Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:27-01-2016 Uruchomiony przez Adrian (2016-02-11 13:31:45) Run:1 Uruchomiony z D:\logi Załadowane profile: Adrian (Dostępne profile: Adrian) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: Task: {01E8C2A4-DDA6-4087-A3D0-9E0449F555BF} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\SymErr.exe Task: {0AA18C7C-D7C0-4840-BCE9-93C5766AA5BC} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe Task: {22ABF820-4BA7-4810-B16B-8DE6628BEB4D} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\SymErr.exe Task: {9CF818F5-312B-46F1-88CD-9EC31F199640} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\WSCStub.exe Task: {B545088B-4E0D-43A6-8EB7-8ADA84DFF62D} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3cpLvzUXL380FmOtICNEwAJPfHAS-01rKsDXICPq14ma65gKeroVykAMoZ_uH1_CSVJBdGCeM6yNVhWv5tCoKt-Yn-7PBmxBjQbn0b2jdM6aJbFtM2j1zVbTtMvZhueJcSxy2O7O7YKtiTA,,&q={searchTerms} HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={40464974-E47A-4443-9A14-447ADDD62DC1}&mid=a32b97eb6e3a47cd9d3e81fe85be307b-8bbd57c7bdd93caccbd38fa50997077194d5beba&lang=pl&ds=AVG&coid=avgtbavg&cmpid=0615piz&pr=fr&d=2015-08-01 11:21:12&v=4.2.0.886&pid=wtu&sg=&sap=hp HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3cpLvzUXL380FmOtICNEwAJPfHAS-01rKsDXICPq14ma65gKeroVykAMoZ_uH1_CSVJBdGCeM6yNVhWv5tCoKt-Yn-7PBmxBjQbn0b2jdM6aJbFtM2j1zVbTtMvZhueJcSxy2O7O7YKtiTA,,&q={searchTerms} HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3cpLvzUXL380FmOtICNEwAJPfHAS-01rKsDXICPq14ma65gKeroVykAMoZ_uH1_CSVJBdGCeM6yNVhWv5tCoKt-Yn-7PBmxBjQbn0b2jdM6aJbFtM2j1zVbTtMvZhueJcSxy2O7O7YKtiTA,,&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = SearchScopes: HKU\S-1-5-21-1229153242-3201741155-1693493588-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={40464974-E47A-4443-9A14-447ADDD62DC1}&mid=a32b97eb6e3a47cd9d3e81fe85be307b-8bbd57c7bdd93caccbd38fa50997077194d5beba&lang=pl&ds=AVG&coid=avgtbavg&cmpid=0615piz&pr=fr&d=2015-08-01 11:21:12&v=4.2.0.886&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-1229153242-3201741155-1693493588-1001 -> {1838EEB7-D790-4C38-977B-7610FC411ABC} URL = SearchScopes: HKU\S-1-5-21-1229153242-3201741155-1693493588-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={40464974-E47A-4443-9A14-447ADDD62DC1}&mid=a32b97eb6e3a47cd9d3e81fe85be307b-8bbd57c7bdd93caccbd38fa50997077194d5beba&lang=pl&ds=AVG&coid=avgtbavg&cmpid=0615piz&pr=fr&d=2015-08-01 11:21:12&v=4.2.0.886&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-1229153242-3201741155-1693493588-1001 -> {ielnksrch} URL = FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.2.5\\npsitesafety.dll [Brak pliku] OPR StartupUrls: "hxxp://www.istartsurf.com/?type=hp&ts=1441130291&z=e4003e303b077efac760026gaz0z5gag0cce9g3qdo&from=cor&uid=ST750LM022XHN-M750MBB_S2RRJ9ECB05080" OPR Session Restore: -> [funkcja włączona] DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security RemoveDirectory: C:\Windows\System32\Tasks\Norton Internet Security C:\ProgramData\Intel\ExtremeGraphics\CUI\Resource\*.lnk C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk C:\Users\Adrian\AppData\Roaming\Microsoft\Word\wniosek_rp7_1304690190933187370\wniosek_rp7_1.doc.lnk C:\Users\Adrian\Desktop\Start Tor Browser.lnk C:\Users\Adrian\Downloads\dffsetup-unarc.exe CMD: netsh advfirewall reset CMD: type C:\ProgramData\MakeMarkerFile.xml EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{01E8C2A4-DDA6-4087-A3D0-9E0449F555BF}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01E8C2A4-DDA6-4087-A3D0-9E0449F555BF}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\Norton Internet Security\Norton Error Analyzer => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Analyzer" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0AA18C7C-D7C0-4840-BCE9-93C5766AA5BC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0AA18C7C-D7C0-4840-BCE9-93C5766AA5BC}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\WLANStartup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WLANStartup" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{22ABF820-4BA7-4810-B16B-8DE6628BEB4D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{22ABF820-4BA7-4810-B16B-8DE6628BEB4D}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\Norton Internet Security\Norton Error Processor => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Processor" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9CF818F5-312B-46F1-88CD-9EC31F199640}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9CF818F5-312B-46F1-88CD-9EC31F199640}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\Norton WSC Integration => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B545088B-4E0D-43A6-8EB7-8ADA84DFF62D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B545088B-4E0D-43A6-8EB7-8ADA84DFF62D}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVGPCTuneUp_Task_BkGndMaintenance" => klucz pomyślnie usunięto HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => Wartość pomyślnie usunięto HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => Wartość pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\ielnksrch => klucz nie znaleziono. HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1838EEB7-D790-4C38-977B-7610FC411ABC}" => klucz pomyślnie usunięto HKCR\CLSID\{1838EEB7-D790-4C38-977B-7610FC411ABC} => klucz nie znaleziono. "HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => klucz pomyślnie usunięto HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => klucz nie znaleziono. "HKU\S-1-5-21-1229153242-3201741155-1693493588-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => klucz pomyślnie usunięto HKCR\CLSID\{ielnksrch} => klucz nie znaleziono. HKLM\Software\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin => klucz nie znaleziono. OPR StartupUrls: "hxxp://www.istartsurf.com/?type=hp&ts=1441130291&z=e4003e303b077efac760026gaz0z5gag0cce9g3qdo&from=cor&uid=ST750LM022XHN-M750MBB_S2RRJ9ECB05080" => pomyślnie usunięto OPR Session Restore: -> [funkcja włączona] => pomyślnie usunięto HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz pomyślnie usunięto HKCU\Software\dobreprogramy => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security => klucz pomyślnie usunięto "C:\Windows\System32\Tasks\Norton Internet Security" => pomyślnie usunięto. =========== "C:\ProgramData\Intel\ExtremeGraphics\CUI\Resource\*.lnk" ========== C:\ProgramData\Intel\ExtremeGraphics\CUI\Resource\Grafika HD Intel®.lnk => pomyślnie przeniesiono C:\ProgramData\Intel\ExtremeGraphics\CUI\Resource\Intel® HD Graphics.lnk => pomyślnie przeniesiono ========= Koniec -> "C:\ProgramData\Intel\ExtremeGraphics\CUI\Resource\*.lnk" ======== C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk => pomyślnie przeniesiono C:\Users\Adrian\AppData\Roaming\Microsoft\Word\wniosek_rp7_1304690190933187370\wniosek_rp7_1.doc.lnk => pomyślnie przeniesiono C:\Users\Adrian\Desktop\Start Tor Browser.lnk => pomyślnie przeniesiono C:\Users\Adrian\Downloads\dffsetup-unarc.exe => pomyślnie przeniesiono ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= ========= type C:\ProgramData\MakeMarkerFile.xml ========= 2008-12-04T11:13:55.9645811 Administrator Run MakeMarkerFile true Users HighestAvailable PT10M PT1H false false IgnoreNew false false false false false true true true false false PT0S 7 "%ProgramData%\MakeMarkerFile.exe" ========= Koniec CMD: ========= EmptyTemp: => 3 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 13:36:07 ====