tak mbam našel:
Processes: 2
PUP.Optional.NetworkUpdate.A, C:\Windows\SysWOW64\nethtsrv.exe, 1800, Delete-on-Reboot, [8b302159e2992c0a8a81b2f3c63c768a]
PUP.Optional.NetworkUpdate.A, C:\Windows\SysWOW64\netupdsrv.exe, 2552, Delete-on-Reboot, [d2e91e5c215aab8b10fc2382a2600000]
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nethfdrv, Quarantined, [7447d9a14a313ef802082f7638caa060],
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NetHttpServ ice, Quarantined, [8b302159e2992c0a8a81b2f3c63c768a],
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ServiceUpda ter, Quarantined, [d2e91e5c215aab8b10fc2382a2600000],
Registry Values: 2
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NETHTTPSERV ICE|ImagePath, C:\Windows\SysWOW64\nethtsrv.exe, Quarantined, [f2c95a2095e61125dd087d80e91ad12f]
PUP.Optional.NetworkUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SERVICEUPDA TER|ImagePath, C:\Windows\SysWOW64\netupdsrv.exe, Quarantined, [c2f9daa0e5961a1cd1157a83ed16b24e]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 4
PUP.Optional.Amonetize.A, C:\Users\JiA?A\AppData\Local\15387\a30278.exe, Quarantined, [f7c4fc7e52292610254775cef30d1fe1],
PUP.Optional.NetworkUpdate.A, C:\Windows\System32\drivers\nethfdrv.sys, Quarantined, [7447d9a14a313ef802082f7638caa060],
PUP.Optional.NetworkUpdate.A, C:\Windows\SysWOW64\nethtsrv.exe, Delete-on-Reboot, [8b302159e2992c0a8a81b2f3c63c768a],
PUP.Optional.NetworkUpdate.A, C:\Windows\SysWOW64\netupdsrv.exe, Delete-on-Reboot, [d2e91e5c215aab8b10fc2382a2600000],
Physical Sectors: 0
(No malicious items detected)