W logach nie widzę niczego podejrzanego.
Kosmetyka:
Otwórz Notatnik i wklej w nim:
S3 cpuz135; \??\C:\Users\tomek\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
S3 WinRing0_1_2_0; \??\E:\Game Booster 3\Driver\WinRing0x64.sys [X]
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
C:\Users\tomek\AppData\Roaming\CamLayout.ini
C:\Users\tomek\AppData\Roaming\CamShapes.ini
C:\Users\tomek\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\tomek\AppData\Local\Temp\Foxit Updater.exe
C:\Users\tomek\AppData\Local\Temp\ggdrive-menu.exe
C:\Users\tomek\AppData\Local\Temp\ggdrive-overlay.exe
C:\Users\tomek\AppData\Local\Temp\installstats.exe
MSCONFIG\startupreg: Sweetpacks Communicator => C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
C:\Program Files (x86)\SweetIM
MSCONFIG\startupreg: SweetIM => C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
Reboot:
Plik zapisz pod nazwą fixlist.txt i umieść obok narzędzia FRST. Uruchom FRST i kliknij w Fix. P
F.