Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.06.2018 01
- Ran by Karola (administrator) on KAROLA-PC (18-06-2018 21:18:28)
- Running from C:\Users\Karola\Desktop\sciagane
- Loaded Profiles: Karola (Available Profiles: Karola)
- Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angielski (Stany Zjednoczone)
- Internet Explorer Version 11 (Default browser: Chrome)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
- (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
- (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
- (Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe
- (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
- () C:\Program Files (x86)\NordVPN\nordvpn-service.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
- (DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
- (Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
- (Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.204\WsAppService.exe
- (Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
- (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (SafeIP) C:\Program Files (x86)\SafeIP\SafeIPS.exe
- (Intel Corporation) C:\Windows\System32\igfxEM.exe
- (Intel Corporation) C:\Windows\System32\igfxHK.exe
- (Google Inc.) C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- (Farbar) C:\Users\Karola\Desktop\sciagane\FRST64 (1).exe
- ==================== Registry (Whitelisted) ===========================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671792 2014-03-14] (Realtek Semiconductor)
- HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
- HKLM\...\Run: [egui] => c:\Program Files\ESET\ESET NOD32 Antivirus\ecmds.exe [178496 2018-04-21] (ESET)
- HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
- HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [456328 2017-06-07] (Power Software Ltd)
- HKU\S-1-5-21-559423208-2678498331-2271372539-1000\...\Run: [GmailNotifierPro] => C:\Program Files (x86)\Gmail Notifier Pro\GmailNotifierPro.exe [2828096 2014-08-12] (IntelliBreeze Software)
- HKU\S-1-5-21-559423208-2678498331-2271372539-1000\...\Run: [Google Update] => C:\Users\Karola\AppData\Local\Google\Update\1.3.33.17\GoogleUpdateCore.exe [601680 2018-05-17] (Google Inc.)
- HKU\S-1-5-21-559423208-2678498331-2271372539-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.)
- HKU\S-1-5-18\...\Run: [] => [X]
- HKU\S-1-5-18\...\Run: [Paltalk] => "C:\Program Files (x86)\Paltalk\Paltalk.exe" minimized
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Winsock: Catalog9 01 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP)
- Winsock: Catalog9 02 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP)
- Winsock: Catalog9 03 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP)
- Winsock: Catalog9 04 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP)
- Winsock: Catalog9 15 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP)
- Winsock: Catalog9-x64 01 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP)
- Winsock: Catalog9-x64 02 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP)
- Winsock: Catalog9-x64 03 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP)
- Winsock: Catalog9-x64 04 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP)
- Winsock: Catalog9-x64 15 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP)
- Tcpip\Parameters: [DhcpNameServer] 8.8.8.8
- Tcpip\..\Interfaces\{38CED0E0-EE39-4EF0-8DB9-C41FDA0030BA}: [DhcpNameServer] 8.8.8.8
- Tcpip\..\Interfaces\{92981694-12E2-4DAC-B56A-25A4F0475331}: [DhcpNameServer] 95.211.101.197 95.211.101.198
- Tcpip\..\Interfaces\{EBEDF5CA-4DDD-4543-A194-7D95423F249D}: [DhcpNameServer] 185.232.23.177 185.232.23.179
- Internet Explorer:
- ==================
- HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
- HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=9&ar=msnhome
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=9&ar=msnhome
- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
- HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
- HKU\S-1-5-21-559423208-2678498331-2271372539-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=avantsearch6
- SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement