Witaj serdecznie @iJuliusz
Wykonałem zgodnie z poleceniami. Poniżej log z fix-a:
Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 27-01-2021
Uruchomiony przez Marcin (02-02-2021 19:40:06) Run:1
Uruchomiony z C:\Users\Marcin\Downloads
Załadowane profile: Marcin
Tryb startu: Normal
fixlist - zawartość:
CloseProcesses:
CreateRestorePoint:
EmptyTemp:
Task: C:\Windows\Tasks{5E9C47D5-C2A3-4B5B-9646-23F9F5362F1A}.job => C:\Program Files (x86)\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.90.exeѧ/i C:\Users\Marcin\AppData\Local\Temp\MTGAinstall\MTGAInstaller.msi AI_SETUPEXEPATH=C:\Program Files (x86)\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.90.exe SETUPEXEDIR=C:\Program Files (x86)\Wizards of the Coast\MTGA\MTGALauncher\Updates\ ADDLOCAL=MainFeature,MicrosoftVisualC ALLUSERS=1 PRIMARYFOLDER=APPDIR ROOTDRIVE=D:\ AI_PREREQFILES=C:\Users\Marcin\AppData\Roaming\Wizards of the Coast\MTGA Launcher\prerequisites\Visual C++ Redistributable for Visual Studio 2015-2019\VC_redist.x64.exe AI_PREREQDIRS=C:\Users\Marcin\AppData\Roaming AI_MISSING_PREREQS=Visual C++ Redistributable for Visual Studio 2017 x64 AI_SETUPEXEPATH=C:\Program Files (x86)\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.90.exe SETUPEXEDIR=C:\Program Files (x86)\Wizards of the Coast\MTGA\MTGALauncher\Updates\ AI_INSTALL=1 BIPROCESSTIME=2020-06-25T15:24:06.1829077Z TARGETLOCKED=TRUE TARGETDIR=D:\ APPDIR=C:\Program Files (x86)\Wizards of the Coast\MTGA\ AI_SETUPEXEPATH_ORIGINAL=C:\Program Files (x86)\Wizards of the Coast\MTGA\MTGALauncher\Updates\MTGAInstaller_1.0.90.exe <==== UWAGA
C:\AdwCleaner
CustomCLSID: HKU\S-1-5-21-2645379238-1908583816-2438023672-1001_Classes\CLSID{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Marcin\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => Brak pliku
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> Brak pliku
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Brak pliku
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku
AlternateDataStreams: C:\ProgramData\PACE:787DFD260BD4240B [217]
SearchScopes: HKLM-x32 -> DefaultScope - brak wartości
FirewallRules: [{D076E259-8179-4B92-92B9-7133EAD9351E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => Brak pliku
FirewallRules: [{6D96605C-4B37-4922-9B18-E3E7B9A0ACDB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => Brak pliku
FirewallRules: [TCP Query User{FDB0D389-4FD4-4902-B99A-52ACE9B0B3FD}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe => Brak pliku
FirewallRules: [UDP Query User{82935FA1-5DE0-4DB7-A933-8ACF9257D320}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe => Brak pliku
FirewallRules: [{C030E208-040A-4B70-A80A-9CA8CB147A80}] => (Allow) C:\Program Files (x86)\3uTools\libXunlei\Download\MiniThunderPlatform.exe => Brak pliku
FirewallRules: [{D3F86488-832F-4052-8116-8EDC46359675}] => (Allow) C:\Program Files (x86)\3uTools\libXunlei\Download\MiniThunderPlatform.exe => Brak pliku
FirewallRules: [{1A897B77-0BAB-4DDB-B229-D7EC0DAC3A60}] => (Allow) LPort=80
FirewallRules: [TCP Query User{55A88718-9C4D-45DD-A0D7-856355131C83}C:\program files\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files\wizards of the coast\mtga\mtga.exe (Wizards of the Coast, LLC -> )
FirewallRules: [UDP Query User{8D0945F6-5BB1-40C1-8B7D-CEEC29B079EE}C:\program files\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files\wizards of the coast\mtga\mtga.exe (Wizards of the Coast, LLC -> )
Procesy zostały pomyślnie zamknięte.
Punkt przywracania został pomyślnie utworzony.
C:\Windows\Tasks{5E9C47D5-C2A3-4B5B-9646-23F9F5362F1A}.job => pomyślnie przeniesiono
C:\AdwCleaner => pomyślnie przeniesiono
HKU\S-1-5-21-2645379238-1908583816-2438023672-1001_Classes\CLSID{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92} => pomyślnie usunięto
HKLM\Software\Classes*\ShellEx\ContextMenuHandlers\ANotepad++64 => pomyślnie usunięto
HKLM\Software\Classes*\ShellEx\ContextMenuHandlers\BriefcaseMenu => pomyślnie usunięto
“HKLM\Software\Classes\CLSID{85BBD920-42A0-1069-A2E4-08002B30309D}” => pomyślnie usunięto
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => pomyślnie usunięto
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => pomyślnie usunięto
C:\ProgramData\PACE => “:787DFD260BD4240B” ADS pomyślnie usunięto
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\“DefaultScope”="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Wartość pomyślnie przywrócono
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{D076E259-8179-4B92-92B9-7133EAD9351E}” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{6D96605C-4B37-4922-9B18-E3E7B9A0ACDB}” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\TCP Query User{FDB0D389-4FD4-4902-B99A-52ACE9B0B3FD}C:\program files (x86)\wizards of the coast\mtga\mtga.exe” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\UDP Query User{82935FA1-5DE0-4DB7-A933-8ACF9257D320}C:\program files (x86)\wizards of the coast\mtga\mtga.exe” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{C030E208-040A-4B70-A80A-9CA8CB147A80}” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{D3F86488-832F-4052-8116-8EDC46359675}” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{1A897B77-0BAB-4DDB-B229-D7EC0DAC3A60}” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\TCP Query User{55A88718-9C4D-45DD-A0D7-856355131C83}C:\program files\wizards of the coast\mtga\mtga.exe” => pomyślnie usunięto
“HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\UDP Query User{8D0945F6-5BB1-40C1-8B7D-CEEC29B079EE}C:\program files\wizards of the coast\mtga\mtga.exe” => pomyślnie usunięto
=========== EmptyTemp: ==========
BITS transfer queue => 10248192 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 151948937 B
Java, Flash, Steam htmlcache => 168540247 B
Windows/system/drivers => 1995781 B
Edge => 1056819 B
Chrome => 22136244 B
Firefox => 1480862293 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 5324 B
NetworkService => 670642 B
Marcin => 49008738 B
RecycleBin => 2451686865 B
EmptyTemp: => 4 GB danych tymczasowych Usunięto.
================================
System wymagał restartu.
==== Koniec Fixlog 19:41:58 ====
PS. Po wgraniu wczoraj malwarebytes ten nie przepuścił mnie na stronę wklejto.pl informując o trojanach (prawda to?)