Nie uzywaj combofix.
Zmien Adobe Reader 8.0 na najnowsza wersje AR.
Odinstaluj: NativeDesktopMediaService
Wykonaj Fixlist.txt dla FRST:
CloseProcesses:
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare\ASCExtMenu.dll -> Brak pliku
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare\ASCExtMenu.dll -> Brak pliku
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files\IObit\Advanced SystemCare\ASCExtMenu.dll -> Brak pliku
AlternateDataStreams: C:\ProgramData\ntuser.dat:alt [758]
HKU\S-1-5-21-627040989-2515010841-1607082337-1001\...\Run: [WinBar] => C:\Program Files\WinBar\WinBar.exe [271360 2009-09-29] (The WinBar Team) [Brak podpisu cyfrowego]
HKU\S-1-5-21-627040989-2515010841-1607082337-1001\...\Run: [Chromium] => c:\users\admin\appdata\local\chromium\application\chrome.exe [4149760 2017-09-22] (The Chromium Authors) [Brak podpisu cyfrowego]
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA
CHR HKU\S-1-5-21-627040989-2515010841-1607082337-1001\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA
Task: {A6FC81CC-56D1-4B94-8482-7882D9C350F0} - System32\Tasks\{319C52B9-98C7-4441-BCD3-256C6819D47B} => C:\Windows\system32\pcalua.exe -a E:\Mechanika\AVDI\abrites_setup_demo.exe -d E:\Mechanika\AVDI
Task: {B391ED75-88A3-4458-BD0E-4FC7B5CE60F9} - System32\Tasks\{E85D7DA8-9929-4FB3-B166-D4E5C54B4566} => G:\Mechanika\Programy Legulacyno-Naprawcze\Ford IDS v86.01\Ford IDS V86 (Web Installer).exe
Task: {C1D7A6F8-42AE-456F-93C9-B7E3408ED753} - System32\Tasks\{426B1565-6ABF-4D1A-A376-88CFE0ADEA31} => C:\Windows\system32\pcalua.exe -a E:\HP_sp54256.exe -d E:\
Task: {CE02EDC5-A968-4753-954A-3A31EE3C2CA4} - System32\Tasks\{1F34A06A-863F-45D9-AB9F-C870EBC4394C} => C:\Windows\system32\pcalua.exe -a "C:\ProgramData\VMware\VMware Workstation\Uninstaller\\uninstall.exe" -c -x -S "C:\ProgramData\VMware\VMware Workstation\Uninstaller\"
Task: {D631C84D-72B5-4610-BAC1-BC8C16019B0B} - System32\Tasks\{9D75CAD4-ACCA-428A-898E-FB5642AE9E49} => C:\Windows\system32\pcalua.exe -a "E:\Programy\Sterowniki hp 6930\sp44789.exe" -d "E:\Programy\Sterowniki hp 6930"
S3 TKFsAvM; C:\Windows\system32\TKFsAv.sys [232592 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== UWAGA
S3 TKFsFtM; C:\Windows\system32\TKFsFt.sys [25848 2018-03-07] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== UWAGA
S3 TKPcFt; C:\Windows\system32\TKPcFtHk.sys [63272 2018-01-30] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== UWAGA
S3 TKRgAc; C:\Windows\system32\TKRgAc2k.sys [134384 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== UWAGA
S3 TKRgFt; C:\Windows\system32\TKRgFtXp.sys [96552 2018-02-04] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== UWAGA
S3 TKSP; C:\Windows\system32\TKSPxp.sys [106368 2018-01-29] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.) <==== UWAGA
S3 catchme; \??\C:\Users\admin\AppData\Local\Temp\catchme.sys [X] <==== UWAGA
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x32.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2019-08-14 16:58 - 2019-08-14 16:58 - 000025610 _____ C:\ComboFix.txt
2019-08-14 16:34 - 2019-08-14 16:58 - 000000000 ____D C:\Qoobox
2019-08-14 16:34 - 2011-06-26 08:45 - 000256000 _____ C:\Windows\PEV.exe
2019-08-14 16:34 - 2010-11-07 19:20 - 000208896 _____ C:\Windows\MBR.exe
2019-08-14 16:34 - 2009-04-20 06:56 - 000060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2019-08-14 16:34 - 2000-08-31 02:00 - 000518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2019-08-14 16:34 - 2000-08-31 02:00 - 000406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2019-08-14 16:34 - 2000-08-31 02:00 - 000098816 _____ C:\Windows\sed.exe
2019-08-14 16:34 - 2000-08-31 02:00 - 000080412 _____ C:\Windows\grep.exe
2019-08-14 16:34 - 2000-08-31 02:00 - 000068096 _____ C:\Windows\zip.exe
2019-08-06 16:00 - 2019-08-06 16:00 - 000005054 _____ C:\ProgramData\ogqnaqsv.zyj
2019-08-04 15:13 - 2019-08-04 15:13 - 000000000 _____ C:\TKSPProtectLog.txt
2019-08-04 15:09 - 2019-08-04 15:09 - 000000000 ____D C:\ProgramData\TACHYON
2019-08-04 15:08 - 2019-08-04 15:14 - 000000000 ____D C:\Program Files\TACHYON
2019-08-04 15:06 - 2019-08-04 15:06 - 000000000 ____D C:\ProgramData\{9CC8DE87-6A1D-A00D-6577-8E2C6590D77D}
2019-08-04 15:06 - 2019-08-04 15:06 - 000000000 ____D C:\ProgramData\{761C4BAC-FF36-4AD9-4EE2-5AC64E050397}
2019-08-04 15:06 - 2019-08-04 15:06 - 000000000 ____D C:\ProgramData\{576D4237-F6AD-6BA8-D5EB-2BE7D50C72B6}
2019-08-04 15:06 - 2019-08-04 15:06 - 000000000 ____D C:\ProgramData\{55F05470-E0EA-6935-92FD-B6E5921AEFB4}
2019-08-04 15:06 - 2019-08-04 15:06 - 000000000 ____D C:\ProgramData\{446C91D0-254A-78A9-3238-2AF432DF73A5}
2019-08-04 15:06 - 2019-08-04 15:06 - 000000000 ____D C:\ProgramData\{2C6842EE-F674-10AD-0CEB-2E9C0C0C77CD}
2018-12-16 20:44 - 2018-12-16 20:44 - 000000000 _____ () C:\Users\admin\AppData\Local\AtStart.txt
2018-12-16 20:44 - 2018-12-16 20:44 - 000000000 _____ () C:\Users\admin\AppData\Local\DSwitch.txt
2018-12-16 20:44 - 2018-12-16 20:44 - 000000000 _____ () C:\Users\admin\AppData\Local\QSwitch.txt
Po wykonaniu zamiesc nowe logi z FRST, ze skanownia.