Odinstaluj:
CCleaner
Driver Booster 6
IObit Uninstaller
SafeFinder (HKLM-x32\...\{008970EC-A545-47E2-9D70-B3A755043C41}) (Version: 1.0.0.0 - Linkury) <==== UWAGA
Smart Defrag 6
Pobierz i skan - usuń wszystko co znajdzie:
https://pl.malwarebytes.com/
Skopiuj i wklej do notatnika:
Spoiler: Pokaż
CloseProcesses:
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Smart Defrag\Pub\PubMonitor.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Smart Defrag\Pub\PreCare.exe
(PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1466\DSAPI.exe
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA
HKU\S-1-5-21-1575415932-2932647771-3859607349-1001\...\MountPoints2: {4fef17bc-a3f2-11e8-9784-d46a6a6e30ac} - "F:\Autorun.exe"
HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2008-09-04] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2008-09-04] (Electronic Arts -> On2.com)
BootExecute: autocheck autochk * SmartDefragBootTime.exe
HKU\S-1-5-21-1575415932-2932647771-3859607349-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19589208 2018-12-10] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1575415932-2932647771-3859607349-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccZ4Zyaa_7aN8lQTFBy3yDfv5DjcB0HuNFNFc3T3RCgRHXC0BZhexcDOteZm15VBZkkm4AVcSO4yc3oJ1RpUD1UslhfP0Is92HqyXEnPiluM0sglhp2S6nIbHH2YEjXFRQGPAgIqp8Q-ZjFTSpMCuQCabuXDew,,&q={searchTerms}
HKU\S-1-5-21-1575415932-2932647771-3859607349-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccZ4Zyaa_7aN8lQTFBy3yDfv5DjcB0HuNFNFc3T3RCgRHXC0BZhexcDOteZm15VBZkkqB4ZQrjPC6R8ZG8099Lb4aZGuZz388s3ncuMA6DmxKccYo6hGZxMy6oqwE3yLPX46CkxcRXjjLXLrZa0KHAgC7YQ7VQ,,
HKU\S-1-5-21-1575415932-2932647771-3859607349-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKLM-x32 -> DefaultScope - brak wartości
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2017-05-22] (IObit Information Technology -> IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
FF NewTab: Mozilla\Firefox\Profiles\nxtheutm.default -> file:///C:/ProgramData/Quoteexs/ff.NT
FF Extension: (Avast SafePrice) - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\nxtheutm.default\Extensions\sp@avast.com.xpi [2018-05-17] [UpdateUrl:hxxps://firefoxext.avcdn.net/firefoxext/avast/sp/update.json]
FF Extension: (Avast Online Security) - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\nxtheutm.default\Extensions\wrc@avast.com.xpi [2018-08-07]
FF Extension: (Java-Redirector) - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\nxtheutm.default\Extensions\{b75af37b-574d-4746-ac34-629fa349cf81}.xpi [2019-02-23]
FF Plugin: @java .com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java .com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @Microsoft .com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @java .com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java .com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @Microsoft .com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft .com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft .com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-03-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @TOOLS .google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc -> Google Inc.)
FF Plugin-x32: @TOOLS .google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc -> Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
CHR Extension: (Adblock Plus - darmowy adblocker) - C:\Users\Patrycja\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-03-13]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx
R2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [206112 2017-06-14] (IObit Information Technology -> IObit)
R3 IUFileFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys [39904 2017-06-06] (IObit Information Technology -> IObit.com)
R3 IURegProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegProcessFilter.sys [39792 2017-09-28] (IObit Information Technology -> IObit.com)
R2 WinDivert1.2; C:\WINDOWS\system32\drivers\WinDivert64.sys [37552 2019-02-28] (Nemea Mjukvaruutveckling AB -> Basil)
S3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2017-05-22] (IObit Information Technology -> IObit)
ContextMenuHandlers1: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\WINDOWS\System32\IObitSmartDefragExtension.dll [2016-03-25] (IObit Information Technology -> IObit)
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2017-05-22] (IObit Information Technology -> IObit)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2017-05-22] (IObit Information Technology -> IObit)
ContextMenuHandlers6: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\WINDOWS\System32\IObitSmartDefragExtension.dll [2016-03-25] (IObit Information Technology -> IObit)
Task: {3BCA4579-9362-432F-8328-F3EF7F84B86A} - System32\Tasks\SmartDefrag_AutoAnalyze => C:\Program Files (x86)\IObit\Smart Defrag\AutoDefrag.exe (IObit Information Technology -> IObit)
Task: {839B61C9-EFC9-4F32-B750-85740A23A9D3} - System32\Tasks\SmartDefrag_Startup => C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe (IObit Information Technology -> IObit)
Task: {8CDA4284-4D26-4A01-9DB7-84622CA83CFA} - System32\Tasks\SmartDefrag_Update => C:\Program Files (x86)\IObit\Smart Defrag\AutoUpdate.exe (IObit Information Technology -> IObit)
Task: {9553267B-2A97-4D97-84E2-158BDDB14834} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe (Piriform Software Ltd -> Piriform Software Ltd)
Task: {B0FF8CC3-BCC2-4280-8FD6-C1C8A37986E2} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
2018-12-04 12:10 - 2018-12-04 12:10 - 000100864 _____ (Rivet Networks) [Brak podpisu cyfrowego] C:\Program Files\Rivet Networks\SmartByte\KillerNetworkServicePS.dll
IE trusted site: HKU\S-1-5-21-1575415932-2932647771-3859607349-1001\...\sharepoint.com -> hxxps://uniekonpoznan-files.sharepoint.com
FirewallRules: [{9FA89016-D791-4D1C-A8D5-488B426E21C7}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.2.0\DriverBooster.exe (IObit Information Technology -> IObit)
FirewallRules: [{E45BC7A8-34AA-4A76-87B7-3002C0058203}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.2.0\DriverBooster.exe (IObit Information Technology -> IObit)
FirewallRules: [{72842242-0977-4044-BE04-617941C5D7A6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.2.0\DBDownloader.exe (IObit Information Technology -> IObit)
FirewallRules: [{87102ED8-630D-450A-99F7-5BE8CD124D25}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.2.0\DBDownloader.exe (IObit Information Technology -> IObit)
FirewallRules: [{D1B578A6-6875-4D8B-822B-726892AAB64B}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.2.0\AutoUpdate.exe (IObit Information Technology -> IObit)
FirewallRules: [{7F3D2FEA-B036-46F0-8D81-8BF7A849E992}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.2.0\AutoUpdate.exe (IObit Information Technology -> IObit)
FirewallRules: [{4952CE22-12F5-4403-92C8-C6DC425A7D46}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{BD249443-2360-4772-A369-CA4625746D10}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [TCP Query User{1A22303A-4480-487E-9E3A-02E7EB81C98D}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe Brak pliku
FirewallRules: [UDP Query User{2FEB0469-77B5-494D-84C0-BCE0905B78CD}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe Brak pliku
FirewallRules: [UDP Query User{730E8D6B-1624-42AA-8EF9-87EA35A66673}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{05200A4F-6D6C-4FAA-96DD-6FAC77DF5904}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag\Smart Defrag Home Page.url -> URL: hxxps://www.iobit.com/en/iobitsmartdefrag.php
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> URL: hxxp://www.ccleaner.com/ccleaner
InternetURL: C:\Users\Patrycja\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
InternetURL: C:\Users\Patrycja\Favorites\Dell\Dell.url -> URL: hxxp://www1.euro.dell.com/content/default.aspx?c=pl&l=pl&s=pad
InternetURL: C:\Users\Patrycja\Favorites\Dell\Support.Dell.Com.url -> URL: hxxp://www.dell.com/support/home
Hosts:
EmptyTemp:
Plik zapisz pod nazwą fixlist.txt i umieść obok FRST w tym samym folderze.
Uruchom FRST i kliknij w Fix/Napraw.
Staraj się korzystać z jednej przeglądarki, resztę odinstaluj.
Usuń też wszystkie inne programy, z których nie korzystasz.