Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-02-2015 Ran by XX at 2015-02-03 12:29:28 Run:2 Running from C:\ Loaded Profiles: XX (Available profiles: XX) Boot Mode: Safe Mode (with Networking) ============================================== Content of fixlist: ***************** CloseProcesses: Task: C:\Windows\Tasks\1014avUpdateInfo.job => C:\ProgramData\Avg_Update_1014av\1014av_AVG-Secure-Search-Update.exe Hosts: C:\ProgramData\Avg_Update_1014av C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\XX\AppData\LocalLow\CertifiedToolbar C:\Users\XX\AppData\Roaming\.minecraft C:\Users\XX\AppData\Roaming\Adetymwu C:\Users\XX\AppData\Roaming\avidemux C:\Users\XX\AppData\Roaming\Audacity C:\Users\XX\AppData\Roaming\Balmora.pl C:\Users\XX\AppData\Roaming\DVD Flick C:\Users\XX\AppData\Roaming\FileZilla C:\Users\XX\AppData\Roaming\com.w3i.FlipToast C:\Users\XX\AppData\Roaming\Gadu-Gadu 10 C:\Users\XX\AppData\Roaming\GoldenGate C:\Users\XX\AppData\Roaming\Igosonne C:\Users\XX\AppData\Roaming\Local Store C:\Users\XX\AppData\Roaming\Mozilla C:\Users\XX\AppData\Roaming\OpenFM C:\Users\XX\AppData\Roaming\Opera C:\Users\XX\AppData\Roaming\SteelSeries C:\Users\XX\AppData\Roaming\Ubkafo C:\Users\XX\AppData\Roaming\wargaming.net C:\Users\XX\AppData\Roaming\WordToPDF C:\Users\XX\AppData\Roaming\Ynehcaac C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\*.LNK C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.bmp C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.txt C:\Windows\system32\Drivers\1DF1592B.sys C:\Windows\system32\Drivers\2F6C59A4.sys C:\Windows\system32\Drivers\5EFA3319.sys C:\Windows\system32\Drivers\61C35F4E.sys C:\Windows\system32\Drivers\2F9C5F72.sys CMD: sc config WinDefend start= demand Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg query "HKCU\Control Panel\Desktop" Reg: reg query "HKCU\Software\Microsoft\Internet Explorer\Desktop" /s Reg: reg query "HKLM\Software\Microsoft\Internet Explorer\Desktop" /s Reg: reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System Reg: reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\XX\AppData\Local CMD: dir /a C:\Users\XX\AppData\LocalLow CMD: dir /a C:\Users\XX\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. C:\Windows\Tasks\1014avUpdateInfo.job => Moved successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. C:\ProgramData\Avg_Update_1014av => Moved successfully. C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\XX\AppData\LocalLow\CertifiedToolbar => Moved successfully. "C:\Users\XX\AppData\Roaming\.minecraft" => File/Directory not found. C:\Users\XX\AppData\Roaming\Adetymwu => Moved successfully. C:\Users\XX\AppData\Roaming\avidemux => Moved successfully. C:\Users\XX\AppData\Roaming\Audacity => Moved successfully. C:\Users\XX\AppData\Roaming\Balmora.pl => Moved successfully. C:\Users\XX\AppData\Roaming\DVD Flick => Moved successfully. C:\Users\XX\AppData\Roaming\FileZilla => Moved successfully. C:\Users\XX\AppData\Roaming\com.w3i.FlipToast => Moved successfully. C:\Users\XX\AppData\Roaming\Gadu-Gadu 10 => Moved successfully. C:\Users\XX\AppData\Roaming\GoldenGate => Moved successfully. C:\Users\XX\AppData\Roaming\Igosonne => Moved successfully. C:\Users\XX\AppData\Roaming\Local Store => Moved successfully. C:\Users\XX\AppData\Roaming\Mozilla => Moved successfully. C:\Users\XX\AppData\Roaming\OpenFM => Moved successfully. C:\Users\XX\AppData\Roaming\Opera => Moved successfully. C:\Users\XX\AppData\Roaming\SteelSeries => Moved successfully. C:\Users\XX\AppData\Roaming\Ubkafo => Moved successfully. C:\Users\XX\AppData\Roaming\wargaming.net => Moved successfully. C:\Users\XX\AppData\Roaming\WordToPDF => Moved successfully. C:\Users\XX\AppData\Roaming\Ynehcaac => Moved successfully. C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\*.LNK => Moved successfully. C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade => Moved successfully. C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries => Moved successfully. C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.bmp => Moved successfully. C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.txt => Moved successfully. C:\Windows\system32\Drivers\1DF1592B.sys => Moved successfully. C:\Windows\system32\Drivers\2F6C59A4.sys => Moved successfully. C:\Windows\system32\Drivers\5EFA3319.sys => Moved successfully. C:\Windows\system32\Drivers\61C35F4E.sys => Moved successfully. C:\Windows\system32\Drivers\2F9C5F72.sys => Moved successfully. ========= sc config WinDefend start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg query "HKCU\Control Panel\Desktop" ========= HKEY_CURRENT_USER\Control Panel\Desktop ScreenSaveActive REG_SZ 1 ActiveWndTrackTimeout REG_DWORD 0x0 BlockSendInputResets REG_SZ 0 CaretWidth REG_DWORD 0x1 ClickLockTime REG_DWORD 0x4b0 CoolSwitchColumns REG_SZ 7 CoolSwitchRows REG_SZ 3 CursorBlinkRate REG_SZ 600 DockMoving REG_SZ 1 DragFromMaximize REG_SZ 1 DragFullWindows REG_SZ 0 DragHeight REG_SZ 4 DragWidth REG_SZ 4 FocusBorderHeight REG_DWORD 0x1 FocusBorderWidth REG_DWORD 0x1 FontSmoothing REG_SZ 0 FontSmoothingGamma REG_DWORD 0x0 FontSmoothingOrientation REG_DWORD 0x1 FontSmoothingType REG_DWORD 0x2 ForegroundFlashCount REG_DWORD 0x7 ForegroundLockTimeout REG_DWORD 0x12eb7c LeftOverlapChars REG_SZ 3 MenuShowDelay REG_SZ 400 PaintDesktopVersion REG_DWORD 0x0 RightOverlapChars REG_SZ 3 SnapSizing REG_SZ 1 TileWallpaper REG_SZ 0 WallpaperOriginX REG_DWORD 0x0 WallpaperOriginY REG_DWORD 0x0 WallpaperStyle REG_SZ 0 WheelScrollChars REG_SZ 3 WheelScrollLines REG_SZ 3 WindowArrangementActive REG_SZ 1 UserPreferencesMask REG_BINARY 9012018010000000 Wallpaper REG_SZ C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.bmp Pattern Upgrade REG_SZ TRUE ScreenSaveTimeOut REG_SZ 300 ScreenSaverIsSecure REG_SZ 0 LogPixels REG_DWORD 0x60 HKEY_CURRENT_USER\Control Panel\Desktop\Colors HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached ========= End of Reg: ========= ========= reg query "HKCU\Software\Microsoft\Internet Explorer\Desktop" /s ========= HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\components HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General WallpaperSource REG_SZ ========= End of Reg: ========= ========= reg query "HKLM\Software\Microsoft\Internet Explorer\Desktop" /s ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System ========= ========= End of Reg: ========= ========= reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System ConsentPromptBehaviorAdmin REG_DWORD 0x0 ConsentPromptBehaviorUser REG_DWORD 0x3 EnableInstallerDetection REG_DWORD 0x1 EnableLUA REG_DWORD 0x0 EnableSecureUIAPaths REG_DWORD 0x1 EnableUIADesktopToggle REG_DWORD 0x0 EnableVirtualization REG_DWORD 0x1 PromptOnSecureDesktop REG_DWORD 0x0 ValidateAdminCodeSignatures REG_DWORD 0x0 dontdisplaylastusername REG_DWORD 0x0 legalnoticecaption REG_SZ legalnoticetext REG_SZ scforceoption REG_DWORD 0x0 shutdownwithoutlogon REG_DWORD 0x1 undockwithoutlogon REG_DWORD 0x1 FilterAdministratorToken REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\UIPI ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 13AA-F385 Katalog: C:\Program Files 2015-02-03 11:47 . 2015-02-03 11:47 .. 2014-02-20 17:59 4Media 2013-09-27 20:25 Adobe 2014-11-14 00:00 Anki 2015-02-01 16:47 ATI Technologies 2015-02-02 01:17 AVG 2014-08-27 13:45 AVG Security Toolbar 2014-08-25 11:10 Avi2Dvd 2015-02-01 16:49 AviSynth 2.5 2014-08-25 16:11 AviToDvdFree 2015-01-23 20:44 Battle.net 2014-03-17 17:45 CCleaner 2015-02-01 16:49 CDBurnerXP 2015-02-03 11:25 Common Files 2011-09-05 20:23 8ÿ391ÿ685 data.ifs 2011-09-05 20:23 8ÿ204 data.ifs.cch 2009-07-14 05:41 174 desktop.ini 2014-03-17 16:10 DivX 2013-06-22 20:14 dumps 2011-09-23 20:32 DVD Maker 2012-12-21 16:49 1ÿ287 esl.cfg 2014-07-29 12:16 Foxit Software 2013-11-27 22:10 GameforgeLive 2014-11-09 12:02 Google 2014-09-07 12:58 Grupa IMAGE 2014-12-20 23:42 HEX 2015-02-02 10:49 HP 2013-04-27 16:56 HTC 2014-11-09 11:31 InstallShield Installation Information 2015-02-03 08:41 Internet Explorer 2015-02-01 17:09 IrfanView 2014-08-25 11:04 K-Lite Codec Pack 2013-12-19 15:04 LG Electronics 2012-06-05 19:16 LG Soft India Pvt Ltd 2012-12-17 16:34 305 liblist.gam 2012-12-19 16:40 5ÿ315 live.cfg 2015-02-01 17:09 LocK-A-FoLdeR 2015-02-03 11:22 Malwarebytes Anti-Malware 2013-04-26 13:58 Microsoft 2010-11-01 22:36 Microsoft FrontPage 2009-07-14 09:28 Microsoft Games 2010-01-27 12:46 Microsoft Media 2013-09-06 09:05 Microsoft Office 2014-08-31 11:38 Microsoft Silverlight 2009-11-26 12:15 Microsoft SQL Server Compact Edition 2009-11-26 12:15 Microsoft Sync Framework 2011-03-29 13:40 Microsoft Virtual PC 2010-11-01 22:40 Microsoft Visual Studio 2013-09-06 09:03 Microsoft Visual Studio 8 2015-02-03 02:21 Microsoft Works 2010-08-17 22:47 Microsoft WSE 2013-09-06 09:04 Microsoft.NET 2014-06-26 20:34 MKJogo 2013-09-06 09:05 MSBuild 2013-07-09 11:14 MSECache 2015-02-03 08:51 MSXML 4.0 2014-07-29 15:52 Nero 2012-12-21 16:43 71 plugins.ini 2014-12-28 12:00 Real 2014-11-09 11:32 Realtek 2009-07-14 05:52 Reference Assemblies 2014-11-09 11:31 screenSHU 2012-12-19 15:48 575 server.cfg 2015-02-01 20:21 Skype 2014-06-26 11:17 Sony 2013-11-09 12:18 Sony Ericsson 2014-02-20 19:11 Sony Setup 2012-12-20 19:59 16 sys_ticrate.cfg 2015-02-01 20:22 TeamSpeak 3 Client 2014-11-09 11:32 Temp 2014-09-07 12:57 Total Video Converter 2009-07-14 05:53 Uninstall Information 2015-02-03 08:41 Windows Defender 2012-06-15 21:21 Windows Journal 2011-09-23 20:32 Windows Mail 2015-02-03 08:41 Windows Media Player 2009-11-26 11:29 Windows NT 2011-09-23 20:32 Windows Photo Viewer 2011-09-23 20:32 Windows Portable Devices 2011-09-23 20:32 Windows Sidebar 2015-02-01 20:35 WinRAR 9 plik(¢w) 8ÿ407ÿ632 bajt¢w 73 katalog(¢w) 7ÿ210ÿ708ÿ992 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files\Common Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 13AA-F385 Katalog: C:\Program Files\Common Files 2015-02-03 11:25 . 2015-02-03 11:25 .. 2014-03-17 17:18 Adobe 2012-08-30 22:08 Adobe AIR 2014-08-31 00:07 Aimersoft 2014-02-20 18:14 AVSMedia 2015-01-23 20:49 Blizzard Entertainment 2013-09-06 09:05 DESIGNER 2014-03-17 16:10 DivX Shared 2010-12-28 14:59 GeoVid 2014-03-10 14:13 Grupa Image 2013-11-18 18:01 Hewlett-Packard 2013-11-18 18:00 HP 2013-01-14 16:10 InstallShield 2010-02-18 11:24 InterVideo 2010-04-10 15:35 MAGIX Services 2011-10-03 17:42 MAGIX Shared 2015-02-03 02:21 microsoft shared 2014-07-29 15:52 Nero 2013-01-14 16:14 PC Tools 2010-02-27 20:23 PX Storage Engine 2015-02-01 16:53 Samsung 2009-07-14 03:37 Services 2014-09-23 06:10 Skype 2009-07-14 03:37 SpeechEngines 2014-12-01 17:26 Steam 2013-01-28 16:57 Symantec Shared 2013-09-06 09:02 System 2009-11-26 12:11 Windows Live 2014-09-12 22:00 Wise Installation Wizard 2010-04-10 15:33 xara 2011-11-13 02:45 xing shared 0 plik(¢w) 0 bajt¢w 32 katalog(¢w) 7ÿ210ÿ704ÿ896 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 13AA-F385 Katalog: C:\ProgramData 2015-02-03 12:29 . 2015-02-03 12:29 .. 2014-11-03 18:18 25ebdc4eb7321999 2015-02-01 16:42 4Media 2014-01-20 21:37 Adobe 2014-07-29 12:16 APN 2010-09-26 12:57 Apple 2009-07-14 05:53 Application Data [C:\ProgramData] 2014-02-20 18:27 Ashampoo 2009-12-03 12:46 ATI 2014-11-09 12:58 AVAST Software 2015-02-01 23:55 AVG2015 2014-08-27 13:45 Avg_Update_0814tb 2014-02-20 18:15 AVS4YOU 2015-02-01 20:24 Battle.net 2014-09-13 20:57 Blizzard Entertainment 2013-08-17 16:40 Canneverbe Limited 2011-03-14 15:55 Common Files 2014-11-09 12:55 CouponFactory 2011-02-02 16:06 DAEMON Tools Lite 2009-11-26 11:29 Dane aplikacji [C:\ProgramData] 2009-07-14 05:53 Desktop [C:\Users\Public\Desktop] 2015-02-01 20:24 DivX 2009-07-14 05:53 Documents [C:\Users\Public\Documents] 2009-11-26 11:29 Dokumenty [C:\Users\Public\Documents] 2011-02-01 13:24 EA Core 2011-04-28 10:17 Easy Driver Pro 2011-02-01 13:31 Electronic Arts 2009-07-14 05:53 Favorites [C:\Users\Public\Favorites] 2014-09-07 20:25 Firefly Studios 2010-01-10 14:57 FLEXnet 2010-04-24 17:52 Gadu-Gadu 10 2010-02-25 14:12 GoldWave 2012-05-29 15:41 Google 2015-02-01 16:49 8ÿ554 HELP_DECRYPT.HTML 2015-02-01 16:49 45ÿ582 HELP_DECRYPT.PNG 2015-02-01 16:49 4ÿ288 HELP_DECRYPT.TXT.wxeezfd 2015-02-01 16:49 276 HELP_DECRYPT.URL 2014-07-29 11:13 House Of Soft 2015-02-01 20:24 HP 2013-11-18 18:04 HP Product Assistant 2015-02-02 10:52 9ÿ486 hpzinstall.log 2012-06-05 19:17 InstallShield 2015-02-01 20:24 MAGIX 2014-11-09 12:37 Malwarebytes 2009-11-26 11:29 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2015-02-03 10:36 MFAData 2015-02-03 09:22 Microsoft 2015-02-03 02:46 Microsoft Help 2010-04-10 15:36 mufin 2015-02-01 20:28 Nero 2012-09-28 19:09 Nexon 2012-09-28 18:55 NexonEU 2010-12-18 21:41 NokiaMusic 2015-02-02 22:45 8 ntuser.pol 2012-09-02 15:29 OpenFM 2015-02-02 22:47 Package Cache 2010-12-18 22:14 PC Suite 2010-02-06 22:27 Pinnacle 2013-02-25 16:26 PMB Files 2009-11-26 11:29 Pulpit [C:\Users\Public\Desktop] 2013-02-25 16:25 Real 2014-07-18 11:09 Riot Games 2012-11-02 00:01 RoboForm 2010-12-18 22:12 Samsung 2014-11-09 12:55 saveron 2015-02-01 20:40 Skype 2015-02-01 20:41 Sony 2013-11-09 12:18 Sony Ericsson 2009-07-14 05:53 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2011-02-05 16:22 STOIK 2010-04-10 16:11 Sun 2009-11-26 11:29 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2009-07-14 05:53 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2013-02-10 23:43 TuneUp Software 2010-04-10 12:53 Ulead Systems 2009-11-26 11:29 Ulubione [C:\Users\Public\Favorites] 2012-08-06 15:23 Web Installer 2013-11-18 18:10 WEBREG 2013-02-10 23:42 {C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 6 plik(¢w) 68ÿ194 bajt¢w 74 katalog(¢w) 7ÿ210ÿ700ÿ800 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\XX\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 13AA-F385 Katalog: C:\Users\XX\AppData\Local 2015-02-03 11:31 . 2015-02-03 11:31 .. 2013-12-08 00:29 .# 2014-12-16 23:52 Adobe 2010-01-27 21:10 Ahead 2014-08-31 00:07 Aimersoft 2010-09-26 12:57 Apple 2010-10-10 09:22 Apple Computer 2013-10-23 18:16 Apps 2014-02-20 18:30 Ashampoo Movie Studio 2010-01-09 10:33 ATI 2015-02-02 00:00 Avg2015 2015-02-01 20:42 Battle.net 2015-02-01 20:42 Blizzard 2015-02-01 20:42 Blizzard Entertainment 2010-01-09 11:30 cache 2014-08-25 16:08 CrashRpt 2010-01-09 10:32 Dane aplikacji [C:\Users\XX\AppData\Local] 2014-10-18 23:26 DayZ 2014-12-02 00:25 18ÿ432 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-12-05 21:02 DDMSettings 2013-10-23 18:16 Deployment 2012-06-02 13:34 Diagnostics 2013-01-14 16:13 Downloaded Installations 2011-02-01 13:31 Electronic Arts 2014-12-17 19:48 ElevatedDiagnostics 2012-10-16 17:18 GamersFirst 2015-02-03 08:47 138ÿ584 GDIPFONTCACHEV1.DAT 2014-12-21 02:20 GGEmpire 2011-01-15 16:42 GHISLER 2014-08-25 16:08 globalUpdate 2015-02-03 11:00 Google 2015-02-01 17:17 8ÿ554 HELP_DECRYPT.HTML 2015-02-01 17:17 45ÿ582 HELP_DECRYPT.PNG 2015-02-01 17:17 1ÿ376 HELP_DECRYPT.TXT.kcirdgd 2015-02-01 17:17 276 HELP_DECRYPT.URL 2010-01-09 10:32 Historia [C:\Users\XX\AppData\Local\Microsoft\Windows\History] 2014-07-16 16:44 HP 2015-02-03 12:25 1ÿ265ÿ760 IconCache.db 2014-11-06 07:47 ICSharpCode.net 2014-08-25 16:08 Installer 2010-12-21 19:14 IsolatedStorage 2010-10-15 22:49 IVONA_INST 2012-06-23 13:40 Macromedia 2011-09-07 15:51 MAGIX 2015-02-01 22:04 MFAData 2015-02-01 20:42 Microsoft 2011-03-17 20:58 Microsoft Games 2013-09-06 09:02 Microsoft Help 2015-02-01 20:44 PMB Files 2012-12-27 17:47 Programs 2015-02-03 11:53 7ÿ639 Resmon.ResmonCfg 2013-04-30 15:28 Seven Zip 2015-02-01 20:44 Skype 2014-02-20 19:15 Sony 2014-11-22 19:00 SteelSeries_ApS 2015-02-03 12:30 Temp 2010-01-09 10:32 Temporary Internet Files [C:\Users\XX\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2014-09-07 20:31 Unity 2011-09-21 22:10 VirtualStore 2010-04-25 18:16 WMTools Downloaded Files 2010-04-10 15:36 Xara 8 plik(¢w) 1ÿ486ÿ203 bajt¢w 54 katalog(¢w) 7ÿ210ÿ696ÿ704 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\XX\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 13AA-F385 Katalog: C:\Users\XX\AppData\LocalLow 2015-02-03 12:29 . 2015-02-03 12:29 .. 2015-02-01 20:57 72C8C5EA 2014-12-18 01:00 Adobe 2010-09-26 12:57 Apple Computer 2014-08-25 16:08 Goobzo 2015-02-01 17:18 8ÿ554 HELP_DECRYPT.HTML 2015-02-01 17:18 45ÿ582 HELP_DECRYPT.PNG 2015-02-01 17:18 1ÿ376 HELP_DECRYPT.TXT.kcirdgd 2015-02-01 17:18 276 HELP_DECRYPT.URL 2012-06-23 13:40 Microsoft 2015-02-03 00:28 0 prvlcl.dat 2012-11-02 00:01 Siber Systems 2014-04-17 10:18 SimplyTech 2013-11-09 12:36 8ÿ220 SkwConfig.bin 2010-02-17 20:18 Temp 2014-11-09 12:32 TheTorntv V10 2014-09-07 20:11 Unity 6 plik(¢w) 64ÿ008 bajt¢w 12 katalog(¢w) 7ÿ210ÿ696ÿ704 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\XX\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 13AA-F385 Katalog: C:\Users\XX\AppData\Roaming 2015-02-03 12:30 . 2015-02-03 12:30 .. 2010-12-21 22:45 .# 2015-02-01 20:45 4Media 2015-02-01 20:45 Adobe 2010-01-27 21:11 Ahead 2012-08-30 22:24 app 2011-01-08 14:27 Apple Computer 2010-01-09 10:33 ATI 2014-08-25 16:08 AviDvdBurner 2015-02-01 21:22 AvitoDvd 2010-10-15 23:01 Avnex 2014-02-20 18:15 AVS4YOU 2015-02-01 20:45 Battle.net 2014-01-18 17:25 BoL 2013-08-17 16:40 Canneverbe Limited 2014-11-09 12:39 CertifiedToolsToolbar 2013-11-08 08:46 Cream Software 2012-09-01 10:49 165 D2Info0 2012-05-29 20:27 DAEMON Tools Lite 2010-10-24 22:29 DeepBurner 2011-02-04 12:42 DivX 2011-09-01 13:01 dll-files.com 2015-02-01 20:45 DMCache 2012-08-30 22:24 Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 2012-08-31 11:52 Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 2012-09-01 12:10 Dofus2 2012-09-01 12:12 8 DofusAppId0_1 2012-08-31 15:31 8 DofusAppId0_2 2011-10-05 11:33 dvdcss 2014-09-07 20:29 Firefly Studios 2014-08-23 12:15 Foxit Software 2012-10-22 22:52 FreeAudioPack 2014-11-09 12:55 GameCenter 2010-12-28 14:59 GeoVid 2010-12-31 23:43 GetRightToGo 2011-01-07 15:27 GHISLER 2011-02-27 22:35 Google 2014-03-10 14:13 Grupa IMAGE 2010-02-18 11:37 gtk-2.0 2015-02-01 21:34 8ÿ554 HELP_DECRYPT.HTML 2015-02-01 21:34 45ÿ739 HELP_DECRYPT.PNG 2015-02-01 21:34 1ÿ376 HELP_DECRYPT.TXT.kcirdgd 2015-02-01 21:34 276 HELP_DECRYPT.URL 2014-10-24 17:57 HP 2010-01-09 10:32 Identities 2014-01-20 22:20 IDM 2015-02-02 02:57 Iduqofen 2012-01-01 19:01 iFree 2011-02-23 17:00 IrfanView 2012-08-27 14:12 LolClient 2010-01-09 11:00 Macromedia 2010-04-10 15:37 MAGIX 2009-07-14 09:27 Media Center Programs 2013-01-14 16:17 Media Player Classic 2012-08-06 15:38 MegaCloud 2015-02-01 21:27 Microsoft 2010-04-06 22:28 Microsoft Web Folders 2013-01-14 14:56 mIRC 2014-05-19 21:48 mplayer 2015-02-01 21:28 Nero 2010-12-18 21:41 Nokia 2010-12-18 22:14 PC Suite 2010-03-08 23:34 proDAD 2010-02-18 11:54 Publish Providers 2015-02-01 21:28 Real 2012-08-30 22:24 Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 2014-03-17 16:10 Riot Games 2012-11-02 00:02 RoboForm 2015-02-01 21:28 Samsung 2015-02-02 22:09 Skype 2012-09-12 18:35 skypePM 2010-02-18 11:54 Sony 2013-05-15 21:10 SumatraPDF 2010-11-06 03:55 Tibia 2015-02-01 22:09 TS3Client 2014-03-17 17:34 TuneUp Software 2010-03-09 18:43 Ulead Systems 2013-01-14 16:17 Ventrilo 2012-03-03 18:46 vlc 2012-08-24 21:58 VOIPlay 2014-11-09 11:58 67 WB.CFG 2010-01-10 14:53 WinRAR 8 plik(¢w) 56ÿ193 bajt¢w 75 katalog(¢w) 7ÿ210ÿ692ÿ608 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 2 GB temporary data. The system needed a reboot. ==== End of Fixlog 12:54:09 ====