Guest User

Untitled

a guest
Nov 29th, 2018
50
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.15 KB | None | 0 0
  1. Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 21.11.2018
  2. Uruchomiony przez Sekretariat (29-11-2018 09:44:52) Run:2
  3. Uruchomiony z C:\Users\Sekretariat\Desktop
  4. Załadowane profile: Sekretariat (Dostępne profile: Sekretariat & Administrator)
  5. Tryb startu: Normal
  6. ==============================================
  7.  
  8. fixlist - zawartość:
  9. *****************
  10. CloseProcesses:
  11. CreateRestorePoint:
  12. EmptyTemp:
  13. VirusTotal: C:\ProgramData\23B080A7\23B08064.dll
  14. VirusTotal: C:\Users\Sekretariat\AppData\Roaming\update2501.exe
  15. HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
  16. HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
  17. HKLM-x32\...\Run: [NeroFilterCheck] => C:\Windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
  18. HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
  19. Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-08-27]
  20. ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
  21. ProxyEnable: [S-1-5-21-1921431682-952469367-1298936472-1000] => Proxy [funkcja włączona]
  22. ProxyServer: [S-1-5-21-1921431682-952469367-1298936472-1000] => 127.0.0.1:1080
  23. ManualProxies: 1127.0.0.1:1080
  24. FF Plugin-x32: @real.com/nppl3260;version=6.0.12.448 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll [2009-10-09] (RealNetworks, Inc.)
  25. FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2009-10-09] (RealNetworks, Inc.)
  26. CHR Extension: (lackfehpdclhclidcbbfcemcpolgdgnb) - C:\Users\Sekretariat\AppData\Local\Google\Chrome\User Data\Default\Extensions\lackfehpdclhclidcbbfcemcpolgdgnb [2015-07-20]
  27. R2 23B080A7; C:\ProgramData\23B080A7\23B08064.dll [2686992 2018-06-29] () [Brak podpisu cyfrowego]
  28. 2013-02-22 12:43 - 2013-02-22 12:43 - 000016090 _____ () C:\Program Files (x86)\borg
  29. 2013-02-20 13:28 - 2013-02-22 12:43 - 000000417 _____ () C:\Program Files (x86)\error.log
  30. 2013-02-20 13:28 - 2013-03-05 08:25 - 000001397 _____ () C:\Program Files (x86)\INST.LOG
  31. 2013-02-20 13:28 - 2013-02-22 12:42 - 000001486 _____ () C:\Program Files (x86)\INST.LOx
  32. 2013-02-20 13:28 - 2013-02-22 12:43 - 000000051 ____N () C:\Program Files (x86)\INSTALL.INI
  33. 2012-06-24 19:03 - 2012-06-24 19:03 - 001718793 _____ () C:\Program Files (x86)\winrar-x64-411pl.exe
  34. 2016-01-25 09:53 - 2016-01-25 09:53 - 001128269 _____ () C:\Users\Sekretariat\AppData\Roaming\2501cr1.scr
  35. 2018-06-29 11:03 - 2018-06-29 11:03 - 000038745 _____ () C:\Users\Sekretariat\AppData\Roaming\RwZwYdI.dll
  36. 2013-05-27 12:21 - 2013-05-27 12:21 - 000000000 _____ () C:\Users\Sekretariat\AppData\Roaming\SharedSettings.ccs
  37. 2018-11-09 07:15 - 2018-11-09 07:15 - 000299070 _____ (Distribution One) C:\Users\Sekretariat\AppData\Roaming\ULsdvJ.dll
  38. 2016-01-25 10:28 - 2016-01-25 10:28 - 001121629 _____ () C:\Users\Sekretariat\AppData\Roaming\update2501.exe
  39. 2018-07-30 07:02 - 2018-07-30 07:02 - 001739776 _____ (Robert Simpson, et al.) C:\Users\Sekretariat\AppData\Local\System.Data.SQLite.dll
  40. 2012-02-29 16:19 - 2012-02-29 16:19 - 000000003 _____ () C:\Users\Sekretariat\AppData\Local\user_data.ini
  41. MarketResearch (HKLM-x32\...\{175F0111-2968-4935-8F70-33108C6A4DE3}) (Version: 130.0.374.000 - Hewlett-Packard) Hidden
  42. Task: {47356C32-051E-4D91-A312-B823F3852352} - System32\Tasks\HP AR Program Upload - c8fb5f7eb3e149aa9e6be9eb9719b8f1b3a40356ae0f4cdb97162c2b984321be => C:\Program Files\HP\HP Deskjet 3540 series\bin\HPRewards.exe [2014-03-06] (TODO: <Company name>)
  43. Task: {47794EDD-0C2F-4102-A952-1442B7A033ED} - System32\Tasks\HP AR Program Upload - 174757233bc2437a8580c76728d8271042b39cfff3874ff2999f56dd533a031c => C:\Program Files\HP\HP Deskjet 3540 series\bin\HPRewards.exe [2014-03-06] (TODO: <Company name>)
  44. Task: {4BD3E0CC-234C-41CD-8257-A04D3F94587D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
  45. Task: {55554E10-5DDF-4F51-B7E9-13A705457861} - System32\Tasks\HP AR Program Upload - 0ea50c37d938455eb61135feed0a51fff5b6e1dd18e44f8fa2ec4da0d79b0bc1 => C:\Program Files\HP\HP Deskjet 3540 series\bin\HPRewards.exe [2014-03-06] (TODO: <Company name>)
  46. Task: {94EDB37C-8ABD-49D8-B988-4A16CB09B45C} - System32\Tasks\HPCustParticipation HP Deskjet 3540 series => C:\Program Files\HP\HP Deskjet 3540 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
  47. Task: {994CB0B6-E2A6-45C7-9247-D38E19E67460} - System32\Tasks\HP AR Program Upload - 3c80e2f519c74b0e955b65398c240f42bb5f4db6b0a043d7997aa890b57b7188 => C:\Program Files\HP\HP Deskjet 3540 series\bin\HPRewards.exe [2014-03-06] (TODO: <Company name>)
  48. Task: {D1980C5B-73C5-4945-99A3-0FCCFB23C1A4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
  49. Task: {E1DECA64-EC0B-4412-A02E-80D56EE13AF6} - System32\Tasks\HP AR Program Upload - e06e4359a51b45298bfa0140cde21b98aa62746a5f544662b017083319ff42c7 => C:\Program Files\HP\HP Deskjet 3540 series\bin\HPRewards.exe [2014-03-06] (TODO: <Company name>)
  50. Task: {E6B63256-4E81-4A85-9657-502422437A03} - System32\Tasks\HP AR Program Upload - 5ba77d516746431e859204a7d147045570aab64d57814d5c9c3b435095afcd3a => C:\Program Files\HP\HP Deskjet 3540 series\bin\HPRewards.exe [2014-03-06] (TODO: <Company name>)
  51. 2018-06-29 11:01 - 2018-06-29 11:01 - 002686992 ___RH () C:\ProgramData\23B080A7\23B08064.dll
  52. 2018-06-29 11:01 - 2018-06-29 11:01 - 001696272 ___RH () C:\ProgramData\23B080A7\23B08032.dll
  53. MSCONFIG\startupfolder: C:^Users^Sekretariat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^mn.jse => C:\Windows\pss\mn.jse.Startup
  54. MSCONFIG\startupfolder: C:^Users^Sekretariat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^sk32.jse => C:\Windows\pss\sk32.jse.Startup
  55. ManualProxies:
  56. RemoveProxy:
  57.  
  58. *****************
  59.  
  60. Procesy zostały pomyślnie zamknięte.
  61. Punkt przywracania został pomyślnie utworzony.
  62. VirusTotal: C:\ProgramData\23B080A7\23B08064.dll => (3) Błąd
  63. VirusTotal: C:\Users\Sekretariat\AppData\Roaming\update2501.exe => https://www.virustotal.com/file/777df254f2c121d47636de30c25d0849d25b05dc7700dacc4a25c2608d47f916/analysis/1543454335/
  64. "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdReg" => pomyślnie usunięto
  65. "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => pomyślnie usunięto
  66. "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck" => pomyślnie usunięto
  67. "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update" => pomyślnie usunięto
  68. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk => pomyślnie przeniesiono
  69. C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe => pomyślnie przeniesiono
  70. "HKU\S-1-5-21-1921431682-952469367-1298936472-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable" => pomyślnie usunięto
  71. "HKU\S-1-5-21-1921431682-952469367-1298936472-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer" => pomyślnie usunięto
  72. "HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\" => pomyślnie usunięto
  73. HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448 => pomyślnie usunięto
  74. C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll => pomyślnie przeniesiono
  75. HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448 => pomyślnie usunięto
  76. C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll => pomyślnie przeniesiono
  77. CHR Extension: (lackfehpdclhclidcbbfcemcpolgdgnb) - C:\Users\Sekretariat\AppData\Local\Google\Chrome\User Data\Default\Extensions\lackfehpdclhclidcbbfcemcpolgdgnb [2015-07-20] => Błąd: Nie znaleziono automatycznej naprawy dla tego wejścia.
  78. 23B080A7 => Nie można zatrzymać usługi.
  79. HKLM\System\CurrentControlSet\Services\23B080A7 => pomyślnie usunięto
  80. 23B080A7 => serwis pomyślnie usunięto
  81. C:\Program Files (x86)\borg => pomyślnie przeniesiono
  82. C:\Program Files (x86)\error.log => pomyślnie przeniesiono
  83. C:\Program Files (x86)\INST.LOG => pomyślnie przeniesiono
  84. C:\Program Files (x86)\INST.LOx => pomyślnie przeniesiono
  85. C:\Program Files (x86)\INSTALL.INI => pomyślnie przeniesiono
  86. C:\Program Files (x86)\winrar-x64-411pl.exe => pomyślnie przeniesiono
  87. C:\Users\Sekretariat\AppData\Roaming\2501cr1.scr => pomyślnie przeniesiono
  88. C:\Users\Sekretariat\AppData\Roaming\RwZwYdI.dll => pomyślnie przeniesiono
  89. C:\Users\Sekretariat\AppData\Roaming\SharedSettings.ccs => pomyślnie przeniesiono
  90. C:\Users\Sekretariat\AppData\Roaming\ULsdvJ.dll => pomyślnie przeniesiono
  91. C:\Users\Sekretariat\AppData\Roaming\update2501.exe => pomyślnie przeniesiono
  92. C:\Users\Sekretariat\AppData\Local\System.Data.SQLite.dll => pomyślnie przeniesiono
  93. C:\Users\Sekretariat\AppData\Local\user_data.ini => pomyślnie przeniesiono
  94. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{175F0111-2968-4935-8F70-33108C6A4DE3}\\SystemComponent" => pomyślnie usunięto
  95. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47356C32-051E-4D91-A312-B823F3852352}" => pomyślnie usunięto
  96. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47356C32-051E-4D91-A312-B823F3852352}" => pomyślnie usunięto
  97. C:\Windows\System32\Tasks\HP AR Program Upload - c8fb5f7eb3e149aa9e6be9eb9719b8f1b3a40356ae0f4cdb97162c2b984321be => pomyślnie przeniesiono
  98. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP AR Program Upload - c8fb5f7eb3e149aa9e6be9eb9719b8f1b3a40356ae0f4cdb97162c2b984321be" => pomyślnie usunięto
  99. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47794EDD-0C2F-4102-A952-1442B7A033ED}" => pomyślnie usunięto
  100. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47794EDD-0C2F-4102-A952-1442B7A033ED}" => pomyślnie usunięto
  101. C:\Windows\System32\Tasks\HP AR Program Upload - 174757233bc2437a8580c76728d8271042b39cfff3874ff2999f56dd533a031c => pomyślnie przeniesiono
  102. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP AR Program Upload - 174757233bc2437a8580c76728d8271042b39cfff3874ff2999f56dd533a031c" => pomyślnie usunięto
  103. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4BD3E0CC-234C-41CD-8257-A04D3F94587D}" => pomyślnie usunięto
  104. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BD3E0CC-234C-41CD-8257-A04D3F94587D}" => pomyślnie usunięto
  105. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => pomyślnie przeniesiono
  106. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => pomyślnie usunięto
  107. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{55554E10-5DDF-4F51-B7E9-13A705457861}" => pomyślnie usunięto
  108. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55554E10-5DDF-4F51-B7E9-13A705457861}" => pomyślnie usunięto
  109. C:\Windows\System32\Tasks\HP AR Program Upload - 0ea50c37d938455eb61135feed0a51fff5b6e1dd18e44f8fa2ec4da0d79b0bc1 => pomyślnie przeniesiono
  110. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP AR Program Upload - 0ea50c37d938455eb61135feed0a51fff5b6e1dd18e44f8fa2ec4da0d79b0bc1" => pomyślnie usunięto
  111. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{94EDB37C-8ABD-49D8-B988-4A16CB09B45C}" => pomyślnie usunięto
  112. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94EDB37C-8ABD-49D8-B988-4A16CB09B45C}" => pomyślnie usunięto
  113. C:\Windows\System32\Tasks\HPCustParticipation HP Deskjet 3540 series => pomyślnie przeniesiono
  114. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPCustParticipation HP Deskjet 3540 series" => pomyślnie usunięto
  115. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{994CB0B6-E2A6-45C7-9247-D38E19E67460}" => pomyślnie usunięto
  116. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{994CB0B6-E2A6-45C7-9247-D38E19E67460}" => pomyślnie usunięto
  117. C:\Windows\System32\Tasks\HP AR Program Upload - 3c80e2f519c74b0e955b65398c240f42bb5f4db6b0a043d7997aa890b57b7188 => pomyślnie przeniesiono
  118. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP AR Program Upload - 3c80e2f519c74b0e955b65398c240f42bb5f4db6b0a043d7997aa890b57b7188" => pomyślnie usunięto
  119. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D1980C5B-73C5-4945-99A3-0FCCFB23C1A4}" => pomyślnie usunięto
  120. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1980C5B-73C5-4945-99A3-0FCCFB23C1A4}" => pomyślnie usunięto
  121. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => pomyślnie przeniesiono
  122. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => pomyślnie usunięto
  123. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E1DECA64-EC0B-4412-A02E-80D56EE13AF6}" => pomyślnie usunięto
  124. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1DECA64-EC0B-4412-A02E-80D56EE13AF6}" => pomyślnie usunięto
  125. C:\Windows\System32\Tasks\HP AR Program Upload - e06e4359a51b45298bfa0140cde21b98aa62746a5f544662b017083319ff42c7 => pomyślnie przeniesiono
  126. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP AR Program Upload - e06e4359a51b45298bfa0140cde21b98aa62746a5f544662b017083319ff42c7" => pomyślnie usunięto
  127. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E6B63256-4E81-4A85-9657-502422437A03}" => pomyślnie usunięto
  128. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B63256-4E81-4A85-9657-502422437A03}" => pomyślnie usunięto
  129. C:\Windows\System32\Tasks\HP AR Program Upload - 5ba77d516746431e859204a7d147045570aab64d57814d5c9c3b435095afcd3a => pomyślnie przeniesiono
  130. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP AR Program Upload - 5ba77d516746431e859204a7d147045570aab64d57814d5c9c3b435095afcd3a" => pomyślnie usunięto
  131. C:\ProgramData\23B080A7\23B08064.dll => pomyślnie przeniesiono
  132. C:\ProgramData\23B080A7\23B08032.dll => pomyślnie przeniesiono
  133. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Sekretariat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^mn.jse => pomyślnie usunięto
  134. C:\Windows\pss\mn.jse.Startup => pomyślnie przeniesiono
  135. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Sekretariat^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^sk32.jse => pomyślnie usunięto
  136. C:\Windows\pss\sk32.jse.Startup => pomyślnie przeniesiono
  137.  
  138. ========= RemoveProxy: =========
  139.  
  140. "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
  141. "HKU\S-1-5-21-1921431682-952469367-1298936472-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => pomyślnie usunięto
  142. "HKU\S-1-5-21-1921431682-952469367-1298936472-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => pomyślnie usunięto
  143.  
  144.  
  145. ========= Koniec RemoveProxy: =========
  146.  
  147.  
  148. =========== EmptyTemp: ==========
  149.  
  150. BITS transfer queue => 0 B
  151. DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 15177816 B
  152. Java, Flash, Steam htmlcache => 510 B
  153. Windows/system/drivers => 24886 B
  154. Edge => 0 B
  155. Chrome => 2961847 B
  156. Firefox => 55574257 B
  157. Opera => 0 B
  158.  
  159. Temp, IE cache, history, cookies, recent:
  160. Users => 0 B
  161. Default => 0 B
  162. Public => 0 B
  163. ProgramData => 0 B
  164. systemprofile => 0 B
  165. systemprofile32 => 0 B
  166. LocalService => 0 B
  167. NetworkService => 0 B
  168. Sekretariat => 4056432 B
  169. Administrator.Sekretariat-kom => 0 B
  170.  
  171. RecycleBin => 629495 B
  172. EmptyTemp: => 74.8 MB danych tymczasowych Usunięto.
  173.  
  174. ================================
  175.  
  176.  
  177. System wymagał restartu.
  178.  
  179. ==== Koniec Fixlog 09:45:53 ====
Add Comment
Please, Sign In to add comment