GridinSoft Anti-Malware (64-bit) v.3.0.52 Report file date: 2017-11-09 22:09:37 Last update: 2016-09-07 23:30:26 Scanning for 719465 virus strains and unwanted programs. Licensed for: Windows version: Windows 10 Pro x64 (version 6.3) Username: Milczek Computer name: DELLLATITUDE Starting the file scan: Full Scan started Scanning process... ----- c:\users\milczek\appdata\local\fluxsoftware\flux\flux.exe ---- Startup Suspicious Startup: Suspicious autostart RegPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Run|f.lux ProdVer: 4, 55, 0, 1 FileVer: 4, 55, 0, 0 Name: f.lux Company: f.lux Software LLC Certificates: F.lux Software LLC; NAC: 0AF790846D8C6D8F67C1DB6AB149A96E:23 MD5: 05EF78B9E274D3B190C18C34361D4024:1678840 RIC: F01766EF9FFC79AADA4ABD5523A2D1D1:18632 RFH: 192:I3DdrXX7Dd2QjVzkkHKKH5iCbzSuhnnhgen8aPatN:6DdPgQj9zHKgPpqenLPat SUBS: Win32 GUI PE: x86 EP: E8B6EF0000E978FEFFFF8BFF558BEC83EC205333DB395D107520E8701700005353535353C70016000000E89D72000083C41483C8FFE9800000008B4D0C568B7508 EPSEC: 0 EPRVA: 000D6674 IBASE: 00400000 SEC: .text:60000020:D7896DC813905ECA2AC44564D1031DFE:1060352 .rdata:40000040:92E67E543F8F94BE0EFC970742314D59:172032 .data:C0000040:07B9C2DABE49DBD7EE14EE70C42D3CE1:359936 .rsrc:40000040:568AD6CB024A091009AE5D72595366D5:27648 .reloc:42000040:D40268071ACFBAE623F8D49450FD9E24:43008 ----- C:\Flashtool\uninstall.exe ---- General Threat Trojan.Win32.Downloader.4B33.vb!ff ProdVer: 0.9.11.0 FileVer: 0.9.11.0 Name: Flashtool Company: Androxyde NAC: 200893AD8C3EAD523858E6FE3514567C:18 MD5: 7FE56AE318B8743C0BC4D6917AA9CE06:74900 FUZ: 1536:WVdePelp2Xy+tuQOzOYE5aXPnSQEyS+EhIBMF8q:pweqOYEUXPnxima RIC: 3B79BA8A76276D10853EBE7B6F45C1A8:23424 RFH: 384:WFJRnuSzgsAkjprAID0PZs4L333Elk1BT5zhjcWjrcCBvmEig:gJRn1zgsA8ahRn3d19QWDF/ SUBS: Win32 GUI PE: x86 EP: 81ECD4020000535556576A2033ED5E896C2418C7442410D8914000896C2414FF15308040006801800000FF15B880400055FF15C08240006A08A3B82E4700E8372A EPSEC: 0 EPRVA: 000039E3 IBASE: 00400000 SEC: .text:60000020:F569E353AF0ED51BF4C216FAA9BED4E7:28672 .rdata:40000040:91EEE43954E068E650F7B73A8B0E6915:11264 .data:C0000040:DB9F7ACBF1C3DDFE255077B699955DFA:512 .ndata:C0000080:00000000000000000000000000000000:0 .rsrc:40000040:4FD85D7F67E72A4B959F58ADF80A23FE:27648 .reloc:42000040:D31FADBE69CCDBAF9DADD6CDDAB671A0:4096 ----- C:\Program Files (x86)\Disk Checker\register.exe ---- General Threat Malware.Win32.Pack.84!se MD5: 317B5DC188733ED74BFE5A24D8EAA9CE:171008 FUZ: 3072:qFhQnwYG+GkdiztHts7DbAssbbrMbvT0q8O1cZPzQ7IXMBc+AMP+QfQEhxFyVU7j:ihqG2izVttwvP6bQ7yMP+DE827bZZ RIC: 23E559F5B14D6D907FE475B4F6EE77E9:32808 RFH: 768:bwxoidY8g0IEW8/opr0aLzBTUwcFA29PCs7Dqwn:bbidgkAIaLzdX0A29PCs7Dn SUBS: Win32 GUI PE: x86 EP: 6801A04100E801000000C3C3037E5ECACA82A8F53A8FD9F88D970CB153769BF0B880EA38A44A4FB06E45ED280B65648B9B98E198E48DCE63D49771C188DD11EED2 EPSEC: 0 EPRVA: 00001000 IBASE: 00400000 SEC: :E0000040:E0B40088A7A3D3B731D3DF3E20921722:20992 :E0000040:1A5F7F43801D12B45EE751A03FF0789F:4608 :E0000040:BBDAD09273D8230431F4F05B714D8D14:1024 .rsrc:E0000040:5F730DF2C40A0E4D34A15E41185176F0:36864 .data:E0000040:B1368FDBF7BAE9305D281DA8571A1929:103424 .adata:E0000040:00000000000000000000000000000000:0 ----- C:\Program Files (x86)\Unlockroot Pro\unlockrootpro.exe ---- General Threat Malware.Win32.Gen.cld MD5: 45A3CD142A21AAA5200024D48B3057C2:4770816 RIC: B1F1760DF030BD079C05359932ECACCB:17472 RFH: 384:HoxB3ziOR3bxrkWmq2w3r2od712aTfyFOCuqacMqgjilLnwlOxdM:k5lh3rJd712Yq4ocWRwcHU SUBS: Win32 GUI PE: x86 EP: E81B0000005650726F7465637420556C74696D6174652076322E312E302E30008D642404E8C6F902005E661C264482301D168466E35D41700547537782267144D3 EPSEC: 1 EPRVA: 003557F0 IBASE: 00400000 SEC: .text:40000000:13E9F148E494AF971DA885A9984EF9E0:2048 NY:E0000000:FB50557B8C8855C13CAE24776733820E:392704 NY:E0000020:2F4BB328259335E41BA1A6BB5E3A1B51:4350464 NY:40000000:BB4308C230C4AB775EC853C17757DCAE:5120 NY:40000000:BEDA7028E2A918F45D282138BECDACDB:19456 ----- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disk Checker\Register.lnk ---- General Threat Malware.Win32.Pack.84!se MD5: 610BCE0CA7DD9E9A57076DEC29420603:1054 ----- C:\Users\Milczek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool\Uninstall Flashtool.lnk ---- General Threat Trojan.Win32.Downloader.4B33.vb!ff MD5: 6B357D3396F5E3D8EC97A6077EA8C4B5:827 ----- C:\Users\Milczek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UnlockRoot Pro\UnlockRoot Pro.lnk ---- General Threat Malware.Win32.Gen.cld MD5: 1CC06F88BF17585D932A5E217B16A207:1183 ----- C:\Users\Milczek\Desktop\NEWPULPIT\SE Bootloader_Unlocking_Relocking_1.6.7z ---- General Threat Malware.Win32.Gen.sm MD5: 74340F89772252D45DCF3623666DDC53:29377089 ----- C:\Users\Milczek\Desktop\NEWPULPIT\SE Bootloader_Unlocking_Relocking_1.6.7z\SE Bootloader_Unlocking_Relocking_1.6\libs\FlashTool.exe ---- General Threat Malware.Win32.Gen.sm MD5: 9C9C938DFDF87D25D896B90BF58045BF:210944 FUZ: 6144:1I/EloG40ztTNP0syc6Hk3wT66vlmkMGoR:y/C40xBxN RIC: 0DF3263C869555C91B90129662588C46:5392 RFH: 48:BRTnxbBdCCCAd/cccM6SSS:/5BdCCCCCCCCCCCCAdP SUBS: Win32 GUI PE: x86 EP: 5589E583EC0883C4F46A01A144154300FFD0E811FEFFFF89EC31C05DC38D76005589E583EC0883C4F46A02A144154300FFD0E8F1FDFFFF89EC5DC3905589E583EC EPSEC: 0 EPRVA: 000011D8 IBASE: 00400000 SEC: .text:60000060:457401F5728035AE0A183900CB1A9C28:132096 .data:C0000040:E710F5817DDCE3877E756388E9765D41:4608 .bss:C0000080:00000000000000000000000000000000:0 .idata:C0000040:C8C3CE30BD4E768EBDA7D9101F48B591:5632 .rsrc:C0000040:2FCA11806BCD31D8ADB1D54041594EC3:7680 ----- C:\Users\Milczek\Desktop\Ostatni PULPIT\Stary Pulpit\Z Pulpitu\Śmieci z Pulpitu\CS2.5.zip ---- General Threat Trojan.Win32.Ursnif.vl!n MD5: 2CA6A55040CFF420E01D8193EBF1D8EF:1318032 ----- C:\Users\Milczek\Desktop\Ostatni PULPIT\Stary Pulpit\Z Pulpitu\Śmieci z Pulpitu\CS2.5.zip\CamStudio2.5\ProducerLANG07.dll ---- General Threat Trojan.Win32.Ursnif.vl!n ProdVer: 1, 0, 0, 1 FileVer: 1, 0, 0, 1 Name: Producer Application NAC: 6AA921A263D79451A84E53DC40721C82:20 MD5: 82B3BF03864BE2B194913E54FECE3025:425984 FUZ: 1536:4UGyheHFyyBanKXBqLwLhW1aVZzGi7KqGfgCAgMwy:y0yk8zoaVZzGi73G4CAgTy SUBS: Win32 GUI PE: x86 EP: 4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000B00000000E SEC: .rsrc:40000040:4F88E5A72A7D527B1B1DC4621160C583:417792 .reloc:42000040:3808644F11BA1EE3CB2B6326FCD2E01A:4096 ----- C:\Users\Milczek\Desktop\Ostatni PULPIT\UnlockRoot Pro.lnk ---- General Threat Malware.Win32.Gen.cld MD5: 6C2BEFC02D87F98C6FC2839E887AEBF1:1147 Przerwane przez użytkownika Scan result: 10 detected items Scan completed in: Scan completed in 2 hour(s) 50 min. 11 sec. Files were scanned: 43975