Odinstaluj:
AVG Web TuneUp
Otwórz notatnik systemowy i wklej:
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP3\Modules\aimp_menu64.dll -> Brak pliku
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku
Task: {2027265F-3C5A-4E48-A3AC-6B1F1569965F} - System32\Tasks\{8B813630-C58B-4309-899E-59AAA7F58789} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\ivo\Ivona_Rehab-1.0\rejestracja_ivony_rehab.exe" -d "C:\Program Files (x86)\ivo\Ivona_Rehab-1.0"
Task: {2A3AD060-1CB0-49D2-B374-A9872A1C4597} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA
Task: {419B41C6-E3A4-494C-ABEB-3D82EA57AB1B} - System32\Tasks\{049E48F1-6314-43FD-8230-4C89F03DD33D} => C:\WINDOWS\system32\pcalua.exe -a "C:\Users\Patryk\Desktop\Chaos A.D Keybinder 2.2\chaosAD Keybinder.exe" -d "C:\Users\Patryk\Desktop\Chaos A.D Keybinder 2.2"
Task: {6F0120D8-8E8B-4E34-A6AB-9AD873A6660A} - System32\Tasks\Opera scheduled Autoupdate 1479508929 => C:\Program Files (x86)\Opera\launcher.exe [2018-07-06] (Opera Software)
Shortcut: C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Intеrnеt Ехрlоrеr.lnk -> C:\Users\Patryk\AppData\Roaming\HPRewriter2\RewRun3.exe (Brak pliku) <==== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk -> C:\Users\Patryk\AppData\Roaming\HPRewriter2\RewRun3.exe (Brak pliku) <==== Cyrillic
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [432]
AlternateDataStreams: C:\Users\Public\AppData:CSM [480]
Hosts:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002\...\MountPoints2: F - "F:\Autorun.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002\...\MountPoints2: {82cf5d29-048d-11e8-8ade-74c63b081dd6} - "F:\Install.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002\...\MountPoints2: {99d41a39-3a7d-11e8-8af0-74c63b081dd6} - "F:\.\Driver\DriverInstaller.exe" -eject
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002\...\MountPoints2: {d8d453b3-0f3c-11e8-8ae0-74c63b081dd6} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018231012031\...\MountPoints2: F - "F:\Autorun.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018231012031\...\MountPoints2: {82cf5d29-048d-11e8-8ade-74c63b081dd6} - "F:\Install.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018231012031\...\MountPoints2: {99d41a39-3a7d-11e8-8af0-74c63b081dd6} - "F:\.\Driver\DriverInstaller.exe" -eject
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018231012031\...\MountPoints2: {d8d453b3-0f3c-11e8-8ae0-74c63b081dd6} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018232304512\...\MountPoints2: F - "F:\Autorun.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018232304512\...\MountPoints2: {82cf5d29-048d-11e8-8ade-74c63b081dd6} - "F:\Install.exe"
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018232304512\...\MountPoints2: {99d41a39-3a7d-11e8-8af0-74c63b081dd6} - "F:\.\Driver\DriverInstaller.exe" -eject
HKU\S-1-5-21-3878112052-3167268427-3778004699-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-07112018232304512\...\MountPoints2: {d8d453b3-0f3c-11e8-8ae0-74c63b081dd6} - "F:\HiSuiteDownLoader.exe"
GroupPolicy: Ograniczenia - Chrome <==== UWAGA
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.7.452\AVG Web TuneUp.dll => Brak pliku
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2015-11-09] [Przestarzałe]
FF Plugin-x32: @AVG.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.7\\npsitesafety.dll [Brak pliku]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [Brak pliku]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [Brak pliku]
CHR StartupUrls: Default -> "hxxp://www.interia.pl/#utm_source=instalki&utm_medium=installer&utm_campaign=instalki","hxxps://www.google.com/","hxxps://www.google.com/","hxxp://www.gazeta.pl/0,0.html?p=190"
2018-07-11 22:55 - 2018-07-11 22:57 - 000000000 ____D C:\AdwCleaner
2018-06-22 23:04 - 2018-06-22 23:05 - 000000013 _____ () C:\Users\Patryk\AppData\Roaming\rbx_hook
2016-10-11 15:42 - 2016-10-11 15:42 - 000000000 ___SH () C:\Users\Patryk\AppData\Local\LumaEmu
2017-12-14 01:44 - 2017-12-14 01:44 - 000000908 _____ () C:\Users\Patryk\AppData\Local\recently-used.xbel
2017-03-02 19:26 - 2017-03-02 19:26 - 000007604 _____ () C:\Users\Patryk\AppData\Local\Resmon.ResmonCfg
2018-02-12 16:32 - 2018-02-12 16:33 - 000000000 _____ () C:\Users\Patryk\AppData\Local\{995EE2A2-F92E-4A11-93ED-3CD931793A77}
EmptyTemp:
Plik zapisz pod nazwą fixlist.txt i umieść w folderze, gdzie masz FRST.exe.
Uruchom FRST i kliknij w Fix/Napraw.