Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 02.08.2018
- Uruchomiony przez mike (07-08-2018 19:40:13) Run:1
- Uruchomiony z C:\Users\mike\Downloads
- Załadowane profile: mike (Dostępne profile: defaultuser0 & mike)
- Tryb startu: Normal
- ==============================================
- fixlist - zawartość:
- *****************
- CloseProcesses:
- CreateRestorePoint:
- EmptyTemp:
- VirusTotal: C:\Users\mike\Downloads\a7ykymh6.exe
- CustomCLSID: HKU\S-1-5-21-3813753414-3908090346-2982434286-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-A94103D4E3CC}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => Brak pliku
- ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll -> Brak pliku
- ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Brak pliku
- ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku
- ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> Brak pliku
- Task: {FFDA825A-3849-46D2-9015-AB5DE0937BC0} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.gmx.com/start?src=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09
- HKU\S-1-5-21-3813753414-3908090346-2982434286-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.gmx.com/start?src=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09
- SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.gmx.com/web/result?origin=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09&q={searchTerms}
- SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.gmx.com/web/result?origin=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09&q={searchTerms}
- SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.gmx.com/web/result?origin=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09&q={searchTerms}
- SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.gmx.com/web/result?origin=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-3813753414-3908090346-2982434286-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.gmx.com/web/result?origin=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-3813753414-3908090346-2982434286-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://search.gmx.com/web/result?origin=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=pl&p_tsrc=301ssg02&p_w=y1w09&q={searchTerms}
- CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <nie znaleziono>
- CHR HKLM-x32\...\Chrome\Extension: [ofoeigeaodhbjogdigckajfhjbonaofg] - hxxps://clients2.google.com/service/update2/crx
- HKLM\SYSTEM\CurrentControlSet\Services\45837DE3BA5D8900 <==== UWAGA (Rootkit!)
- C:\Users\mike\Downloads\a7ykymh6.exe
- *****************
- Procesy zostały pomyślnie zamknięte.
- Błąd: (0) Nie udało się utworzyć punktu przywracania.
- VirusTotal: C:\Users\mike\Downloads\a7ykymh6.exe => D41D8CD98F00B204E9800998ECF8427E (0-byte MD5)
- "HKU\S-1-5-21-3813753414-3908090346-2982434286-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-A94103D4E3CC}" => pomyślnie usunięto
- "HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Cover Designer" => pomyślnie usunięto
- "HKLM\Software\Wow6432Node\Classes\CLSID\{73FCA462-9BD5-4065-A73F-A8E5F6904EF7}" => pomyślnie usunięto
- "HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PowerISO" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => nie znaleziono
- "HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => nie znaleziono
- "HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PowerISO" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => nie znaleziono
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FFDA825A-3849-46D2-9015-AB5DE0937BC0}" => pomyślnie usunięto
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFDA825A-3849-46D2-9015-AB5DE0937BC0}" => pomyślnie usunięto
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => nie znaleziono
- HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono
- HKU\S-1-5-21-3813753414-3908090346-2982434286-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono
- "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => nie znaleziono
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => pomyślnie usunięto
- HKLM\Software\Wow6432Node\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => nie znaleziono
- "HKU\S-1-5-21-3813753414-3908090346-2982434286-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => pomyślnie usunięto
- "HKU\S-1-5-21-3813753414-3908090346-2982434286-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => pomyślnie usunięto
- HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => nie znaleziono
- "HKLM\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek" => pomyślnie usunięto
- "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ofoeigeaodhbjogdigckajfhjbonaofg" => pomyślnie usunięto
- HKLM\SYSTEM\CurrentControlSet\Services\45837DE3BA5D8900 <==== UWAGA (Rootkit!) => Błąd: Nie znaleziono automatycznej naprawy dla tego wejścia.
- C:\Users\mike\Downloads\a7ykymh6.exe => pomyślnie przeniesiono
- =========== EmptyTemp: ==========
- BITS transfer queue => 6053888 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 13080112 B
- Java, Flash, Steam htmlcache => 71605247 B
- Windows/system/drivers => 671795 B
- Edge => 2426649 B
- Chrome => 0 B
- Firefox => 390216971 B
- Opera => 0 B
- Temp, IE cache, history, cookies, recent:
- Default => 6656 B
- Users => 0 B
- ProgramData => 0 B
- Public => 0 B
- systemprofile => 0 B
- systemprofile32 => 0 B
- LocalService => 0 B
- LocalService => 0 B
- NetworkService => 0 B
- NetworkService => 0 B
- defaultuser0 => 0 B
- mike => 212471324 B
- RecycleBin => 0 B
- EmptyTemp: => 664.3 MB danych tymczasowych Usunięto.
- ================================
- System wymagał restartu.
- ==== Koniec Fixlog 19:40:58 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement