Rezultat naprawy Farbar Recovery Scan Tool (x86) Wersja:07-11-2015 Uruchomiony przez Ja (2015-11-14 21:02:59) Run:1 Uruchomiony z C:\ ZaÅ‚adowane profile: Ja & Administrator (DostÄ™pne profile: Ja & Administrator) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== UWAGA HKLM Group Policy restriction on software: C:\Program Files\Alwil Software <====== UWAGA HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k HKU\S-1-5-21-484763869-287218729-725345543-1003\...\Run: [NokiaPCInternetAccess] => "C:\Program Files\Nokia\PC Internet Access\NPCIA.exe" /b HKU\S-1-5-21-484763869-287218729-725345543-500\...\RunOnce: [Del450640] => cmd.exe /Q /D /c del "C:\DOCUME~1\ADMINI~1.000\USTAWI~1\Temp\0.del" <===== UWAGA Winlogon\Notify\WgaLogon: WgaLogon.dll [X] Task: C:\WINDOWS\Tasks\EPUpdater.job => C:\DOCUME~1\ADMINI~1.000\DANEAP~1\BABSOL~1\Shared\BabMaint.exe <==== UWAGA BootExecute: autocheck autochk * aswBoot.exe /M:29cec3ea4378 /dir:C:\Program S3 ADIHdAudAddService; system32\drivers\ADIHdAud.sys [X] S3 AEAudio; system32\drivers\AEAudio.sys [X] S3 catchme; \??\C:\DOCUME~1\Ja\USTAWI~1\Temp\catchme.sys [X] S3 CtClsFlt; system32\DRIVERS\CtClsFlt.sys [X] S3 EverestDriver; \??\C:\Documents and Settings\Ja\Pulpit\everestultimate_build_1066\kerneld.wnt [X] S3 GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS [X] S3 SenFiltService; system32\drivers\Senfilt.sys [X] ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => Brak pliku CustomCLSID: HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\Ja\Dane aplikacji\Dropbox\bin\Dropbox.exe /autoplay => Brak pliku CustomCLSID: HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\Ja\Dane aplikacji\Dropbox\bin\Dropbox.exe /wiacallback => Brak pliku StartMenuInternet: chrome.exe - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.22find.com/?utm_source=b&utm_medium=501&from=501&uid=SAMSUNGXHD252HJ_S17HJ9DQ402510&ts=1359556452 CHR StartupUrls: Default -> "hxxp://kl.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=876&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=PL&install_date=20130208&user_guid=9ABB1EEF6AF84127A188AA841AE180F6&machine_id=f17123d12604361b6e951b71ec099dee&browser=CR&os=win&os_version=5.1-x86-SP2" FF Session Restore: -> [funkcja wÅ‚Ä…czona] FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.9.0\\npsitesafety.dll [Brak pliku] FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll [2012-02-25] (Sun Microsystems, Inc.) FF Plugin: @mcafee.com/McAfeeMssPlugin -> C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll [2013-02-05] (McAfee, Inc.) FF Plugin: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll [2008-04-28] (RealNetworks, Inc.) FF Plugin: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll [2008-04-28] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll [2008-04-28] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll [2008-04-28] (RealNetworks, Inc.) FF Plugin: @VideoDownloadConverter_4z.com/Plugin -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll [2014-04-05] (Mindspark) FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF HKLM\...\Firefox\Extensions: [statuswinks@StatusWinks] - C:\Documents and Settings\Ja\Dane aplikacji\Mozilla\Extensions\statuswinks@StatusWinks FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF HKU\S-1-5-21-484763869-287218729-725345543-1003\...\Firefox\Extensions: [statuswinks@StatusWinks] - C:\Documents and Settings\Ja\Dane aplikacji\Mozilla\Extensions\statuswinks@StatusWinks HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=121845&babsrc=HP_ss&mntrId=7012A0F3C1320345 HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKU\S-1-5-21-484763869-287218729-725345543-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=121845&babsrc=HP_ss&mntrId=7012A0F3C1320345 HKU\S-1-5-21-484763869-287218729-725345543-500\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?affID=121845&babsrc=HP_ss&mntrId=7012A0F3C1320345 URLSearchHook: HKU\S-1-5-21-484763869-287218729-725345543-1003 - (Brak nazwy) - {93a3111f-4f74-4ed8-895e-d9708497629e} - Brak pliku URLSearchHook: [S-1-5-21-484763869-287218729-725345543-500] UWAGA => Brak domyÅ›lnego URLSearchHook SearchScopes: HKLM -> DefaultScope {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^pl&si=pconvIE&ptb=B3C08734-4B05-4A09-A3F8-9B80B65B6874&ind=2014040507&n=780bd1bb&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKLM -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://startsear.ch/?aff=1&src=sp&cf=658f9106-3646-11e1-a41e-001d92fcc647&q={searchTerms} SearchScopes: HKLM -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^pl&si=pconvIE&ptb=B3C08734-4B05-4A09-A3F8-9B80B65B6874&ind=2014040507&n=780bd1bb&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKLM -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms} SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> DefaultScope {B224AA02-F7C8-3A2B-859F-560B80767E4A} URL = hxxp://kl.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=876&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=PL&install_date=20130208&user_guid=9ABB1EEF6AF84127A188AA841AE180F6&machine_id=f17123d12604361b6e951b71ec099dee&browser=IE&os=win&os_version=5.1-x86-SP2&iesrc={referrer:source} SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {043C5167-00BB-4324-AF7E-62013FAEDACF} URL = hxxp://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch=dsp SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=118722&tt=0313_3&babsrc=SP_ss&mntrId=7012dd250000000000008c89a56842bf SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.22find.com/web/?utm_source=b&utm_medium=501&from=501&uid=SAMSUNGXHD252HJ_S17HJ9DQ402510&ts=1359556467 SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = hxxp://www.daemon-search.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {AE18CCFC-EB56-403E-988D-63288173B42F} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15000&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=PV&apn_dtid=YYYYYYYYPL&apn_uid=75f87e41-f4b0-4882-91da-0be8bf89eb67&apn_sauid=EC6FC408-320B-4E88-91F9-250DCC496F21 SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {B224AA02-F7C8-3A2B-859F-560B80767E4A} URL = hxxp://kl.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=876&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=PL&install_date=20130208&user_guid=9ABB1EEF6AF84127A188AA841AE180F6&machine_id=f17123d12604361b6e951b71ec099dee&browser=IE&os=win&os_version=5.1-x86-SP2&iesrc={referrer:source} SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^pl&si=pconvIE&ptb=B3C08734-4B05-4A09-A3F8-9B80B65B6874&ind=2014040507&n=780bd1bb&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms} SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> {F2B5AF9F-1C92-4912-9D12-B96FB65BA847} URL = hxxp://search.babylon.com/?q={searchTerms}&AF=108603&babsrc=SP_ss&mntrId=7012dd25000000000000001d92fcc647 SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-500 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKU\S-1-5-21-484763869-287218729-725345543-500 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=121845&babsrc=SP_ss&mntrId=7012A0F3C1320345 BHO: Brak nazwy -> {c547c6c2-561b-4169-a2a5-20ba771ca93b} -> Brak pliku Toolbar: HKU\S-1-5-21-484763869-287218729-725345543-1003 -> Brak nazwy - {32099AAC-C132-4136-9E9A-4E364A424E17} - Brak pliku DPF: {31435657-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/B/0/6/B06D48C0-917B-44E2-92E0-6B3E159624A6/wmv9vcm.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\BabSolution C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\Babylon C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\TestApp C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Menu Start\Programy\MiPony C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Pulpit\MiPony.lnk C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search C:\Documents and Settings\All Users\Dane aplikacji\MFAData C:\Documents and Settings\All Users\Menu Start\Programy\FlvPlayer C:\Documents and Settings\All Users\Menu Start\Programy\McAfee Security Scan Plus C:\Documents and Settings\All Users\Menu Start\Programy\Nokia PC Internet Access\Nokia PC Internet Access.lnk C:\Documents and Settings\Ja\Skrót do Ja.lnk C:\Documents and Settings\Ja\Dane aplikacji\skype.ini C:\Documents and Settings\Ja\Dane aplikacji\Babylon C:\Documents and Settings\Ja\Dane aplikacji\Desk 365 C:\Documents and Settings\Ja\Dane aplikacji\Mozilla\Extensions C:\Documents and Settings\Ja\Dane aplikacji\StartNow Toolbar C:\Documents and Settings\Ja\Dane aplikacji\StatusWinks C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\*.LNK C:\Documents and Settings\Ja\Menu Start\Programy\BitGuard C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Preferences C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Web Data C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Torpedo C:\Program Files\Desk 365 C:\Program Files\File Scout C:\Program Files\Java C:\Program Files\VideoDownloadConverter_4z C:\Program Files\WebCake C:\Program Files\Mozilla Firefox\extensions C:\Program Files\Mozilla Firefox\plugins C:\Program Files\Common Files\AVG Secure Search C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup C:\WINDOWS\pss\TorpedoCopy.lnkStartup RemoveDirectory: C:\ComboFix(2) DisableService: sptd CMD: del /q C:\ComboFix.txt.id-9850759202_helpme@freespeechmail.org Reg: reg delete HKCU\Software\Google\Chrome\Extensions /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^McAfee Security Scan Plus.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Ja^Menu Start^Programy^Autostart^TorpedoCopy.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Desk 365" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths" /s Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths" /s Reg: reg query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" CMD: set CMD: netsh firewall reset CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a "C:\Documents and Settings\All Users\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Ustawienia lokalne\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\Ja\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji" EmptyTemp: ***************** Procesy zostaÅ‚y pomyÅ›lnie zamkniÄ™te. Punkt przywracania zostaÅ‚ pomyÅ›lnie utworzony. HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== UWAGA => pomyÅ›lnie przywrócono HKLM Group Policy restriction on software: C:\Program Files\Alwil Software <====== UWAGA => pomyÅ›lnie przywrócono HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\NokiaPCInternetAccess => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-484763869-287218729-725345543-500\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del450640 => Wartość pomyÅ›lnie usuniÄ™to "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon" => klucz pomyÅ›lnie usuniÄ™to C:\WINDOWS\Tasks\EPUpdater.job => pomyÅ›lnie przeniesiono hklm\System\CurrentControlSet\Control\Session Manager\\BootExecute => Wartość pomyÅ›lnie przywrócono ADIHdAudAddService => serwis pomyÅ›lnie usuniÄ™to AEAudio => serwis pomyÅ›lnie usuniÄ™to catchme => serwis pomyÅ›lnie usuniÄ™to CtClsFlt => serwis pomyÅ›lnie usuniÄ™to EverestDriver => serwis pomyÅ›lnie usuniÄ™to GMSIPCI => serwis pomyÅ›lnie usuniÄ™to SenFiltService => serwis pomyÅ›lnie usuniÄ™to "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => klucz pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}" => klucz pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}" => klucz pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}" => klucz pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-484763869-287218729-725345543-1003_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}" => klucz pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Clients\StartMenuInternet\chrome.exe\shell\open\command\\Default => Wartość pomyÅ›lnie przywrócono Chrome StartupUrls => pomyÅ›lnie usuniÄ™to FF Session Restore: -> pomyÅ›lnie usuniÄ™to "HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin" => klucz pomyÅ›lnie usuniÄ™to HKLM\Software\MozillaPlugins\@java.com/JavaPlugin => klucz nie znaleziono. C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll => nie znaleziono. HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin => klucz nie znaleziono. C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll => nie znaleziono. HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852 => klucz nie znaleziono. C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll => nie znaleziono. HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46 => klucz nie znaleziono. C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll => nie znaleziono. HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662 => klucz nie znaleziono. C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll => nie znaleziono. HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46 => klucz nie znaleziono. C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll => nie znaleziono. HKLM\Software\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin => klucz nie znaleziono. C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll => nie znaleziono. HKLM\Software\Mozilla\Firefox\Extensions\\jqs@sun.com => Wartość nie znaleziono. HKLM\Software\Mozilla\Firefox\Extensions\\statuswinks@StatusWinks => Wartość pomyÅ›lnie usuniÄ™to HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Mozilla\Firefox\Extensions\\statuswinks@StatusWinks => Wartość pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => klucz pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer" => klucz pomyÅ›lnie usuniÄ™to HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Search Bar => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-484763869-287218729-725345543-500\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-484763869-287218729-725345543-500\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{93a3111f-4f74-4ed8-895e-d9708497629e} => Wartość nie znaleziono. Nie można przywrócić DomyÅ›lne URLSearchHook. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie przywrócono "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => klucz nie znaleziono. HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AE18CCFC-EB56-403E-988D-63288173B42F}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{AE18CCFC-EB56-403E-988D-63288173B42F} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B224AA02-F7C8-3A2B-859F-560B80767E4A}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{B224AA02-F7C8-3A2B-859F-560B80767E4A} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => klucz nie znaleziono. "HKU\S-1-5-21-484763869-287218729-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F2B5AF9F-1C92-4912-9D12-B96FB65BA847}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{F2B5AF9F-1C92-4912-9D12-B96FB65BA847} => klucz nie znaleziono. HKU\S-1-5-21-484763869-287218729-725345543-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Wartość pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-484763869-287218729-725345543-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => klucz nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b} => klucz nie znaleziono. HKCR\CLSID\{c547c6c2-561b-4169-a2a5-20ba771ca93b} => klucz nie znaleziono. HKU\S-1-5-21-484763869-287218729-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Wartość pomyÅ›lnie usuniÄ™to HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31435657-9980-0010-8000-00AA00389B71}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{31435657-9980-0010-8000-00AA00389B71} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-0000-0010-8000-00AA00389B71}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{33564D57-0000-0010-8000-00AA00389B71} => klucz nie znaleziono. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93} => klucz nie znaleziono. HKCR\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} => klucz nie znaleziono. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} => klucz nie znaleziono. HKCR\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} => klucz nie znaleziono. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} => klucz nie znaleziono. HKCR\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} => klucz nie znaleziono. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} => klucz nie znaleziono. HKCR\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} => klucz nie znaleziono. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} => klucz nie znaleziono. HKCR\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} => klucz nie znaleziono. C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\BabSolution => pomyÅ›lnie przeniesiono C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\Babylon => pomyÅ›lnie przeniesiono C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\TestApp => pomyÅ›lnie przeniesiono C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk => pomyÅ›lnie przeniesiono C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Menu Start\Programy\MiPony => pomyÅ›lnie przeniesiono C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Pulpit\MiPony.lnk => pomyÅ›lnie przeniesiono C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search => pomyÅ›lnie przeniesiono C:\Documents and Settings\All Users\Dane aplikacji\MFAData => pomyÅ›lnie przeniesiono C:\Documents and Settings\All Users\Menu Start\Programy\FlvPlayer => pomyÅ›lnie przeniesiono "C:\Documents and Settings\All Users\Menu Start\Programy\McAfee Security Scan Plus" => nie znaleziono. C:\Documents and Settings\All Users\Menu Start\Programy\Nokia PC Internet Access\Nokia PC Internet Access.lnk => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Skrót do Ja.lnk => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\skype.ini => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Babylon => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Desk 365 => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Mozilla\Extensions => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\StartNow Toolbar => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\StatusWinks => pomyÅ›lnie przeniesiono =========== "C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\*.LNK" ========== C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Adresy 2010.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Bóg was miÅ‚uje drogie dzieci.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Chorzy.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Co może przynieść nowy dzieÅ„.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\I Komunia Åšw.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\JAWA.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Katecheza.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Korespondencja.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Moje dokumenty.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\prezentacja na dzieÅ„ papieski.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Przedszkole.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Pulpit.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Teksty piosenek.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\UzupeÅ‚nianka.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Wspólnota KapÅ‚aÅ„ska.LNK => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\Åšpieszmy siÄ™ kochać.LNK => pomyÅ›lnie przeniesiono ========= Koniec -> "C:\Documents and Settings\Ja\Dane aplikacji\Microsoft\Office\Niedawny\*.LNK" ======== C:\Documents and Settings\Ja\Menu Start\Programy\BitGuard => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Preferences => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Web Data => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx => pomyÅ›lnie przeniesiono C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Torpedo => pomyÅ›lnie przeniesiono C:\Program Files\Desk 365 => pomyÅ›lnie przeniesiono C:\Program Files\File Scout => pomyÅ›lnie przeniesiono "C:\Program Files\Java" => nie znaleziono. C:\Program Files\VideoDownloadConverter_4z => pomyÅ›lnie przeniesiono "C:\Program Files\WebCake" => nie znaleziono. C:\Program Files\Mozilla Firefox\extensions => pomyÅ›lnie przeniesiono C:\Program Files\Mozilla Firefox\plugins => pomyÅ›lnie przeniesiono C:\Program Files\Common Files\AVG Secure Search => pomyÅ›lnie przeniesiono C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => pomyÅ›lnie przeniesiono C:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup => pomyÅ›lnie przeniesiono C:\WINDOWS\pss\TorpedoCopy.lnkStartup => pomyÅ›lnie przeniesiono "C:\ComboFix(2)" => pomyÅ›lnie usuniÄ™to. sptd => usÅ‚ugÄ™ wyÅ‚Ä…czono ========= del /q C:\ComboFix.txt.id-9850759202_helpme@freespeechmail.org ========= ========= Koniec CMD: ========= ========= reg delete HKCU\Software\Google\Chrome\Extensions /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^McAfee Security Scan Plus.lnk" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Ja^Menu Start^Programy^Autostart^TorpedoCopy.lnk" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Desk 365" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= BÅ‚Ä…d: system nie może odnaleźć okreÅ›lonego klucza rejestru lub wartoÅ›ci. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= BÅ‚Ä…d: system nie może odnaleźć okreÅ›lonego klucza rejestru lub wartoÅ›ci. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= BÅ‚Ä…d: system nie może odnaleźć okreÅ›lonego klucza rejestru lub wartoÅ›ci. ========= Koniec Reg: ========= ========= reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths" /s ========= ! REG.EXE VERSION 3.0 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths ========= Koniec Reg: ========= ========= reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths" /s ========= ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AcroRd32.exe REG_SZ C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe Path REG_SZ C:\Program Files\Adobe\Reader 11.0\Reader\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AvastUI.exe Path REG_SZ C:\Program Files\AVAST Software\Avast;C:\Program Files\AVAST Software\Avast\Setup REG_SZ C:\Program Files\AVAST Software\Avast\AvastUI.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\bckgzm.exe REG_SZ C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chkrzm.exe REG_SZ C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe Path REG_SZ C:\Program Files\Google\Chrome\Application REG_SZ C:\Program Files\Google\Chrome\Application\chrome.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe Path REG_SZ C:\WINDOWS\system32 CmstpExtensionDll REG_SZ C:\WINDOWS\system32\cmcfg32.dll CMInternalVersion REG_SZ 1.2 CmNative REG_DWORD 0x1 ProfilesUpgraded REG_DWORD 0x2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe REG_SZ C:\Documents and Settings\Ja\Pulpit\ComboFix.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\CONF.EXE REG_SZ C:\Program Files\NetMeeting\conf.exe Path REG_SZ C:\Program Files\NetMeeting; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\CtAfxApp.exe Path REG_SZ C:\Program Files\Creative\Creative Live! Cam\AudioFX HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\dialer.exe REG_SZ C:\Program Files\Windows NT\dialer.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\excel.exe REG_SZ C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ SaveURL REG_SZ 1 useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe REG_SZ C:\Program Files\Mozilla Firefox\firefox.exe Path REG_SZ C:\Program Files\Mozilla Firefox HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\GROOVE.EXE REG_SZ C:\PROGRA~1\MICROS~2\Office12\GROOVE.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HELPCTR.EXE REG_EXPAND_SZ %Systemroot%\PCHealth\HelpCtr\Binaries\HelpCtr.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\hrtzzm.exe REG_SZ C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\hypertrm.exe REG_SZ "C:\Program Files\Windows NT\hypertrm.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ICWCONN1.EXE REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE" Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ICWCONN2.EXE REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE" Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE REG_SZ C:\Program Files\Internet Explorer\IEXPLORE.EXE Path REG_SZ C:\Program Files\Internet Explorer; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\INETWIZ.EXE REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE" Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\infopath.exe REG_SZ C:\PROGRA~1\MICROS~2\Office12\INFOPATH.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\install.exe RunAsOnNonAdminInstall REG_DWORD 0x1 BlockOnTSNonInstallMode REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ISIGNUP.EXE REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE" Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\migwiz.exe REG_EXPAND_SZ %SystemRoot%\system32\usmt\migwiz.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ML-1610 CommonSM Path REG_SZ C:\Program Files\Samsung ML-1610 Series HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\moviemk.exe REG_SZ C:\Program Files\Movie Maker\moviemk.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mpc-hc.exe REG_SZ "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe" Path REG_SZ "C:\Program Files\K-Lite Codec Pack\Media Player Classic" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mplayer2.exe REG_SZ "C:\Program Files\Windows Media Player\mplayer2.exe" Path REG_SZ "C:\Program Files\Windows Media Player" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSACCESS.EXE REG_SZ C:\PROGRA~1\MICROS~2\Office12\MSACCESS.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSCONFIG.EXE REG_EXPAND_SZ %systemroot%\pchealth\helpctr\Binaries\MSCONFIG.EXE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\msimn.exe REG_EXPAND_SZ %ProgramFiles%\Outlook Express\msimn.exe Path REG_EXPAND_SZ %ProgramFiles%\Outlook Express HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\msinfo32.exe REG_SZ C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe Path REG_SZ C:\Program Files\Common Files\Microsoft Shared\MSInfo HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE REG_SZ C:\Program Files\Messenger\msmsgs.exe Path REG_SZ C:\Program Files\Messenger; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MsoHtmEd.exe useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\msoxmled.exe REG_SZ C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLED.EXE useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSPUB.EXE REG_SZ C:\PROGRA~1\MICROS~2\Office12\MSPUB.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ useURL REG_DWORD 0x1 SaveURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OCLUTL.exe Path REG_SZ C:\Program Files\Okidata\Colour Correct Utility REG_SZ C:\Program Files\Okidata\Colour Correct Utility\OCLUTL.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ois.exe REG_SZ C:\PROGRA~1\MICROS~2\Office12\OIS.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ SaveURL REG_SZ 0 useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OneNote.exe REG_SZ C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ SaveURL REG_SZ 1 useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Opera.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE REG_SZ C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pbrush.exe REG_EXPAND_SZ %SystemRoot%\system32\mspaint.exe Path REG_EXPAND_SZ %SystemRoot%\system32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pinball.exe REG_SZ C:\Program Files\Windows NT\Pinball\pinball.exe Path REG_SZ C:\Program Files\Windows NT\Pinball HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\powerpnt.exe REG_SZ C:\PROGRA~1\MICROS~2\Office12\POWERPNT.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ useURL REG_SZ 1 SaveURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\rvsezm.exe REG_SZ C:\Program Files\MSN Gaming Zone\Windows\rvsezm.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\setup.exe RunAsOnNonAdminInstall REG_DWORD 0x1 BlockOnTSNonInstallMode REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\shvlzm.exe REG_SZ C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smax4pnp.exe REG_SZ C:\Program Files\Analog Devices\Core\smax4pnp.exe Path REG_SZ C:\Program Files\Analog Devices\Core HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smax4wiz.exe REG_SZ C:\Program Files\Analog Devices\SoundMAX\smax4wiz.exe Path REG_SZ C:\Program Files\Analog Devices\Core HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SMaxCore REG_SZ C:\Program Files\Analog Devices\Core Path REG_SZ C:\Program Files\Analog Devices\Core HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smwdmif.dll REG_SZ C:\Program Files\Analog Devices\Core\smwdmif.dll Path REG_SZ C:\Program Files\Analog Devices\Core HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SoundMAX Path REG_SZ C:\Program Files\Analog Devices\SoundMAX REG_SZ C:\Program Files\Analog Devices\SoundMAX HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\table30.exe UseShortName REG_SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wab.exe REG_EXPAND_SZ %ProgramFiles%\Outlook Express\wab.exe Path REG_EXPAND_SZ %ProgramFiles%\Outlook Express HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wabmig.exe REG_EXPAND_SZ %ProgramFiles%\Outlook Express\wabmig.exe Path REG_EXPAND_SZ %ProgramFiles%\Outlook Express HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\winamp.exe REG_SZ C:\Program Files\Winamp\winamp.exe Path REG_SZ C:\Program Files\Winamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\winnt32.exe RunAsOnNonAdminInstall REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe REG_SZ C:\Program Files\WinRAR\WinRAR.exe Path REG_SZ C:\Program Files\WinRAR HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe REG_SZ C:\PROGRA~1\MICROS~2\Office12\WINWORD.EXE Path REG_SZ C:\Program Files\Microsoft Office\Office12\ useURL REG_SZ 1 SaveURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.exe REG_SZ C:\Program Files\Windows Media Player\wmplayer.exe Path REG_SZ C:\Program Files\Windows Media Player HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WORDPAD.EXE REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WRITE.EXE REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\XPSViewer.exe REG_SZ "C:\WINDOWS\system32\XPSViewer\XPSViewer.exe" ========= Koniec Reg: ========= ========= reg query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" ========= ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe Path REG_EXPAND_SZ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\Skype\Phone\ windir REG_EXPAND_SZ %SystemRoot% FP_NO_HOST_CHECK REG_SZ NO OS REG_SZ Windows_NT PROCESSOR_ARCHITECTURE REG_SZ x86 PROCESSOR_LEVEL REG_SZ 6 PROCESSOR_IDENTIFIER REG_SZ x86 Family 6 Model 23 Stepping 6, GenuineIntel PROCESSOR_REVISION REG_SZ 1706 NUMBER_OF_PROCESSORS REG_SZ 2 PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH TEMP REG_EXPAND_SZ %SystemRoot%\TEMP TMP REG_EXPAND_SZ %SystemRoot%\TEMP ========= Koniec Reg: ========= ========= set ========= ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Ja\Dane aplikacji CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=XXX-8C2238048E0 ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Ja LOGONSERVER=\\XXX-8C2238048E0 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\Skype\Phone\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 23 Stepping 6, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=1706 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Ja\USTAWI~1\Temp TMP=C:\DOCUME~1\Ja\USTAWI~1\Temp USERDOMAIN=XXX-8C2238048E0 USERNAME=Ja USERPROFILE=C:\Documents and Settings\Ja windir=C:\WINDOWS __COMPAT_LAYER=EnableNXShowUI ========= Koniec CMD: ========= ========= netsh firewall reset ========= Ok. ========= Koniec CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 7012-DD25 Katalog: C:\Program Files 2015-11-14 21:03 . 2015-11-14 21:03 .. 2014-04-05 12:34 197 016 4zres.dll 2014-04-05 12:34 860 232 4zUninstall VideoDownloadConverter.dll 2014-04-05 11:47 ACD Systems 2015-11-14 20:02 Adobe 2010-11-09 15:39 Alwil Software 2008-10-28 08:46 Analog Devices 2012-09-11 09:15 Audiograbber 2013-04-09 21:13 AVAST Software 2015-10-01 06:41 AVG Secure Search 2014-08-26 17:51 AVG Security Toolbar 2015-11-14 20:09 Common Files 2008-07-29 13:45 ComPlus Applications 2013-10-08 15:30 Creative 2011-06-02 13:09 DIFX 2013-11-30 15:01 DVDVideoSoft 2008-07-29 14:40 Foxit Software 2014-04-10 09:52 Google 2013-01-22 16:39 GUM21.tmp 2013-01-22 16:40 GUM2A.tmp 2013-01-22 16:41 GUM39.tmp 2013-01-22 16:38 GUMD.tmp 2010-01-08 17:09 HotPotatoes6 2012-09-11 09:15 ImgBurn 2014-12-29 19:33 InstallShield Installation Information 2009-01-23 23:01 Intel 2014-04-10 07:02 Internet Explorer 2014-05-28 14:14 IrfanView 2013-02-08 17:41 K-Lite Codec Pack 2013-04-09 19:03 Messenger 2008-07-29 13:48 microsoft frontpage 2011-02-23 15:35 Microsoft Office 2012-11-29 15:33 Microsoft Silverlight 2008-07-29 14:14 Microsoft Visual Studio 2011-02-23 15:35 Microsoft Works 2013-04-09 18:50 Movie Maker 2015-11-14 21:03 Mozilla Firefox 2015-10-18 05:25 Mozilla Maintenance Service 2013-10-17 17:23 MSBuild 2008-07-29 13:45 MSN Gaming Zone 2013-01-20 20:17 NAPI-PROJEKT 2013-02-25 15:46 NetMeeting 2013-10-10 18:21 Nokia 2010-01-19 15:15 Okidata 2014-05-28 14:11 Opera 2013-04-09 18:51 Outlook Express 2013-10-10 18:20 PC Connectivity Solution 2008-12-16 19:24 Pekka Kana 2 2014-12-29 19:33 Realtek 2013-10-17 17:23 Reference Assemblies 2008-07-30 07:31 Samsung ML-1610 Series 2010-01-19 09:05 SkanerOnline 2015-08-21 06:45 Skype 2012-09-11 09:15 SlimCleaner 2008-10-13 13:13 SokoMind 2011-07-20 20:27 SubEdit-Player 2013-12-14 18:34 TeamViewer 2008-07-29 13:52 Uninstall Information 2008-07-29 13:46 Us³ugi online 2014-12-29 19:32 VIA 2010-04-06 17:59 Winamp 2015-11-14 20:13 Winamp Toolbar 2013-10-04 09:19 Windows Media Connect 2 2013-10-04 09:21 Windows Media Player 2013-02-25 15:46 Windows NT 2008-07-29 13:46 WindowsUpdate 2009-08-06 08:11 WinRAR 2009-11-17 08:07 Wru 2008-07-29 13:48 xerox 2 plik(ów) 1 057 248 bajtów 68 katalog(ów) 6 505 230 336 bajtów wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Program Files\Common Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 7012-DD25 Katalog: C:\Program Files\Common Files 2015-11-14 21:03 . 2015-11-14 21:03 .. 2013-02-06 07:45 337 2014-05-14 07:05 Adobe 2011-02-23 15:35 DESIGNER 2013-11-30 15:01 DVDVideoSoft 2014-12-29 19:32 InstallShield 2011-02-23 15:39 Microsoft Shared 2008-07-29 13:46 MSSoap 2013-10-10 18:21 Nokia 2008-07-29 15:40 ODBC 2013-10-10 18:21 PCSuite 2008-07-29 13:46 Services 2015-08-21 06:45 Skype 2008-07-29 15:40 SpeechEngines 2013-02-25 15:53 System 0 plik(ów) 0 bajtów 16 katalog(ów) 6 505 160 704 bajtów wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Documents and Settings\All Users\Dane aplikacji" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 7012-DD25 Katalog: C:\Documents and Settings\All Users\Dane aplikacji 2015-11-14 21:03 . 2015-11-14 21:03 .. 2013-10-26 08:25 Adobe 2010-11-09 15:35 Alwil Software 2014-01-16 21:07 AVAST Software 2013-11-30 15:08 AVG 2013-04-09 20:37 AVG2013 2014-08-26 16:51 Avg_Update_0814tb 2012-01-18 16:40 Babylon 2012-09-09 17:55 Common Files 2013-10-25 18:18 Creative 2011-05-27 15:10 DAEMON Tools Lite 2008-07-29 15:39 62 desktop.ini 2008-11-12 20:18 GARMIN 2013-08-21 14:51 GG 2013-05-16 06:40 Google 2015-03-16 13:38 Google Updater 2013-10-10 18:18 Installations 2013-04-09 04:52 Malwarebytes 2010-04-18 17:03 McAfee 2013-10-10 18:28 Microsoft 2015-11-11 13:59 Microsoft Help 2012-09-07 15:22 Mozilla 2010-04-18 19:41 NOS 2008-10-25 18:02 nView_Profiles 2014-09-09 18:43 PC Suite 2013-04-09 05:02 PC Tools 2015-10-19 12:42 Skype 2010-03-12 07:43 Sun 2015-11-14 20:14 Tarma Installer 2013-02-16 15:48 TP-LINK 2013-04-09 19:52 Windows Genuine Advantage 2009-11-17 08:09 Wru 2013-12-01 18:40 {01BD4FC9-2F86-4706-A62E-774BB7E9D308} 1 plik(ów) 62 bajtów 33 katalog(ów) 6 505 160 704 bajtów wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 7012-DD25 Katalog: C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Dane aplikacji 2015-11-14 21:03 . 2015-11-14 21:03 .. 2013-06-17 21:28 0D0S1L2Z1P1B0T1P1B2Z 2013-04-08 21:27 Adobe 2013-06-17 21:28 Delta 2008-07-29 15:39 62 desktop.ini 2013-06-17 21:27 DSite 2010-04-18 17:03 Macromedia 2013-04-09 04:52 Malwarebytes 2013-04-09 04:50 Microsoft 2013-04-08 21:28 Mozilla 1 plik(ów) 62 bajtów 10 katalog(ów) 6 505 156 608 bajtów wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Ustawienia lokalne\Dane aplikacji" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 7012-DD25 Katalog: C:\Documents and Settings\Administrator.XXX-8C2238048E0.000\Ustawienia lokalne\Dane aplikacji 2015-10-26 15:29 . 2015-10-26 15:29 .. 2010-04-18 17:13 Adobe 2013-04-08 21:57 Google 2015-10-26 15:29 3 712 660 IconCache.db.id-9850759202_helpme@freespeechmail.org 2013-06-17 21:27 Microsoft 2013-04-08 21:27 Mozilla 1 plik(ów) 3 712 660 bajtów 6 katalog(ów) 6 505 156 608 bajtów wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Documents and Settings\Ja\Dane aplikacji" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 7012-DD25 Katalog: C:\Documents and Settings\Ja\Dane aplikacji 2015-11-14 21:03 . 2015-11-14 21:03 .. 2008-07-30 07:37 ABBYY 2014-04-05 11:48 ACD Systems 2013-11-07 20:26 Adobe 2014-01-16 21:30 AVAST Software 2013-11-30 15:08 AVG 2012-09-09 17:56 AVG Secure Search 2013-04-09 20:25 AVG2013 2014-04-17 06:09 Creative 2012-08-11 14:27 DAEMON Tools Lite 2008-07-29 15:39 62 desktop.ini 2013-11-30 15:02 DVDVideoSoft 2008-07-29 14:40 Gadu-Gadu 2008-11-12 20:18 GARMIN 2014-09-25 18:33 GG 2013-05-16 06:52 Google 2013-01-30 15:36 GoPlayer 2009-08-06 08:11 Help 2008-07-29 13:52 Identities 2012-08-11 14:04 ImgBurn 2008-07-30 07:43 Macromedia 2013-04-09 06:05 Malwarebytes 2008-10-13 13:04 Media Player Classic 2015-04-29 07:16 Microsoft 2008-07-30 07:38 Mozilla 2013-10-10 18:28 Nokia 2013-11-30 15:01 OpenCandy 2014-04-05 11:45 Opera Software 2013-10-10 18:28 PC Suite 2013-01-16 15:11 PerformerSoft 2015-11-14 17:33 Skype 2014-08-24 15:08 skypePM 2008-07-29 14:40 Sun 2014-11-07 09:30 Systweak 2013-12-14 18:34 TeamViewer 2013-04-09 20:23 TuneUp Software 2015-10-26 15:30 uTorrent 2014-04-05 12:43 WeatherBlink 2008-07-30 16:29 WebCompiler3 2015-10-26 15:30 Winamp 1 plik(ów) 62 bajtów 40 katalog(ów) 6 505 156 608 bajtów wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 7012-DD25 Katalog: C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji 2015-11-14 21:03 . 2015-11-14 21:03 .. 2008-09-16 16:45 ABBYY 2013-09-18 18:42 Adobe 2011-12-09 17:53 APN 2011-04-12 12:06 Apple Computer 2012-09-09 17:57 AVG Secure Search 2013-04-09 20:20 Avg2013 2013-11-30 15:33 Avg2014 2013-09-17 20:41 avgchrome 2013-01-20 17:50 129 024 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-12-14 18:49 69 736 GDIPFONTCACHEV1.DAT 2014-08-22 09:09 GG 2015-10-26 15:28 Google 2009-08-06 08:11 Help 2014-04-05 12:34 IAC 2015-11-14 19:54 4 825 770 IconCache.db 2015-11-11 13:49 5 890 816 IconCache.db.id-6844075619_helpme@freespeechmail.org 2015-10-26 15:28 4 809 338 IconCache.db.id-9850759202_helpme@freespeechmail.org 2008-07-29 14:37 Identities 2013-04-09 20:20 MFAData 2015-04-29 07:16 Microsoft 2011-02-23 15:30 Microsoft Help 2008-07-30 07:38 Mozilla 2014-04-05 11:45 Opera Software 2013-10-10 10:16 PCHealth 2014-04-10 09:54 Programs 2014-08-27 16:17 Skype 2012-08-11 14:24 SlimWare Utilities Inc 2014-03-30 11:41 Temp 5 plik(ów) 15 724 684 bajtów 25 katalog(ów) 6 505 152 512 bajtów wolnych ========= Koniec CMD: ========= EmptyTemp: => 3 GB danych tymczasowych UsuniÄ™to. System wymagaÅ‚ restartu. ==== Koniec Fixlog 21:05:55 ====