Odinstaluj:
Ashampoo WinOptimizer 2021 (HKLM-x32\...\{4209F371-026D-496E-1D65-20A8FD672082}_is1) (Version: 18.00.19 - Ashampoo GmbH & Co. KG)
Avira Fallback Updater (HKLM-x32\...\Avira Fallback Updater) (Version: - ) Hidden
Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.41.1.25731 - Avira Operations GmbH & Co. KG) Hidden
Avira Security (HKLM-x32\...\Avira Security_is1) (Version: 1.1.88.1 - Avira Operations GmbH) Hidden
Avira Security (HKLM-x32\...\AviraSecurityUninstaller) (Version: - Avira Operations GmbH)
Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 6.25.0.17 - Avira Operations GmbH) Hidden
Zemana AntiMalware (wersja 3.2.28) (HKLM-x32\...\{4E1F3677-C72E-4F7D-B66E-85467B1A289E}_is1) (Version: 3.2.28 - Zemana)
Fixlist.txt:
AdBlock Shield 1.0.0.0 (HKU\S-1-5-21-1630318968-2378711795-1619992835-1001\...\{d8df10a5-1b31-4f61-97b7-4a74472bd094}) (Version: 1.0.0.0 - ivanovsasha224) Hidden
Odinstaluj:
AdBlock Shield 1.0.0.0
Kolejny Fixlist.txt:
CloseProcesses:
C:\Users\Domino\AppData\Roaming\NTSystem\
C:\Users\Domino\Downloads\spacebourne-v-hotfix_zmU3KJtT\
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1630318968-2378711795-1619992835-1001\...\Run: [MicrosoftEdgeAutoLaunch_77439EE7B33CF4156FFF05A827B621E2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4152256 2023-05-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1630318968-2378711795-1619992835-1001\...\Run: [] => [X]
Task: {82134ED5-7E90-47F8-A5D9-259DB5E14F4C} - System32\Tasks\AdLock Update Task-S-1-5-21-1630318968-2378711795-1619992835-1001 => C:\WINDOWS\System32\msiexec.exe [103936 2022-11-10] (Microsoft Windows -> Microsoft Corporation) -> /i "C:\Users\Domino\AppData\Local\Programs\ivanovsasha224\c9be02b6a8.msi" /quiet CHROME=1
C:\Users\Domino\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bnaebcjlolajbgllgjlmlfobobdemmki
Edge Extension: (Adblocker for Youtube™) - C:\Users\Domino\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bnaebcjlolajbgllgjlmlfobobdemmki [2023-05-10] [UpdateUrl:hxxps://clients42.google.com/service/update2/crx] <==== UWAGA
Edge HKLM-x32\...\Edge\Extension: [caiblelclndcckfafdaggpephhgfpoip]
Edge HKLM-x32\...\Edge\Extension: [emgfgdclgfeldebanedpihppahgngnle]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
C:\Users\Domino\AppData\Roaming\Opera Software\Opera Stable\Extensions\ioipkkmonpmomecbmggejienahinjkjj
OPR Extension: (Adblocker for Youtube™) - C:\Users\Domino\AppData\Roaming\Opera Software\Opera Stable\Extensions\ioipkkmonpmomecbmggejienahinjkjj [2023-05-10]
C:\Users\Domino\AppData\Local\Programs\ivanovsasha224
C:\Users\Domino\AppData\Roaming\Opera Software\Opera Stable\Extensions\mljbnbeedpkgakdchcmfapkjhfcogaoc
OPR Extension: (Opera AI Prompts) - C:\Users\Domino\AppData\Roaming\Opera Software\Opera Stable\Extensions\mljbnbeedpkgakdchcmfapkjhfcogaoc [2023-05-16]
S1 ifqevskn; \??\C:\WINDOWS\system32\drivers\ifqevskn.sys [X]
S3 netprotection_network_filter2; System32\drivers\netprotection_network_filter2.sys [X]
2023-05-12 22:41 - 2023-05-12 22:41 - 000000000 ____D C:\ProgramData\Norton
2023-05-12 22:24 - 2023-05-12 22:25 - 000000000 ____D C:\AdwCleaner
2023-05-11 21:53 - 2023-05-11 21:53 - 000000000 ____D C:\Users\Domino\Documents\Simply Super Software
2023-05-10 23:56 - 2023-05-11 21:39 - 000000000 ____D C:\Program Files (x86)\WskELFDsrQUn
2023-05-10 23:56 - 2023-05-11 21:39 - 000000000 ____D C:\Program Files (x86)\QGAsmJBctYwU2
2023-05-10 23:56 - 2023-05-11 21:39 - 000000000 ____D C:\Program Files (x86)\KRwWMXFMsGdKC
2023-05-10 23:56 - 2023-05-11 21:39 - 000000000 ____D C:\Program Files (x86)\DHXBscOFOjvhtNsLjGR
2023-05-10 23:56 - 2023-05-11 21:39 - 000000000 ____D C:\Program Files (x86)\BFCdZmgJU
2023-05-10 23:55 - 2023-05-11 21:49 - 000000000 ____D C:\WINDOWS\system32\Tasks\NvStray
2023-05-10 23:55 - 2023-05-11 21:49 - 000000000 ____D C:\Users\Domino\AppData\Roaming\oQFNcw
2023-05-10 23:55 - 2023-05-11 21:39 - 000000000 ____D C:\Users\Domino\AppData\Roaming\9LLLqHAuQOA
2023-05-10 23:55 - 2023-05-11 21:37 - 000000000 ____D C:\Users\Domino\AppData\Roaming\NTSystem
2023-05-10 23:55 - 2023-05-10 23:55 - 000000347 _____ C:\logs.uce
2023-05-10 23:55 - 2023-05-10 23:55 - 000000000 ____D C:\Users\Domino\AppData\Roaming\SFyOdm0
2023-05-10 23:55 - 2023-05-10 23:55 - 000000000 ____D C:\Users\Domino\AppData\Local\SystemCache
2023-05-10 23:54 - 2023-05-12 22:08 - 000000000 ____D C:\Program Files (x86)\Rkalo 4.19
2023-05-10 23:54 - 2023-05-11 21:49 - 000000000 ____D C:\ProgramData\FileOptimizer
2023-05-10 23:54 - 2023-05-10 23:54 - 000004160 _____ C:\WINDOWS\system32\Tasks\AdLock Update Task-S-1-5-21-1630318968-2378711795-1619992835-1001
2021-06-22 15:48 - 2021-06-22 15:59 - 000000004 _____ () C:\ProgramData\lock.dat
2021-06-22 15:49 - 2021-06-22 15:59 - 000000004 _____ () C:\ProgramData\rc.dat
2021-06-22 15:48 - 2021-06-22 15:48 - 000000008 _____ () C:\ProgramData\ts.dat
2021-07-13 00:36 - 2023-03-25 19:55 - 000012288 _____ () C:\Users\Domino\AppData\Roaming\emp.bin
2023-03-18 20:11 - 2023-03-18 20:11 - 000000078 _____ () C:\Users\Domino\AppData\Roaming\PCA.dat
2023-03-18 20:21 - 2023-03-18 20:21 - 000000078 _____ () C:\Users\Domino\AppData\Roaming\PCO.dat
EmptyTemp:
Tak sie konczy bezmyslne infekowanie, wyloguj wszsytkie sesje z konta, zmien haslo, sprawdz czy ktos nie zmienil numeru, maila itd, ustaw logowanie dwuetapowe.