Odinstaluj:
McAfee WebAdvisor
YTD Video Downloader 5.9.9
Wykonaj Fixlist.txt dla FRST:
CloseProcesses:
Task: {049BFDC4-0409-4F19-86EB-6FEFF1B5FE57} - Brak ścieżki do pliku
Task: {2BD810E3-7A09-4A78-84FD-49743A5F1CEA} - System32\Tasks\Opera scheduled Autoupdate 1535121462 => C:\Users\Master\AppData\Local\Programs\Opera\launcher.exe [2018-09-13] (Opera Software)
Task: {4363F607-9E97-43F2-A068-F3E4CC8D11B6} - System32\Tasks\Opera scheduled Autoupdate 1527868626 => C:\Users\Master\AppData\Local\Programs\Opera\launcher.exe [2018-09-13] (Opera Software)
Task: {A6A0FFCB-99AF-4024-A4B2-17C35107DB9F} - Brak ścieżki do pliku
Task: {B0571D6E-11CC-495D-BF1C-AFD7CB355CAA} - System32\Tasks\Opera scheduled Autoupdate 1536941049 => C:\Users\Master\AppData\Local\Programs\Opera\launcher.exe [2018-09-13] (Opera Software)
Task: {C457A2E0-73CF-49BE-81E4-9D3724273D97} - \Microsoft\Windows\Media Center\PBDADiscoveryW1 -> Brak pliku C:\Users\Master\AppData\Local\Programs\Opera\launcher.exe [2018-09-13] (Opera Software)
2018-07-30 11:47 - 2018-06-06 00:22 - 002117632 ___SH () C:\Users\Master\AppData\Roaming\w73pU7LIC084W7K8\zXNxJ7epZqE6.exe
AlternateDataStreams: C:\ProgramData:NT [40]
AlternateDataStreams: C:\ProgramData:NT2 [432]
AlternateDataStreams: C:\Users\All Users:NT [40]
AlternateDataStreams: C:\Users\All Users:NT2 [432]
AlternateDataStreams: C:\ProgramData\Application Data:NT [40]
AlternateDataStreams: C:\ProgramData\Application Data:NT2 [432]
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT [40]
AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2 [432]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [432]
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F [134]
AlternateDataStreams: C:\ProgramData\TEMP:F6C0CA66 [114]
AlternateDataStreams: C:\Users\Master\Dane aplikacji:NT [40]
AlternateDataStreams: C:\Users\Master\Dane aplikacji:NT2 [432]
AlternateDataStreams: C:\Users\Master\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\Master\AppData\Roaming:NT2 [432]
AlternateDataStreams: C:\Users\Public\AppData:CSM [474]
() C:\Users\Master\AppData\Roaming\w73pU7LIC084W7K8\zXNxJ7epZqE6.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(GreenTree Applications SRL) C:\Program Files (x86)\GreenTree Applications\YTD Video Downloader\ytd.exe
HKU\S-1-5-21-2340840887-376378962-1285225641-1000\...\Winlogon: [Shell] "C:\Users\Master\AppData\Roaming\w73pU7LIC084W7K8\zXNxJ7epZqE6.exe",explorer.exe {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-07-17] (McAfee, Inc.)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-07-17] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-07-17] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-07-17] (McAfee, Inc.)
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Brak pliku
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [2018-05-15]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
CHR DefaultSearchURL: Default -> hxxps://pandasecurity.mystart.com/results.php?pr=vmn&id=pandasafeweb&v=1_0_chromeextension_unknown__&searchfeed=web&hsimp=yhs-panda1&ent=ch_ss&q={searchTerms}
CHR DefaultSearchKeyword: Default -> safeWeb
CHR HKLM\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [604824 2018-07-17] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X]
S3 NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [X]
S1 UimBus; system32\DRIVERS\uimbus.sys [X]
S1 Uim_DEVIM; system32\DRIVERS\uimdevim.sys [X]
2018-09-09 21:06 - 2018-09-09 21:06 - 000000000 __SHD C:\found.006
2018-08-31 08:36 - 2018-08-31 08:36 - 000000000 __SHD C:\found.005
C:\Users\Master\AppData\Roaming\w73pU7LIC084W7K8\
Po wykonaniu usun katalog C:\FRST.
Uzyj AdwCleaner, opcja Scan/Szukaj i Clean/Usun:
http://www.bleepingcomputer.com/download/adwcleaner/
Zrob pelny skan przy pomocy Mbam i usun to co wykryje:
http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/