Odinstaluj:
- OpenOffice.org 3.3.0 Packages
Otwórz notatnik i wklej zawartość z ramki:
Quote: CloseProcesses:
CreateRestorePoint:
(Rivet Networks LLC -> CloudBees, Inc.) C:\Windows\System32\drivers\RivetNetworks\Killer\xTendUtilityService.exe
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2743709897-2927809125-361951545-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-2743709897-2927809125-361951545-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2743709897-2927809125-361951545-1001\...\Winlogon: [Shell] %comspec% <==== UWAGA
HKU\S-1-5-21-2743709897-2927809125-361951545-1001\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist "C:\Users\Władca Śmierci\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" ( start /MIN "" "C:\Users\Władca Śmierci\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== UWAGA
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Ograniczenia <==== UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA
Task: {1350ABE2-E9A7-4C97-B1C2-49BB3F86BF76} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA
Task: {15217ABC-F6EB-431C-B404-327BAD375049} - \CCleanerSkipUAC -> Brak pliku <==== UWAGA
Task: {299AB1F5-E82E-4F92-99A3-46BBC9A879BD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA
Task: {304B707C-FDD0-45A4-B5DD-80217E394DEB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA
Task: {374ECD2D-ADFF-4410-8034-E8A1D7AD39EF} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA
Task: {6F0E11DE-B6A1-411B-8F89-27641EF13061} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA
Task: {9104AFAC-2EE0-43BD-B9A4-C17B1AAE10ED} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA
Task: {98E9A7E5-D8DE-442D-9A9D-0ED62405D5AC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA
Task: {A17C0152-A907-4710-958E-F33C2AFD5481} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA
Task: {AEAE375F-0B18-4D09-8080-ED7060982C05} - System32\Tasks\Opera scheduled Autoupdate 1440018900 => C:\Program Files (x86)\Opera\launcher.exe
Task: {BD11B08B-482F-472C-8459-5C7E3FF3257E} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA
Task: {DBEDCC39-E2C7-4FBF-938D-25A85675D937} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA
Task: {E6CF7C8B-8D10-48D6-80E8-81E13F9DF1C6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA
Task: {EA7BE97A-223A-4A62-81AC-435688543DE1} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA
Task: C:\WINDOWS\Tasks\KTJgTK1Ds8tS7uLg.job => C:\Users\Wadca mierci\AppData\Roaming\KTJgTK1Ds8tS7uLg.exe <==== UWAGA
Tcpip\..\Interfaces\{03d5c451-1bad-4782-8af7-9a14c31983ed}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{295c15a8-be0f-4dea-acae-6938d91a4f0e}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{36f215f6-5845-47e9-8bf1-75e229cd8ae0}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{69f6255d-0fe6-49da-8944-87e7b9c9dd19}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{a1ce9a0c-5c30-4b64-98b4-1bed0611d1d5}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{c6206301-48b5-4169-8552-7638c3b3c027}: [DhcpNameServer] 192.168.8.1 192.168.8.1
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131207460548694144&GUID=BEDEDB18-9E79-418D-8296-F5C25450C120
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2743709897-2927809125-361951545-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE03&ocid=UE03DHP
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2743709897-2927809125-361951545-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
SearchScopes: HKU\S-1-5-21-2743709897-2927809125-361951545-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
SearchScopes: HKU\S-1-5-21-2743709897-2927809125-361951545-1001 -> {DCB25748-814A-4D74-A782-EC4F7E7F847D} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=11467
SearchScopes: HKU\S-1-5-21-2743709897-2927809125-361951545-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll => Brak pliku
BHO-x32: Brak nazwy -> {42D79B50-CC4A-4A8E-860F-BE674AF053A2} -> Brak pliku
Toolbar: HKLM-x32 - Brak nazwy - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - Brak pliku
FF Plugin HKU\S-1-5-21-2743709897-2927809125-361951545-1001: @m_y.com/Games -> C:\Users\Władca Śmierci\AppData\Local\MyComGames\NPMyComDetector.dll [Brak pliku]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <nie znaleziono>
HKU\S-1-5-21-2743709897-2927809125-361951545-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Eastmy\Application\chrome.exe <==== UWAGA
S2 xTendSoftAPService; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\xTendSoftAPService.exe [72880 2018-06-15] (Rivet Networks LLC -> CloudBees, Inc.)
R2 xTendUtilityService; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\xTendUtilityService.exe [72888 2018-06-15] (Rivet Networks LLC -> CloudBees, Inc.)
S3 OSFMount; \??\E:\OSFMount\OSFMount.sys [X]
2020-01-06 20:24 - 2020-01-06 20:24 - 000000008 __RSH C:\ProgramData\ntuser.pol
2020-01-06 20:51 - 2019-12-20 15:01 - 000003338 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1440018900
2019-11-22 16:11 - 2019-11-22 16:12 - 003673088 _____ (SoundMixer) C:\Users\Władca Śmierci\AppData\Roaming\Launcher_091.exe
HKU\S-1-5-21-2743709897-2927809125-361951545-1001\...\ChromeHTML: -> <==== UWAGA
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll -> Brak pliku
ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll -> Brak pliku
ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll -> Brak pliku
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [478]
EmptyTemp:
Plik zapisz pod nazwą fixlist.txt i umieść w folderze gdzie masz FRST.exe.
Uruchom FRST i kliknij w Fix/Napraw.