Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-11-2014 Ran by Remek at 2014-11-18 18:28:44 Run:1 Running from C:\Users\Remek\Downloads Loaded Profile: Remek (Available profiles: Remek & serwis) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: (Microsoft Corporation) C:\Windows\explorer.exe ShellIconOverlayIdentifiers: [1SecureIconsProvider] -> {FC9D8189-520A-4417-AED7-9EAC810C6FBA} => C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll () HKU\S-1-5-21-553344540-897006182-1067068338-1000\...\Run: [IZsoft] => regsvr32.exe C:\Users\Remek\AppData\Local\IZsoft\Acrofx32.dll <===== ATTENTION HKU\S-1-5-21-553344540-897006182-1067068338-1000\...\Run: [Iksoft] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Remek\AppData\Local\Ugmedia\Acrofx32.dll HKU\S-1-5-21-553344540-897006182-1067068338-1000\...\Policies\Explorer: [Run] "C:\Users\Remek\AppData\Roaming\Microsoft\Windows\IEUpdate\esentutl.exe" Reg: reg query HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce HKU\S-1-5-18\...\RunOnce: [Application Restart #2] => C:\Windows\SysWOW64\calc.exe [776192 2010-11-20] (Microsoft Corporation) BootExecute: autocheck autochk * lsdelete S2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe -service [X] S3 KiesAllShare; C:\Program Files (x86)\Samsung\Kies\WiselinkPro\WiselinkPro.exe [X] S2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X] S3 GPU-Z; \??\C:\Users\Remek\AppData\Local\Temp\GPU-Z.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] U3 tmlwf; No ImagePath U3 tmwfp; No ImagePath Task: {296C04A8-FA06-460F-B2CC-5B0F211837A2} - System32\Tasks\RI => C:\Users\Remek\AppData\Roaming\RI.exe <==== ATTENTION Task: {2D7D7070-A6F2-4A0B-989D-929A5D843999} - \Security Center Update - 3469905027 No Task File <==== ATTENTION Task: {44964D54-A3A5-4B7C-AB80-40A05E58AC04} - System32\Tasks\{0F5489D2-F6D9-40DF-A18E-F15B1A266CE5} => D:\gry\Total War Shogun 2\Shogun2.exe Task: {667C0599-BD1A-413B-A92C-A039A1E01175} - System32\Tasks\{7EAE4927-8A23-423A-B96D-79524BED8A8A} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=5.1.0.112.259&LastError=0 Task: {C8E21006-6E2E-4EF5-8CAD-EB6E1A9D8712} - System32\Tasks\SELU => C:\Users\Remek\AppData\Roaming\SELU.exe <==== ATTENTION Task: {D418128A-7712-45F1-A1FA-FE8B62F98BEC} - System32\Tasks\ISXX => C:\Users\Remek\AppData\Roaming\ISXX.exe <==== ATTENTION Task: {EEE16566-BFFE-429E-BE04-D8D0126A311F} - System32\Tasks\VIQHFUCG => C:\Users\Remek\AppData\Roaming\VIQHFUCG.exe <==== ATTENTION Task: {EFBB96C5-C6BF-4C1F-994B-043B0553F2A0} - System32\Tasks\NSUROF => C:\Users\Remek\AppData\Roaming\NSUROF.exe <==== ATTENTION Task: {F238DCBF-E828-4C73-9605-8B46CC7036E2} - System32\Tasks\WEMJ => C:\Users\Remek\AppData\Roaming\WEMJ.exe <==== ATTENTION Task: {F2B5BCBC-30E7-416B-89CF-2B853CFB4634} - System32\Tasks\{8F931B67-8B77-405E-8DA2-3AE9B6C6FBF6} => D:\gry\Total War Shogun 2\Shogun2.exe Task: C:\Windows\Tasks\ISXX.job => C:\Users\Remek\AppData\Roaming\ISXX.exe <==== ATTENTION Task: C:\Windows\Tasks\NSUROF.job => C:\Users\Remek\AppData\Roaming\NSUROF.exe <==== ATTENTION Task: C:\Windows\Tasks\RI.job => C:\Users\Remek\AppData\Roaming\RI.exe <==== ATTENTION Task: C:\Windows\Tasks\SELU.job => C:\Users\Remek\AppData\Roaming\SELU.exe <==== ATTENTION Task: C:\Windows\Tasks\VIQHFUCG.job => C:\Users\Remek\AppData\Roaming\VIQHFUCG.exe <==== ATTENTION Task: C:\Windows\Tasks\WEMJ.job => C:\Users\Remek\AppData\Roaming\WEMJ.exe <==== ATTENTION ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK ShortcutWithArgument: C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK ShortcutWithArgument: C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK ShortcutWithArgument: C:\Users\Remek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK ShortcutWithArgument: C:\Users\Remek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK ShortcutWithArgument: C:\Users\Remek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK&q={searchTerms} SearchScopes: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> DefaultScope {0D7562AE-8EF6-416d-A838-AB665251703A} URL = http://start.facemoods.com/?a=ostpl&s={searchTerms}&f=4 SearchScopes: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> {0D7562AE-8EF6-416d-A838-AB665251703A} URL = http://start.facemoods.com/?a=ostpl&s={searchTerms}&f=4 SearchScopes: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1411055437&from=ild&uid=ST9320423AS_5VH33EHKXXXX5VH33EHK&q={searchTerms} SearchScopes: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> {5F970FDE-702B-4ef9-920C-5F2848A5AF26} URL = http://www.daemon-search.com/search/web?q={searchTerms} SearchScopes: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search/web?q={searchTerms} SearchScopes: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> {E8FA2325-7F80-4757-83C1-4DA099082835} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=F9A780BD-8EF8-4ACB-B625-28DB11D43D6E&apn_sauid=FCD22013-E420-4A72-ADE2-B432F89CD7DE BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File Toolbar: HKLM - No Name - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - No File Toolbar: HKU\S-1-5-21-553344540-897006182-1067068338-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: HKLM-x32 {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Remek\AppData\Roaming\Mozilla\Firefox\Profiles\5xlcivj9.default-1341663662249\extensions\faststartff@gmail.com C:\Program Files (x86)\mozilla firefox\browser\searchplugins\istartsurf.xml C:\Program Files (x86)\mozilla firefox\extensions C:\Program Files (x86)\mozilla firefox\plugins C:\Program Files (x86)\hdvidcodec.com C:\ProgramData\*.dll C:\ProgramData\IePluginServices C:\ProgramData\Microsoft\Secure C:\ProgramData\Temp C:\ProgramData\WindowsMangerProtect C:\Users\Remek\AppData\Local\IZsoft C:\Users\Remek\AppData\Local\Mobogenie C:\Users\Remek\AppData\Local\Ugmedia C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage C:\Users\Remek\AppData\Roaming\newnext.me C:\Users\Remek\AppData\Roaming\Temp C:\Users\Remek\AppData\Roaming\VOPackage C:\Users\Remek\AppData\Roaming\WebExtend C:\Users\Remek\AppData\Roaming\Zaboti C:\Users\Remek\AppData\Roaming\Microsoft\Windows\IEUpdate C:\Users\serwis\AppData\Roaming\Asus WebStorage C:\Windows\system32\Drivers\etc\hosts.txt Hosts: Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search" /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Remek\AppData\Local CMD: dir /a C:\Users\Remek\AppData\LocalLow CMD: dir /a C:\Users\Remek\AppData\Roaming CMD: dir /a C:\Users\Remek\AppData\Roaming\Microsoft\Windows ***************** Processes closed successfully. [2780] C:\Windows\explorer.exe => Process closed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\1SecureIconsProvider" => Key deleted successfully. "HKCR\CLSID\{FC9D8189-520A-4417-AED7-9EAC810C6FBA}" => Key deleted successfully. HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Windows\CurrentVersion\Run\\IZsoft => value deleted successfully. HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Iksoft => value deleted successfully. HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\Run => value deleted successfully. ========= reg query HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce ========= HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce Application Restart #2 REG_SZ C:\Windows\SysWOW64\calc.exe /restart ========= End of Reg: ========= HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #2 => value deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. IePluginServices => Service deleted successfully. KiesAllShare => Service deleted successfully. WindowsMangerProtect => Service deleted successfully. EagleX64 => Service deleted successfully. ewusbmbb => Service deleted successfully. GPU-Z => Service deleted successfully. huawei_cdcacm => Service deleted successfully. huawei_cdcecm => Service deleted successfully. huawei_enumerator => Service deleted successfully. huawei_ext_ctrl => Service deleted successfully. hwusbdev => Service deleted successfully. sptd => Service deleted successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{296C04A8-FA06-460F-B2CC-5B0F211837A2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{296C04A8-FA06-460F-B2CC-5B0F211837A2}" => Key deleted successfully. C:\Windows\System32\Tasks\RI => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RI" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2D7D7070-A6F2-4A0B-989D-929A5D843999}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D7D7070-A6F2-4A0B-989D-929A5D843999}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 3469905027" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{44964D54-A3A5-4B7C-AB80-40A05E58AC04}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44964D54-A3A5-4B7C-AB80-40A05E58AC04}" => Key deleted successfully. C:\Windows\System32\Tasks\{0F5489D2-F6D9-40DF-A18E-F15B1A266CE5} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0F5489D2-F6D9-40DF-A18E-F15B1A266CE5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{667C0599-BD1A-413B-A92C-A039A1E01175}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{667C0599-BD1A-413B-A92C-A039A1E01175}" => Key deleted successfully. C:\Windows\System32\Tasks\{7EAE4927-8A23-423A-B96D-79524BED8A8A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7EAE4927-8A23-423A-B96D-79524BED8A8A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C8E21006-6E2E-4EF5-8CAD-EB6E1A9D8712}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8E21006-6E2E-4EF5-8CAD-EB6E1A9D8712}" => Key deleted successfully. C:\Windows\System32\Tasks\SELU => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SELU" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D418128A-7712-45F1-A1FA-FE8B62F98BEC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D418128A-7712-45F1-A1FA-FE8B62F98BEC}" => Key deleted successfully. C:\Windows\System32\Tasks\ISXX => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ISXX" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EEE16566-BFFE-429E-BE04-D8D0126A311F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEE16566-BFFE-429E-BE04-D8D0126A311F}" => Key deleted successfully. C:\Windows\System32\Tasks\VIQHFUCG => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\VIQHFUCG" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EFBB96C5-C6BF-4C1F-994B-043B0553F2A0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFBB96C5-C6BF-4C1F-994B-043B0553F2A0}" => Key deleted successfully. C:\Windows\System32\Tasks\NSUROF => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NSUROF" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F238DCBF-E828-4C73-9605-8B46CC7036E2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F238DCBF-E828-4C73-9605-8B46CC7036E2}" => Key deleted successfully. C:\Windows\System32\Tasks\WEMJ => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WEMJ" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F2B5BCBC-30E7-416B-89CF-2B853CFB4634}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F2B5BCBC-30E7-416B-89CF-2B853CFB4634}" => Key deleted successfully. C:\Windows\System32\Tasks\{8F931B67-8B77-405E-8DA2-3AE9B6C6FBF6} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8F931B67-8B77-405E-8DA2-3AE9B6C6FBF6}" => Key deleted successfully. C:\Windows\Tasks\ISXX.job => Moved successfully. C:\Windows\Tasks\NSUROF.job => Moved successfully. C:\Windows\Tasks\RI.job => Moved successfully. C:\Windows\Tasks\SELU.job => Moved successfully. C:\Windows\Tasks\VIQHFUCG.job => Moved successfully. C:\Windows\Tasks\WEMJ.job => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Shortcut argument was removed successfully. HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKU\S-1-5-21-553344540-897006182-1067068338-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-553344540-897006182-1067068338-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKU\S-1-5-21-553344540-897006182-1067068338-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}" => Key deleted successfully. "HKCR\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}" => Key not found. "HKU\S-1-5-21-553344540-897006182-1067068338-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKU\S-1-5-21-553344540-897006182-1067068338-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5F970FDE-702B-4ef9-920C-5F2848A5AF26}" => Key deleted successfully. "HKCR\CLSID\{5F970FDE-702B-4ef9-920C-5F2848A5AF26}" => Key not found. "HKU\S-1-5-21-553344540-897006182-1067068338-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}" => Key deleted successfully. "HKCR\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}" => Key not found. "HKU\S-1-5-21-553344540-897006182-1067068338-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E8FA2325-7F80-4757-83C1-4DA099082835}" => Key deleted successfully. "HKCR\CLSID\{E8FA2325-7F80-4757-83C1-4DA099082835}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EFEED92A-A33D-4873-BA8F-32BAA631E54D} => value deleted successfully. "HKCR\CLSID\{EFEED92A-A33D-4873-BA8F-32BAA631E54D}" => Key not found. HKU\S-1-5-21-553344540-897006182-1067068338-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully. "HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55}" => Key deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b} => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\faststartff@gmail.com => value deleted successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\istartsurf.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\extensions => Moved successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. C:\Program Files (x86)\hdvidcodec.com => Moved successfully. C:\ProgramData\*.dll => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\Microsoft\Secure => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\Users\Remek\AppData\Local\IZsoft => Moved successfully. C:\Users\Remek\AppData\Local\Mobogenie => Moved successfully. C:\Users\Remek\AppData\Local\Ugmedia => Moved successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com => Moved successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie => Moved successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage => Moved successfully. C:\Users\Remek\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Remek\AppData\Roaming\Temp => Moved successfully. C:\Users\Remek\AppData\Roaming\VOPackage => Moved successfully. C:\Users\Remek\AppData\Roaming\WebExtend => Moved successfully. C:\Users\Remek\AppData\Roaming\Zaboti => Moved successfully. C:\Users\Remek\AppData\Roaming\Microsoft\Windows\IEUpdate => Moved successfully. C:\Users\serwis\AppData\Roaming\Asus WebStorage => Moved successfully. C:\Windows\system32\Drivers\etc\hosts.txt => Moved successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C to OS Numer seryjny woluminu: B690-7C2E Katalog: C:\Program Files 2014-09-18 17:06 . 2014-09-18 17:06 .. 2010-10-22 19:36 ASUS 2014-01-27 10:21 Blender Foundation 2011-02-26 17:34 CCleaner 2014-10-30 12:03 Common Files 2014-07-23 21:12 Compiled Driver Disk (Samsung) 2011-10-31 14:08 DAEMON Tools 2011-11-12 19:18 DAEMON Tools Lite 2014-08-11 14:14 DAUM 2009-07-14 05:54 174 desktop.ini 2012-10-28 16:22 DIFX 2011-10-24 13:00 DivX 2011-02-23 22:34 DVD Maker 2010-10-22 19:05 Elantech 2014-11-04 15:25 Google 2012-11-08 20:58 HP 2014-11-13 15:35 Internet Explorer 2010-10-22 19:30 LSI SoftModem 2014-09-12 18:10 Microsoft Security Client 2014-08-07 14:06 Microsoft Silverlight 2014-01-31 15:31 Microsoft SQL Server 2014-01-31 15:31 Microsoft.NET 2009-07-14 06:32 MSBuild 2010-10-22 19:34 P4G 2014-07-23 21:12 Phone Drivers Downloader 2010-10-22 19:23 Realtek 2009-07-14 06:32 Reference Assemblies 2012-10-04 11:03 SAMSUNG 2011-08-02 22:10 SkanerOnline 2012-01-15 13:34 TeamTalk4 2009-07-14 06:09 Uninstall Information 2010-10-22 19:28 WIDCOMM 2013-07-17 08:17 Windows Defender 2014-07-10 19:42 Windows Journal 2011-02-23 22:34 Windows Mail 2014-10-16 23:43 Windows Media Player 2009-07-14 06:32 Windows NT 2011-02-23 22:34 Windows Photo Viewer 2011-02-23 22:34 Windows Portable Devices 2011-02-23 22:34 Windows Sidebar 2011-01-27 11:22 WinRAR 1 plik(¢w) 174 bajt¢w 41 katalog(¢w) 3ÿ619ÿ393ÿ536 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C to OS Numer seryjny woluminu: B690-7C2E Katalog: C:\Program Files (x86) 2014-11-18 18:29 . 2014-11-18 18:29 .. 2013-12-26 16:29 3G Connection Manager 2011-08-02 07:22 ABCPC_KursCorel 2014-10-10 10:15 Adobe 2013-05-29 23:22 AGEIA Technologies 2011-08-03 11:02 AMD 2010-10-22 19:24 AmIcoSingLun 2011-04-11 10:21 AnvSoft 2014-08-12 21:10 Astroburn Toolbar 2014-08-12 21:13 ASUS 2010-10-22 19:25 Atheros 2010-10-22 19:12 Boingo 2014-01-31 15:32 Business Objects 2011-02-02 19:56 Combined Community Codec Pack 2014-08-12 21:21 Common Files 2014-07-23 21:29 COMPELSON Labs 2011-04-09 06:20 ConvertHelper 2011-02-11 21:52 Corel 2010-10-22 19:10 CyberLink 2014-11-18 08:57 DAEMON Tools Lite 2009-07-14 05:54 174 desktop.ini 2011-08-02 07:22 Din's Curse 2011-12-30 11:05 DivX 2014-10-23 14:30 DjVuLibre 2012-09-20 17:46 35ÿ216 DLS8Uninstall.log 2012-09-20 17:44 DYMO 2011-10-02 09:48 Elaborate Bytes 2010-10-22 19:24 EmvSmartCardReader 2011-02-23 22:28 Feedback Tool 2011-03-22 11:24 FlashGet Network 2012-11-24 20:23 foobar2000 2012-10-08 11:05 Foxit Software 2011-08-02 07:22 Games 2014-09-19 07:33 globalUpdate 2014-11-17 21:02 Google 2014-05-12 19:03 IKEA HomePlanner 2010-10-22 19:31 Infineon 2014-11-04 15:25 InstallShield Installation Information 2011-11-12 19:15 Intel 2014-11-13 15:35 Internet Explorer 2014-08-08 11:11 IrfanView 2014-08-12 20:57 Java 2011-02-27 10:22 Lavasoft 2014-03-20 14:33 LibreOffice 3 2014-10-03 13:56 LibreOffice 4 2011-08-02 07:22 MarkAny 2014-07-10 21:03 Matroska Pack 2014-08-22 17:05 MegaDev 2014-04-01 16:51 Microsoft Games for Windows - LIVE 2014-09-12 18:10 Microsoft Security Client 2014-08-07 14:06 Microsoft Silverlight 2014-01-31 15:31 Microsoft SQL Server 2014-08-12 21:22 Microsoft.NET 2013-12-26 16:31 Mobile Broadband drivers 2014-07-23 21:29 MOBILedit! Enterprise 2014-03-17 09:37 Movie Subtitles Searcher 2014-11-18 18:29 Mozilla Firefox 2014-11-13 15:36 Mozilla Maintenance Service 2014-06-26 16:28 Mozilla Thunderbird 2014-08-12 21:21 MSBuild 2010-10-22 19:17 MSXML 4.0 2012-12-01 20:13 MyFree Codec 2014-09-22 17:38 NAPI-PROJEKT 2012-02-01 20:24 Nero 2012-10-28 16:23 Nokia 2013-05-29 23:21 NVIDIA Corporation 2014-03-28 12:23 Odkurzacz 2011-08-02 22:10 OpenSubtitlesPlayer 2014-09-18 17:07 Opera 2012-07-11 13:29 Oracle 2011-11-21 23:04 Pando Networks 2012-10-28 16:22 PC Connectivity Solution 2012-08-13 11:05 PDFCreator 2014-04-23 18:10 PIT Projekt 2013 2011-08-02 22:10 Pity Format 2010 2014-04-30 08:10 Podatnik.info 2011-08-02 07:22 PRO100 Demo 2013-02-12 15:49 QuickTime 2014-11-04 13:50 Realtek 2009-07-14 06:32 Reference Assemblies 2013-09-03 17:07 Samsung 2011-02-27 10:28 Security Task Manager 2014-03-05 08:36 Skype 2014-08-11 13:55 Soneta 2012-10-20 11:56 SpywareBlaster 2014-09-18 19:49 SupTab 2013-12-27 15:26 Sweet Home 3D 2010-10-22 19:16 syncables 2013-09-01 13:05 SystemRequirementsLab 2012-04-05 17:09 TeamSpeak 3 Client 2013-12-26 16:27 Temp 2012-05-03 12:43 The KMPlayer 2013-06-22 20:24 Ubisoft 2009-07-14 05:57 Uninstall Information 2014-05-13 11:21 uTorrent 2012-10-11 07:20 v9Soft 2011-08-02 22:10 Winamp 2011-01-27 12:30 Winamp Detect 2013-07-17 08:17 Windows Defender 2011-01-31 09:03 Windows Live 2011-01-27 09:00 Windows Live SkyDrive 2011-02-23 22:34 Windows Mail 2014-10-16 23:43 Windows Media Player 2009-07-14 06:32 Windows NT 2011-02-23 22:34 Windows Photo Viewer 2011-02-23 22:34 Windows Portable Devices 2011-02-23 22:34 Windows Sidebar 2014-02-21 13:08 WinHTTrack 2012-05-25 12:24 Winmail Opener 2012-01-17 22:53 WinSCP 2 plik(¢w) 35ÿ390 bajt¢w 109 katalog(¢w) 3ÿ619ÿ389ÿ440 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C to OS Numer seryjny woluminu: B690-7C2E Katalog: C:\ProgramData 2014-11-18 18:29 . 2014-11-18 18:29 .. 2014-10-10 10:15 Adobe 2012-02-01 20:25 Ahead 2010-10-22 19:24 AmUStor 2013-02-12 15:47 Apple 2013-02-12 15:48 Apple Computer 2009-07-14 06:08 Application Data [C:\ProgramData] 2012-08-24 18:33 ArcSoft 2012-07-11 13:29 Ask 2012-02-01 17:44 Astroburn Lite 2011-01-31 19:55 ASUS 2010-10-22 19:25 Atheros 2013-04-17 18:18 Battle.net 2013-04-17 18:45 Blizzard Entertainment 2014-07-29 19:47 boost_interprocess 2013-12-26 16:29 BVRP Software 2012-09-29 13:55 CMUV 2011-02-11 21:52 Corel 2010-10-22 19:10 CyberLink 2014-11-04 15:26 DAEMON Tools Lite 2013-09-30 16:22 DatacardService 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2011-04-21 18:16 DinsCurse 2011-12-30 11:05 DivX 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2012-09-20 17:44 DYMO 2013-05-04 18:24 EA Core 2013-05-04 18:28 EA Logs 2013-05-04 18:24 Electronic Arts 2010-10-22 19:24 EmvSCard 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2010-07-07 00:10 131ÿ472 FullRemove.exe 2010-10-22 19:12 GoBoingo 2010-10-22 19:31 Infineon 2014-11-04 13:51 InstallShield 2011-11-13 13:50 Intel 2011-09-18 15:33 Lavasoft 2011-03-03 14:37 McAfee 2012-09-08 11:47 Media Center Programs 2014-11-18 18:29 Microsoft 2014-08-12 21:23 Microsoft Help 2012-08-24 18:24 Mirillis 2013-09-30 12:08 Mobile Partner 2012-04-27 07:01 Mozilla 2012-02-01 20:24 Nero 2012-10-28 16:23 Nokia 2011-08-02 22:22 Norton 2011-08-02 22:17 NortonInstaller 2011-02-02 20:03 Oberon Media 2011-08-02 07:21 OberonGameConsole 2014-08-12 20:54 Oracle 2011-08-02 22:10 P4G 2011-02-26 17:01 Partner 2011-02-02 22:16 PC Suite 2011-03-11 21:29 PlayFirst 2012-08-25 01:09 PMB Files 2014-03-21 13:28 RICOH_DRV 2011-12-04 21:03 Samsung 2011-02-27 11:02 SecTaskMan 2014-03-25 18:43 SimCity Societies 2014-03-05 08:36 Skype 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2011-01-27 12:09 Sun 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2011-08-06 18:05 Trymedia 2013-06-22 20:31 Ubisoft 2013-09-01 13:29 WarThunder 2013-05-08 16:45 Western Digital 2011-02-27 10:53 Windows Genuine Advantage 2010-10-22 19:10 105 {40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2010-10-22 19:09 107 {C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 3 plik(¢w) 131ÿ684 bajt¢w 69 katalog(¢w) 3ÿ619ÿ385ÿ344 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Remek\AppData\Local ========= Wolumin w stacji C to OS Numer seryjny woluminu: B690-7C2E Katalog: C:\Users\Remek\AppData\Local 2014-11-18 18:30 . 2014-11-18 18:30 .. 2014-11-08 15:39 Adobe 2012-02-01 20:27 Ahead 2013-12-26 16:39 ALLPlayer 2013-02-12 15:47 Apple 2011-09-24 13:06 ApplicationHistory 2011-01-27 20:37 Apps 2012-08-24 18:34 ArcSoft 2012-10-01 10:45 assembly 2011-03-18 12:30 ASUS 2011-01-27 09:06 Broadcom 2014-03-17 09:18 cache 2014-10-27 10:14 CrashDumps 2011-01-27 08:59 Dane aplikacji [C:\Users\Remek\AppData\Local] 2014-04-03 21:24 8ÿ192 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-10-31 19:40 DDMSettings 2012-06-05 16:44 Deployment 2011-11-21 10:00 Diagnostics 2011-04-21 18:16 DinsCurse 2013-07-23 18:20 Downloaded Installations 2012-09-20 17:48 DYMO 2014-03-21 13:20 ElevatedDiagnostics 2014-11-13 15:46 EmieBrowserModeList 2014-08-22 16:54 EmieSiteList 2014-08-22 16:54 EmieUserList 2014-04-24 16:16 FLCrossfireGecko 2014-05-29 13:57 Foxit Reader 2014-05-05 17:46 Freelancer 2011-09-24 12:59 93 fusioncache.dat 2014-11-11 18:15 136ÿ024 GDIPFONTCACHEV1.DAT 2014-09-18 19:49 genienext 2013-02-11 09:04 GHISLER 2014-09-18 16:49 globalUpdate 2014-11-04 14:24 Google 2011-02-27 10:55 Help 2011-01-27 08:59 Historia [C:\Users\Remek\AppData\Local\Microsoft\Windows\History] 2014-11-18 10:30 1ÿ727ÿ080 IconCache.db 2012-06-19 08:01 Macromedia 2014-11-04 13:56 Microsoft 2012-03-14 09:12 Microsoft Help 2012-08-24 18:30 Mirillis 2013-10-01 20:33 Mozilla 2012-10-28 16:24 Nokia 2012-10-28 16:46 NokiaAccount 2014-09-18 17:07 Opera Software 2014-11-18 18:28 PMB Files 2011-01-27 08:59 Power2Go 2014-01-08 09:49 Programs 2012-06-05 21:02 7ÿ646 Resmon.ResmonCfg 2012-02-17 21:25 Samsung 2012-09-20 17:48 Sanford,_L.P 2011-09-26 20:28 SKIDROW 2012-06-15 10:30 Soneta 2011-02-27 10:24 Sunbelt Software 2014-11-18 18:30 Temp 2011-01-27 08:59 Temporary Internet Files [C:\Users\Remek\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2011-01-28 08:58 THQ 2011-03-02 13:05 Thunderbird 2013-06-22 20:33 Ubisoft Game Launcher 2014-08-12 21:12 24ÿ576 uninst.tmp 2012-11-17 19:48 Unity 2014-04-30 13:19 utrack 2011-11-12 19:18 VirtualStore 2013-08-31 16:20 WarThunder 2013-05-08 16:43 Western Digital 6 plik(¢w) 1ÿ903ÿ611 bajt¢w 60 katalog(¢w) 3ÿ619ÿ381ÿ248 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Remek\AppData\LocalLow ========= Wolumin w stacji C to OS Numer seryjny woluminu: B690-7C2E Katalog: C:\Users\Remek\AppData\LocalLow 2014-09-18 17:08 . 2014-09-18 17:08 .. 2012-07-01 16:37 Adobe 2011-07-22 10:37 Apple Computer 2014-10-21 19:21 boost_interprocess 2011-06-23 17:50 facemoods.com 2011-02-04 15:15 Google 2012-07-01 16:37 Macromedia 2014-01-10 12:05 Microsoft 2012-07-11 13:28 Oracle 2013-11-24 16:40 splitscreen 2011-01-27 12:07 Sun 2011-03-03 15:32 Temp 2012-11-17 19:48 Unity 0 plik(¢w) 0 bajt¢w 14 katalog(¢w) 3ÿ619ÿ381ÿ248 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Remek\AppData\Roaming ========= Wolumin w stacji C to OS Numer seryjny woluminu: B690-7C2E Katalog: C:\Users\Remek\AppData\Roaming 2014-11-18 18:30 . 2014-11-18 18:30 .. 2011-02-28 14:52 Adobe 2012-02-01 20:35 Ahead 2011-04-11 10:21 AnvSoft 2013-02-14 14:34 Apple Computer 2012-08-24 18:34 ArcSoft 2012-01-15 13:34 BearWare.dk 2013-03-30 12:02 Bioshock 2014-04-10 17:09 Bioshock2 2011-03-22 11:32 BITS 2011-02-11 21:58 Corel 2011-01-27 19:49 CyberLink 2011-07-10 11:40 DAEMON Tools Lite 2011-04-12 10:11 DivX 2013-02-27 14:32 EeeStorageUploader 2011-03-22 11:24 FlashGet 2011-03-22 11:29 FlashGetBHO 2012-11-24 20:27 foobar2000 2013-04-27 21:25 Foxit Software 2011-08-02 22:10 GHISLER 2011-02-26 17:47 GoBoingo 2014-08-20 14:50 GOG 2011-02-27 10:55 Help 2014-10-30 12:04 help_images_otherUI 2011-01-27 09:05 Identities 2011-01-27 09:06 Infineon 2014-01-14 14:34 Intelli-studio 2014-08-08 11:11 IrfanView 2014-09-01 09:18 1ÿ248 ISXX 2011-12-31 14:06 Kalypso Media 2013-09-30 16:22 Leadertech 2014-03-20 14:41 LibreOffice 2011-11-24 17:33 LolClient 2012-05-25 16:37 LolClient2 2011-01-27 10:29 Macromedia 2009-07-14 08:45 Media Center Programs 2014-03-03 19:57 Media Player Classic 2014-04-24 09:09 Microsoft 2012-09-08 12:42 Microsoft Game Studios 2011-01-31 14:57 Microsoft Games 2012-08-24 18:24 Mirillis 2014-07-23 21:58 MOBILedit 2011-01-27 10:24 Mozilla 2012-06-05 21:10 NapiProjekt 2012-10-28 16:32 Nokia 2012-10-28 16:32 Nokia Suite 2014-09-01 09:18 1ÿ248 NSUROF 2014-09-18 17:07 Opera Software 2014-08-12 20:56 Oracle 2012-10-28 16:25 PC Suite 2012-08-13 11:05 pdfforge 2011-03-11 21:29 PlayFirst 2014-04-30 08:10 Podatnik.info 2014-08-11 14:15 PotPlayerMini64 2014-09-01 09:18 2ÿ086 RI 2012-10-15 17:20 Samsung 2012-09-10 19:57 SecuROM 2014-09-01 09:18 2ÿ086 SELU 2013-11-01 14:40 Skype 2013-05-11 14:11 skypePM 2013-03-03 11:34 Soneta 2013-05-20 18:41 The Creative Assembly 2011-10-11 10:21 Thinstall 2011-01-27 10:35 Thunderbird 2011-08-02 07:25 Tific 2013-05-29 23:25 Touchstone 2012-04-05 17:19 TS3Client 2013-06-22 20:31 Ubisoft 2014-11-18 18:24 uTorrent 2014-09-01 09:18 1ÿ248 VIQHFUCG 2011-10-02 08:13 wargaming.net 2014-09-01 09:18 2ÿ086 WEMJ 2012-11-24 14:16 Winamp 2011-01-27 11:22 WinRAR 2012-01-17 22:59 600 winscp.rnd 7 plik(¢w) 10ÿ602 bajt¢w 69 katalog(¢w) 3ÿ619ÿ377ÿ152 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Remek\AppData\Roaming\Microsoft\Windows ========= Wolumin w stacji C to OS Numer seryjny woluminu: B690-7C2E Katalog: C:\Users\Remek\AppData\Roaming\Microsoft\Windows 2014-11-18 18:30 . 2014-11-18 18:30 .. 2014-11-18 17:28 Cookies 2014-01-17 09:51 DNTException 2013-05-18 09:43 IECompatCache 2013-05-20 09:12 IECompatUACache 2013-08-24 19:52 IEDownloadHistory 2013-05-18 09:42 IETldCache 2014-08-12 21:06 Libraries 2009-07-14 03:34 Network Shortcuts 2009-07-14 03:35 Printer Shortcuts 2013-05-18 09:42 PrivacIE 2014-08-12 21:06 Recent 2013-03-25 18:25 SendTo 2014-08-12 21:06 Start Menu 2011-07-30 09:23 Templates 2011-03-11 18:35 Themes 0 plik(¢w) 0 bajt¢w 17 katalog(¢w) 3ÿ619ÿ377ÿ152 bajt¢w wolnych ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ====