Tak v nouzovém režimu to spustit šlo. Po skenu a následném mazání se zdá , že už je vše jako dřív

díky za pomoc
AdwCleaner 7.0.0.0 - Logfile created on Mon Jul 31 14:09:00 2017
# Updated on 2017/17/07 by Malwarebytes
# Database: 07-16-2017.1
# Running on Windows 10 Pro (X64)
# Mode: scan
# Support:
https://www.malwarebytes.com/support
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
PUP.Optional.Legacy, C:\Users\Public\Documents\XMUpdate
Adware.OnlineIO, C:\ProgramData\Microleaves
Adware.OnlineIO, C:\Program Files (x86)\Microleaves
Adware.OnlineIO, C:\Users\All Users\Microleaves
PUP.Optional.MagicDisk, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mgdisk
PUP.Optional.MagicDisk, C:\Program Files (x86)\mgdisk
PUP.Optional.SystemHealer, C:\Program Files (x86)\SystemHealer
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group
PUP.Optional.SpyHunter, C:\Users\koko\AppData\Roaming\Enigma Software Group
PUP.Optional.SpyHunter, C:\sh4ldr
PUP.Optional.PCCleanPlus, C:\Program Files (x86)\pccleanplus
PUP.Adware.Heuristic, C:/ProgramData\47a8dbda
PUP.Adware.Heuristic, C:/ProgramData\5c174926-00c1-1
PUP.Adware.Heuristic, C:/ProgramData\5c174926-2531-0
PUP.Adware.Heuristic, C:/ProgramData\8d1314e1-2481-1
PUP.Adware.Heuristic, C:/ProgramData\8d1314e1-6705-0
PUP.Adware.Heuristic, C:/ProgramData\{26746d22-212c-1}
PUP.Adware.Heuristic, C:/ProgramData\{55e0299c-512c-0}
PUP.Adware.Heuristic, C:/ProgramData\{5f85583c-112c-1}
PUP.Adware.Heuristic, C:/ProgramData\{6ddf451e-512c-0}
***** [ Files ] *****
PUP.Optional.Legacy, C:\Users\koko\Favorites\Mail.Ru.url
PUP.Optional.Legacy, C:\Users\koko\appdata\local\installationconfiguration.xml
PUP.Optional.Legacy, C:\Users\koko\Favorites\Mail.Ru Агент - используй для общения!.url
PUP.Optional.Legacy, C:\Users\koko\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\UC浏览器.lnk
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
PUP.Optional.Legacy, Online Application V2G1
PUP.Optional.Legacy, Online Application V2G3
PUP.Optional.Legacy, Online Application V2G2
PUP.Optional.OnlineIO, Updater_Online_Application
***** [ Registry ] *****
Adware.Elex, [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER | ENABLESHELLEXECUTEHOOKS
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\
www.yeadesktop.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeadesktop.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\akamaihd.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\cdncache-a.akamaihd.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\akamaihd.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\cdncache-a.akamaihd.net
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\PopWnd
PUP.Optional.Legacy, [Key] - HKCU\Software\PopWnd
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{43769158-3B03-4932-8D8A-8F0F344BF024}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A89A7E3-6ADD-4EF9-8EE7-A3C3B7D83BB0}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
PUP.Optional.Legacy, [Value] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run | YeaDesktop
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
PUP.Optional.Reimage, [Key] - HKLM\SOFTWARE\Reimage
PUP.Optional.YeaDesktop, [Value] - HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION | YeaDesktop.exe
PUP.Optional.YeaDesktop, [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION | YeaDesktop.exe
Adware.FileTour, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Installer
Adware.FileTour, [Key] - HKCU\Software\Installer
Adware.OnlineIO, [Key] - HKLM\SOFTWARE\Microleaves
PUP.Optional.MoneyFriend, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\msaver
PUP.Optional.MoneyFriend, [Key] - HKCU\Software\msaver
PUP.Optional.DiskPower, [Key] - HKLM\SOFTWARE\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb}
PUP.Optional.DiskPower, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb}
PUP.Optional.DiskPower, [Key] - HKCU\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb}
PUP.Optional.SpyHunter, [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
PUP.Optional.WiperSoft, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\WiperSoft
PUP.Optional.WiperSoft, [Key] - HKCU\Software\WiperSoft
PUP.Optional.Yontoo, [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Amigo
PUP.Optional.Yontoo, [Key] - HKCU\Software\Amigo
PUP.Optional.OnlineIO, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries.
*************************
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########
AdwCleaner 7.0.0.0 - Logfile created on Mon Jul 31 14:10:35 2017
# Updated on 2017/17/07 by Malwarebytes
# Running on Windows 10 Pro (X64)
# Mode: clean
# Support:
https://www.malwarebytes.com/support
***** [ Services ] *****
No malicious services deleted.
***** [ Folders ] *****
Deleted: C:\Users\Public\Documents\XMUpdate
Deleted: C:\ProgramData\Microleaves
Deleted: C:\Program Files (x86)\Microleaves
Deleted: C:\Users\All Users\Microleaves
Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mgdisk
Deleted: C:\Program Files (x86)\mgdisk
Deleted: C:\Program Files (x86)\SystemHealer
Deleted: C:\Program Files\Enigma Software Group
Deleted: C:\Users\koko\AppData\Roaming\Enigma Software Group
Deleted: C:\sh4ldr
Deleted: C:\Program Files (x86)\pccleanplus
Deleted: C:/ProgramData\47a8dbda
Deleted: C:/ProgramData\5c174926-00c1-1
Deleted: C:/ProgramData\5c174926-2531-0
Deleted: C:/ProgramData\8d1314e1-2481-1
Deleted: C:/ProgramData\8d1314e1-6705-0
Deleted: C:/ProgramData\{26746d22-212c-1}
Deleted: C:/ProgramData\{55e0299c-512c-0}
Deleted: C:/ProgramData\{5f85583c-112c-1}
Deleted: C:/ProgramData\{6ddf451e-512c-0}
***** [ Files ] *****
Deleted: C:\Users\koko\Favorites\Mail.Ru.url
Deleted: C:\Users\koko\appdata\local\installationconfiguration.xml
Deleted: C:\Users\koko\Favorites\Mail.Ru Агент - используй для общения!.url
Deleted: C:\Users\koko\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\UC浏览器.lnk
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
Deleted: Online Application V2G1
Deleted: Online Application V2G3
Deleted: Online Application V2G2
Deleted: Updater_Online_Application
***** [ Registry ] *****
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ENABLESHELLEXECUTEHOOKS
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\
www.yeadesktop.com
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeadesktop.com
Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\akamaihd.net
Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\cdncache-a.akamaihd.net
Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\akamaihd.net
Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\cdncache-a.akamaihd.net
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\PopWnd
Deleted: [Key] - HKCU\Software\PopWnd
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}
Deleted: [Key] - HKCU\Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
Deleted: [Key] - HKCU\Software\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{3A188115-B81B-48F2-A958-F974C8F3F309}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{43769158-3B03-4932-8D8A-8F0F344BF024}
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A89A7E3-6ADD-4EF9-8EE7-A3C3B7D83BB0}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
Deleted: [Value] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|YeaDesktop
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\SMBarBroker.EXE
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
Deleted: [Key] - HKLM\SOFTWARE\Reimage
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|YeaDesktop.exe
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|YeaDesktop.exe
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Installer
Deleted: [Key] - HKCU\Software\Installer
Deleted: [Key] - HKLM\SOFTWARE\Microleaves
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\msaver
Deleted: [Key] - HKCU\Software\msaver
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb}
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb}
Deleted: [Key] - HKCU\Software\Microsoft\{6711eba6-cf08-4edw-9528-86004fa424bb}
Deleted: [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\WiperSoft
Deleted: [Key] - HKCU\Software\WiperSoft
Deleted: [Key] - HKU\S-1-5-21-1568842524-76667080-1656113233-1000\Software\Amigo
Deleted: [Key] - HKCU\Software\Amigo
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\UCHTML
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries deleted.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries deleted.
*************************
::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0
*************************
C:/AdwCleaner/AdwCleaner[S0].txt - [7685 B] - [2017/7/31 14:9:0]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########