Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:19-11-2015 Uruchomiony przez Julka (2015-11-20 13:41:21) Run:1 Uruchomiony z C:\Users\Julka\Desktop ZaÅ‚adowane profile: Julka (DostÄ™pne profile: Julka) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: (Microsoft Corporation) C:\Windows\explorer.exe CreateRestorePoint: HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\...\Run: [fgdh4563] => C:\Users\Julka\AppData\Roaming\xffue-a.exe [331776 2015-11-18] () HKLM-x32\...\Run: [fgdh4563] => C:\Users\Julka\AppData\Roaming\xffue-a.exe [331776 2015-11-18] () HKLM-x32\...\Run: [] => [X] HKLM\...\Run: [PopularScreensavers Home Page Guard 64 bit] => "C:\PROGRA~2\POPULA~2\bar\1.bin\AppIntegrator64.exe" Startup: C:\Users\Julka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_moe.HTML [2015-11-19] () Startup: C:\Users\Julka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_moe.TXT [2015-11-19] () Task: {94C61E71-06F2-469E-88BD-298D56CAC2C7} - System32\Tasks\ghokswaBrowserUpdateUA => C:\Program Files (x86)\ghokswa Browser\ghokswa\bin\browserServer.exe [2015-10-20] () <==== UWAGA Task: {A4D461FF-94E3-42DB-A797-4DC786B93C17} - System32\Tasks\ghokswaBrowserUpdateCore => C:\Program Files (x86)\ghokswa Browser\ghokswa\bin\browserServer.exe [2015-10-20] () <==== UWAGA S2 browserServer_2015.08.27.11.31.05; C:\Program Files (x86)\ghokswa Browser\ghokswa\bin\browserServer.exe [362208 2015-10-20] () R0 pavboot; C:\Windows\System32\drivers\pavboot64.sys [33800 2009-06-30] (Panda Security, S.L.) S3 cpuz134; \??\C:\Users\Julka\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X] S1 {90280f97-bcf9-4f01-b773-3eeda0515e95}Gw64; system32\drivers\{90280f97-bcf9-4f01-b773-3eeda0515e95}Gw64.sys [X] HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.v9.com?type=hp&ts=1441000773&from=mych123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.v9.com?type=hp&ts=1441000773&from=mych123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com?type=hp&ts=1441000773&from=mych123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com?type=hp&ts=1441000773&from=mych123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.v9.com/?type=hp&ts=1441000773&from=mych123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com?type=hp&ts=1441000773&from=mych123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1441000773&from=zzgbkk123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo&q={searchTerms} SearchScopes: HKLM-x32 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://startsear.ch/?aff=1&src=sp&cf=11708afd-eac7-11e0-a1b0-2c27d7a5566a&q={searchTerms} SearchScopes: HKU\S-1-5-21-4176386080-2144407497-1899277294-1001 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1441000773&from=zzgbkk123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo&q={searchTerms} SearchScopes: HKU\S-1-5-21-4176386080-2144407497-1899277294-1001 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1441000773&from=zzgbkk123&uid=hitachixhts725050a9a364_110228pck404glh04xwjx&z=789c91bd0847027c3eb99a8g1zez9g1e1efeetacdo&q={searchTerms} SearchScopes: HKU\S-1-5-21-4176386080-2144407497-1899277294-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = SearchScopes: HKU\S-1-5-21-4176386080-2144407497-1899277294-1001 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = BHO-x32: Brak nazwy -> {b6d2ec49-14f2-c18a-896a-d4ca7857cc1a} -> Brak pliku Toolbar: HKU\S-1-5-21-4176386080-2144407497-1899277294-1001 -> Brak nazwy - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Brak pliku Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Brak pliku FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: delta-homes FF SelectedSearchEngine: delta-homes FF Homepage: hxxp://www.delta-homes.com/?type=hp&ts=1430819501&from=wpm05053&uid=HitachiXHTS725050A9A364_110228PCK404GLH04XWJX FF Plugin HKU\S-1-5-21-4176386080-2144407497-1899277294-1001: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll [Brak pliku] FF SearchPlugin: C:\Users\Julka\AppData\Roaming\Mozilla\Firefox\Profiles\yyu7xbvz.default-1413487133669\searchplugins\delta-homes.xml [2015-11-12] FF SearchPlugin: C:\Users\Julka\AppData\Roaming\Mozilla\Firefox\Profiles\yyu7xbvz.default-1413487133669\searchplugins\_how_recover_moe.HTML [2015-11-19] FF SearchPlugin: C:\Users\Julka\AppData\Roaming\Mozilla\Firefox\Profiles\yyu7xbvz.default-1413487133669\searchplugins\_how_recover_moe.TXT [2015-11-19] CHR HomePage: Default -> hxxp://www.delta-homes.com/?type=hp&ts=1430819501&from=wpm05053&uid=HitachiXHTS725050A9A364_110228PCK404GLH04XWJX CHR StartupUrls: Default -> "hxxp://www.delta-homes.com/?type=hp&ts=1430819501&from=wpm05053&uid=HitachiXHTS725050A9A364_110228PCK404GLH04XWJX" CHR DefaultSearchURL: Default -> hxxp://search.delta-homes.com/web/?type=ds&ts=1430819501&from=wpm05053&uid=HitachiXHTS725050A9A364_110228PCK404GLH04XWJX&q={searchTerms} CHR DefaultSearchKeyword: Default -> delta-homes AlternateDataStreams: C:\Users\Julka\Local Settings:init C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml C:\Program Files (x86)\SSFK.exe C:\Program Files (x86)\ghokswa Browser C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} C:\ProgramData\Temp C:\Users\Julka\xobglu16.dll C:\Users\Julka\xobglu32.dll C:\Users\Julka\AppData\Local\70149b02515b3bb20dd492.47983420 C:\Users\Julka\AppData\Local\8546 C:\Users\Julka\AppData\Local\Chromium C:\Users\Julka\AppData\Local\CRE C:\Users\Julka\AppData\Local\fabulous_09111903 C:\Users\Julka\AppData\Local\ghokswa C:\Users\Julka\AppData\Roaming\xffue-a.exe C:\Users\Julka\AppData\Roaming\E0F416BD-1428165423-D85B-F0AC-2C27D7A5566A C:\Users\Julka\AppData\Roaming\Godeb C:\Users\Julka\AppData\Roaming\Hoolapp Packages C:\Users\Julka\AppData\Roaming\Kiehve C:\Users\Julka\AppData\Roaming\wi_upd C:\Users\Julka\AppData\Roaming\Xuerw C:\Users\Julka\AppData\Roaming\Yzda C:\Users\Julka\Downloads\File.Downloader__9581_il196.exe C:\Users\Julka\Downloads\Spyhunter-4.5.7.3531-Key-Generator.rar.ccc C:\Users\Julka\Downloads\SpyHunter-Installer.exe C:\Users\Public\Documents\ghokswa C:\Windows\System32\drivers\pavboot64.sys CMD: for /d %f in (C:\Users\Julka\AppData\Local\{*}) do rd /s /q "%f" Reg: reg delete HKCU\Software\Classes\ghokswaHTM /f Reg: reg delete HKCU\Software\ghokswa /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKLM\SOFTWARE\Clients\StartMenuInternet\ghokswa /f Reg: reg delete HKLM\SOFTWARE\RegisteredApplications /v ghokswa /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\ghokswa /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\SpyHunter 4 Service" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\facemoods" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft Default Manager" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh firewall reset EmptyTemp: ***************** Procesy zostaÅ‚y pomyÅ›lnie zamkniÄ™te. [1688] C:\Windows\explorer.exe => proces pomyÅ›lnie zamkniÄ™ty. Punkt przywracania zostaÅ‚ pomyÅ›lnie utworzony. HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\Software\Microsoft\Windows\CurrentVersion\Run\\fgdh4563 => Wartość pomyÅ›lnie usuniÄ™to HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fgdh4563 => Wartość pomyÅ›lnie usuniÄ™to HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wartość pomyÅ›lnie usuniÄ™to HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\PopularScreensavers Home Page Guard 64 bit => Wartość pomyÅ›lnie usuniÄ™to C:\Users\Julka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_moe.HTML => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_moe.TXT => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{94C61E71-06F2-469E-88BD-298D56CAC2C7}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94C61E71-06F2-469E-88BD-298D56CAC2C7}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\ghokswaBrowserUpdateUA => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ghokswaBrowserUpdateUA" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4D461FF-94E3-42DB-A797-4DC786B93C17}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4D461FF-94E3-42DB-A797-4DC786B93C17}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\ghokswaBrowserUpdateCore => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ghokswaBrowserUpdateCore" => klucz pomyÅ›lnie usuniÄ™to browserServer_2015.08.27.11.31.05 => serwis pomyÅ›lnie usuniÄ™to pavboot => Nie można zatrzymać usÅ‚ugi. pavboot => serwis pomyÅ›lnie usuniÄ™to cpuz134 => serwis pomyÅ›lnie usuniÄ™to iSafeKrnlBoot => serwis nie znaleziono. {90280f97-bcf9-4f01-b773-3eeda0515e95}Gw64 => serwis pomyÅ›lnie usuniÄ™to HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie przywrócono "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => klucz nie znaleziono. HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => klucz nie znaleziono. "HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => klucz nie znaleziono. "HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6d2ec49-14f2-c18a-896a-d4ca7857cc1a}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{b6d2ec49-14f2-c18a-896a-d4ca7857cc1a} => klucz nie znaleziono. HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Wartość pomyÅ›lnie usuniÄ™to HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => klucz nie znaleziono. "HKCR\PROTOCOLS\Handler\linkscanner" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => klucz nie znaleziono. Firefox "newtab" pomyÅ›lnie usuniÄ™to Firefox DefaultSearchEngine pomyÅ›lnie usuniÄ™to Firefox SelectedSearchEngine pomyÅ›lnie usuniÄ™to Firefox "homepage" pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-4176386080-2144407497-1899277294-1001\Software\MozillaPlugins\@lightspark.github.com/Lightspark;version=1" => klucz pomyÅ›lnie usuniÄ™to C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll => nie znaleziono. C:\Users\Julka\AppData\Roaming\Mozilla\Firefox\Profiles\yyu7xbvz.default-1413487133669\searchplugins\delta-homes.xml => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Mozilla\Firefox\Profiles\yyu7xbvz.default-1413487133669\searchplugins\_how_recover_moe.HTML => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Mozilla\Firefox\Profiles\yyu7xbvz.default-1413487133669\searchplugins\_how_recover_moe.TXT => pomyÅ›lnie przeniesiono Chrome HomePage => pomyÅ›lnie usuniÄ™to Chrome StartupUrls => pomyÅ›lnie usuniÄ™to Chrome DefaultSearchURL => pomyÅ›lnie usuniÄ™to Chrome DefaultSearchKeyword => pomyÅ›lnie usuniÄ™to C:\Users\Julka\Local Settings => ":init" ADS pomyÅ›lnie usuniÄ™to. C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml => pomyÅ›lnie przeniesiono C:\Program Files (x86)\SSFK.exe => pomyÅ›lnie przeniesiono C:\Program Files (x86)\ghokswa Browser => pomyÅ›lnie przeniesiono "C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}" folder - przenoszenie: Nie można przenieść "C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}" => Zaplanowany do przeniesienia przy restarcie. C:\ProgramData\Temp => pomyÅ›lnie przeniesiono C:\Users\Julka\xobglu16.dll => pomyÅ›lnie przeniesiono C:\Users\Julka\xobglu32.dll => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Local\70149b02515b3bb20dd492.47983420 => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Local\8546 => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Local\Chromium => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Local\CRE => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Local\fabulous_09111903 => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Local\ghokswa => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\xffue-a.exe => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\E0F416BD-1428165423-D85B-F0AC-2C27D7A5566A => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Godeb => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Hoolapp Packages => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Kiehve => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\wi_upd => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Xuerw => pomyÅ›lnie przeniesiono C:\Users\Julka\AppData\Roaming\Yzda => pomyÅ›lnie przeniesiono C:\Users\Julka\Downloads\File.Downloader__9581_il196.exe => pomyÅ›lnie przeniesiono C:\Users\Julka\Downloads\Spyhunter-4.5.7.3531-Key-Generator.rar.ccc => pomyÅ›lnie przeniesiono C:\Users\Julka\Downloads\SpyHunter-Installer.exe => pomyÅ›lnie przeniesiono C:\Users\Public\Documents\ghokswa => pomyÅ›lnie przeniesiono C:\Windows\System32\drivers\pavboot64.sys => pomyÅ›lnie przeniesiono ========= for /d %f in (C:\Users\Julka\AppData\Local\{*}) do rd /s /q "%f" ========= ========= Koniec CMD: ========= ========= reg delete HKCU\Software\Classes\ghokswaHTM /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\ghokswa /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Clients\StartMenuInternet\ghokswa /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\RegisteredApplications /v ghokswa /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\ghokswa /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\SpyHunter 4 Service" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\facemoods" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Microsoft Default Manager" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= netsh firewall reset ========= WA½NE: Polecenie zostaˆo wykonane pomy˜lnie. Jednak polecenie "netsh firewall" jest wycofywane. Zamiast niego nale¾y u¾ywa† polecenia "netsh advfirewall firewall". Wi©cej informacji na temat u¾ywania polecenia "netsh advfirewall firewall" zamiast polecenia "netsh firewall" mo¾na znale«† w artykule 947709 z Bazy wiedzy pod adresem http://go.microsoft.com/fwlink/?linkid=121488. Ok. ========= Koniec CMD: ========= EmptyTemp: => 5 GB danych tymczasowych UsuniÄ™to. Rezultat przenoszenia plików przy restarcie (Tryb startu: Normal) (Data i godzina: 2015-11-20 13:56:45) C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} => zostaÅ‚ pomyÅ›lnie przeniesiony ==== Koniec Fixlog 13:56:45 ====