Otwórz notatnik systemowy i wklej:
Task: {204D2715-4183-4F81-8713-D26979CA91EC} - System32\Tasks\{99DB45F7-7743-87F2-9654-D32345EC9FCB} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://cssnews.ru/cl/?guid=vhrcn5o2kli1gdm3kbcn2q34gc71cwxx&prid=1&pid=4_1324_0
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-257770890-2282901805-686063059-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2016-11-21] (Microsoft Corporation) <==== UWAGA (Brak ServiceDLL)
U3 aswbdisk; Brak ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
2018-07-30 21:21 - 2018-07-30 21:21 - 000023908 _____ C:\ComboFix.txt
2018-07-30 21:14 - 2018-07-30 21:14 - 000000000 ____D C:\AdwCleaner
2018-07-30 03:02 - 2011-06-26 08:45 - 000256000 _____ C:\Windows\PEV.exe
2018-07-30 03:02 - 2010-11-07 19:20 - 000208896 _____ C:\Windows\MBR.exe
2018-07-30 03:02 - 2009-04-20 06:56 - 000060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2018-07-30 03:02 - 2000-08-31 02:00 - 000518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2018-07-30 03:02 - 2000-08-31 02:00 - 000406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2018-07-30 03:02 - 2000-08-31 02:00 - 000098816 _____ C:\Windows\sed.exe
2018-07-30 03:02 - 2000-08-31 02:00 - 000080412 _____ C:\Windows\grep.exe
2018-07-30 03:02 - 2000-08-31 02:00 - 000068096 _____ C:\Windows\zip.exe
2018-07-30 03:01 - 2018-07-30 21:21 - 000000000 ____D C:\Qoobox
2018-07-30 03:01 - 2018-07-30 03:07 - 000000000 ____D C:\Windows\erdnt
2018-07-30 02:29 - 2018-07-30 02:29 - 000000000 ____D C:\Users\BARDAS\Doctor Web
2018-07-30 02:29 - 2018-07-30 02:29 - 000000000 ____D C:\ProgramData\Doctor Web
2009-07-14 03:14 - 2009-07-14 03:14 - 000073216 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\utlZiRUaoHyEn.exe
EmptyTemp:
Plik zapisz pod nazwą fixlist.txt i umieść w folderze, gdzie masz FRST.exe.
Uruchom FRST i kliknij w Fix/Napraw.
I na przyszłość nie używaj combofixa.