Uruchom FRST. NA klawiaturze naciśnij jednocześnie
CTRL+
Y.Otworzy się Notatnik - wklej do niego:
HKLM\...\Run: [JServicesManager] => C:\Program Files\SystemNanoPacks\Nano Service Pack\nano.ex
RemoveDirectory: C:\Program Files\SystemNanoPacks
HKLM-x32\...\Run: [JServicesManager] => C:\Program Files\SystemNanoPacks\Nano Service Pack\nano.ex
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
S3 NanoServicePackUpdate64; C:\Program Files\SystemNanoPacks\Nano Service Pack\NanoServicePackUpdater.exe [594432 2018-07-22] (SystemNanoPacks) [Brak podpisu cyfrowego]
C:\Users\Jarecki\Downloads\zszlpmtzze.txt
C:\Users\Jarecki\Downloads\xnhhuikxjnhpy.txt
C:\Users\Jarecki\Downloads\wrsjnjfkzmxubl.txt
C:\WINDOWS\System32\Tasks\NanoPackUpdate_6.0.1
RemoveDirectory: C:\ProgramData\SystemNanoPacks
Nano Service Pack (HKLM\...\{46100BDA-DC4C-4B20-BD54-33095057AEC5}) (Version: 6.0.1 - SystemNanoPacks) Hidden
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{46100BDA-DC4C-4B20-BD54-33095057AEC5}
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{46100BDA-DC4C-4B20-BD54-33095057AEC5}
Task: {213DE322-1DD2-4808-9BCB-301F6DE8CDCF} - System32\Tasks\AppLoaderHelpers => C:\Program Files\SystemNanoPacks\Nano Service Pack\nano.exe [2018-07-17] ()
Task: {2D51B051-B6CF-46FF-B2AF-B1E262F12AD0} - \NanoPackTask -> Brak pliku <==== UWAGA
Task: {69B3F87F-4BE7-4F9D-AC45-FA4A3CE0C575} - System32\Tasks\NanoPackUpdate_6.0.1 => C:\Program Files\SystemNanoPacks\Nano Service Pack\NanoServicePackUpdater.exe [2018-07-22] (SystemNanoPacks)
Task: {D1EFBF58-758A-4A06-BDAF-C5757741FF03} - System32\Tasks\AppLoaderPM => C:\Program Files\SystemNanoPacks\Nano Service Pack\nano.exe [2018-07-17] ()
HKLM\...\StartupApproved\Run: => "JServicesManager"
HKLM\...\StartupApproved\Run32: => "JServicesManager"
FirewallRules: [{2F086439-1CA9-4F42-9449-74BAD2AADEA8}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{171A8328-DE18-4284-89C7-80C84EAA2F39}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{37ECBF41-BA07-447B-8691-A14A422EA113}] => (Allow) C:\Windows\System32\rundll32.exe
HOSTS:
EmptyTemp:
Na klawiaturze naciśnij jednocześnie
CTRL+
S. W FRST kliknij na Fix (NAPRA.W).
F