Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:06-05-2016 Uruchomiony przez Kasia (2016-05-06 14:22:28) Run:2 Uruchomiony z H:\AV Załadowane profile: Kasia & UpdatusUser (Dostępne profile: Kasia & UpdatusUser) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Clients\StartMenuInternet\IHeeaWAHTM DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.htm\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.html\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.shtml\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xht\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xhtml\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\ftp\UserChoice DeleteKey: HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Clients\StartMenuInternet /v IHeeaWAHTM /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\RegisteredApplications /v IHeeaWAHTM /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.htm\OpenWithProgids /v IHeeaWAHTM /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.html\OpenWithProgids /v IHeeaWAHTM /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.shtml\OpenWithProgids /v IHeeaWAHTM /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.xht\OpenWithProgids /v IHeeaWAHTM /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.xhtml\OpenWithProgids /v IHeeaWAHTM /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.htm /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.html /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.shtml /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.xht /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.xhtml /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_https /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_ftp /f Reg: reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_http /f CMD: del /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk" RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\FRST\Quarantine ***************** HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Clients\StartMenuInternet\IHeeaWAHTM => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Clients\StartMenuInternet\IHeeaWAHTM => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.htm\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.html\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.shtml\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xht\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\FileExts\.xhtml\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Roaming\OpenWith\UrlAssociations\ftp\UserChoice => klucz pomyślnie usunięto HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice => klucz pomyślnie usunięto ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Clients\StartMenuInternet /v IHeeaWAHTM /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\RegisteredApplications /v IHeeaWAHTM /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.htm\OpenWithProgids /v IHeeaWAHTM /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.html\OpenWithProgids /v IHeeaWAHTM /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.shtml\OpenWithProgids /v IHeeaWAHTM /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.xht\OpenWithProgids /v IHeeaWAHTM /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Classes\.xhtml\OpenWithProgids /v IHeeaWAHTM /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.htm /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.html /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.shtml /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.xht /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_.xhtml /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_https /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_ftp /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-27256294-3351816481-630482978-1001\Software\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts /v IHeeaWAHTM_http /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= del /q "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk" ========= ========= Koniec CMD: ========= "C:\AdwCleaner" => nie znaleziono. "C:\FRST\Quarantine" => pomyślnie usunięto. ==== Koniec Fixlog 14:22:47 ====