-A94D-4E74-8AC2-6B0E43DFC69F} - \syslog -> Brak pliku <==== UWAGA
    Task: {91D778AC-808A-4A8F-A192-2549C6A0DE75} - \KlAEYQtzmHgics -> Brak pliku <==== UWAGA
    Task: {C4BD3823-1CC4-43B7-8B5A-43A491593388} - \XeRTeJCMKPYXWyYqW2 -> Brak pliku <==== UWAGA
    Task: {E8A72D4E-C837-4C5D-8AF4-307CB1501A43} - System32\Tasks\{CEFBDCDA-6B6B-41DD-B93F-EB5D1781912E} => C:\Windows\system32\pcalua.exe -a "D:\807 Network Joystick(4a12k)3.70a - 副本 (2).exe" -d D:\
    Task: {FE16D069-E280-4877-B4AA-D21AC9C3B565} - \xRZOrQVCBWPMscb2 -> Brak pliku <==== UWAGA
    ShortcutWithArgument: C:\Users\kazo\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> "hxxp://bartati.ru/?utm_source=startlink03&utm_content=3ac05f4b1a9035c00012231ae7218634&utm_term=76F9B78C2545BD56AA00589451F626C1&utm_d=20161016&utm_medium=p_14712_16121"




    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {0278a730-2bfa-11e5-8813-d43d7e4e76d2} - L:\setup.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {0fedf3be-fe9b-11e7-a681-d43d7e4e76d2} - Q:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {0fedf3c7-fe9b-11e7-a681-d43d7e4e76d2} - Q:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {6b6e7a5d-77ac-11e7-8287-d43d7e4e76d2} - E:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {7b2e0f2d-2be7-11e5-ba7d-806e6f6e6963} - D:\BlueBirds.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {a2296633-7b9f-11e7-8840-d43d7e4e76d2} - E:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {a2296637-7b9f-11e7-8840-d43d7e4e76d2} - Q:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {e077279b-475d-11e5-a020-d43d7e4e76d2} - E:\LGAutoRun.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\MountPoints2: {ec2ae0e6-71e3-11e5-8e6a-d43d7e4e76d2} - Q:\LGAutoRun.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0278a730-2bfa-11e5-8813-d43d7e4e76d2} - L:\setup.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0fedf3be-fe9b-11e7-a681-d43d7e4e76d2} - Q:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0fedf3c7-fe9b-11e7-a681-d43d7e4e76d2} - Q:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {6b6e7a5d-77ac-11e7-8287-d43d7e4e76d2} - E:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {7b2e0f2d-2be7-11e5-ba7d-806e6f6e6963} - D:\BlueBirds.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {a2296633-7b9f-11e7-8840-d43d7e4e76d2} - E:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {a2296637-7b9f-11e7-8840-d43d7e4e76d2} - Q:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {e077279b-475d-11e5-a020-d43d7e4e76d2} - E:\LGAutoRun.exe
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {ec2ae0e6-71e3-11e5-8e6a-d43d7e4e76d2} - Q:\LGAutoRun.exe
    HKU\S-1-5-18\...\Policies\system: [DisableLockWorkstation] 0
    GroupPolicy: Ograniczenia - Chrome <==== UWAGA
    GroupPolicy\User: Ograniczenia <==== UWAGA
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = about:blank
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page =
    SearchScopes: HKU\S-1-5-21-1549175157-624555591-3790381870-1000 -> DefaultScope {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL =
    SearchScopes: HKU\S-1-5-21-1549175157-624555591-3790381870-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B10BD8BB1-6E46-46F2-8114-C8F53383A437%7D&gp=855503
    SearchScopes: HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL =
    SearchScopes: HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B10BD8BB1-6E46-46F2-8114-C8F53383A437%7D&gp=855503
    BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-03-19] (McAfee, Inc.)
    BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-03-19] (McAfee, Inc.)
    BHO-x32: YoutubeAdBlock -> {C0D38E5A-7CF8-4105-8FE8-31B81443A114} -> C:\Program Files (x86)\oPjpQbAMIIE\kbrc10B.dll => Brak pliku
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-03-19] (McAfee, Inc.)
    Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-03-19] (McAfee, Inc.)
    FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
    FF Extension: (McAfee® WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [2018-04-06]
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
    FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => nie znaleziono
    FF Extension: (IDM CC) - C:\Users\kazo\AppData\Roaming\IDM\idmmzcc5 [2016-05-26] [Przestarzałe] [Brak podpisu cyfrowego]
    FF HKU\S-1-5-21-1549175157-624555591-3790381870-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\kazo\AppData\Roaming\IDM\idmmzcc5
    FF HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\kazo\AppData\Roaming\IDM\idmmzcc5
    FF HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\kazo\AppData\Roaming\IDM\idmmzcc5
    CHR HomePage: Default -> inline.go.mail.ru
    CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\kazo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcadgijmedbfgciegjomfpjcdchlhnif [2018-04-07]
    CHR HKU\S-1-5-21-1549175157-624555591-3790381870-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-1549175157-624555591-3790381870-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [lhemechcanjmilllmccjbjldonmnnjjj] - hxxps://clients2.google.com/service/update2/crx
    R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [604312 2018-03-19] (McAfee, Inc.)
    S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [X]
    S3 NvStreamNetworkSvc; "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" [X]
    S2 NvStreamSvc; "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe" [X]
    R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
    U3 aalqjoop; C:\Windows\System32\Drivers\aalqjoop.sys [0 ] (Microsoft Corporation) <==== UWAGA (zerobajtowy plik/folder)
    S3 DUMeterDrv; \??\C:\Program Files (x86)\DU Meter\DUMETR64.SYS [X]
    2018-04-07 21:02 - 2018-04-07 21:12 - 000000000 ____D C:\AdwCleaner
    2018-03-23 21:18 - 2018-02-17 19:35 - 000000000 ____D C:\Program Files (x86)\McAfee
    2016-04-30 16:41 - 2016-04-30 16:41 - 000093696 _____ () C:\Users\kazo\AppData\Roaming\ezpinst.exe
    2015-07-17 20:36 - 2015-07-17 20:36 - 000099384 _____ () C:\Users\kazo\AppData\Roaming\inst.exe
    2015-07-17 20:36 - 2016-04-30 16:41 - 000007176 _____ () C:\Users\kazo\AppData\Roaming\pcouffin.cat
    2015-07-17 20:36 - 2016-04-30 16:41 - 000001167 _____ () C:\Users\kazo\AppData\Roaming\pcouffin.inf
    2015-07-17 20:36 - 2016-04-30 17:03 - 000000033 _____ () C:\Users\kazo\AppData\Roaming\pcouffin.log
    2015-07-17 20:36 - 2016-04-30 16:41 - 000082048 _____ (VSO Software) C:\Users\kazo\AppData\Roaming\pcouffin.sys
    2015-08-01 01:12 - 2015-08-01 01:12 - 000000000 ___SH () C:\Users\kazo\AppData\Local\LumaEmu
    2015-08-22 11:38 - 2016-03-06 23:18 - 000007611 _____ () C:\Users\kazo\AppData\Local\Resmon.ResmonCfg
    2016-02-14 20:34 - 2016-02-14 20:34 - 000000017 _____ () C:\Users\kazo\AppData\Local\si
    EmptyTemp:

    Plik zapisz pod nazwą fixlist.txt i umieść w folderze, gdzie masz FRST.exe.
    Uruchom FRST i kliknij w Fix/Napraw.

    0
  • Pomocny post
    #4 08 Kwi 2018 15:18
    dt1
    Moderator - Komputery Serwis

    Na Twoim miejscu zdecydowałbym się na jeden program antywirusowy, chyba że komputer Ci za szybko działa lub ma za mało problemów (wybrałbym ESET lub ANVI, ale nie oba).

    Uzupełniająca fixlista:

    Code:
    FF Plugin: @microsoft.com/GENUINE -> disabled [Brak pliku]
    
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Brak pliku]
    S2 0273741523184196mcinstcleanup; C:\Users\kazo\AppData\Local\Temp\027374~1.EXE -cleanup -nolog [X] <==== UWAGA
    U3 a26bw1ht; C:\Windows\System32\Drivers\a26bw1ht.sys [0 ] (Microsoft Corporation) <==== UWAGA (zerobajtowy plik/folder)
    AlternateDataStreams: C:\ProgramData\Temp:05EE1EEF [1018]
    AlternateDataStreams: C:\ProgramData\Temp:CB0AACC9 [139]
    EmptyTemp:


    Nie masz zainstalowanych wszystkich sterowników - powinieneś to uczynić, niezależnie od tego czy niezainstalowane urządzenia są przez Ciebie używane, czy nie.

    0
  • #5 08 Kwi 2018 20:48
    kazo.m
    Poziom 15  

    Witam.
    Sterowniki zainstalowane i zaktualizowane.
    Jednak Malwerbytes jeszcze znalazł 8 zagrożeń. W załączniku przesyłam raporty ze skanowania i logi z FRST.
    Przeglądarka nadal próbuje nawiązać kontakt z jakąś rumuńską stroną.

    0
  • Pomocny post
    #6 08 Kwi 2018 22:13
    Kolobos
    Spec od komputerów

    Usun recznie plik C:\Users\kazo\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт.lnk

    Wykonaj Fixlist.txt dla FRST:
    Tcpip\..\Interfaces\{AD2261F4-FAB1-4D6D-9C3A-8313129E9B7F}: [NameServer] 35.177.46.238,46.101.28.31,,192.168.1.1
    C:\Users\kazo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhhhfgfhbjnkpaoedekoofphhbagpooj
    CHR Extension: (Adblocker for Youtube™) - C:\Users\kazo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhhhfgfhbjnkpaoedekoofphhbagpooj [2018-04-07]
    C:\Users\kazo\AppData\Roaming\Opera Software\Opera Stable\Extensions\kjmiajamiimndhpicnkbijomngkocnfn
    U3 amyv9dn9; C:\Windows\System32\Drivers\amyv9dn9.sys [0 ] (Microsoft Corporation) <==== UWAGA (zerobajtowy plik/folder)
    2018-04-07 19:58 - 2018-04-07 19:58 - 000000000 ____D C:\Users\kazo\AppData\LocalLow\gwnxXYQfvfqza
    2018-04-07 19:56 - 2018-04-08 12:45 - 000000008 __RSH C:\Users\kazo\ntuser.pol
    2018-04-07 19:48 - 2018-04-08 12:45 - 000000008 __RSH C:\ProgramData\ntuser.pol
    2018-04-07 19:48 - 2018-04-07 19:48 - 000000000 ____D C:\Program Files (x86)\IUpWUBcycmhgC


    Jezeli nic sie nie zmieni po wykonaniu to zgraj zakladki z Chrome i usun katalog proflu przegladarki: C:\Users\kazo\AppData\Local\Google\Chrome\User Data\Default

    0
  • #7 09 Kwi 2018 21:14
    kazo.m
    Poziom 15  

    Świetnie! Usunięcie profilu przeglądarki pomogło. Malwerbytes już nic nie wykrywa.
    Dla pewności przeskanuje jeszcze Anvi Smart Defenderem.
    Jeszcze raz bardzo dziękuję wszystkim za nieocenioną pomoc. Punkty lecą.

    0