CHR DefaultProfile: ChromeDefaultData
CHR Profile: C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2 [2017-01-01] <==== UWAGA
Uruchom Google Chrome
> Naciśnij klawisze: lewy Alt+F i kliknij przycisk Ustawienia >
> Sekcja: OSOBY
>zaznacz (wybierz):
user0kliknij znaczek
X znajdujący się po prawej stronie
>zaznacz (wybierz):
user2kliknij znaczek
X znajdujący się po prawej stronie
2) Otwórz Notatnik i wklej w nim:
AlternateDataStreams: C:\Windows\system32\drivers:ucdrv-x64.sys [23652]
AlternateDataStreams: C:\Windows\system32\drivers:x64 [1479458]
AlternateDataStreams: C:\Windows\system32\drivers:x86 [1205026]
RemoveDirectory: C:\Program Files (x86)\UCBrowser
RemoveDirectory: C:\Program Files (x86)\Maoha
RemoveDirectory: c:\program files (x86)\qphchfepy
RemoveDirectory: C:\Program Files\żěŃą
RemoveDirectory: C:\ProgramData\860420v3a975h48
RemoveDirectory: C:\Program Files (x86)\Therlaiedstation Agent
ShortcutWithArgument: C:\Users\x\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\x\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://kipuu.cn/
ShortcutWithArgument: C:\Users\x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://kipuu.cn/
ShortcutWithArgument: C:\Users\x\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\x\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://kipuu.cn/
ShortcutWithArgument: C:\Users\x\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://kipuu.cn/
ShortcutWithArgument: C:\Users\x\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://kipuu.cn/
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\x\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://kipuu.cn/
WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA
Task: {C24BE66F-6C15-4C15-B84B-0410C3F587CF} - System32\Tasks\860420v3a975h48 => Rundll32.exe "C:\ProgramData\860420v3a975h48\860420v3a975h48.dll",bgozrak <==== UWAGA
Task: {3BC18B7C-CF2D-4F2C-8076-8A99F84F04AF} - System32\Tasks\UCBrowserSecureUpdater => C:\Program Files (x86)\UCBrowser\Security\uclauncher.exe [2017-01-01] (UC Web Inc.) <==== UWAGA
2013-02-07 13:22 - 2013-02-07 13:22 - 0050330 _____ () C:\Program Files (x86)\AntiDust.exe
2017-01-01 17:16 - 2017-01-01 17:16 - 7316480 _____ () C:\Users\x\AppData\Roaming\agent.dat
2017-01-01 17:16 - 2017-01-01 17:16 - 0070704 _____ () C:\Users\x\AppData\Roaming\Config.xml
2017-01-01 17:15 - 2017-01-01 17:15 - 0017808 _____ () C:\Users\x\AppData\Roaming\InstallationConfiguration.xml
2017-01-01 17:15 - 2017-01-01 17:15 - 0140288 _____ () C:\Users\x\AppData\Roaming\Installer.dat
2017-01-01 17:16 - 2017-01-01 17:16 - 0018432 _____ () C:\Users\x\AppData\Roaming\Main.dat
2017-01-01 17:16 - 2017-01-01 17:16 - 0005568 _____ () C:\Users\x\AppData\Roaming\md.xml
2017-01-01 17:16 - 2017-01-01 17:16 - 0126464 _____ () C:\Users\x\AppData\Roaming\noah.dat
2017-01-01 17:16 - 2017-01-01 17:16 - 1938535 _____ () C:\Users\x\AppData\Roaming\TouchFind.bin
2017-01-01 17:16 - 2017-01-01 17:15 - 0629760 _____ () C:\Users\x\AppData\Roaming\Trantamtom.exe
2017-01-01 17:16 - 2017-01-01 17:16 - 1908230 _____ () C:\Users\x\AppData\Roaming\Trantamtom.tst
2017-01-01 17:15 - 2017-01-01 17:15 - 0278519 _____ () C:\Users\x\AppData\Roaming\TrioTop.bin
2017-01-01 17:16 - 2017-01-01 17:16 - 0032038 _____ () C:\Users\x\AppData\Roaming\uninstall_temp.ico
2017-01-01 17:15 - 2017-01-01 17:15 - 0136826 _____ () C:\Users\x\AppData\Roaming\Zoo-Touch.bin
2017-01-01 16:08 - 2017-01-01 16:08 - 00000000 ___HD C:\ProgramData\860420v3a975h48
2017-01-01 16:08 - 2017-01-01 18:38 - 00000000 ____D C:\Users\x\AppData\Roaming\Wvaqucuge
2017-01-01 16:08 - 2017-01-01 18:28 - 00000000 ____D C:\Program Files (x86)\Qphchfepy
2017-01-01 16:08 - 2017-01-01 17:17 - 00000000 ____D C:\Users\x\AppData\Local\Cdryanerguther
2017-01-01 16:12 - 2017-01-01 16:12 - 00001526 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器.lnk
2017-01-01 16:12 - 2017-01-01 16:12 - 00000837 _____ C:\Users\x\AppData\Roaming\Microsoft\Windows\Start Menu\żěŃą.lnk
2017-01-01 16:12 - 2017-01-01 16:12 - 00000000 ____D C:\Users\x\AppData\Local\UCBrowser
2017-01-01 16:12 - 2017-01-01 16:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UC浏览器
2017-01-01 16:11 - 2017-01-01 16:42 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2017-01-01 16:11 - 2017-01-01 16:11 - 00000000 ____D C:\Program Files\żěŃą
2017-01-01 16:10 - 2017-01-01 16:10 - 00000000 ____D C:\ProgramData\ProductData
2017-01-01 16:10 - 2017-01-01 16:10 - 00000000 ____D C:\Program Files (x86)\Therlaiedstation Agent
2017-01-01 16:10 - 2017-01-01 16:10 - 00000000 ____D C:\Program Files (x86)\Maoha
2017-01-01 16:09 - 2017-01-01 18:48 - 00016710 _____ C:\Windows\System32\Tasks\860420v3a975h48
2017-01-01 17:11 - 2017-01-01 17:11 - 00000000 ____D C:\Program Files\OXFNV2X70U
2017-01-01 17:11 - 2017-01-01 17:11 - 00000000 ____D C:\Program Files\O0LTLDI97Y
2017-01-01 17:11 - 2017-01-01 17:11 - 00000000 ____D C:\Program Files\3Z60ATVZPE
2017-01-01 17:09 - 2017-01-01 18:28 - 00000000 ____D C:\Program Files\SpaceSoundPro
2017-01-01 17:17 - 2017-01-01 17:17 - 00000000 ____D C:\Program Files (x86)\Coverly Collector
2017-01-01 17:16 - 2017-01-01 18:26 - 00000000 ____D C:\Program Files\pclient
2017-01-01 18:32 - 2017-01-01 18:46 - 00000000 ____D C:\Users\x\AppData\Roaming\KuaiZip
2017-01-01 18:30 - 2017-01-01 18:30 - 00003476 _____ C:\Windows\System32\Tasks\UCBrowserSecureUpdater
2017-01-01 18:30 - 2017-01-01 16:11 - 00092832 _____ (WinMount International Inc) C:\Windows\system32\Drivers\KuaiZipDrive.sys
U1 ucdrv; C:\Program Files (x86)\UCBrowser\Security:ucdrv-x64.sys [23652 ] (UC Web Inc.) <==== UWAGA
S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [X]
R2 Reatotainatqot; C:\Program Files (x86)\Qphchfepy\shrcll.dll [180224 2017-01-01] () [Brak podpisu cyfrowego]
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP2DAqp-XHW6O6ALVpuKMYLBCXvPWolIZEoXVkFTLpY9j8UlGaWMO1Q6sxayiQ2ko1WQupX-FqVq3bb8rWGyt5eoVXRBb_sNRhp5wq402NKO8WrzBBdiieW23F6WTMppi_Pkmc6aq-HoNFr7dhF5XpioC87nGNpS5IKFdpAt_fOw3lzoQz9Uw,
CHR StartupUrls: ChromeDefaultData -> "hxxp://google.pl/"
CHR Profile: C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-01-01] <==== UWAGA
CHR Extension: (Dokumenty Google) - C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-01]
CHR Extension: (Dysk Google) - C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-01]
CHR Extension: (YouTube) - C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-01]
CHR Extension: (Płatności w sklepie Chrome Web Store) - C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-01]
CHR Extension: (Gmail) - C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-01]
CHR Extension: (Chrome Media Router) - C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-01]
CHR Profile: C:\Users\x\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2 [2017-01-01] <==== UWAGA
Toolbar: HKU\S-1-5-21-1784672152-1549703708-2963603635-1000 -> Brak nazwy - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - Brak pliku
HKU\S-1-5-21-1784672152-1549703708-2963603635-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP2DAqp-XHW6O6ALVpuKMYLBCXvPWolIZEoXVkFTLpY9j8UlGaWMO1Q6sxayiQ2ko1WQupX-FqVq3bb8rWGyt5eoVXRA38j1cnTTj__2AqRQk-FNBe8Xefp7r644JrRmavpx-A-FiobbLYlXNVVrjPuC5oqXYSdKOy5BZfqF9Ed0KMz4LIw4E,&q={searchTerms}
HKU\S-1-5-21-1784672152-1549703708-2963603635-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP2DAqp-XHW6O6ALVpuKMYLBCXvPWolIZEoXVkFTLpY9j8UlGaWMO1Q6sxayiQ2ko1WQupX-FqVq3bb8rWGyt5eoVXSMR9DdBUIMDhHqL2QVB_eWcGyGWMBw5RQuEgxlVjkHC0tCJX-VLYNH0FNOOURX9Mu5WQ1dB0xnY57q3ua07vFg4-EJg,
HKU\S-1-5-21-1784672152-1549703708-2963603635-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP2DAqp-XHW6O6ALVpuKMYLBCXvPWolIZEoXVkFTLpY9j8UlGaWMO1Q6sxayiQ2ko1WQupX-FqVq3bb8rWGyt5eoVXSMR9DdBUIMDhHqL2QVB_eWcGyGWMBw5RQuEgxlVjkHC0tCJX-VLYNH0FNOOURX9Mu5WQ1dB0xnY57q3ua07vFg4-EJg,
HKU\S-1-5-21-1784672152-1549703708-2963603635-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP2DAqp-XHW6O6ALVpuKMYLBCXvPWolIZEoXVkFTLpY9j8UlGaWMO1Q6sxayiQ2ko1WQupX-FqVq3bb8rWGyt5eoVXRA38j1cnTTj__2AqRQk-FNBe8Xefp7r644JrRmavpx-A-FiobbLYlXNVVrjPuC5oqXYSdKOy5BZfqF9Ed0KMz4LIw4E,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKU\S-1-5-21-1784672152-1549703708-2963603635-1000 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKU\S-1-5-21-1784672152-1549703708-2963603635-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP2DAqp-XHW6O6ALVpuKMYLBCXvPWolIZEoXVkFTLpY9j8UlGaWMO1Q6sxayiQ2ko1WQupX-FqVq3bb8rWGyt5eoVXRA38j1cnTTj__2AqRQk-FNBe8Xefp7r644JrRmavpx-A-FiobbLYlXNVVrjPuC5oqXYSdKOy5BZfqF9Ed0KMz4LIw4E,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1784672152-1549703708-2963603635-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBP2DAqp-XHW6O6ALVpuKMYLBCXvPWolIZEoXVkFTLpY9j8UlGaWMO1Q6sxayiQ2ko1WQupX-FqVq3bb8rWGyt5eoVXRA38j1cnTTj__2AqRQk-FNBe8Xefp7r644JrRmavpx-A-FiobbLYlXNVVrjPuC5oqXYSdKOy5BZfqF9Ed0KMz4LIw4E,&q={searchTerms}
GroupPolicy: Ograniczenia - Windows Defender <======= UWAGA
ShellExecuteHooks: Brak nazwy - {4C92D118-CCF4-11E6-965E-64006A5CFC23} - C:\Users\x\AppData\Roaming\Wvaqucuge\Chicerry.dll -> Brak pliku
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => C:\Program Files\żěŃą\X64\KZipShell.dll [2017-01-01] ()
HKLM\...\RunOnce: [OTUTPRODUCT_4Y5GZ] => C:\Users\x\AppData\Local\Temp\378N1EY68Y.exe [243200 2017-01-01] (OK) <===== UWAGA
HKLM\...\RunOnce: [OTUTPRODUCT_1HFB2] => C:\Users\x\AppData\Local\Temp\ZV3JKYAZR5.exe [243200 2017-01-01] (OK) <===== UWAGA
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{918FCF15-06EC-42A7-B8A4-8DC1C9B1B816}
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{918FCF15-06EC-42A7-B8A4-8DC1C9B1B816}
DeleteKey: HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes
DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes
FirewallRules: [TCP Query User{62AC7CA6-06E3-4093-A6E9-EFBCBBF5D88E}C:\users\x\appdata\local\temp\is-8q5kq.tmp\download\minithunderplatform.exe] => C:\users\x\appdata\local\temp\is-8q5kq.tmp\download\minithunderplatform.exe
FirewallRules: [UDP Query User{E35E1BAC-4571-48C7-AB04-18CE5237CA6A}C:\users\x\appdata\local\temp\is-8q5kq.tmp\download\minithunderplatform.exe] => C:\users\x\appdata\local\temp\is-8q5kq.tmp\download\minithunderplatform.exe
FirewallRules: [{4C9C91E1-BE5E-459C-AEFF-E172E9B19596}] => C:\Program Files (x86)\Maoha\MaohaAP\MaohaWifiSvr.exe
FirewallRules: [{4593762F-4E04-48BA-9462-60A77922801C}] => C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
FirewallRules: [{7E3DB44D-F9AA-4F9D-94F8-C3907C75E7C4}] => C:\Program Files (x86)\UCBrowser\Application\Downloader\download\MiniThunderPlatform.exe
FirewallRules: [{2AACDDBD-A9B2-4D04-90A1-0B8401C1CBD5}] => C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe
HOSTS:
EmptyTemp:
>>Menu Notatnika >> Plik >>
>>Zapisz jako >>
Nazwa pliku:
fixlistZapisz jako typ:
Dokumenty tekstoweKodowanie:
UTF-8>>Zapisz
Plik umieść w C:\Users\x\Desktop
Uruchom FRST i kliknij przycisk Fix (NAPRAW).
3) Zrób nowe logi FRST.
Przed skanem zaznacz "Addition.txt" oraz "Shortcut.txt"
.