Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 12.05.2018
- Uruchomiony przez void (16-05-2018 19:35:10) Run:2
- Uruchomiony z C:\Users\shitter\Desktop
- Załadowane profile: void (Dostępne profile: void & Administrator)
- Tryb startu: Normal
- ==============================================
- fixlist - zawartość:
- *****************
- CloseProcesses:
- CreateRestorePoint:
- EmptyTemp:
- VirusTotal: C:\ProgramData\msbftbgnm.exe
- HKLM-x32\...\RunOnce: [] => [X]
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\Policies\Explorer: []
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {478ab8c4-e05d-11e7-be88-b8763f9fdb8e} - "G:\Setup.exe"
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {487e5227-cef4-11e6-be8c-b8763f9fdb8e} - "F:\autorun.exe"
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {c853757c-0361-11e8-be88-b8763f9fdb8e} - "H:\autorun.exe"
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\...\MountPoints2: {c8537587-0361-11e8-be88-b8763f9fdb8e} - "H:\autorun.exe"
- Tcpip\..\Interfaces\{3B79996C-3219-4CC1-8163-8D6C46D62BC6}: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{76E471E9-3FCC-4313-81F1-B79177EA5F48}: [DhcpNameServer] 212.87.0.72 193.0.71.130
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com?pc=HPNTDFJS
- Toolbar: HKU\S-1-5-21-3145501433-2751271693-2052433869-1001 -> Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Brak pliku
- ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => -> Brak pliku
- Task: {3439DF23-41E5-4315-9359-3E617B4FCCF9} - System32\Tasks\{F2C41152-7938-4D07-A213-B8D3B6664DB4} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\setup.exe" -c /z-uninstall
- Startup: C:\Users\shitter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk [2017-11-09]
- ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
- Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
- *****************
- Procesy zostały pomyślnie zamknięte.
- Punkt przywracania został pomyślnie utworzony.
- VirusTotal: C:\ProgramData\msbftbgnm.exe => D41D8CD98F00B204E9800998ECF8427E (0-byte MD5)
- "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\" => pomyślnie usunięto
- "HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => pomyślnie usunięto
- "HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{478ab8c4-e05d-11e7-be88-b8763f9fdb8e}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{478ab8c4-e05d-11e7-be88-b8763f9fdb8e} => nie znaleziono
- "HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{487e5227-cef4-11e6-be8c-b8763f9fdb8e}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{487e5227-cef4-11e6-be8c-b8763f9fdb8e} => nie znaleziono
- "HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c853757c-0361-11e8-be88-b8763f9fdb8e}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{c853757c-0361-11e8-be88-b8763f9fdb8e} => nie znaleziono
- "HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c8537587-0361-11e8-be88-b8763f9fdb8e}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{c8537587-0361-11e8-be88-b8763f9fdb8e} => nie znaleziono
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3B79996C-3219-4CC1-8163-8D6C46D62BC6}\\DhcpNameServer" => pomyślnie usunięto
- "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{76E471E9-3FCC-4313-81F1-B79177EA5F48}\\DhcpNameServer" => pomyślnie usunięto
- HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono
- HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono
- "HKU\S-1-5-21-3145501433-2751271693-2052433869-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => nie znaleziono
- "HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\PDFCreator.ShellContextMenu" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{d9cea52e-100d-4159-89ea-76e845bc13e1} => nie znaleziono
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3439DF23-41E5-4315-9359-3E617B4FCCF9}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3439DF23-41E5-4315-9359-3E617B4FCCF9}" => pomyślnie usunięto
- C:\Windows\System32\Tasks\{F2C41152-7938-4D07-A213-B8D3B6664DB4} => pomyślnie przeniesiono
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F2C41152-7938-4D07-A213-B8D3B6664DB4}" => pomyślnie usunięto
- C:\Users\shitter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk => pomyślnie przeniesiono
- C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE => pomyślnie przeniesiono
- ========= wevtutil el | Foreach-Object {wevtutil cl "$_"} =========
- ========= Koniec Powershell: =========
- =========== EmptyTemp: ==========
- BITS transfer queue => 8388608 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9686590 B
- Java, Flash, Steam htmlcache => 0 B
- Windows/system/drivers => 1878129 B
- Edge => 0 B
- Chrome => 0 B
- Firefox => 15799402 B
- Opera => 395784626 B
- Temp, IE cache, history, cookies, recent:
- Default => 0 B
- Users => 0 B
- ProgramData => 0 B
- Public => 0 B
- systemprofile => 0 B
- systemprofile32 => 128 B
- LocalService => 1386 B
- NetworkService => 0 B
- shitter => 7608831 B
- Administrator => 0 B
- RecycleBin => 544 B
- EmptyTemp: => 418.8 MB danych tymczasowych Usunięto.
- ================================
- System wymagał restartu.
- ==== Koniec Fixlog 19:37:23 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement