Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 13-05-2020 01 Uruchomiony przez piotr (23-05-2020 10:47:12) Run:4 Uruchomiony z C:\Users\piotr\Desktop\Nowy folder Załadowane profile: piotr Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: VirusTotal: C:\Program Files\Windows Sidebar\sidebar.exe VirusTotal: C:\Program Files\Common Files\Commtouch\AntiVirus5\vseamps.exe Startup: C:\Users\piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar101.lnk [2019-12-29] ShortcutTarget: Sidebar101.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe ( (Microsoft Corporation) [Brak podpisu cyfrowego]) [Plik w użyciu ] Tcpip\..\Interfaces\{8e43ee1d-19fb-4e7c-ae7a-60ccee768a53}: [DhcpNameServer] 192.168.8.1 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=255141 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://go.microsoft.com/fwlink/p/?LinkId=255141 HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP HKU\S-1-5-21-2830509316-4061959040-275529259-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.pl/ SearchScopes: HKU\S-1-5-21-2830509316-4061959040-275529259-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04 SearchScopes: HKU\S-1-5-21-2830509316-4061959040-275529259-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04 Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Brak pliku U4 ekrn; Brak ImagePath AVSDK5 (HKLM\...\{D5A6E342-907C-4CEF-96CC-FC2F4990DC9C}) (Version: 6.2.0 - CYREN Inc.) Hidden ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> Brak pliku ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> Brak pliku ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Brak pliku ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> Brak pliku ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Brak pliku ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Brak pliku ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Brak pliku FirewallRules: [{74F6E651-2D48-4245-9017-657F0A762232}] => (Allow) LPort=8501 FirewallRules: [{19AF389E-1BF7-4DB7-B317-F89163EC6CA5}] => (Allow) LPort=8501 FirewallRules: [{B8E7B2F6-243E-4880-9A0D-BD2FD70D5A58}] => (Allow) LPort=2869 FirewallRules: [{75E619D0-4A65-4A59-AD9E-1F10E7025417}] => (Allow) LPort=1900 FirewallRules: [{56D21D74-3D0B-4115-B7D6-3F40FF4DBF22}] => (Allow) LPort=5357 StartBatch: cd C:\WINDOWS\system32\config\systemprofile\AppData\Local mkdir TileDataLayer cd TileDataLayer mkdir Database EndBatch: Reboot: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. VirusTotal: C:\Program Files\Windows Sidebar\sidebar.exe => https://www.virustotal.com/gui/file/ba9603faca19fb9fbcef28a6ef87c82c13911f8debd00fab42d37ecb9f40d24b/detection/f-ba9603faca19fb9fbcef28a6ef87c82c13911f8debd00fab42d37ecb9f40d24b-1589851089 VirusTotal: C:\Program Files\Common Files\Commtouch\AntiVirus5\vseamps.exe => https://www.virustotal.com/gui/file/1a6fbe4c9ad7cb3736149325bee7b5ae3e9521ba4947926401ae3a6a73ff08b6/detection/f-1a6fbe4c9ad7cb3736149325bee7b5ae3e9521ba4947926401ae3a6a73ff08b6-1563852301 C:\Users\piotr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar101.lnk => pomyślnie przeniesiono "C:\Program Files\Windows Sidebar\sidebar.exe (" => nie znaleziono "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8e43ee1d-19fb-4e7c-ae7a-60ccee768a53}\\DhcpNameServer" => pomyślnie usunięto HKLM\Software\\Microsoft\Internet Explorer\Main\\"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => Wartość pomyślnie przywrócono "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page" => pomyślnie usunięto HKU\S-1-5-21-2830509316-4061959040-275529259-1001\Software\Microsoft\Internet Explorer\Main\\"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" => Wartość pomyślnie przywrócono "HKU\S-1-5-21-2830509316-4061959040-275529259-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => pomyślnie usunięto HKU\S-1-5-21-2830509316-4061959040-275529259-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => pomyślnie usunięto HKLM\Software\Classes\PROTOCOLS\Handler\wlmailhtml => pomyślnie usunięto HKLM\System\CurrentControlSet\Services\ekrn => pomyślnie usunięto ekrn => serwis pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5A6E342-907C-4CEF-96CC-FC2F4990DC9C}\\SystemComponent" => pomyślnie usunięto HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => pomyślnie usunięto HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => pomyślnie usunięto HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => pomyślnie usunięto "HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => pomyślnie usunięto HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => pomyślnie usunięto HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => pomyślnie usunięto HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => pomyślnie usunięto HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => pomyślnie usunięto HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{74F6E651-2D48-4245-9017-657F0A762232}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{19AF389E-1BF7-4DB7-B317-F89163EC6CA5}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B8E7B2F6-243E-4880-9A0D-BD2FD70D5A58}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{75E619D0-4A65-4A59-AD9E-1F10E7025417}" => pomyślnie usunięto "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{56D21D74-3D0B-4115-B7D6-3F40FF4DBF22}" => pomyślnie usunięto ========= Batch: ========= ========= Koniec Batch: ========= System wymagał restartu. ==== Koniec Fixlog 10:47:43 ====