Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:26-11-2015 Uruchomiony przez Benedykt (2015-11-27 14:00:29) Run:1 Uruchomiony z C:\Users\Benedykt\Desktop Załadowane profile: Benedykt (Dostępne profile: Benedykt) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: Startup: C:\Users\Benedykt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\home.vbe [2015-09-08] () HKU\S-1-5-21-2484522157-3572153485-187122026-1000\...\Run: [home] => wscript.exe //B "C:\Users\Benedykt\AppData\Roaming\home.vbe" HKU\S-1-5-21-2484522157-3572153485-187122026-1000\...\Run: [CyberGhost] => "C:\Program Files\CyberGhost 5\CyberGhost.exe" /autostart /min HKU\S-1-5-21-2484522157-3572153485-187122026-1000\...\Run: [BingSvc] => C:\Users\Benedykt\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-12] (© 2015 Microsoft Corporation) Task: {31B35F76-6CCA-46B3-805C-8F320061952F} - System32\Tasks\{A2362858-9A57-4169-ACC7-47B16D1B09E5} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.0.0.100&LastError=404 Task: {B0B4801C-D078-44F6-A6FD-F0EBB917CB41} - System32\Tasks\{EB46F74E-DB82-483D-BE74-3E9720EAA1F1} => Chrome.exe hxxp://ui.skype.com/ui/0/7.5.0.101/pl/abandoninstall?page=tsMain Task: {DE1B5D91-198D-4ABC-A1A0-03C7B0B7F934} - System32\Tasks\{3C58274C-BE88-4E21-87C0-E8F5478AAE6E} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.5.0.101&LastError=12002 C:\ProgramData\AskPartnerNetwork C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Cleaner Pro C:\Users\Benedykt\AppData\Local\Microsoft\BingSvc C:\Users\Benedykt\AppData\Roaming\home.vbe Reg: reg delete HKCU\Software\Google\Chrome\Extensions /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths" /s Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths" /s Reg: reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths" /s Reg: reg query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. C:\Users\Benedykt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\home.vbe => pomyślnie przeniesiono HKU\S-1-5-21-2484522157-3572153485-187122026-1000\Software\Microsoft\Windows\CurrentVersion\Run\\home => Wartość pomyślnie usunięto HKU\S-1-5-21-2484522157-3572153485-187122026-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CyberGhost => Wartość pomyślnie usunięto HKU\S-1-5-21-2484522157-3572153485-187122026-1000\Software\Microsoft\Windows\CurrentVersion\Run\\BingSvc => Wartość pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{31B35F76-6CCA-46B3-805C-8F320061952F}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{31B35F76-6CCA-46B3-805C-8F320061952F}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{A2362858-9A57-4169-ACC7-47B16D1B09E5} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A2362858-9A57-4169-ACC7-47B16D1B09E5}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B0B4801C-D078-44F6-A6FD-F0EBB917CB41}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0B4801C-D078-44F6-A6FD-F0EBB917CB41}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{EB46F74E-DB82-483D-BE74-3E9720EAA1F1} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EB46F74E-DB82-483D-BE74-3E9720EAA1F1}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE1B5D91-198D-4ABC-A1A0-03C7B0B7F934}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE1B5D91-198D-4ABC-A1A0-03C7B0B7F934}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{3C58274C-BE88-4E21-87C0-E8F5478AAE6E} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3C58274C-BE88-4E21-87C0-E8F5478AAE6E}" => klucz pomyślnie usunięto "C:\ProgramData\AskPartnerNetwork" => nie znaleziono. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Cleaner Pro => pomyślnie przeniesiono C:\Users\Benedykt\AppData\Local\Microsoft\BingSvc => pomyślnie przeniesiono C:\Users\Benedykt\AppData\Roaming\home.vbe => pomyślnie przeniesiono ========= reg delete HKCU\Software\Google\Chrome\Extensions /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths" /s ========= HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\PSPad.exe (domy˜lny) REG_SZ D:\Program Files (x86)\PSPad editor\PSPad.exe Path REG_SZ D:\Program Files (x86)\PSPad editor ========= Koniec Reg: ========= ========= reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ccleaner.exe (domy˜lny) REG_SZ C:\Program Files\CCleaner\CCleaner64.exe Path REG_SZ C:\Program Files\CCleaner HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Path REG_SZ C:\Program Files (x86)\Google\Chrome\Application HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe CmstpExtensionDll REG_SZ C:\Windows\system32\cmcfg32.dll CmNative REG_DWORD 0x2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\dexplore.exe (domy˜lny) REG_SZ "C:\Program Files (x86)\Common Files\Microsoft Shared\Help 8\dexplore.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\dvdmaker.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\DVD Maker\dvdmaker.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\excel.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\EXCEL.EXE Path REG_SZ D:\Microsoft Office\Office12\ SaveURL REG_SZ 1 useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\fsquirt.exe DropTarget REG_SZ {047ea9a0-93bb-415f-a1c3-d7aeb3dd5087} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEDIAG.EXE (domy˜lny) REG_SZ C:\Program Files\Internet Explorer\IEDIAGCMD.EXE Path REG_SZ C:\Program Files\Internet Explorer; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEDIAGCMD.EXE (domy˜lny) REG_SZ C:\Program Files\Internet Explorer\IEDIAGCMD.EXE Path REG_SZ C:\Program Files\Internet Explorer; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE (domy˜lny) REG_SZ C:\Program Files\Internet Explorer\IEXPLORE.EXE Path REG_SZ C:\Program Files\Internet Explorer; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE\SupportedProtocols https REG_SZ about REG_SZ mhtml REG_SZ mk REG_SZ file REG_SZ ftp REG_SZ res REG_SZ local REG_SZ http REG_SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\install.exe BlockOnTSNonInstallMode REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Journal.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\Windows Journal\Journal.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LangSelector.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\LangSelector.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MasterPDFEditor.exe MasterPDFEditor.exe REG_SZ C:\Program Files\Code Industry\Master PDF Editor 3\MasterPDFEditor.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mip.exe (domy˜lny) REG_EXPAND_SZ %CommonProgramFiles%\Microsoft Shared\Ink\mip.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MovieMaker.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mplayer2.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe Path REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSACCESS.EXE (domy˜lny) REG_SZ D:\MICROS~1\Office12\MSACCESS.EXE Path REG_SZ D:\Microsoft Office\Office12\ useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MsoHtmEd.exe useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\msoxmled.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLED.EXE useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ois.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\OIS.EXE Path REG_SZ D:\Microsoft Office\Office12\ SaveURL REG_SZ 0 useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pbrush.exe (domy˜lny) REG_EXPAND_SZ %SystemRoot%\System32\mspaint.exe Path REG_EXPAND_SZ %SystemRoot%\System32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pcdrcui.exe (domy˜lny) REG_SZ C:\Program Files\Dell\SupportAssist\pcdrcui.exe Path REG_SZ C:\Program Files\Dell\SupportAssist\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\powerpnt.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\POWERPNT.EXE Path REG_SZ D:\Microsoft Office\Office12\ useURL REG_SZ 1 SaveURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PowerShell.exe (domy˜lny) REG_SZ %SystemRoot%\system32\WindowsPowerShell\v1.0\PowerShell.exe Path REG_SZ %SystemRoot%\system32\WindowsPowerShell\v1.0\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PSPad.exe (domy˜lny) REG_SZ D:\Program Files (x86)\PSPad editor\PSPad.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pvexpress.exe (domy˜lny) REG_SZ C:\Program Files\PTC\Creo 3.0\View Express\bin\pvexpress.exe Path REG_SZ C:\Program Files\PTC\Creo 3.0\View Express\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\setup.exe BlockOnTSNonInstallMode REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sidebar.exe (domy˜lny) REG_EXPAND_SZ "%ProgramFiles%\Windows Sidebar\sidebar.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SnippingTool.exe (domy˜lny) REG_EXPAND_SZ %SystemRoot%\system32\SnippingTool.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\table30.exe UseShortName REG_SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TabTip.exe (domy˜lny) REG_EXPAND_SZ %CommonProgramFiles%\microsoft shared\ink\TabTip.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VCExpress.exe (domy˜lny) REG_SZ D:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\VCExpress.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\vsta.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\vsta.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wab.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\Windows Mail\wab.exe Path REG_EXPAND_SZ %ProgramFiles%\Windows Mail HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wabmig.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\Windows Mail\wabmig.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe (domy˜lny) REG_SZ D:\Program Files (x86)\WinRAR\WinRAR.exe Path REG_SZ D:\Program Files (x86)\WinRAR HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\WINWORD.EXE Path REG_SZ D:\Microsoft Office\Office12\ useURL REG_SZ 1 SaveURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wlarp.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\wlarp.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wlsettings.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\wlsettings.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wlstartup.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\wlstartup.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WLXAlbumDownloadWizard.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Photo Gallery\WLXAlbumDownloadWizard.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WLXPhotoGallery.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe Path REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WORDPAD.EXE (domy˜lny) REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WRITE.EXE (domy˜lny) REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" ========= Koniec Reg: ========= ========= reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\ccleaner.exe (domy˜lny) REG_SZ C:\Program Files\CCleaner\CCleaner64.exe Path REG_SZ C:\Program Files\CCleaner HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Path REG_SZ C:\Program Files (x86)\Google\Chrome\Application HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe CmstpExtensionDll REG_SZ C:\Windows\system32\cmcfg32.dll CmNative REG_DWORD 0x2 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\dexplore.exe (domy˜lny) REG_SZ "C:\Program Files (x86)\Common Files\Microsoft Shared\Help 8\dexplore.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\dvdmaker.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\DVD Maker\dvdmaker.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\excel.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\EXCEL.EXE Path REG_SZ D:\Microsoft Office\Office12\ SaveURL REG_SZ 1 useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\fsquirt.exe DropTarget REG_SZ {047ea9a0-93bb-415f-a1c3-d7aeb3dd5087} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEDIAG.EXE (domy˜lny) REG_SZ C:\Program Files\Internet Explorer\IEDIAGCMD.EXE Path REG_SZ C:\Program Files\Internet Explorer; HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEDIAGCMD.EXE (domy˜lny) REG_SZ C:\Program Files\Internet Explorer\IEDIAGCMD.EXE Path REG_SZ C:\Program Files\Internet Explorer; HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE (domy˜lny) REG_SZ C:\Program Files\Internet Explorer\IEXPLORE.EXE Path REG_SZ C:\Program Files\Internet Explorer; HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE\SupportedProtocols https REG_SZ about REG_SZ mhtml REG_SZ mk REG_SZ file REG_SZ ftp REG_SZ res REG_SZ local REG_SZ http REG_SZ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\install.exe BlockOnTSNonInstallMode REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Journal.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\Windows Journal\Journal.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\LangSelector.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\LangSelector.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\MasterPDFEditor.exe MasterPDFEditor.exe REG_SZ C:\Program Files\Code Industry\Master PDF Editor 3\MasterPDFEditor.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\mip.exe (domy˜lny) REG_EXPAND_SZ %CommonProgramFiles%\Microsoft Shared\Ink\mip.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\MovieMaker.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\mplayer2.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe Path REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\MSACCESS.EXE (domy˜lny) REG_SZ D:\MICROS~1\Office12\MSACCESS.EXE Path REG_SZ D:\Microsoft Office\Office12\ useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\MsoHtmEd.exe useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\msoxmled.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSOXMLED.EXE useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\ois.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\OIS.EXE Path REG_SZ D:\Microsoft Office\Office12\ SaveURL REG_SZ 0 useURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\pbrush.exe (domy˜lny) REG_EXPAND_SZ %SystemRoot%\System32\mspaint.exe Path REG_EXPAND_SZ %SystemRoot%\System32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\pcdrcui.exe (domy˜lny) REG_SZ C:\Program Files\Dell\SupportAssist\pcdrcui.exe Path REG_SZ C:\Program Files\Dell\SupportAssist\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\powerpnt.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\POWERPNT.EXE Path REG_SZ D:\Microsoft Office\Office12\ useURL REG_SZ 1 SaveURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\PowerShell.exe (domy˜lny) REG_SZ %SystemRoot%\system32\WindowsPowerShell\v1.0\PowerShell.exe Path REG_SZ %SystemRoot%\system32\WindowsPowerShell\v1.0\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\PSPad.exe (domy˜lny) REG_SZ D:\Program Files (x86)\PSPad editor\PSPad.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\pvexpress.exe (domy˜lny) REG_SZ C:\Program Files\PTC\Creo 3.0\View Express\bin\pvexpress.exe Path REG_SZ C:\Program Files\PTC\Creo 3.0\View Express\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\setup.exe BlockOnTSNonInstallMode REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\sidebar.exe (domy˜lny) REG_EXPAND_SZ "%ProgramFiles%\Windows Sidebar\sidebar.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\SnippingTool.exe (domy˜lny) REG_EXPAND_SZ %SystemRoot%\system32\SnippingTool.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\table30.exe UseShortName REG_SZ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\TabTip.exe (domy˜lny) REG_EXPAND_SZ %CommonProgramFiles%\microsoft shared\ink\TabTip.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\VCExpress.exe (domy˜lny) REG_SZ D:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\VCExpress.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\vsta.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\vsta.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\wab.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\Windows Mail\wab.exe Path REG_EXPAND_SZ %ProgramFiles%\Windows Mail HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\wabmig.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles%\Windows Mail\wabmig.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe (domy˜lny) REG_SZ D:\Program Files (x86)\WinRAR\WinRAR.exe Path REG_SZ D:\Program Files (x86)\WinRAR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe (domy˜lny) REG_SZ D:\MICROS~1\Office12\WINWORD.EXE Path REG_SZ D:\Microsoft Office\Office12\ useURL REG_SZ 1 SaveURL REG_SZ 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\wlarp.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\wlarp.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\wlsettings.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\wlsettings.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\wlstartup.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Installer\wlstartup.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\WLXAlbumDownloadWizard.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Photo Gallery\WLXAlbumDownloadWizard.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\WLXPhotoGallery.exe (domy˜lny) REG_SZ C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe Path REG_SZ C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.exe (domy˜lny) REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe Path REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Media Player HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\WORDPAD.EXE (domy˜lny) REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\WRITE.EXE (domy˜lny) REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" ========= Koniec Reg: ========= ========= reg query "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment" ========= HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe FP_NO_HOST_CHECK REG_SZ NO OS REG_SZ Windows_NT Path REG_EXPAND_SZ C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Windows Live\Shared PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE REG_SZ AMD64 TEMP REG_EXPAND_SZ %SystemRoot%\TEMP TMP REG_EXPAND_SZ %SystemRoot%\TEMP USERNAME REG_SZ SYSTEM windir REG_EXPAND_SZ %SystemRoot% PSModulePath REG_EXPAND_SZ %SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\ NUMBER_OF_PROCESSORS REG_SZ 4 PROCESSOR_LEVEL REG_SZ 6 PROCESSOR_IDENTIFIER REG_SZ Intel64 Family 6 Model 69 Stepping 1, GenuineIntel PROCESSOR_REVISION REG_SZ 4501 windows_tracing_logfile REG_SZ C:\BVTBin\Tests\installpackage\csilogfile.log windows_tracing_flags REG_SZ 3 ESET_OPTIONS REG_SZ VS90COMNTOOLS REG_SZ D:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\Tools\ ========= Koniec Reg: ========= EmptyTemp: => 1.2 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 14:00:40 ====