Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:09-12-2015 Uruchomiony przez Asia (2015-12-10 20:37:40) Run:1 Uruchomiony z C:\Users\Asia\Downloads Załadowane profile: Asia & UpdatusUser (Dostępne profile: Asia & UpdatusUser) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: R2 IhPul; C:\Users\Asia\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: ) R2 WdMan; C:\ProgramData\MWdMM\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] S2 cewiqigy; C:\Users\Asia\AppData\Roaming\VOPackage\nsrD2B2.tmpfs [X] S2 serverjo; C:\Users\Asia\AppData\Roaming\VOPackage\JOSrv.exe [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 L1C; system32\DRIVERS\L1C62x64.sys [X] S1 wfdrvr_vt_1_10_0_28; system32\drivers\wfdrvr_vt_1_10_0_28.sys [X] S1 wpnfd_1_10_0_9; system32\drivers\wpnfd_1_10_0_9.sys [X] ShortcutWithArgument: C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA ShortcutWithArgument: C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA ShortcutWithArgument: C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA ShortcutWithArgument: C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA ShortcutWithArgument: C:\Users\Asia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA ShortcutWithArgument: C:\Users\Asia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA ShortcutWithArgument: C:\Users\Asia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 <==== UWAGA StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1446941988&z=32fe40539e6d14bf8115ecbgfzaz6q4t2zfg8m1g4g&from=cornl&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1429820466&from=cor&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1429820466&from=cor&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7&q={searchTerms} HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1429820466&from=cor&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7&q={searchTerms} HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449731038&z=3a5578b47ff78afeb63028bg2z9z3temcccgbe8zeg&from=ient07021&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7 HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1429820466&from=cor&uid=ST1000LM014-1EJ164_W380KKV7XXXXW380KKV7&q={searchTerms} SearchScopes: HKU\S-1-5-21-3791551304-1605642030-3926548003-1003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: Media View -> {91e22662-2e45-4335-ba74-745049e5a7ea} -> C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha763\ie\MediaViewV1alpha763.dll => Brak pliku BHO-x32: Media Watch -> {9977a7da-db58-4139-9200-fca246fff1bf} -> C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home630\ie\MediaWatchV1home630.dll => Brak pliku BHO-x32: Media Player -> {a5039609-ab5b-42fb-ac34-7c2d5f62a9c5} -> C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha774\ie\MediaPlayerV1alpha774.dll => Brak pliku BHO-x32: Video Player -> {a85ef1e9-bbb4-4e0d-9546-831c482cde00} -> C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2985\ie\VideoPlayerV3beta2985.dll => Brak pliku CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA CHR HKLM-x32\...\Chrome\Extension: [gfnlgeljjnnbnnapcpppkipgggkmgbfo] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha763\ch\MediaViewV1alpha763.crx CHR HKLM-x32\...\Chrome\Extension: [jnhkealinadhpoolehpnfjnogaddkgpi] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home630\ch\MediaWatchV1home630.crx CHR HKLM-x32\...\Chrome\Extension: [mbkanhkelbmeipinmjmmaoieefdhlpcn] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta2985\ch\VideoPlayerV3beta2985.crx HKLM\...\Run: [Windows NTV Host Monitor] => C:\Program Files\Retro PC Calculator\ntvmon32.exe HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\...\Run: [ChicaPasswordManager] => "C:\Program Files (x86)\ChicaLogic\Chica Password Manager\stpass.exe" /autorunned Task: {623AD434-2274-4122-8A96-A7763FF26B71} - System32\Tasks\{355FDAE7-5F65-4E92-ABD8-B934B862C5F6} => pcalua.exe -a "C:\Users\Asia\Downloads\dotNetFx35setup (1).exe" -d C:\Users\Asia\Downloads Task: {D0F7AB26-9C77-4DD5-A749-B59D2F47253B} - System32\Tasks\{C5D18A72-8183-40C3-BBFB-9D3F6096162E} => pcalua.exe -a C:\PROGRA~2\Ubisoft\PETZ4~1\UNWISE.EXE -c C:\PROGRA~2\Ubisoft\PETZ4~1\INSTALL.LOG C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\SFK C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\ProgramData\mntemp C:\ProgramData\BWdMB C:\ProgramData\MWdMM C:\ProgramData\Mozilla C:\ProgramData\Nero C:\ProgramData\Norton C:\ProgramData\NortonInstaller C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks C:\Users\Asia\AppData\Local\nsr9BB0.tmp C:\Users\Asia\AppData\Local\Mozilla C:\Users\Asia\AppData\Local\Opera Software C:\Users\Asia\AppData\Local\WMTools Downloaded Files C:\Users\Asia\AppData\Roaming\.# C:\Users\Asia\AppData\Roaming\Mozilla C:\Users\Asia\AppData\Roaming\Opera Software C:\Users\Asia\AppData\Roaming\TSv C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gametree C:\Users\Asia\Desktop\RODZICE\PIT pro 2013.lnk C:\Users\Asia\Documents\ľŮ¸®»ţ\µżżµ»ó\łěČ­ µżżµ»ó Ŕç»ý ÄÚµ¦ ĽłÄˇ.lnk C:\Users\Asia\Downloads\*.crdownload C:\Users\UpdatusUser\Desktop\*.lnk C:\Windows\SysWOW64\pl.html Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MediaPlayerV1alpha774 /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MediaViewV1alpha763 /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MediaWatchV1home630 /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh advfirewall reset EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. IhPul => serwis pomyślnie usunięto SSFK => Usługa pomyślnie zatrzymana. SSFK => serwis pomyślnie usunięto WdMan => serwis pomyślnie usunięto cewiqigy => serwis pomyślnie usunięto serverjo => serwis pomyślnie usunięto EagleX64 => serwis pomyślnie usunięto L1C => serwis pomyślnie usunięto wfdrvr_vt_1_10_0_28 => serwis pomyślnie usunięto wpnfd_1_10_0_9 => serwis pomyślnie usunięto C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk => Skrót - argument pomyślnie usunięto. C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Skrót - argument pomyślnie przywrócono C:\Users\Asia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Asia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Asia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-3791551304-1605642030-3926548003-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91e22662-2e45-4335-ba74-745049e5a7ea}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{91e22662-2e45-4335-ba74-745049e5a7ea}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9977a7da-db58-4139-9200-fca246fff1bf}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{9977a7da-db58-4139-9200-fca246fff1bf}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a5039609-ab5b-42fb-ac34-7c2d5f62a9c5}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{a5039609-ab5b-42fb-ac34-7c2d5f62a9c5}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a85ef1e9-bbb4-4e0d-9546-831c482cde00}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{a85ef1e9-bbb4-4e0d-9546-831c482cde00}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Policies\Google" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gfnlgeljjnnbnnapcpppkipgggkmgbfo" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jnhkealinadhpoolehpnfjnogaddkgpi" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mbkanhkelbmeipinmjmmaoieefdhlpcn" => klucz pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Windows NTV Host Monitor => Wartość pomyślnie usunięto HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wartość pomyślnie usunięto HKU\S-1-5-21-3791551304-1605642030-3926548003-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ChicaPasswordManager => Wartość pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{623AD434-2274-4122-8A96-A7763FF26B71}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{623AD434-2274-4122-8A96-A7763FF26B71}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{355FDAE7-5F65-4E92-ABD8-B934B862C5F6} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{355FDAE7-5F65-4E92-ABD8-B934B862C5F6}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D0F7AB26-9C77-4DD5-A749-B59D2F47253B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0F7AB26-9C77-4DD5-A749-B59D2F47253B}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{C5D18A72-8183-40C3-BBFB-9D3F6096162E} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C5D18A72-8183-40C3-BBFB-9D3F6096162E}" => klucz pomyślnie usunięto C:\Program Files (x86)\Mozilla Firefox => pomyślnie przeniesiono C:\Program Files (x86)\SFK => pomyślnie przeniesiono C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => pomyślnie przeniesiono C:\ProgramData\mntemp => pomyślnie przeniesiono C:\ProgramData\BWdMB => pomyślnie przeniesiono C:\ProgramData\MWdMM => pomyślnie przeniesiono C:\ProgramData\Mozilla => pomyślnie przeniesiono C:\ProgramData\Nero => pomyślnie przeniesiono C:\ProgramData\Norton => pomyślnie przeniesiono C:\ProgramData\NortonInstaller => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightworks => pomyślnie przeniesiono C:\Users\Asia\AppData\Local\nsr9BB0.tmp => pomyślnie przeniesiono C:\Users\Asia\AppData\Local\Mozilla => pomyślnie przeniesiono C:\Users\Asia\AppData\Local\Opera Software => pomyślnie przeniesiono C:\Users\Asia\AppData\Local\WMTools Downloaded Files => pomyślnie przeniesiono C:\Users\Asia\AppData\Roaming\.# => pomyślnie przeniesiono C:\Users\Asia\AppData\Roaming\Mozilla => pomyślnie przeniesiono C:\Users\Asia\AppData\Roaming\Opera Software => pomyślnie przeniesiono C:\Users\Asia\AppData\Roaming\TSv => pomyślnie przeniesiono C:\Users\Asia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gametree => pomyślnie przeniesiono C:\Users\Asia\Desktop\RODZICE\PIT pro 2013.lnk => pomyślnie przeniesiono C:\Users\Asia\Documents\ľŮ¸®»ţ\µżżµ»ó\łěČ­ µżżµ»ó Ŕç»ý ÄÚµ¦ ĽłÄˇ.lnk => pomyślnie przeniesiono =========== "C:\Users\Asia\Downloads\*.crdownload" ========== C:\Users\Asia\Downloads\Niepotwierdzony 845810.crdownload => pomyślnie przeniesiono ========= Koniec -> "C:\Users\Asia\Downloads\*.crdownload" ======== =========== "C:\Users\UpdatusUser\Desktop\*.lnk" ========== C:\Users\UpdatusUser\Desktop\Alicia.lnk => pomyślnie przeniesiono C:\Users\UpdatusUser\Desktop\Pet Workshop.lnk => pomyślnie przeniesiono C:\Users\UpdatusUser\Desktop\Petz 5.lnk => pomyślnie przeniesiono C:\Users\UpdatusUser\Desktop\게임트리.lnk => pomyślnie przeniesiono ========= Koniec -> "C:\Users\UpdatusUser\Desktop\*.lnk" ======== C:\Windows\SysWOW64\pl.html => pomyślnie przeniesiono ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MediaPlayerV1alpha774 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MediaViewV1alpha763 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MediaWatchV1home630 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= EmptyTemp: => 11.8 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 20:39:49 ====