Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 27.01.2018 Uruchomiony przez Paweł (03-02-2018 18:03:52) Run:1 Uruchomiony z C:\Users\Paweł\Downloads Załadowane profile: Paweł (Dostępne profile: Paweł) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku Task: {9C3563E0-7F0C-4849-82AE-49C184276496} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA Task: {AB464B26-C529-4945-A057-1FBFB67FFC11} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> Brak pliku <==== UWAGA Task: {CB9C9C1A-2CD9-4747-B4A8-286A83EE9C62} - System32\Tasks\PawełMamboesSaddensV2 => rundll32.exe FootwornFetches.dll,main 7 1 <==== UWAGA C:\Users\Paweł\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AmazonShopping.lnk C:\Users\Paweł\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TripAdvisor.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Booking.com.lnk C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\SendTo\Android (ALLPlayer Pilot).lnk HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA SearchScopes: HKLM-x32 -> {10D9232D-2CBA-4864-8DB1-AFABE825FE16} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-3208788881-2320139874-4189469546-1001 -> {10D9232D-2CBA-4864-8DB1-AFABE825FE16} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw" => pomyślnie usunięto HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => klucz nie znaleziono "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => pomyślnie usunięto HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => klucz nie znaleziono "HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => pomyślnie usunięto HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => klucz nie znaleziono HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9C3563E0-7F0C-4849-82AE-49C184276496} => niepowodzenie przy usuwaniu klucz. ErrorCode1: 0x00000002 "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C3563E0-7F0C-4849-82AE-49C184276496}" => pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => klucz nie znaleziono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AB464B26-C529-4945-A057-1FBFB67FFC11}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB464B26-C529-4945-A057-1FBFB67FFC11}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CB9C9C1A-2CD9-4747-B4A8-286A83EE9C62}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB9C9C1A-2CD9-4747-B4A8-286A83EE9C62}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\PawełMamboesSaddensV2 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PawełMamboesSaddensV2" => pomyślnie usunięto C:\Users\Paweł\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AmazonShopping.lnk => pomyślnie przeniesiono C:\Users\Paweł\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TripAdvisor.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Booking.com.lnk => pomyślnie przeniesiono C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\SendTo\Android (ALLPlayer Pilot).lnk => pomyślnie przeniesiono HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== UWAGA => pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{10D9232D-2CBA-4864-8DB1-AFABE825FE16}" => pomyślnie usunięto HKLM\Software\Wow6432Node\Classes\CLSID\{10D9232D-2CBA-4864-8DB1-AFABE825FE16} => klucz nie znaleziono "HKU\S-1-5-21-3208788881-2320139874-4189469546-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{10D9232D-2CBA-4864-8DB1-AFABE825FE16}" => pomyślnie usunięto HKLM\Software\Classes\CLSID\{10D9232D-2CBA-4864-8DB1-AFABE825FE16} => klucz nie znaleziono =========== EmptyTemp: ========== BITS transfer queue => 7888896 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 44899967 B Java, Flash, Steam htmlcache => 1608 B Windows/system/drivers => 5860401 B Edge => 5771138 B Chrome => 811152521 B Firefox => 44781896 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 5096 B NetworkService => 45378 B Paweł => 20069330 B RecycleBin => 0 B EmptyTemp: => 896.9 MB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 18:13:02 ====