Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 13-10-2016 Uruchomiony przez LOCKERZ (14-10-2016 09:43:33) Run:1 Uruchomiony z C:\Users\LOCKERZ\Desktop\Angielski Załadowane profile: LOCKERZ (Dostępne profile: LOCKERZ & mama & ADMIN & Classic .NET AppPool & DefaultAppPool) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\...\Run: [{EC495FB6-A04D-8085-07E5-4A678EBE46D6}] => C:\Users\LOCKERZ\AppData\Roaming\{49EFEF0E-F50F-8ED2-8FA9-099599544FA5}\ybfpnrmcj.exe [104961536 2016-10-07] (smile) HKLM-x32\...\Run: [RazerCortex] => D:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe -autorun Task: {066DBDD0-FBF7-446F-A7E6-5D509526FDAF} - System32\Tasks\{3279D542-38F4-4847-AC03-3BB537790B7B} => pcalua.exe -a "D:\Instalki-Programy\Windows 7\speed2\397-ST330_VistaSetup_v0.3.exe" -d "D:\Instalki-Programy\Windows 7\speed2" Task: {27152390-D38F-46A9-97D8-EC0E9A39EB61} - System32\Tasks\{24F2297C-2894-486C-A790-6A0AA6F2BE01} => pcalua.exe -a "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista\SpeedTouch330seriesR4.0.0.5.exe" -d "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista" Task: {32193D3A-0DC6-44BD-BFDF-D925DF19FABA} - System32\Tasks\LOCKERZStretchedBilingualV2 => Rundll32.exe UptownsInseminates.dll,main 7 1 <==== UWAGA Task: {4195BFC7-8627-4AF5-85A8-5701B873655E} - System32\Tasks\{5C881262-692A-4E88-8AF8-D080E851ABBE} => C:\Users\LOCKERZ\Desktop\397-ST330_VistaSetup_v0.3.exe Task: {441A14BA-FBF5-4CE5-BCC4-5368FD3F5940} - System32\Tasks\{34A4218F-4663-4FE0-B8AA-DD658EDDB57D} => pcalua.exe -a C:\Users\LOCKERZ\Desktop\397-ST330_VistaSetup_v0.3.exe -d C:\Users\LOCKERZ\Desktop Task: {467F50B2-AA8B-481C-B013-44CCEBA6D446} - System32\Tasks\{942153CC-7A1B-4E64-A8A5-CEDB48BC897C} => pcalua.exe -a "C:\Program Files (x86)\thriXXX\WebLaunch\WebLaunchUninstall.exe" Task: {482AEC6E-2529-45C6-AEA6-31052E006744} - System32\Tasks\{D326FE30-5CD6-4ECC-87CE-2CF39B4FE512} => pcalua.exe -a "C:\Program Files (x86)\Thomson\ST330\Uninstall\stInstall.exe" -c -s:scen_uninstall_st330.xml -l:pl Task: {49A5C001-1F4D-41A4-A539-7D7F83B81A8C} - System32\Tasks\{A6364742-CDCA-4273-B26C-57360FED63C6} => pcalua.exe -a "D:\Instalki-Programy\Windows 7\SpeedTouch330_for_Vista\setup.exe" -d "D:\Instalki-Programy\Windows 7\SpeedTouch330_for_Vista" Task: {4BEB87C5-BA79-49F2-A6C2-73275F3409D1} - System32\Tasks\{F34654C4-F88D-45F0-99CF-3ED3A627DC6D} => pcalua.exe -a D:\Instalki-Programy\Flash_Disinfector.exe -d D:\Instalki-Programy Task: {7AD8332A-A691-4913-9AB7-281FAA71B68C} - System32\Tasks\{0CFBF47D-25FB-4E8D-B0E1-7119156A7FA3} => pcalua.exe -a "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista\STHIW\stInstall.exe" -d "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista\STHIW" Task: {95758718-FB55-407B-9EEE-1DC071DB6CC9} - System32\Tasks\{61249075-9D71-4723-8625-4CC38CC34961} => pcalua.exe -a C:\PROGRA~2\NEOSTR~1\INSTAL~1.EXE -d C:\PROGRA~2\NEOSTR~1 -c ListeModeAcces=ADSLUSB,DriverADSLUSB=THOMSSPEEDTOUCHUSB Task: {981B3721-744A-40B5-977C-7DFE6D5ED107} - System32\Tasks\{696BD7AC-4436-4D9F-80BD-FE073DFE54E4} => pcalua.exe -a "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista\STHIWv\stInstall.exe" -d "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista\STHIWv" Task: {C43C5C1E-E163-4108-954E-5CED3B16D112} - System32\Tasks\SLOW-PCfighter64-LOCKERZ-Startup => D:\Program Files\Fighters\SLOW-PCfighter\SLOW-PCfighter64.exe Task: {CB6D32AA-8747-485E-996F-789893C55613} - System32\Tasks\{AF66950C-7A39-4218-8D45-1B11631787AB} => pcalua.exe -a "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista\setup.exe" -d "D:\Instalki-Programy\Windows 7\Speed\SpeedTouch330_for_Vista" Task: {D362EE8E-3919-44EC-AAF9-B1254D1E8D84} - System32\Tasks\{11AD3EB2-749C-90B4-77B0-5988AF507931} => C:\Users\LOCKERZ\AppData\Roaming\PRICEF~1\updater.exe <==== UWAGA Task: {DB901E45-A4E9-4524-8675-3A31ECEE1874} - System32\Tasks\{CB5C5B72-9DBF-4F63-AB34-EEEA0A2AEABF} => pcalua.exe -a "D:\Instalki-Programy\Windows 7\SpeedTouch330_for_Vista\397-ST330_VistaSetup_v0.3.exe" -d "D:\Instalki-Programy\Windows 7\SpeedTouch330_for_Vista" Task: C:\Windows\Tasks\{11AD3EB2-749C-90B4-77B0-5988AF507931}.job => C:\Users\LOCKERZ\AppData\Roaming\PRICEF~1\updater.exe <==== UWAGA Task: C:\Windows\Tasks\{34969D2D-6A6A-4308-8901-FD7B1BD3E859}.job => c:\program files (x86)\google\chrome\application\chrome.exeKhxxp:/ui.skype.com/ui/0/6.6.0.106/pl/go/ MSCONFIG\Services: CacheBoost Service => 2 MSCONFIG\Services: Enlightened Shoal => 2 MSCONFIG\Services: OverwolfUpdaterService => 3 MSCONFIG\Services: Update FindRight => 2 MSCONFIG\Services: Util FindRight => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk => C:\Windows\pss\O&O Defrag Tray.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1.bat => C:\Windows\pss\1.bat.Startup MSCONFIG\startupfolder: C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk => C:\Windows\pss\OpenOffice.org 3.3.lnk.Startup MSCONFIG\startupfolder: C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Rejestracja FIFA 10.lnk => C:\Windows\pss\Rejestracja FIFA 10.lnk.Startup MSCONFIG\startupfolder: C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Start Freenet.lnk => C:\Windows\pss\Start Freenet.lnk.Startup MSCONFIG\startupreg: AceStream => C:\Users\LOCKERZ\AppData\Roaming\ACEStream\engine\ace_engine.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: CacheBoost => C:\Program Files (x86)\Systweak\Systweak CacheBoost\trayicon.exe MSCONFIG\startupreg: GmailNotifierPro => C:\Users\LOCKERZ\Desktop\GmailNotifierPro\GmailNotifierPro.exe /minimized MSCONFIG\startupreg: IObit Malware Fighter => "D:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart MSCONFIG\startupreg: KiesAirMessage => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup MSCONFIG\startupreg: KiesPDLR => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe MSCONFIG\startupreg: KiesPreload => D:\Program Files\Kies\Kies.exe /preload MSCONFIG\startupreg: KiesTrayAgent => D:\Program Files\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: MyBrowserCash => C:\Program Files (x86)\MyBrowserCash\MyBrowserCash.exe MSCONFIG\startupreg: OODefragTray => D:\Program Files\OO Software\Defrag\oodtray.exe MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent MSCONFIG\startupreg: Pokki => "C:\Users\LOCKERZ\AppData\Local\Pokki\v0.260.6.332\pokki.exe" MSCONFIG\startupreg: PPS Accelerator => D:\PPS.tv\PPStream\PPSKernel.exe MSCONFIG\startupreg: PPSDynamicDesktop => C:\Program Files (x86)\PPSGame\PPSDynamicDesktop.exe MSCONFIG\startupreg: SpybotSD TeaTimer => D:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe MSCONFIG\startupreg: Twoo => "C:\Users\LOCKERZ\AppData\Roaming\Massive Media\Twoo.exe" MSCONFIG\startupreg: Waiting1690 => C:\Windows\stid1690.exe S3 4F97E7A5DF399D88; \??\C:\Users\LOCKERZ\AppData\Local\Temp\73CEB197.sys [X] S3 ALSysIO; \??\C:\Users\LOCKERZ\AppData\Local\Temp\ALSysIO64.sys [X] S3 ATICDSDr; \??\C:\Users\LOCKERZ\AppData\Local\Temp\ATICDSDr.sys [X] S3 ATP; system32\DRIVERS\cmdatp.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] S3 zghsser; system32\DRIVERS\zghsser.sys [X] D:\Program Files (x86)\uusee C:\Program Files (x86)\VMware C:\ProgramData\TEMP C:\ProgramData\VMware C:\ProgramData\Microsoft\Windows\GameExplorer\{20D6AB38-04B5-48E5-BD4B-5809C4B4F0E2} C:\Users\ADMIN\Desktop\SWAT 4.lnk C:\Users\ADMIN\Desktop\Watchtower Library 2007 - wydanie polskie.lnk C:\Users\LOCKERZ\AppData\Local\Microsoft\Windows\GameExplorer\{9593D187-5C4D-4C35-A365-F4DDFC6E2096} C:\Users\LOCKERZ\AppData\Local\Microsoft\Windows\GameExplorer\{0CDF294F-BF7C-48EC-AD72-56AD2D1513D1} C:\Users\LOCKERZ\AppData\Local\StretchedBilingual C:\Users\LOCKERZ\AppData\Roaming\{49EFEF0E-F50F-8ED2-8FA9-099599544FA5} C:\Users\LOCKERZ\AppData\Roaming\tor C:\Users\LOCKERZ\AppData\Roaming\VMware C:\Users\LOCKERZ\Favorites\ÓĆĘÓÓÎĎ·ÖĐĐÄ.lnk C:\Users\LOCKERZ\Favorites\şÜżěĘÓƵËŃË÷.lnk C:\Users\mama\Desktop\SWAT 4.lnk C:\Users\mama\Desktop\Watchtower Library 2007 - wydanie polskie.lnk C:\Users\mama\Desktop\Watchtower Library 2009 - wydanie polskie.lnk C:\Users\mama\Desktop\Watchtower Library 2012 - wydanie polskie.lnk FF Plugin-x32: @pps.tv/npWebPlayer -> D:\PPS.tv\PPStream\npWebPlayer.dll [Brak pliku] CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA CHR HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\LOCKERZ\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx CHR HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [egnimkioipookhfihpljiedpgjffibpa] - C:\Program Files (x86)\MyBrowserCash\MBC_chrome.crx HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93} DPF: HKLM-x32 {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} DPF: HKLM-x32 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} DeleteKey: HKCU\Software\Mozilla\Firefox\Extensions DeleteKey: HKCU\Software\Mozilla\SeaMonkey DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f CMD: netsh advfirewall reset CMD: type C:\Windows\system32\GroupPolicy\User\Registry.pol EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\Software\Microsoft\Windows\CurrentVersion\Run\\{EC495FB6-A04D-8085-07E5-4A678EBE46D6} => Wartość pomyślnie usunięto HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\RazerCortex => Wartość pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{066DBDD0-FBF7-446F-A7E6-5D509526FDAF}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{066DBDD0-FBF7-446F-A7E6-5D509526FDAF}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{3279D542-38F4-4847-AC03-3BB537790B7B} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3279D542-38F4-4847-AC03-3BB537790B7B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27152390-D38F-46A9-97D8-EC0E9A39EB61}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27152390-D38F-46A9-97D8-EC0E9A39EB61}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{24F2297C-2894-486C-A790-6A0AA6F2BE01} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{24F2297C-2894-486C-A790-6A0AA6F2BE01}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{32193D3A-0DC6-44BD-BFDF-D925DF19FABA}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32193D3A-0DC6-44BD-BFDF-D925DF19FABA}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\LOCKERZStretchedBilingualV2 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LOCKERZStretchedBilingualV2" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4195BFC7-8627-4AF5-85A8-5701B873655E}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4195BFC7-8627-4AF5-85A8-5701B873655E}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{5C881262-692A-4E88-8AF8-D080E851ABBE} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5C881262-692A-4E88-8AF8-D080E851ABBE}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{441A14BA-FBF5-4CE5-BCC4-5368FD3F5940}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{441A14BA-FBF5-4CE5-BCC4-5368FD3F5940}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{34A4218F-4663-4FE0-B8AA-DD658EDDB57D} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{34A4218F-4663-4FE0-B8AA-DD658EDDB57D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{467F50B2-AA8B-481C-B013-44CCEBA6D446}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{467F50B2-AA8B-481C-B013-44CCEBA6D446}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{942153CC-7A1B-4E64-A8A5-CEDB48BC897C} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{942153CC-7A1B-4E64-A8A5-CEDB48BC897C}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{482AEC6E-2529-45C6-AEA6-31052E006744}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{482AEC6E-2529-45C6-AEA6-31052E006744}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{D326FE30-5CD6-4ECC-87CE-2CF39B4FE512} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D326FE30-5CD6-4ECC-87CE-2CF39B4FE512}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{49A5C001-1F4D-41A4-A539-7D7F83B81A8C}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49A5C001-1F4D-41A4-A539-7D7F83B81A8C}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{A6364742-CDCA-4273-B26C-57360FED63C6} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A6364742-CDCA-4273-B26C-57360FED63C6}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4BEB87C5-BA79-49F2-A6C2-73275F3409D1}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BEB87C5-BA79-49F2-A6C2-73275F3409D1}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{F34654C4-F88D-45F0-99CF-3ED3A627DC6D} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F34654C4-F88D-45F0-99CF-3ED3A627DC6D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7AD8332A-A691-4913-9AB7-281FAA71B68C}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AD8332A-A691-4913-9AB7-281FAA71B68C}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{0CFBF47D-25FB-4E8D-B0E1-7119156A7FA3} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0CFBF47D-25FB-4E8D-B0E1-7119156A7FA3}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{95758718-FB55-407B-9EEE-1DC071DB6CC9}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95758718-FB55-407B-9EEE-1DC071DB6CC9}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{61249075-9D71-4723-8625-4CC38CC34961} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{61249075-9D71-4723-8625-4CC38CC34961}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{981B3721-744A-40B5-977C-7DFE6D5ED107}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{981B3721-744A-40B5-977C-7DFE6D5ED107}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{696BD7AC-4436-4D9F-80BD-FE073DFE54E4} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{696BD7AC-4436-4D9F-80BD-FE073DFE54E4}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C43C5C1E-E163-4108-954E-5CED3B16D112}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C43C5C1E-E163-4108-954E-5CED3B16D112}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\SLOW-PCfighter64-LOCKERZ-Startup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SLOW-PCfighter64-LOCKERZ-Startup" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CB6D32AA-8747-485E-996F-789893C55613}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB6D32AA-8747-485E-996F-789893C55613}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{AF66950C-7A39-4218-8D45-1B11631787AB} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AF66950C-7A39-4218-8D45-1B11631787AB}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D362EE8E-3919-44EC-AAF9-B1254D1E8D84}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D362EE8E-3919-44EC-AAF9-B1254D1E8D84}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{11AD3EB2-749C-90B4-77B0-5988AF507931} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{11AD3EB2-749C-90B4-77B0-5988AF507931}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB901E45-A4E9-4524-8675-3A31ECEE1874}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB901E45-A4E9-4524-8675-3A31ECEE1874}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{CB5C5B72-9DBF-4F63-AB34-EEEA0A2AEABF} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CB5C5B72-9DBF-4F63-AB34-EEEA0A2AEABF}" => klucz pomyślnie usunięto C:\Windows\Tasks\{11AD3EB2-749C-90B4-77B0-5988AF507931}.job => pomyślnie przeniesiono C:\Windows\Tasks\{34969D2D-6A6A-4308-8901-FD7B1BD3E859}.job => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\CacheBoost Service" => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Services\CacheBoost Service => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Enlightened Shoal" => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Services\Enlightened Shoal => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\OverwolfUpdaterService" => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Services\OverwolfUpdaterService => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Update FindRight" => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Services\Update FindRight => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Util FindRight" => klucz pomyślnie usunięto HKLM\System\CurrentControlSet\Services\Util FindRight => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk" => klucz pomyślnie usunięto C:\Windows\pss\O&O Defrag Tray.lnk.CommonStartup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1.bat" => klucz pomyślnie usunięto C:\Windows\pss\1.bat.Startup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk" => klucz pomyślnie usunięto C:\Windows\pss\OpenOffice.org 3.3.lnk.Startup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Rejestracja FIFA 10.lnk" => klucz pomyślnie usunięto C:\Windows\pss\Rejestracja FIFA 10.lnk.Startup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^LOCKERZ^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Start Freenet.lnk" => klucz pomyślnie usunięto C:\Windows\pss\Start Freenet.lnk.Startup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AceStream" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CacheBoost" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GmailNotifierPro" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IObit Malware Fighter" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesAirMessage" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPDLR" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPreload" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MyBrowserCash" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OODefragTray" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Overwolf" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Pokki" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PPS Accelerator" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PPSDynamicDesktop" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpybotSD TeaTimer" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Twoo" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Waiting1690" => klucz pomyślnie usunięto 4F97E7A5DF399D88 => serwis pomyślnie usunięto ALSysIO => serwis pomyślnie usunięto ATICDSDr => serwis pomyślnie usunięto ATP => serwis pomyślnie usunięto catchme => serwis pomyślnie usunięto EagleX64 => serwis pomyślnie usunięto VGPU => serwis pomyślnie usunięto vmci => serwis pomyślnie usunięto VMnetAdapter => serwis pomyślnie usunięto zghsser => serwis pomyślnie usunięto D:\Program Files (x86)\uusee => pomyślnie przeniesiono C:\Program Files (x86)\VMware => pomyślnie przeniesiono C:\ProgramData\TEMP => pomyślnie przeniesiono C:\ProgramData\VMware => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\GameExplorer\{20D6AB38-04B5-48E5-BD4B-5809C4B4F0E2} => pomyślnie przeniesiono C:\Users\ADMIN\Desktop\SWAT 4.lnk => pomyślnie przeniesiono C:\Users\ADMIN\Desktop\Watchtower Library 2007 - wydanie polskie.lnk => pomyślnie przeniesiono C:\Users\LOCKERZ\AppData\Local\Microsoft\Windows\GameExplorer\{9593D187-5C4D-4C35-A365-F4DDFC6E2096} => pomyślnie przeniesiono C:\Users\LOCKERZ\AppData\Local\Microsoft\Windows\GameExplorer\{0CDF294F-BF7C-48EC-AD72-56AD2D1513D1} => pomyślnie przeniesiono "C:\Users\LOCKERZ\AppData\Local\StretchedBilingual" => nie znaleziono. C:\Users\LOCKERZ\AppData\Roaming\{49EFEF0E-F50F-8ED2-8FA9-099599544FA5} => pomyślnie przeniesiono C:\Users\LOCKERZ\AppData\Roaming\tor => pomyślnie przeniesiono C:\Users\LOCKERZ\AppData\Roaming\VMware => pomyślnie przeniesiono C:\Users\LOCKERZ\Favorites\ÓĆĘÓÓÎĎ·ÖĐĐÄ.lnk => pomyślnie przeniesiono C:\Users\LOCKERZ\Favorites\şÜżěĘÓƵËŃË÷.lnk => pomyślnie przeniesiono C:\Users\mama\Desktop\SWAT 4.lnk => pomyślnie przeniesiono C:\Users\mama\Desktop\Watchtower Library 2007 - wydanie polskie.lnk => pomyślnie przeniesiono C:\Users\mama\Desktop\Watchtower Library 2009 - wydanie polskie.lnk => pomyślnie przeniesiono C:\Users\mama\Desktop\Watchtower Library 2012 - wydanie polskie.lnk => pomyślnie przeniesiono "HKLM\Software\Wow6432Node\MozillaPlugins\@pps.tv/npWebPlayer" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Policies\Google" => klucz pomyślnie usunięto "HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\SOFTWARE\Google\Chrome\Extensions\apdfllckaahabafndbhieahigkjlhalf" => klucz pomyślnie usunięto HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\SOFTWARE\Google\Chrome\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\egnimkioipookhfihpljiedpgjffibpa" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => klucz pomyślnie usunięto "HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => klucz pomyślnie usunięto HKU\S-1-5-21-3693199113-3486577660-3927935120-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => klucz pomyślnie usunięto HKCU\Software\Mozilla\Firefox\Extensions => klucz pomyślnie usunięto HKCU\Software\Mozilla\SeaMonkey => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Mozilla\SeaMonkey => klucz pomyślnie usunięto HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main => klucz pomyślnie usunięto HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => klucz pomyślnie usunięto HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes => klucz pomyślnie usunięto HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => klucz pomyślnie usunięto ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= ========= type C:\Windows\system32\GroupPolicy\User\Registry.pol ========= PReg ========= Koniec CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19117799 B Java, Flash, Steam htmlcache => 1407 B Windows/system/drivers => 3076098 B Edge => 0 B Chrome => 287007492 B Firefox => 444592628 B Opera => 928322443 B Temp, IE cache, history, cookies, recent: Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 101023 B systemprofile32 => 464087 B LocalService => 0 B NetworkService => 0 B LOCKERZ => 41919404 B UpdatusUser => 0 B UpdatusUser => 0 B mama => 1100148 B ADMIN => 65498 B Classic .NET AppPool => 0 B DefaultAppPool.IIS APPPOOL => 0 B RecycleBin => 288336438 B EmptyTemp: => 1.9 GB danych tymczasowych Usunito. ================================ System wymaga restartu. ==== Koniec Fixlog 09:47:03 ====