Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:09-12-2015 Uruchomiony przez lucky (2015-12-11 02:53:39) Run:2 Uruchomiony z C:\Users\lucky\Downloads Załadowane profile: lucky (Dostępne profile: lucky) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: InternetURL: C:\Users\lucky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ATIODE.url -> file:///C:\Users\lucky\AppData\Roaming\Microsoft\ATIODE.exe Task: {25F81A29-F1E7-430E-B1BD-CA2B1074A35F} - System32\Tasks\Virtual Disk Service Manager => C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc\mssvc.exe Task: {7BEAB4D9-CE36-4D0F-BE1D-042A8331893A} - System32\Tasks\Driver Booster SkipUAC (lucky) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {E71B6B39-0F70-4C16-B860-C6F5002CD766} - System32\Tasks\Updates\Security Update Checker => C:\Users\lucky\AppData\Roaming\Microsoft\SysHex.exe DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updates CHR HKU\S-1-5-21-823081088-4079517195-30393728-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx BootExecute: autocheck autochk * C:\ProgramData\ddf2c5aa08022b15bbf75cb48d8afde6fd92b21c C:\Users\lucky\AppData\Local\Opera Software C:\Users\lucky\AppData\Roaming\Opera Software C:\Users\lucky\AppData\Roaming\services C:\Users\lucky\AppData\Roaming\Microsoft\*.exe C:\Users\lucky\Downloads\IOBit Driver Booster Pro 3.1.0.332 + Crack [S0ft4PC] C:\WINDOWS\Tasks\ImCleanDisabled C:\Windows\System32\Tasks\Updates Folder: C:\Users\lucky\AppData\Roaming\TS3Client CMD: netsh advfirewall reset EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. C:\Users\lucky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ATIODE.url => nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25F81A29-F1E7-430E-B1BD-CA2B1074A35F}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25F81A29-F1E7-430E-B1BD-CA2B1074A35F}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\Virtual Disk Service Manager => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Virtual Disk Service Manager" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7BEAB4D9-CE36-4D0F-BE1D-042A8331893A}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7BEAB4D9-CE36-4D0F-BE1D-042A8331893A}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (lucky) => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (lucky)" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E71B6B39-0F70-4C16-B860-C6F5002CD766}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E71B6B39-0F70-4C16-B860-C6F5002CD766}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\Updates\Security Update Checker => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updates\Security Update Checker" => klucz pomyślnie usunięto HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updates => klucz pomyślnie usunięto "HKU\S-1-5-21-823081088-4079517195-30393728-1001\SOFTWARE\Google\Chrome\Extensions\bknbnapaddjdnbilpmlacdkjdkjmbjhd" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bknbnapaddjdnbilpmlacdkjdkjmbjhd" => klucz pomyślnie usunięto hklm\System\CurrentControlSet\Control\Session Manager\\BootExecute => Wartość pomyślnie przywrócono C:\ProgramData\ddf2c5aa08022b15bbf75cb48d8afde6fd92b21c => pomyślnie przeniesiono C:\Users\lucky\AppData\Local\Opera Software => pomyślnie przeniesiono C:\Users\lucky\AppData\Roaming\Opera Software => pomyślnie przeniesiono C:\Users\lucky\AppData\Roaming\services => pomyślnie przeniesiono =========== "C:\Users\lucky\AppData\Roaming\Microsoft\*.exe" ========== C:\Users\lucky\AppData\Roaming\Microsoft\ATIODE.exe => pomyślnie przeniesiono C:\Users\lucky\AppData\Roaming\Microsoft\SysTskEdit.exe => pomyślnie przeniesiono ========= Koniec -> "C:\Users\lucky\AppData\Roaming\Microsoft\*.exe" ======== C:\Users\lucky\Downloads\IOBit Driver Booster Pro 3.1.0.332 + Crack [S0ft4PC] => pomyślnie przeniesiono C:\WINDOWS\Tasks\ImCleanDisabled => pomyślnie przeniesiono C:\Windows\System32\Tasks\Updates => pomyślnie przeniesiono ========================= Folder: C:\Users\lucky\AppData\Roaming\TS3Client ======================== 2015-08-06 00:21 - 2015-12-07 02:25 - 0000104 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\resolved.dat 2015-08-05 21:58 - 2015-12-07 02:25 - 0058368 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\settings.db 2015-08-06 00:21 - 2015-12-07 02:25 - 0000004 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\subscribemode.dat 2015-12-06 23:10 - 2015-12-06 23:10 - 0000832 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\ts3clientui_qt.secrets.conf 2015-08-05 21:59 - 2015-12-07 02:10 - 0055296 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\urls.db 2015-08-05 21:59 - 2015-12-01 16:16 - 0000000 ____D () C:\Users\lucky\AppData\Roaming\TS3Client\chats 2015-11-18 01:16 - 2015-11-18 22:40 - 0000000 ____D () C:\Users\lucky\AppData\Roaming\TS3Client\chats\NUlhMC9LOWYvRXRnQzl6SmhlckFZK2pRbElVPQ== 2015-11-18 01:16 - 2015-11-18 22:40 - 0001177 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\NUlhMC9LOWYvRXRnQzl6SmhlckFZK2pRbElVPQ==\channel.html 2015-11-18 22:40 - 2015-11-18 22:40 - 0000037 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\NUlhMC9LOWYvRXRnQzl6SmhlckFZK2pRbElVPQ==\channel.txt 2015-11-18 01:16 - 2015-11-18 22:40 - 0004620 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\NUlhMC9LOWYvRXRnQzl6SmhlckFZK2pRbElVPQ==\server.html 2015-11-18 22:40 - 2015-11-18 22:40 - 0000036 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\NUlhMC9LOWYvRXRnQzl6SmhlckFZK2pRbElVPQ==\server.txt 2015-12-01 16:16 - 2015-12-01 16:16 - 0000000 ____D () C:\Users\lucky\AppData\Roaming\TS3Client\chats\RThDQzdnUEVFYVR1VnhBSStyWS9iZ2w4OVZjPQ== 2015-12-01 16:16 - 2015-12-02 19:40 - 0000990 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\RThDQzdnUEVFYVR1VnhBSStyWS9iZ2w4OVZjPQ==\channel.html 2015-12-01 16:16 - 2015-12-02 19:40 - 0000074 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\RThDQzdnUEVFYVR1VnhBSStyWS9iZ2w4OVZjPQ==\channel.txt 2015-12-01 16:16 - 2015-12-02 19:40 - 0001997 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\RThDQzdnUEVFYVR1VnhBSStyWS9iZ2w4OVZjPQ==\server.html 2015-12-01 16:16 - 2015-12-02 19:40 - 0000072 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\RThDQzdnUEVFYVR1VnhBSStyWS9iZ2w4OVZjPQ==\server.txt 2015-08-05 21:59 - 2015-08-05 21:59 - 0000000 ____D () C:\Users\lucky\AppData\Roaming\TS3Client\chats\Z2RMNmxDZmpIRzN6YkQ4NlFCQnNWbVJBMmtzPQ== 2015-08-05 21:59 - 2015-12-07 02:25 - 0150626 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\Z2RMNmxDZmpIRzN6YkQ4NlFCQnNWbVJBMmtzPQ==\channel.html 2015-08-05 21:59 - 2015-12-07 02:10 - 0017514 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\Z2RMNmxDZmpIRzN6YkQ4NlFCQnNWbVJBMmtzPQ==\channel.txt 2015-08-05 21:59 - 2015-12-07 02:25 - 17569615 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\Z2RMNmxDZmpIRzN6YkQ4NlFCQnNWbVJBMmtzPQ==\server.html 2015-08-05 21:59 - 2015-12-07 00:00 - 0005900 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\chats\Z2RMNmxDZmpIRzN6YkQ4NlFCQnNWbVJBMmtzPQ==\server.txt 2015-08-05 21:58 - 2015-08-05 21:58 - 0000000 ____D () C:\Users\lucky\AppData\Roaming\TS3Client\crashdumps 2015-08-05 21:58 - 2015-12-07 17:12 - 0000000 ____D () C:\Users\lucky\AppData\Roaming\TS3Client\logs 2015-11-19 01:18 - 2015-11-24 00:42 - 0000000 ____D () C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc 2015-11-19 01:18 - 2015-11-19 01:18 - 0003182 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc\config.xml 2015-11-19 01:18 - 2015-11-19 01:18 - 0000036 _____ () C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc\dics.dat 2015-11-19 01:18 - 2015-11-19 01:18 - 0278016 _____ (The cURL library, http://curl.haxx.se/) C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc\libcurl.dll 2015-11-19 01:18 - 2015-11-19 01:18 - 0094208 _____ (Free Software Foundation) C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc\libmicrohttpd-dll.dll 2015-11-19 01:18 - 2015-11-19 01:18 - 0660128 _____ (Microsoft Corporation) C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc\msvcp120.dll 2015-11-19 01:18 - 2015-11-19 01:18 - 0963232 _____ (Microsoft Corporation) C:\Users\lucky\AppData\Roaming\TS3Client\MSSvc\msvcr120.dll ====== Koniec Folder: ====== ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= EmptyTemp: => 1.9 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 02:53:51 ====