ADVERTISEMENT

Fixlog.txt

Wirus podmieniający numery kont bankowych – jak skutecznie usunąć z komputera?

Czy w fixlogu wszystko jest okey?


Download file - link to post

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014
Ran by Foka at 2014-09-16 17:39:09 Run:1
Running from C:\Users\Foka\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Task: {4B842A86-4600-4164-8D26-AFDD2B1D4097} - System32\Tasks\WinSTAT = & gt; C:\ProgramData\WinSTAT\WinSTAT.exe [2014-09-05] (Microsoft® Corporation)
HKLM-x32\...\Run: [Windows(R) Statistics Service] = & gt; C:\ProgramData\WinSTAT\WinSTAT.exe [1460224 2014-09-05] (Microsoft® Corporation)
HKU\S-1-5-21-1271825148-1157551935-490607080-1000\...\Run: [Akamai NetSession Interface] = & gt; C:\Users\Foka\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1271825148-1157551935-490607080-1000\...\Run: [Windows(R) Statistics Service] = & gt; C:\ProgramData\WinSTAT\WinSTAT.exe [1460224 2014-09-05] (Microsoft® Corporation)
CHR Extension: (AVG Secure Search) - C:\Users\Foka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2014-08-18]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2014-09-05 18:59 - 2014-09-09 13:49 - 00003074 _____ () C:\Windows\System32\Tasks\WinSTAT
2014-09-05 18:59 - 2014-09-05 19:07 - 00000000 ____D () C:\ProgramData\WinSTAT
EmptyTemp:
*****************

" HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4B842A86-4600-4164-8D26-AFDD2B1D4097} " = & gt; Key deleted successfully.
" HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B842A86-4600-4164-8D26-AFDD2B1D4097} " = & gt; Key deleted successfully.
C:\Windows\System32\Tasks\WinSTAT = & gt; Moved successfully.
" HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinSTAT " = & gt; Key deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Windows(R) Statistics Service = & gt; value deleted successfully.
HKU\S-1-5-21-1271825148-1157551935-490607080-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface = & gt; value deleted successfully.
HKU\S-1-5-21-1271825148-1157551935-490607080-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Windows(R) Statistics Service = & gt; value deleted successfully.
C:\Users\Foka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof = & gt; Moved successfully.
EagleX64 = & gt; Service deleted successfully.
nvlddmkm = & gt; Service deleted successfully.
nvvad_WaveExtensible = & gt; Service deleted successfully.
VGPU = & gt; Service deleted successfully.
" C:\Windows\System32\Tasks\WinSTAT " = & gt; File/Directory not found.

" C:\ProgramData\WinSTAT " directory move:

C:\ProgramData\WinSTAT\source.ini = & gt; Moved successfully.
C:\ProgramData\WinSTAT\SYS.exe = & gt; Moved successfully.
C:\ProgramData\WinSTAT\uid.ini = & gt; Moved successfully.
C:\ProgramData\WinSTAT\WinSTAT.exe = & gt; Moved successfully.
C:\ProgramData\WinSTAT\pids\6124.pid = & gt; Moved successfully.
C:\ProgramData\WinSTAT\data\winhost32.exe = & gt; Moved successfully.
Could not move " C:\ProgramData\WinSTAT " directory. = & gt; Scheduled to move on reboot.

EmptyTemp: = & gt; Removed 371.7 MB temporary data.

= & gt; Result of Scheduled Files to move (Boot Mode: Normal) (Date & Time: 2014-09-16 17:44:38) & lt; =

C:\ProgramData\WinSTAT = & gt; Is moved successfully.

==== End of Fixlog ====