Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 12.02.2018
Uruchomiony przez pklos (13-02-2018 20:08:39) Run:1
Uruchomiony z C:\Users\pklos\Downloads
Załadowane profile: pklos (Dostępne profile: pklos)
Tryb startu: Normal
==============================================
fixlist - zawartość:
*****************
CloseProcesses:
CreateRestorePoint:
C:\Users\pklos\Documents\INTERsoft\ArCADia-START\6.5 PL\Print Styles\Create a Print Style Table.lnk
C:\Users\pklos\Desktop\Auslogics DiskDefrag.lnk
CustomCLSID: HKU\S-1-5-21-1307399746-3321642949-2734818087-1001_Classes\CLSID\{49E0BE0A-39E0-4932-B7BE-F249D56ACD31}\InprocServer32 -> csp16.dll => Brak pliku
Task: {27D13405-9702-4343-A295-DC4497BCFA05} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA
HKLM\...\Run: [SERVICE] => [X]
HKLM\...\RunOnce: [x4zzmy5u5ag] => C:\Program Files (x86)\ccc\ccc.exe [670208 2018-02-11] ()
HKLM\...\RunOnce: [pqgyl4fam1f] => C:\Program Files (x86)\ccc\ccc.exe [670208 2018-02-11] ()
C:\Program Files (x86)\ccc
HKU\S-1-5-21-1307399746-3321642949-2734818087-1001\...\Policies\Explorer: []
AppInit_DLLs: C:\ProgramData\Quoteex\Dripranfix.dll => Brak pliku
AppInit_DLLs-x32: C:\ProgramData\Quoteex\Driptech.dll => Brak pliku
C:\ProgramData\Quoteex
IFEO\OSppSvc.exe: [Debugger] KMS-R@1nHook.exe
IFEO\SppExtComObj.exe: [Debugger] KMS-R@1nHook.exe
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Ograniczenia - Chrome <==== UWAGA
HKU\S-1-5-21-1307399746-3321642949-2734818087-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <==== UWAGA
HKU\S-1-5-21-1307399746-3321642949-2734818087-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGk3GzeHhcr-ccYrAlKCo1kNn6F9vcF55hOQj6P9k6WrOGoLccoB77SOD-E_nl2Ja0e9z4E-Qq7umdnTrL2pKx7ADSs5fDKilpQ7nI8Q25B1bt_NZg30rpdle0ZkmtmGbGvA5MPWKWXvnZmv6g887a8EvGLsc9RoH_gzqAijFw,,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope - brak wartości
FF NewTab: Mozilla\Firefox\Profiles\34v2zedf.default -> C:\\ProgramData\\Quoteexs\\ff.NT
CHR StartupUrls: Default -> "hxxps://search.safefinder.com/?st=sc&q="
S1 elauxnoe; \??\C:\WINDOWS\system32\drivers\elauxnoe.sys [X]
S1 fndzutse; \??\C:\WINDOWS\system32\drivers\fndzutse.sys [X]
2018-02-11 22:55 - 2018-02-11 22:55 - 007576064 _____ () C:\Users\pklos\AppData\Local\agent.dat
2018-02-11 22:55 - 2018-02-11 22:55 - 000070896 _____ () C:\Users\pklos\AppData\Local\Config.xml
2018-02-11 22:55 - 2018-02-11 22:55 - 000140800 _____ () C:\Users\pklos\AppData\Local\installer.dat
2018-02-11 22:55 - 2018-02-11 22:55 - 000005568 _____ () C:\Users\pklos\AppData\Local\md.xml
2018-02-11 22:55 - 2018-02-11 22:55 - 000126464 _____ () C:\Users\pklos\AppData\Local\noah.dat
2018-02-11 22:55 - 2018-02-11 22:55 - 000278509 _____ () C:\Users\pklos\AppData\Local\Rankronstring.tst
2018-02-11 22:55 - 2018-02-11 22:55 - 001983026 _____ () C:\Users\pklos\AppData\Local\Subhome.tst
Tcpip\..\Interfaces\{2cc371c0-e1e4-4191-ad71-68a0ab659df2}: [NameServer] 82.163.142.8,95.211.158.136
Tcpip\..\Interfaces\{6997474f-c083-4230-bc4d-cdf004e68961}: [NameServer] 82.163.142.8,95.211.158.136
CMD: ipconfig /flushdns
VirusTotal: C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe
CMD: dir /a "C:\Program Files"
CMD: dir /a "C:\Program Files (x86)"
CMD: dir /a "C:\Program Files\Common Files\System"
CMD: dir /a "C:\Program Files (x86)\Common Files\System"
CMD: dir /a C:\ProgramData
CMD: dir /a C:\Users\pklos\AppData\Local
CMD: dir /a C:\Users\pklos\AppData\LocalLow
CMD: dir /a C:\Users\pklos\AppData\Roaming
Hosts:
Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
EmptyTemp:
*****************
Procesy zostały pomyślnie zamknięte.
Punkt przywracania został pomyślnie utworzony.
C:\Users\pklos\Documents\INTERsoft\ArCADia-START\6.5 PL\Print Styles\Create a Print Style Table.lnk => pomyślnie przeniesiono
C:\Users\pklos\Desktop\Auslogics DiskDefrag.lnk => pomyślnie przeniesiono
"HKU\S-1-5-21-1307399746-3321642949-2734818087-1001_Classes\CLSID\{49E0BE0A-39E0-4932-B7BE-F249D56ACD31}" => pomyślnie usunięto
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27D13405-9702-4343-A295-DC4497BCFA05} => niepowodzenie przy usuwaniu klucz. ErrorCode1: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27D13405-9702-4343-A295-DC4497BCFA05} => niepowodzenie przy usuwaniu klucz. ErrorCode1: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => niepowodzenie przy usuwaniu klucz. ErrorCode1: 0x00000001
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SERVICE" => pomyślnie usunięto
"HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\x4zzmy5u5ag" => pomyślnie usunięto
"HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\pqgyl4fam1f" => pomyślnie usunięto
C:\Program Files (x86)\ccc => pomyślnie przeniesiono
"HKU\S-1-5-21-1307399746-3321642949-2734818087-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => pomyślnie usunięto
"C:\ProgramData\Quoteex\Dripranfix.dll" => Dane wartości pomyślnie usunięto
"C:\ProgramData\Quoteex\Driptech.dll" => Dane wartości pomyślnie usunięto
"C:\ProgramData\Quoteex" => nie znaleziono
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\OSppSvc.exe" => pomyślnie usunięto
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SppExtComObj.exe" => pomyślnie usunięto
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Wartość pomyślnie przywrócono
C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono
C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono
"HKU\S-1-5-21-1307399746-3321642949-2734818087-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => pomyślnie usunięto
HKU\S-1-5-21-1307399746-3321642949-2734818087-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono
"Firefox newtab" => pomyślnie usunięto
"Chrome StartupUrls" => pomyślnie usunięto
"HKLM\System\CurrentControlSet\Services\elauxnoe" => pomyślnie usunięto
elauxnoe => serwis pomyślnie usunięto
"HKLM\System\CurrentControlSet\Services\fndzutse" => pomyślnie usunięto
fndzutse => serwis pomyślnie usunięto
C:\Users\pklos\AppData\Local\agent.dat => pomyślnie przeniesiono
C:\Users\pklos\AppData\Local\Config.xml => pomyślnie przeniesiono
C:\Users\pklos\AppData\Local\installer.dat => pomyślnie przeniesiono
C:\Users\pklos\AppData\Local\md.xml => pomyślnie przeniesiono
C:\Users\pklos\AppData\Local\noah.dat => pomyślnie przeniesiono
C:\Users\pklos\AppData\Local\Rankronstring.tst => pomyślnie przeniesiono
C:\Users\pklos\AppData\Local\Subhome.tst => pomyślnie przeniesiono
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2cc371c0-e1e4-4191-ad71-68a0ab659df2}\\NameServer" => pomyślnie usunięto
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6997474f-c083-4230-bc4d-cdf004e68961}\\NameServer" => pomyślnie usunięto
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= Koniec CMD: =========
VirusTotal: C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe => https://www.virustotal.com/file/ce9fe2fc90e69ae640de53b677098e77ddfe6eac64e4db1544cccce0a01fb06c/analysis/1510314619/
========= dir /a "C:\Program Files" =========
Volume in drive C has no label.
Volume Serial Number is DC33-D2C5
Directory of C:\Program Files
12.02.2018 22:05
.
12.02.2018 22:05 ..
08.04.2016 10:04 7-Zip
19.12.2017 19:58 AMD
18.10.2017 20:41 Android
09.04.2017 22:40 Apache Software Foundation
17.02.2016 02:08 Application Verifier
19.12.2017 21:04 ATI Technologies
21.02.2017 11:29 Autodesk
23.04.2017 08:29 Boris FX, Inc
13.09.2016 08:55 CCleaner
19.12.2017 20:52 Common Files
16.02.2016 11:27 DAEMON Tools Lite
29.09.2017 14:44 174 desktop.ini
04.12.2017 10:06 dotnet
12.10.2017 15:07 FileZilla FTP Client
28.03.2016 13:00 GIMP 2
15.03.2017 12:52 Git
16.02.2016 20:37 HWiNFO64
19.12.2017 20:52 IIS
04.12.2017 10:11 IIS Express
26.07.2017 22:57 Inkscape
22.12.2017 10:08 internet explorer
18.01.2018 19:28 Java
18.10.2017 20:47 JetBrains
04.12.2017 10:06 Microsoft ASP.NET Core Runtime Package Store
26.11.2016 01:10 Microsoft Office
26.11.2016 01:11 Microsoft Office 15
04.12.2017 10:12 Microsoft SDKs
15.06.2017 11:29 Microsoft Silverlight
05.06.2017 21:05 Microsoft SQL Server
17.02.2016 00:13 Microsoft SQL Server Compact Edition
02.09.2016 17:00 MPC-HC
19.12.2017 19:43 MSBuild
22.09.2017 21:34 MySQL
12.02.2018 22:05 nodejs
12.02.2018 22:54 Opera
11.02.2018 22:10 Oracle
17.02.2017 14:47 QGIS 2.18
19.12.2017 19:43 Reference Assemblies
08.12.2017 11:03 rempl
16.02.2016 12:01 TeamSpeak 3 Client
16.02.2016 01:40 Uninstall Information
19.12.2017 20:52 UNP
04.12.2017 10:12 VS2010Schemas
04.12.2017 10:12 VS2012Schemas
22.12.2017 10:08 Windows Defender
19.12.2017 19:58 Windows Mail
30.09.2017 15:29 Windows Media Player
29.09.2017 14:46 Windows Multimedia Platform
19.12.2017 21:30 windows nt
30.09.2017 15:28 Windows Photo Viewer
29.09.2017 14:46 Windows Portable Devices
29.09.2017 14:46 Windows Security
29.09.2017 14:46 Windows Sidebar
13.02.2018 18:30 WindowsApps
29.09.2017 14:46 WindowsPowerShell
1 File(s) 174 bytes
56 Dir(s) 29˙151˙178˙752 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files (x86)" =========
Volume in drive C has no label.
Volume Serial Number is DC33-D2C5
Directory of C:\Program Files (x86)
13.02.2018 20:09 .
13.02.2018 20:09 ..
27.07.2017 10:59 ActiveState Komodo Edit 10
23.02.2017 21:06 Adobe
12.04.2017 09:58 Apple Software Update
17.02.2016 02:08 Application Verifier
19.12.2017 21:03 ATI Technologies
05.11.2017 21:51 Audacity
21.02.2017 11:24 Autodesk
29.03.2017 08:36 Boris FX, Inc
19.06.2017 16:55 BRS
11.02.2018 23:18 Common Files
29.09.2017 14:44 174 desktop.ini
04.12.2017 10:01 Entity Framework Tools
16.02.2016 11:54 foobar2000
21.08.2017 15:06 Foxit Software
26.11.2017 23:08 Geekbench 4
16.02.2016 02:03 Google
29.12.2017 23:27 Hewlett-Packard
17.02.2016 03:01 IIS
04.12.2017 10:11 IIS Express
10.07.2017 11:12 ImgBurn
18.09.2017 21:15 InstallShield Installation Information
16.02.2016 02:08 Intel
22.12.2017 10:08 Internet Explorer
18.10.2017 20:39 JetBrains
17.02.2016 00:21 Microsoft Help Viewer
04.02.2018 14:21 Microsoft Office
19.12.2017 12:43 Microsoft SDKs
15.06.2017 11:29 Microsoft Silverlight
04.12.2017 10:11 Microsoft SQL Server
17.02.2016 00:13 Microsoft SQL Server Compact Edition
12.02.2018 20:27 Microsoft Toolkit Final
04.12.2017 09:59 Microsoft Visual Studio
19.12.2017 11:22 Microsoft Visual Studio 11.0
19.12.2017 11:22 Microsoft Visual Studio 12.0
19.12.2017 12:47 Microsoft Visual Studio 14.0
19.12.2017 12:30 Microsoft Web Tools
19.12.2017 20:52 Microsoft.NET
04.02.2018 21:47 Mozilla Firefox
04.02.2018 21:47 Mozilla Maintenance Service
19.12.2017 20:52 MSBuild
25.06.2016 10:04 MyPhoneExplorer
22.09.2017 21:09 MySQL
13.01.2017 08:55 NapiProjekt
19.12.2017 12:32 NuGet
19.06.2017 16:55 OpenAL
07.04.2017 18:17 QuickTime
19.12.2017 19:43 Reference Assemblies
28.05.2017 11:54 Rockstar Games
18.09.2017 21:14 Samsung
04.07.2016 16:21 Skype
13.02.2018 00:05 Spybot - Search & Destroy 2
11.03.2017 20:38 uTorrent
30.09.2017 15:28 Windows Defender
17.02.2016 02:54 Windows Kits
19.12.2017 19:59 Windows Mail
30.09.2017 15:29 Windows Media Player
29.09.2017 14:46 Windows Multimedia Platform
29.09.2017 14:46 windows nt
30.09.2017 15:28 Windows Photo Viewer
29.09.2017 14:46 Windows Portable Devices
29.09.2017 14:46 Windows Sidebar
29.09.2017 14:46 WindowsPowerShell
11.12.2002 22:11 4˙085˙904 wmfdist.exe
15.04.2003 19:27 793˙536 wmpcdcs8.exe
14.03.2017 10:42 Zero G Registry
3 File(s) 4˙879˙614 bytes
64 Dir(s) 29˙150˙617˙600 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files\Common Files\System" =========
Volume in drive C has no label.
Volume Serial Number is DC33-D2C5
Directory of C:\Program Files\Common Files\System
30.09.2017 15:28 .
30.09.2017 15:28 ..
30.09.2017 15:28 ado
30.09.2017 15:28 en-US
30.09.2017 15:28 msadc
30.09.2017 15:28 ole db
30.09.2017 15:28 pl-PL
29.09.2017 14:41 863˙744 wab32.dll
29.09.2017 14:41 964˙096 wab32res.dll
2 File(s) 1˙827˙840 bytes
7 Dir(s) 29˙150˙486˙528 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files (x86)\Common Files\System" =========
Volume in drive C has no label.
Volume Serial Number is DC33-D2C5
Directory of C:\Program Files (x86)\Common Files\System
30.09.2017 15:28 .
30.09.2017 15:28 ..
30.09.2017 15:28 ado
30.09.2017 15:28 en-US
30.09.2017 15:28 msadc
30.09.2017 15:28 ole db
30.09.2017 15:28 pl-PL
29.09.2017 14:42 748˙032 wab32.dll
29.09.2017 14:42 964˙096 wab32res.dll
2 File(s) 1˙712˙128 bytes
7 Dir(s) 29˙150˙486˙528 bytes free
========= Koniec CMD: =========
========= dir /a C:\ProgramData =========
Volume in drive C has no label.
Volume Serial Number is DC33-D2C5
Directory of C:\ProgramData
13.02.2018 18:36 .
13.02.2018 18:36 ..
31.05.2017 14:34 .mono
23.02.2017 21:06 Adobe
27.01.2018 19:53 Anaconda2
07.04.2017 18:16 Apple
07.04.2017 18:17 Apple Computer
16.02.2016 12:16 Applications
19.12.2017 21:35 ATI
10.03.2017 21:43 Autodesk
20.02.2017 15:08 boost_interprocess
30.05.2017 21:08 CDProjekt RED
23.06.2017 20:33 Codemasters
16.07.2016 12:47 Comms
16.02.2016 11:26 DAEMON Tools Lite
16.02.2016 01:37 Dane aplikacji [C:\ProgramData]
04.12.2017 10:12 dftmp
16.02.2016 01:37 Dokumenty [C:\Users\Public\Documents]
19.06.2017 17:35 DSS
20.02.2016 22:40 EA Core
20.02.2016 22:40 Electronic Arts
21.11.2016 19:50 19˙535 empty.ico
17.02.2017 13:49 ESRI
16.02.2016 15:14 FARO
17.02.2017 14:01 FLEXnet
03.10.2016 21:34 Foxit ContentPlatform
21.08.2017 15:08 Foxit Software
29.03.2017 08:36 FXHOME
15.03.2017 12:52 Git
13.06.2017 14:50 GOG.com
11.05.2016 09:47 HEC
11.02.2018 22:55 438 installer_logfile.log
25.03.2016 20:54 IsolatedStorage
16.02.2016 01:37 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu]
13.02.2018 00:04 Microsoft
17.02.2016 03:16 Microsoft DNX
26.11.2016 01:10 Microsoft Help
19.12.2017 21:34 Microsoft OneDrive
16.02.2016 13:35 133 Microsoft.SqlServer.Compact.351.64.bc
22.09.2017 21:34 MySQL
11.02.2018 22:56 266 ntuser.pol
15.03.2016 21:09 OO Software
18.01.2018 19:28 Oracle
19.12.2017 21:03 Package Cache
16.02.2016 01:37 Pulpit [C:\Users\Public\Desktop]
04.02.2018 14:23 regid.1991-06.com.microsoft
18.09.2017 21:14 Samsung
04.07.2016 16:21 Skype
29.09.2017 14:46 SoftwareDistribution
13.02.2018 00:04 Spybot - Search & Destroy
16.02.2016 01:37 Szablony [C:\ProgramData\Microsoft\Windows\Templates]
19.12.2017 21:09 USOPrivate
19.12.2017 21:09 USOShared
17.02.2016 00:10 VsTelemetry
17.02.2016 02:08 Windows App Certification Kit
30.09.2017 15:30 WindowsHolographicDevices
4 File(s) 20˙372 bytes
52 Dir(s) 29˙150˙478˙336 bytes free
========= Koniec CMD: =========
========= dir /a C:\Users\pklos\AppData\Local =========
Volume in drive C has no label.
Volume Serial Number is DC33-D2C5
Directory of C:\Users\pklos\AppData\Local
13.02.2018 20:09 .
13.02.2018 20:09 ..
22.04.2017 15:55 .distlib
04.12.2017 10:53 .IdentityService
20.03.2017 23:36 A
19.06.2017 12:09 ActiveState
16.02.2016 01:49 ActiveSync
23.02.2017 08:47 Adobe
13.02.2018 18:24 Akamai
29.02.2016 20:11 AMD
18.10.2017 20:42 Android
07.04.2017 18:16 Apple
20.02.2017 13:35 ArcGISRuntime
06.12.2017 18:42 ASP.NET
20.12.2017 21:23 assembly
19.12.2017 21:02 ATI
05.11.2017 21:51 Audacity
21.02.2017 11:30 Autodesk
26.05.2016 22:33 CEF
11.05.2017 08:32 Chromium
16.02.2016 01:49 Comms
06.01.2018 12:26 conda
19.12.2017 21:33 ConnectedDevicesPlatform
28.01.2018 14:02 CrashDumps
29.03.2017 08:39 Crashpad
19.12.2017 21:04 Dane aplikacji [C:\Users\pklos\AppData\Local]
20.12.2017 17:31 DBG
30.12.2016 20:57 Diagnostics
16.02.2016 11:28 Disc_Soft_Ltd
18.09.2017 20:53 Downloaded Installations
04.02.2018 15:51 Eclipse
22.02.2017 18:21 ESRI
17.02.2017 14:15 ESRI_Licensing
12.10.2017 15:08 FileZilla
22.02.2016 23:35 FluxSoftware
28.03.2016 21:30 fontconfig
03.10.2016 21:31 Foxit Reader
29.03.2017 08:39 FXHOME
29.03.2017 08:39 FXHOME Helper
28.03.2016 21:30 gegl-0.2
30.05.2017 20:49 GOG.com
30.10.2016 19:35 Google
09.12.2017 11:37 gtk-2.0
23.11.2016 21:57 HEC
19.12.2017 21:04 Historia [C:\Users\pklos\AppData\Local\Microsoft\Windows\History]
29.03.2017 08:39 HitFilm 4 Express Activation
23.11.2016 22:04 Hydrologic_Engineering_Ce
13.02.2018 18:37 6˙291˙456 IconCache.db
10.03.2017 21:43 IsolatedStorage
19.12.2017 21:31 Microsoft
16.02.2016 11:35 Microsoft Help
23.02.2016 11:35 MicrosoftEdge
27.12.2016 21:23 Mozilla
26.11.2016 01:24 mpress
16.02.2016 14:48 NetworkTiles
11.12.2017 21:04 NFS Underground 2
06.12.2017 18:45 NuGet
15.03.2016 21:10 O&O
13.09.2016 08:47 Ohdsics
23.12.2017 18:01 Opera Software
22.04.2017 15:53 Package Cache
19.01.2018 20:24 Packages
17.10.2017 21:24 pip
07.08.2016 10:40 Programs
16.02.2016 01:48 Publishers
28.04.2017 21:47 Python Tools
09.12.2017 11:37 2˙567 recently-used.xbel
12.01.2017 11:46 7˙589 Resmon.ResmonCfg
18.09.2017 21:17 Samsung
03.12.2017 23:05 ServiceHub
16.02.2016 16:27