Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 08-10-2017 Uruchomiony przez Adrian (09-10-2017 19:22:59) Run:3 Uruchomiony z C:\Users\Adrian\Desktop Załadowane profile: Adrian (Dostępne profile: Adrian & Administrator) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: Task: {4D04664E-D746-4DD6-84B5-4F705E0948E2} - System32\Tasks\DentaCopy Race Contract => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\DentaCopy Race Contract\DentaCopy Race Contract.dll",zaOcqA <==== UWAGA C:\Program Files\DentaCopy Race Contract HKLM\...\RunOnce: [DESKTOP-M3GD7NQ] => C:\WINDOWS\TEMP\gC3AD.tmp.exe [212992 2017-10-09] () <==== UWAGA HKLM\ DisallowedCertificates: 03D22C9C66915D58C88912B64C1F984B8344EF09 (Comodo Security Solutions) <==== UWAGA HKLM\ DisallowedCertificates: 0F684EC1163281085C6AF20528878103ACEFCAAB (F-Secure Corporation) <==== UWAGA HKLM\ DisallowedCertificates: 1667908C9E22EFBD0590E088715CC74BE4C60884 (FRISK Software International/F-Prot) <==== UWAGA HKLM\ DisallowedCertificates: 18DEA4EFA93B06AE997D234411F3FD72A677EECE (Bitdefender SRL) <==== UWAGA HKLM\ DisallowedCertificates: 2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF (G DATA Software AG) <==== UWAGA HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== UWAGA HKLM\ DisallowedCertificates: 31AC96A6C17C425222C46D55C3CCA6BA12E54DAF (Symantec Corporation) <==== UWAGA HKLM\ DisallowedCertificates: 331E2046A1CCA7BFEF766724394BE6112B4CA3F7 (Trend Micro) <==== UWAGA HKLM\ DisallowedCertificates: 3353EA609334A9F23A701B9159E30CB6C22D4C59 (Webroot Inc.) <==== UWAGA HKLM\ DisallowedCertificates: 373C33726722D3A5D1EDD1F1585D5D25B39BEA1A (SUPERAntiSpyware.com) <==== UWAGA HKLM\ DisallowedCertificates: 3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F (Kaspersky Lab) <==== UWAGA HKLM\ DisallowedCertificates: 3D496FA682E65FC122351EC29B55AB94F3BB03FC (AVG Technologies CZ) <==== UWAGA HKLM\ DisallowedCertificates: 4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 (PC Tools) <==== UWAGA HKLM\ DisallowedCertificates: 42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 (K7 Computing Pvt Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 4420C99742DF11DD0795BC15B7B0ABF090DC84DF (Doctor Web Ltd.) <==== UWAGA HKLM\ DisallowedCertificates: 4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF (Emsisoft Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 5240AB5B05D11B37900AC7712A3C6AE42F377C8C (Check Point Software Technologies Ltd.) <==== UWAGA HKLM\ DisallowedCertificates: 5DD3D41810F28B2A13E9A004E6412061E28FA48D (Emsisoft Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 7457A3793086DBB58B3858D6476889E3311E550E (K7 Computing Pvt Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 76A9295EF4343E12DFC5FE05DC57227C1AB00D29 (BullGuard Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== UWAGA HKLM\ DisallowedCertificates: 872CD334B7E7B3C3D1C6114CD6B221026D505EAB (Comodo Security Solutions) <==== UWAGA HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== UWAGA HKLM\ DisallowedCertificates: 9132E8B079D080E01D52631690BE18EBC2347C1E (Adaware Software) <==== UWAGA HKLM\ DisallowedCertificates: 982D98951CF3C0CA2A02814D474A976CBFF6BDB1 (Safer Networking Ltd.) <==== UWAGA HKLM\ DisallowedCertificates: 9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 (Webroot Inc.) <==== UWAGA HKLM\ DisallowedCertificates: 9C43F665E690AB4D486D4717B456C5554D4BCEB5 (ThreatTrack Security) <==== UWAGA HKLM\ DisallowedCertificates: 9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 (CURIOLAB S.M.B.A.) <==== UWAGA HKLM\ DisallowedCertificates: A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 (Avira Operations GmbH & Co. KG) <==== UWAGA HKLM\ DisallowedCertificates: A5341949ABE1407DD7BF7DFE75460D9608FBC309 (BullGuard Ltd) <==== UWAGA HKLM\ DisallowedCertificates: A59CC32724DD07A6FC33F7806945481A2D13CA2F (ESET) <==== UWAGA HKLM\ DisallowedCertificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== UWAGA HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== UWAGA HKLM\ DisallowedCertificates: AD96BB64BA36379D2E354660780C2067B81DA2E0 (Symantec Corporation) <==== UWAGA HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== UWAGA HKLM\ DisallowedCertificates: CDC37C22FE9272D8F2610206AD397A45040326B8 (Trend Micro) <==== UWAGA HKLM\ DisallowedCertificates: D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 (Kaspersky Lab) <==== UWAGA HKLM\ DisallowedCertificates: DB303C9B61282DE525DC754A535CA2D6A9BD3D87 (ThreatTrack Security) <==== UWAGA HKLM\ DisallowedCertificates: DB77E5CFEC34459146748B667C97B185619251BA (Avast Antivirus/Software) <==== UWAGA HKLM\ DisallowedCertificates: E22240E837B52E691C71DF248F12D27F96441C00 (Total Defense, Inc.) <==== UWAGA HKLM\ DisallowedCertificates: E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF (AVG Technologies CZ) <==== UWAGA HKLM\ DisallowedCertificates: ED841A61C0F76025598421BC1B00E24189E68D54 (Bitdefender SRL) <==== UWAGA HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== UWAGA HKLM\ DisallowedCertificates: FBB42F089AF2D570F2BF6F493D107A3255A9BB1A (Panda Security S.L) <==== UWAGA HKLM\ DisallowedCertificates: FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 (Doctor Web Ltd.) <==== UWAGA HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA R2 SecureIM; C:\ProgramData\SecureIM.exe [2908824 2017-10-08] (Adobe Systems Incorporated) <==== UWAGA C:\ProgramData\SecureIM.exe C:\Program Files (x86)\Everness C:\Users\Adrian\AppData\Local\Everness C:\Users\Adrian\AppData\Roaming\Everness C:\Program Files (x86)\Firefox C:\Users\Adrian\AppData\Local\Firefox C:\Users\Adrian\AppData\Roaming\Firefox HKU\S-1-5-21-1123165568-1724948108-1352480687-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Everness\Application\chrome.exe <==== UWAGA IFEO\DisplaySwitch.exe: [Debugger] IFEO\taskmgr.exe: [Debugger] 2017-10-09 16:54 - 2017-10-09 16:54 - 000245776 _____ (Mozilla) C:\Users\Adrian\Downloads\Firefox Installer.exe 2017-10-09 16:52 - 2017-10-09 16:52 - 000000000 ____D C:\Program Files (x86)\TQoarIXzU 2017-10-09 16:52 - 2017-10-09 16:52 - 000000000 ____D C:\Program Files (x86)\ICBaloCIDxXU2 2017-10-09 16:52 - 2017-10-09 16:52 - 000000000 ____D C:\Program Files (x86)\CKCpTyVyQIE 2017-10-09 16:52 - 2017-10-09 16:52 - 000000000 ____D C:\Program Files (x86)\AvMVIUoBwtUn 2017-10-08 14:32 - 2017-10-08 14:32 - 000000000 ____D C:\Users\Adrian\AppData\Roaming\lp2p5taby2n 2017-10-08 14:32 - 2017-10-08 14:32 - 000000000 ____D C:\Users\Adrian\AppData\Roaming\34ylgubbfdc 2017-10-08 14:32 - 2017-10-08 14:32 - 000000000 ____D C:\Users\Adrian\AppData\Roaming\0gmhtlqkfnc 2017-10-08 14:32 - 2017-10-08 14:32 - 000000000 ____D C:\ProgramData\f8e566b8-7433-0 2017-10-08 14:32 - 2017-10-08 14:32 - 000000000 ____D C:\ProgramData\f8e566b8-0ba1-1 2017-10-08 14:32 - 2017-10-08 14:32 - 000000000 ____D C:\Program Files\R5HMV2S75W 2017-10-08 14:32 - 2017-10-08 14:32 - 000000000 ____D C:\Program Files\2ZR0WTQQ80 C:\ProgramData\Microleaves C:\Users\Adrian\AppData\Roaming\Microleaves C:\Program Files (x86)\ShutdownTime C:\Users\Adrian\AppData\Local\Microsoft\Windows\GameExplorer\{A20033EC-848B-4990-955E-D40CD74FFC50}\PlayTasks\2\Readme.lnk C:\Users\Adrian\AppData\Local\Microsoft\Windows\GameExplorer\{A20033EC-848B-4990-955E-D40CD74FFC50}\PlayTasks\1\Manual.lnk C:\Users\Adrian\AppData\Local\Microsoft\Windows\GameExplorer\{A20033EC-848B-4990-955E-D40CD74FFC50}\PlayTasks\0\Play.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PLAY\Warlords Battlecry III\Podręcznik Gracza.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PLAY\Warlords Battlecry III\Warlords Battlecry III.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Uninstall Warlords Battlecry 3.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Warlords Battlecry 3.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Documents\Manual.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Documents\Readme.lnk DeleteKey: HKCU\Software\Eastness DeleteKey: HKCU\Software\Firefox DeleteKey: HKLM\SOFTWARE\WOW6432Node\Eastness DeleteKey: HKLM\SOFTWARE\WOW6432Node\Firefox DeleteKey: HKCU\Software\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Adrian\AppData\Local CMD: dir /a C:\Users\Adrian\AppData\LocalLow CMD: dir /a C:\Users\Adrian\AppData\Roaming CMD: netsh advfirewall reset Hosts: EmptyTemp:̩ ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{4D04664E-D746-4DD6-84B5-4F705E0948E2} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D04664E-D746-4DD6-84B5-4F705E0948E2} => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\DentaCopy Race Contract => pomyślnie przeniesiono HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DentaCopy Race Contract => klucz pomyślnie usunięto C:\Program Files\DentaCopy Race Contract => pomyślnie przeniesiono HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DESKTOP-M3GD7NQ => Wartość pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\03D22C9C66915D58C88912B64C1F984B8344EF09 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\0F684EC1163281085C6AF20528878103ACEFCAAB => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\1667908C9E22EFBD0590E088715CC74BE4C60884 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\18DEA4EFA93B06AE997D234411F3FD72A677EECE => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\249BDA38A611CD746A132FA2AF995A2D3C941264 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\31AC96A6C17C425222C46D55C3CCA6BA12E54DAF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\331E2046A1CCA7BFEF766724394BE6112B4CA3F7 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3353EA609334A9F23A701B9159E30CB6C22D4C59 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\373C33726722D3A5D1EDD1F1585D5D25B39BEA1A => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3D496FA682E65FC122351EC29B55AB94F3BB03FC => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4420C99742DF11DD0795BC15B7B0ABF090DC84DF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5240AB5B05D11B37900AC7712A3C6AE42F377C8C => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5DD3D41810F28B2A13E9A004E6412061E28FA48D => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\7457A3793086DBB58B3858D6476889E3311E550E => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\76A9295EF4343E12DFC5FE05DC57227C1AB00D29 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\775B373B33B9D15B58BC02B184704332B97C3CAF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\872CD334B7E7B3C3D1C6114CD6B221026D505EAB => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\88AD5DFE24126872B33175D1778687B642323ACF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9132E8B079D080E01D52631690BE18EBC2347C1E => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\982D98951CF3C0CA2A02814D474A976CBFF6BDB1 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9C43F665E690AB4D486D4717B456C5554D4BCEB5 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A5341949ABE1407DD7BF7DFE75460D9608FBC309 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A59CC32724DD07A6FC33F7806945481A2D13CA2F => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD4C5429E10F4FF6C01840C20ABA344D7401209F => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD96BB64BA36379D2E354660780C2067B81DA2E0 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\CDC37C22FE9272D8F2610206AD397A45040326B8 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB303C9B61282DE525DC754A535CA2D6A9BD3D87 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB77E5CFEC34459146748B667C97B185619251BA => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E22240E837B52E691C71DF248F12D27F96441C00 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\ED841A61C0F76025598421BC1B00E24189E68D54 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\F83099622B4A9F72CB5081F742164AD1B8D048C9 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FBB42F089AF2D570F2BF6F493D107A3255A9BB1A => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 => klucz pomyślnie usunięto HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Services\SecureIM => klucz pomyślnie usunięto SecureIM => serwis pomyślnie usunięto C:\ProgramData\SecureIM.exe => pomyślnie przeniesiono "C:\Program Files (x86)\Everness" => nie znaleziono. "C:\Users\Adrian\AppData\Local\Everness" => nie znaleziono. "C:\Users\Adrian\AppData\Roaming\Everness" => nie znaleziono. C:\Program Files (x86)\Firefox => pomyślnie przeniesiono C:\Users\Adrian\AppData\Local\Firefox => pomyślnie przeniesiono C:\Users\Adrian\AppData\Roaming\Firefox => pomyślnie przeniesiono HKU\S-1-5-21-1123165568-1724948108-1352480687-1001\SOFTWARE\Clients\StartMenuInternet\ChromeHTML => klucz pomyślnie usunięto HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\DisplaySwitch.exe => klucz pomyślnie usunięto HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe => klucz pomyślnie usunięto C:\Users\Adrian\Downloads\Firefox Installer.exe => pomyślnie przeniesiono "C:\Program Files (x86)\TQoarIXzU" => nie znaleziono. "C:\Program Files (x86)\ICBaloCIDxXU2" => nie znaleziono. "C:\Program Files (x86)\CKCpTyVyQIE" => nie znaleziono. "C:\Program Files (x86)\AvMVIUoBwtUn" => nie znaleziono. C:\Users\Adrian\AppData\Roaming\lp2p5taby2n => pomyślnie przeniesiono C:\Users\Adrian\AppData\Roaming\34ylgubbfdc => pomyślnie przeniesiono C:\Users\Adrian\AppData\Roaming\0gmhtlqkfnc => pomyślnie przeniesiono C:\ProgramData\f8e566b8-7433-0 => pomyślnie przeniesiono C:\ProgramData\f8e566b8-0ba1-1 => pomyślnie przeniesiono C:\Program Files\R5HMV2S75W => pomyślnie przeniesiono C:\Program Files\2ZR0WTQQ80 => pomyślnie przeniesiono C:\ProgramData\Microleaves => pomyślnie przeniesiono C:\Users\Adrian\AppData\Roaming\Microleaves => pomyślnie przeniesiono C:\Program Files (x86)\ShutdownTime => pomyślnie przeniesiono C:\Users\Adrian\AppData\Local\Microsoft\Windows\GameExplorer\{A20033EC-848B-4990-955E-D40CD74FFC50}\PlayTasks\2\Readme.lnk => pomyślnie przeniesiono C:\Users\Adrian\AppData\Local\Microsoft\Windows\GameExplorer\{A20033EC-848B-4990-955E-D40CD74FFC50}\PlayTasks\1\Manual.lnk => pomyślnie przeniesiono C:\Users\Adrian\AppData\Local\Microsoft\Windows\GameExplorer\{A20033EC-848B-4990-955E-D40CD74FFC50}\PlayTasks\0\Play.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PLAY\Warlords Battlecry III\Podręcznik Gracza.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PLAY\Warlords Battlecry III\Warlords Battlecry III.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Uninstall Warlords Battlecry 3.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Warlords Battlecry 3.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Documents\Manual.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com\Warlords Battlecry 3\Documents\Readme.lnk => pomyślnie przeniesiono HKCU\Software\Eastness => klucz nie znaleziono. HKCU\Software\Firefox => klucz pomyślnie usunięto HKLM\SOFTWARE\WOW6432Node\Eastness => klucz nie znaleziono. HKLM\SOFTWARE\WOW6432Node\Firefox => klucz pomyślnie usunięto HKCU\Software\Google => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Google => klucz pomyślnie usunięto ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\Program Files 09.10.2017 19:23 . 09.10.2017 19:23 .. 07.10.2016 17:38 7-Zip 23.09.2016 17:34 ASRock Utility 18.03.2017 23:03 Common Files 23.09.2016 20:49 CPUID 24.09.2016 18:17 DAEMON Tools Lite 18.03.2017 23:01 174 desktop.ini 14.04.2017 16:19 GIANTS Software 19.11.2016 22:35 GIMP 2 28.05.2017 11:32 Intel 15.09.2017 18:08 Internet Explorer 08.10.2017 14:35 LaCie Private Public 09.10.2017 16:55 Mozilla Firefox 28.05.2017 12:18 MSBuild 09.10.2017 18:03 NVIDIA Corporation 28.05.2017 11:29 Realtek 28.05.2017 12:18 Reference Assemblies 30.08.2017 08:39 Rockstar Games 08.10.2017 17:51 Uninstall Information 13.05.2017 18:42 UNP 13.07.2017 00:38 Windows Defender 15.09.2017 18:08 Windows Mail 20.03.2017 06:00 Windows Media Player 18.03.2017 23:03 Windows Multimedia Platform 28.05.2017 11:44 Windows NT 15.09.2017 18:08 Windows Photo Viewer 18.03.2017 23:03 Windows Portable Devices 18.03.2017 23:03 Windows Security 18.03.2017 23:03 Windows Sidebar 02.10.2017 20:38 WindowsApps 18.03.2017 23:03 WindowsPowerShell 24.09.2016 18:23 WinRAR 1 File(s) 174 bytes 32 Dir(s) 53˙202˙747˙392 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\Program Files (x86) 09.10.2017 19:23 . 09.10.2017 19:23 .. 23.09.2016 17:34 ASRock Utility 19.08.2017 13:20 Common Files 18.03.2017 23:01 174 desktop.ini 13.03.2017 18:12 Geeks3D 23.09.2016 17:44 GIGABYTE 21.08.2017 17:02 GtkSharp 15.08.2017 11:15 InstallShield Installation Information 23.09.2016 17:36 Intel 15.09.2017 18:08 Internet Explorer 13.05.2017 20:10 Java 09.10.2017 16:59 Microsoft Application Compatibility Toolkit 11.03.2017 12:13 Microsoft Visual Studio 18.03.2017 23:03 Microsoft.NET 09.10.2017 17:14 Mozilla Maintenance Service 28.05.2017 12:18 MSBuild 02.01.2017 21:18 Notepad++ 09.10.2017 18:03 NVIDIA Corporation 13.11.2016 14:05 OpenAL 28.04.2017 15:46 OSCAR Editor X7 24.09.2016 17:04 OscarEditor 23.09.2016 18:19 PLAY ONLINE 19.08.2017 13:20 Razer 23.09.2016 17:33 Realtek 28.05.2017 12:18 Reference Assemblies 24.10.2016 12:57 RocketDock 30.08.2017 08:39 Rockstar Games 21.09.2017 21:07 Steam 28.04.2017 15:39 System 01.10.2016 20:14 Ubisoft 28.05.2017 11:29 Uninstall Information 18.02.2017 19:23 USB Vibration 09.10.2017 18:04 VulkanRT 13.07.2017 00:38 Windows Defender 15.09.2017 18:08 Windows Mail 20.03.2017 06:00 Windows Media Player 18.03.2017 23:03 Windows Multimedia Platform 18.03.2017 23:03 Windows NT 15.09.2017 18:08 Windows Photo Viewer 18.03.2017 23:03 Windows Portable Devices 18.03.2017 23:03 Windows Sidebar 18.03.2017 23:03 WindowsPowerShell 1 File(s) 174 bytes 42 Dir(s) 53˙202˙743˙296 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files\Common Files\System" ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\Program Files\Common Files\System 20.03.2017 05:59 . 20.03.2017 05:59 .. 28.05.2017 12:24 ado 18.03.2017 22:59 32˙768 DirectDB.dll 20.03.2017 05:59 en-US 20.03.2017 05:59 msadc 20.03.2017 05:59 Ole DB 20.03.2017 05:59 pl-PL 18.03.2017 22:57 854˙528 wab32.dll 18.03.2017 22:57 964˙096 wab32res.dll 3 File(s) 1˙851˙392 bytes 7 Dir(s) 53˙202˙747˙392 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files\System" ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\Program Files (x86)\Common Files\System 20.03.2017 05:59 . 20.03.2017 05:59 .. 28.05.2017 12:24 ado 18.03.2017 22:59 27˙648 DirectDB.dll 20.03.2017 05:59 en-US 20.03.2017 05:59 msadc 20.03.2017 05:59 Ole DB 20.03.2017 05:59 pl-PL 18.03.2017 22:58 741˙888 wab32.dll 18.03.2017 22:58 964˙096 wab32res.dll 3 File(s) 1˙733˙632 bytes 7 Dir(s) 53˙202˙743˙296 bytes free ========= Koniec CMD: ========= ========= dir /a C:\ProgramData ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\ProgramData 09.10.2017 19:23 . 09.10.2017 19:23 .. 25.05.2017 17:30 .mono 26.04.2017 15:33 Apple 15.08.2017 09:03 ASRock 23.09.2016 20:08 AVAST Software 06.02.2017 16:21 Caphyon 19.01.2017 23:04 CDProjekt RED 13.11.2016 14:05 Codemasters 08.08.2017 18:23 Common Diagnostics 23.09.2016 20:51 DAEMON Tools Lite 23.09.2016 17:11 Dane aplikacji [C:\ProgramData] 23.09.2016 18:19 DatacardService 08.08.2017 18:23 Delphi 23.09.2016 17:11 Dokumenty [C:\Users\Public\Documents] 28.05.2017 11:29 0 DP45977C.lfl 28.04.2017 15:46 Electronic Arts 23.07.2017 22:40 Football Manager 2017 19.08.2017 22:08 GOG.com 09.10.2017 18:26 36 hgf.3dew 04.10.2016 19:19 HP 23.09.2016 17:44 Intel 23.09.2016 17:36 Intel(R) Update Manager 15.02.2017 12:39 IsolatedStorage 13.08.2017 17:00 Malwarebytes 05.10.2016 20:03 McAfee 23.09.2016 17:11 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 09.10.2017 16:59 Microsoft 28.05.2017 11:47 Microsoft OneDrive 08.08.2017 18:23 88 Microsoft.SqlServer.Compact.351.32.bc 28.04.2017 15:46 Norton 23.09.2016 17:37 NortonInstaller 09.10.2017 17:13 8 ntuser.pol 09.10.2017 19:23 NVIDIA 09.10.2017 18:05 NVIDIA Corporation 13.01.2017 14:05 10˙108 NvTelemetryContainer.log 06.01.2017 20:42 4˙604 NvTelemetryContainer.log_backup1 13.05.2017 20:10 Oracle 06.06.2017 21:05 Orbit 19.08.2017 16:54 Origin 09.10.2017 16:50 Package Cache 23.09.2016 18:19 PLAY ONLINE 23.09.2016 17:11 Pulpit [C:\Users\Public\Desktop] 19.08.2017 13:20 Razer 28.05.2017 11:42 regid.1991-06.com.microsoft 15.07.2017 22:10 Sniper Elite 4 16.10.2016 13:49 Socialclub 18.03.2017 23:03 SoftwareDistribution 26.09.2016 19:07 Steam 23.09.2016 17:11 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 28.05.2017 11:45 USOPrivate 28.05.2017 11:45 USOShared 20.03.2017 06:01 WindowsHolographicDevices 6 File(s) 14˙844 bytes 47 Dir(s) 53˙202˙739˙200 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\Adrian\AppData\Local ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\Users\Adrian\AppData\Local 09.10.2017 19:23 . 09.10.2017 19:23 .. 25.09.2017 18:51 2K Games 08.10.2017 14:05 AdvinstAnalytics 22.03.2017 14:45 Alamer99 23.09.2016 19:37 CEF 14.12.2016 16:48 Chromium 25.05.2017 17:30 Colossal Order 19.08.2017 12:56 Comms 19.08.2017 16:34 ConnectedDevicesPlatform 09.10.2017 16:56 CrashDumps 28.05.2017 11:30 Dane aplikacji [C:\Users\Adrian\AppData\Local] 16.12.2016 15:58 Daybreak Game Company 28.05.2017 17:36 DBG 06.10.2017 18:42 Diagnostics 24.09.2016 18:18 Disc_Soft_Ltd 09.10.2017 19:21 ElevatedDiagnostics 19.11.2016 22:36 fontconfig 19.01.2017 23:05 GalaxyCommunicationService 19.11.2016 22:36 gegl-0.2 09.09.2017 20:22 GIANTS Editor 64bit 6.0.5 09.09.2017 20:22 GIANTS Editor 64bit 7.0.5 26.04.2017 17:56 GIANTS Editor 64bit 7.1.0 27.10.2016 19:22 GIANTSPackageRegistry 19.08.2017 21:02 GOG.com 28.04.2017 15:46 Google 08.10.2017 19:16 gtk-2.0 28.05.2017 11:30 Historia [C:\Users\Adrian\AppData\Local\Microsoft\Windows\History] 09.10.2017 18:20 201˙417 IconCache.db 15.02.2017 12:50 IIIQF 28.04.2017 16:46 Macromedia 08.10.2017 14:05 Microsoft 28.05.2017 11:45 MicrosoftEdge 04.11.2016 20:09 Microsoft_Corporation 23.09.2016 19:37 Mozilla 09.10.2017 18:47 NVIDIA 14.08.2017 17:45 NVIDIA Corporation 09.10.2017 16:51 Opera Software 22.11.2016 18:30 Origin 19.08.2017 12:55 Packages 09.10.2017 16:50 Programs 28.05.2017 11:45 Publishers 19.08.2017 13:20 Razer 08.10.2017 19:16 22˙747 recently-used.xbel 09.08.2017 17:19 Recovery 13.03.2017 14:56 7˙597 Resmon.ResmonCfg 15.08.2017 12:58 Rockstar Games 03.11.2016 14:03 Rockstar_Games 11.03.2017 12:14 ServiceHub 27.09.2017 13:46 SKIDROW 04.02.2017 20:45 SkinSoft 07.03.2017 13:25 Sniper3 15.07.2017 22:12 SniperElite4 12.09.2017 18:47 speech 23.07.2017 22:40 Sports Interactive 14.12.2016 16:48 Steam 09.10.2017 19:21 Temp 28.05.2017 11:30 Temporary Internet Files [C:\Users\Adrian\AppData\Local\Microsoft\Windows\INetCache] 01.10.2017 18:43 The Witcher 23.09.2016 17:14 TileDataLayer 02.09.2017 12:22 Ubisoft Game Launcher 14.05.2017 05:13 UNP 27.09.2017 13:24 VirtualStore 3 File(s) 231˙761 bytes 60 Dir(s) 53˙202˙735˙104 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\Adrian\AppData\LocalLow ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\Users\Adrian\AppData\LocalLow 08.10.2017 15:51 . 08.10.2017 15:51 .. 19.01.2017 23:04 CDProjektRED 16.12.2016 16:02 Daybreak Game Company 28.04.2017 16:46 Microsoft 08.10.2017 14:31 Mozilla 08.08.2017 17:58 Red Dot Games 05.11.2016 12:44 SKS 08.12.2016 14:25 Sony Online Entertainment 06.10.2016 19:46 Sun 09.10.2017 17:12 Temp 0 File(s) 0 bytes 11 Dir(s) 53˙202˙739˙200 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\Adrian\AppData\Roaming ========= Volume in drive C has no label. Volume Serial Number is C824-471A Directory of C:\Users\Adrian\AppData\Roaming 09.10.2017 19:23 . 09.10.2017 19:23 .. 25.05.2017 17:30 .mono 12.10.2016 18:12 A5BF9F 08.10.2017 14:06 Adobe 24.09.2016 18:18 DAEMON Tools Lite 08.08.2017 18:23 Delphi 08.10.2017 14:41 Easeware 09.12.2016 19:17 FiraxisLive 19.08.2017 21:40 FMRTE17 23.09.2016 17:29 Intel Corporation 15.02.2017 12:39 IsolatedStorage 21.08.2017 16:05 Launchpad 23.09.2016 18:04 Macromedia 09.08.2017 17:29 Microsoft 28.04.2017 15:48 Mozilla 26.01.2017 13:50 Notepad++ 09.10.2017 18:04 NVIDIA 13.08.2017 08:58 Obsidium 09.10.2017 16:51 Opera Software 19.08.2017 16:54 Origin 08.10.2017 14:35 PDSoft, Inc 25.09.2016 19:01 Skype 28.04.2017 15:46 SmartSteamEmu 14.11.2016 20:45 Steam 13.05.2017 20:10 Sun 24.10.2016 12:29 TeamViewer 08.10.2017 15:51 uTorrent 13.03.2017 15:04 Visual Studio Setup 11.03.2017 12:14 vstelemetry 17.11.2016 23:14 Wargaming.net 27.09.2016 17:46 WinRAR 0 File(s) 0 bytes 32 Dir(s) 53˙202˙731˙008 bytes free ========= Koniec CMD: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono Hosts pomyślnie przywrócono. =========== EmptyTemp: ========== BITS transfer queue => 8151040 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 21231617 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 710662 B Edge => 0 B Chrome => 0 B Firefox => 247496456 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 50054 B systemprofile32 => 128 B LocalService => 1650 B NetworkService => 0 B Adrian => 34702047 B Administrator => 0 B RecycleBin => 62036459 B EmptyTemp: => 357 MB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 19:23:30 ====