
Wiadomo o co chodzi, bardzo proszę o rozwiązanie mojego problemu bo popadam w depresję.
Załączniki w załącznikach

SpyHunter 4 (HKLM\...\SpyHunter) (Version: 4.19.13.4482 - Enigma Software Group, LLC)
Task: C:\WINDOWS\Tasks\VfNxGDQuMTNKHR.job => C:\Documents and Settings\Adek\Dane aplikacji\VfNxGDQuMTNKHR.exe
Task: C:\WINDOWS\Tasks\winter_web_notification_service.job => C:\Documents and Settings\Adek\Ustawienia lokalne\Dane aplikacji\winter web\winter_web_notification_service.exeć/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='winter web' /appid='73143' /srcid='2913' /bic='0b45d8ed53a4d8aa90664a8e6608fe6a' /verifier='b1d922d7143914bc9f0e277a1d48d6bd' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif
Task: C:\WINDOWS\Tasks\winter_web_updating_service.job => C:\Documents and Settings\Adek\Ustawienia lokalne\Dane aplikacji\winter web\winter_web_updating_service.exe« /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=winter_web_updating_service /funurl=http:/stats.buildomserv.com
HKU\S-1-5-21-1645522239-1409082233-725345543-1003\Software\Classes\.exe: exefile => <===== ATTENTION!
HKU\S-1-5-21-1645522239-1409082233-725345543-1003\Software\Classes\exefile: <===== ATTENTION!
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
HKLM\...\Run: [tuto4pc_pl_5] => [X]
HKLM\...\Run: [SpyHunter Security Suite] => C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
C:\Program Files\Enigma Software Group
Winlogon\Notify\TPSvc: TPSvc.dll [X]
HKU\S-1-5-21-1645522239-1409082233-725345543-1003\...\MountPoints2: {fc0f6c76-73b0-11e2-9a11-d89f561a7f7b} - D:\nbuq.pif
D:\nbuq.pif
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1645522239-1409082233-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
S2 szserver; "C:\Program Files\STOPzilla!\SZServer.exe" [X]
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys
C:\WINDOWS\System32\DRIVERS\EsgScanner.sys
S1 AmdPPM; system32\DRIVERS\AmdPPM.sys [X]
S3 NTIOLib_1_0_C; \??\F:\NTIOLib.sys [X]
S1 sbaphd; system32\drivers\sbaphd.sys [X]
S2 sbapifs; system32\drivers\sbapifs.sys [X]
S0 szkgfs; system32\drivers\szkgfs.sys [X]
C:\sh4ldr
C:\Documents and Settings\Adek\Dane aplikacji\Enigma Software Group
C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7
C:\WINDOWS\Tasks\VfNxGDQuMTNKHR.job
C:\WINDOWS\Tasks\winter_web_notification_service.job
C:\WINDOWS\Tasks\winter_web_updating_service.job
C:\Documents and Settings\Adek\Ustawienia lokalne\Dane aplikacji\winter web
C:\Documents and Settings\Adek\Dane aplikacji\VfNxGDQuMTNKHR
Shortcut: C:\Documents and Settings\Adek\Start Menu\Programs\SpyHunter\SpyHunter.lnk -> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
Shortcut: C:\Documents and Settings\Adek\Desktop\SpyHunter.lnk -> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.)
ShortcutWithArgument: C:\Documents and Settings\Adek\Start Menu\Programs\SpyHunter\SpyHunter Emergency Startup.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.com"
ShortcutWithArgument: C:\Documents and Settings\Adek\Start Menu\Programs\SpyHunter\Uninstall.lnk -> C:\Documents and Settings\Adek\Dane aplikacji\Enigma Software Group\sh_installer.exe (Enigma Software Group USA, LLC.) -> -r sh
EmptyTemp:
S2 NvUpdSrv; C:\Program Files\NVIDIA Corporation\Updates\NvdUpd.exe [108544 2015-04-02] () [File not signed]
C:\Program Files\NVIDIA Corporation\Updates\NvdUpd.exe
EmptyTemp:
O co tu chodzi, ze w kazdym podobnym problemie na forum widze jeden tekst do wklejenia w notepadzie i wszyscy dziekują za rozwiazanie problemu a Ty mi moj drogi przyjacielu podajesz setki jakichs tekstow i nic to nie daje?
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 5 gości