Jak widac usluge masz i jest nawet uruchomiona. Windows Update zepsula Ci infekcja.
Masz popsute uslugi zwiazane z WU + blokada w rejestrze.
Napisales w zlym dziale.
Zrob skan przy pomocy mbam i usun to co wykryje.
W FRST nacisnij ctrl+y, do okna notatnika wklej:
CloseProcesses:
AV: AVG Antivirus (Enabled - Up to date) {4FC75CA5-1654-5411-7CFB-1893D506BCF4}
BHO: Brak nazwy -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> Brak pliku
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706344 2021-06-09] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Ograniczenia <==== UWAGA
HKU\S-1-5-21-3405622378-2249436035-1226526367-1001\...\Run: [ProductAuthenticationService] => C:\Users\pc\AppData\Roaming\ProductAuthenticationService\pas.exe [1003024 2021-08-25] (DVJ LIMITED -> DVJ LIMITED) <==== UWAGA
HKU\S-1-5-21-3405622378-2249436035-1226526367-1001\...\Run: [MicrosoftEdgeAutoLaunch_72FC07CE8FBC282A90F28F3BD5668C8E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3795360 2022-09-08] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3405622378-2249436035-1226526367-1001\...\MountPoints2: {601ce881-d21a-11e9-aef2-000e2e4812d7} - "G:\setup.exe"
Policies: C:\ProgramData\NTUSER.pol: Ograniczenia <==== UWAGA
Task: {4B760A2A-B329-42C7-8A6B-B89B8F268B66} - System32\Tasks\Ultimate Eraser Update Task-S-1-5-21-3405622378-2249436035-1226526367-1001 => "%WINDIR%\System32\msiexec.exe" /i "C:\Users\pc\AppData\Local\Programs\asevcuk865\dcc8b5750b.msi" /quiet CHROME=1
C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb
CHR Extension: (Safe Torrent Scanner) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2022-06-15]
C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhgjfmdjomnlhfacokoibjlcmcmgoec
CHR Extension: (Google Slides Offline) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhgjfmdjomnlhfacokoibjlcmcmgoec [2022-09-11] [UpdateUrl:hxxps://clients64.google.com/service/update2/crx] <==== UWAGA
C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkojhcnbjmmecmhbjnobopbbplmhfme
CHR Extension: (FasTube - Faster YouTube) - C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkojhcnbjmmecmhbjnobopbbplmhfme [2019-09-09]
CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [hkmfdialkjnljbcnincgpollobclebaf]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
C:\Users\pc\AppData\Roaming\Opera Software\Opera Stable\Extensions\ioipkkmonpmomecbmggejienahinjkjj
OPR Extension: (Adblocker for Youtube™) - C:\Users\pc\AppData\Roaming\Opera Software\Opera Stable\Extensions\ioipkkmonpmomecbmggejienahinjkjj [2022-09-11]
S3 dosvc; C:\WINDOWS\System32\svchost.exe [55320 2022-07-18] (Microsoft Windows Publisher -> Microsoft Corporation) <==== UWAGA (Brak ServiceDLL)
S3 dosvc; C:\WINDOWS\SysWOW64\svchost.exe [46504 2022-07-18] (Microsoft Windows Publisher -> Microsoft Corporation) <==== UWAGA (Brak ServiceDLL)
S2 UsoSvc; C:\WINDOWS\system32\svchost.exe [55320 2022-07-18] (Microsoft Windows Publisher -> Microsoft Corporation) <==== UWAGA (Brak ServiceDLL)
S2 UsoSvc; C:\WINDOWS\SysWOW64\svchost.exe [46504 2022-07-18] (Microsoft Windows Publisher -> Microsoft Corporation) <==== UWAGA (Brak ServiceDLL)
U4 napagent; Brak ImagePath
2022-09-11 12:17 - 2022-09-11 12:47 - 000000004 _____ C:\ProgramData\rc.dat
2022-09-11 12:16 - 2022-09-11 12:50 - 000000020 _____ C:\ProgramData\lir.bats
2022-09-11 12:16 - 2022-09-11 12:50 - 000000004 _____ C:\ProgramData\lock.dat
2022-09-11 12:16 - 2022-09-11 12:16 - 000000008 _____ C:\ProgramData\ts.dat
2022-09-11 12:14 - 2022-09-11 12:15 - 000000000 ____D C:\AdwCleaner
2022-09-11 12:08 - 2022-09-11 13:01 - 000000000 ____D C:\Program Files (x86)\yeRQgBGSMBHU2
2022-09-11 12:08 - 2022-09-11 13:01 - 000000000 ____D C:\Program Files (x86)\xdRAhPwTjDdnMzyIvpR
2022-09-11 12:08 - 2022-09-11 13:01 - 000000000 ____D C:\Program Files (x86)\NVmdYDkqRZykC
2022-09-11 12:08 - 2022-09-11 13:01 - 000000000 ____D C:\Program Files (x86)\MHFgJiABkFUn
2022-09-11 12:08 - 2022-09-11 13:01 - 000000000 ____D C:\Program Files (x86)\dEugwkTrU
2022-09-11 12:08 - 2022-09-11 12:08 - 000000000 _____ C:\ProgramData\90691652701502315262.exe
2022-09-11 12:07 - 2022-09-11 12:07 - 000000000 ____D C:\Program Files\Platform
2022-09-11 12:07 - 2022-09-11 12:07 - 000000000 _____ C:\Users\pc\AppData\Roaming\EB9.tmp
2022-09-11 12:06 - 2022-09-12 07:41 - 000000000 ____D C:\Users\pc\AppData\Roaming\EBpJV2
2022-09-11 12:06 - 2022-09-12 07:41 - 000000000 ____D C:\Users\pc\AppData\Roaming\0oL5fX9fi
2022-09-11 12:06 - 2022-09-11 13:01 - 000000000 ____D C:\Users\pc\AppData\Roaming\toc
2022-09-11 12:06 - 2022-09-11 13:01 - 000000000 ____D C:\Users\pc\AppData\Roaming\mvOOoX4hQDX
2022-09-11 12:06 - 2022-09-11 12:50 - 000000000 ____D C:\ProgramData\DiskOptimizer
2022-09-11 12:06 - 2022-09-11 12:08 - 000000000 ____D C:\Users\pc\AppData\Roaming\42uBUX
2022-09-11 12:06 - 2022-09-11 12:07 - 000000000 ____D C:\Program Files (x86)\Floppy Disk Master
2022-09-11 12:06 - 2022-09-11 12:06 - 000684984 _____ (Mozilla Foundation) C:\Users\pc\AppData\LocalLow\freebl3.dll
2022-09-11 12:06 - 2022-09-11 12:06 - 000627128 _____ (Mozilla Foundation) C:\Users\pc\AppData\LocalLow\mozglue.dll
2022-09-11 12:06 - 2022-09-11 12:06 - 000254392 _____ (Mozilla Foundation) C:\Users\pc\AppData\LocalLow\softokn3.dll
2022-09-11 12:06 - 2022-09-11 12:06 - 000004162 _____ C:\WINDOWS\system32\Tasks\Ultimate Eraser Update Task-S-1-5-21-3405622378-2249436035-1226526367-1001
2022-09-11 12:06 - 2022-09-11 12:06 - 000000000 ____D C:\Users\pc\AppData\Local\Package Cache
2022-09-11 12:06 - 2022-09-11 12:06 - 000000000 ____D C:\Program Files (x86)\Exfe E. Ronie
2022-09-11 12:06 - 2022-09-11 12:06 - 000000000 ____D C:\Program Files (x86)\Acgbyte
2022-09-11 12:08 - 2022-09-11 12:08 - 000000000 _____ () C:\ProgramData\90691652701502315262.exe
2022-09-11 12:16 - 2022-09-11 12:50 - 000000004 _____ () C:\ProgramData\lock.dat
2022-09-11 12:17 - 2022-09-11 12:47 - 000000004 _____ () C:\ProgramData\rc.dat
2022-09-11 12:16 - 2022-09-11 12:16 - 000000008 _____ () C:\ProgramData\ts.dat
2022-09-11 12:07 - 2022-09-11 12:07 - 000000000 _____ () C:\Users\pc\AppData\Roaming\EB9.tmp
Nacisnij ctrl+s i w FRST wybierz Napraw.
Po wykonaniu sprawdz czy Windows Update dziala, jezeli nie to sciagnij i uruchom:
https://www.tenforums.com/attachments/tutoria...-windows-10-a-update_orchestrator_service.reg
https://www.tenforums.com/attachments/tutoria...rvices-windows-10-a-delivery_optimization.reg