Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 19-02-2017 Uruchomiony przez oem (21-02-2017 16:57:08) Run:1 Uruchomiony z C:\Users\oem\Documents\Favorites\Desktop Załadowane profile: oem (Dostępne profile: oem) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-642869367-1592473142-3323770084-1000\...\ChromeHTML: -> C:\Program Files (x86)\Cupface\Application\chrome.exe (Google Inc.) <==== UWAGA RemoveDirectory: C:\Program Files (x86)\Cupface Task: {611061C1-8DF3-433D-982C-092391135454} - System32\Tasks\Microsoft\Windows\Multimedia\MailruSetup => C:\Users\oem\AppData\Local\MailruSetup\MailruSetup.exe [2016-10-21] () <==== UWAGA WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA ShortcutWithArgument: C:\Users\oem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://qtipr.com/ ShortcutWithArgument: C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Cupface\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\oem\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/ ShortcutWithArgument: C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://qtipr.com/ ShortcutWithArgument: C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk -> C:\Program Files (x86)\Cupface\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\oem\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/ ShortcutWithArgument: C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7eacadfa43776aec\Google Chrome.lnk -> C:\Program Files (x86)\Cupface\Application\chrome.exe (Google Inc.) -> --profile-directory=ChromeDefaultData2 ShortcutWithArgument: C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\6dc87d5b8be063a4\Google Chrome.lnk -> C:\Program Files (x86)\Cupface\Application\chrome.exe (Google Inc.) -> --profile-directory=ChromeDefaultData2 ShortcutWithArgument: C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\361178be4aa3110f\Google Chrome.lnk -> C:\Program Files (x86)\Cupface\Application\chrome.exe (Google Inc.) -> --profile-directory=ChromeDefaultData ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Cupface\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\oem\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/ ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://qtipr.com/ FirewallRules: [{7E8C8C42-4906-4316-BC82-143C231CEECE}] => (Allow) C:\Program Files (x86)\Cupface\Application\chrome.exe FirewallRules: [{1A8DF41A-B61C-434F-A328-9A27E08AC912}] => (Allow) C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe FirewallRules: [{B40BDFA0-A664-4803-AC8A-E44700CA8573}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe RemoveDirectory: C:\Program Files (x86)\Firefox HKLM\...\Providers\vh9ggz5t: C:\Program Files (x86)\Clokisevuboly Reports\local64spl.dll [290816 2017-01-20] () C:\Program Files (x86)\Clokisevuboly Reports ShellExecuteHooks: Brak nazwy - {7BCBF2F8-9E93-11E6-BA23-64006A5CFC23} - -> Brak pliku ShellExecuteHooks: Brak nazwy - {D6A4F024-A5A8-11E6-9A93-64006A5CFC23} - -> Brak pliku ShellExecuteHooks: Brak nazwy - {5EBD559E-A5BA-11E6-B9FD-64006A5CFC23} - -> Brak pliku ShellExecuteHooks: Brak nazwy - {FFC5BCD0-A5C1-11E6-B87D-64006A5CFC23} - -> Brak pliku ShellExecuteHooks: Brak nazwy - {73538FB6-AB7F-11E6-9B77-64006A5CFC23} - -> Brak pliku ShellExecuteHooks: Brak nazwy - {C37C42DA-DC66-11E6-A37E-64006A5CFC23} - -> Brak pliku ShellExecuteHooks: Brak nazwy - {0AAE96C8-DE2A-11E6-9E44-64006A5CFC35} - -> Brak pliku ShellExecuteHooks: Brak nazwy - {036CBE24-DE3B-11E6-95A0-64006A5CFC23} - -> Brak pliku ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => -> Brak pliku GroupPolicy: Ograniczenia - Chrome <======= UWAGA GroupPolicy\User: Ograniczenia <======= UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKU\S-1-5-21-642869367-1592473142-3323770084-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA ShellExecuteHooks: Brak nazwy - {58B532E2-DE3B-11E6-8BCE-64006A5CFC23} - -> Brak pliku HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525&q={searchTerms} HKU\S-1-5-21-642869367-1592473142-3323770084-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525 HKU\S-1-5-21-642869367-1592473142-3323770084-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525 URLSearchHook: HKLM-x32 -> Domyślne = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525&q={searchTerms} SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-642869367-1592473142-3323770084-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525&q={searchTerms} SearchScopes: HKU\S-1-5-21-642869367-1592473142-3323770084-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525&q={searchTerms} SearchScopes: HKU\S-1-5-21-642869367-1592473142-3323770084-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = CHR HomePage: Default -> hxxp://www.startpageing123.com/?type=hp&ts=1487675442&z=8b662479ca4e8ce41d2527egfzbbcm6q6mfwdz3z1q&from=ggg0221&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525 CHR StartupUrls: Default -> "hxxp://www.startpageing123.com/?type=hp&ts=1487675442&z=8b662479ca4e8ce41d2527egfzbbcm6q6mfwdz3z1q&from=ggg0221&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525" CHR DefaultSearchURL: Default -> hxxp://www.startpageing123.com/search/?type=ds&ts=1487664333&z=c5725b9e0e6fc0e05c3d6d7g9z2b3mdqaqcz4c8c8q&from=che0812&uid=WDCXWD10EURX-73FH1Y0_WD-WMC1U763552535525&q={searchTerms} CHR DefaultSearchKeyword: Default -> startpageing123 R2 bilibili; C:\Program Files (x86)\bilibili\bilibili.dll [122880 2017-02-14] () [Brak podpisu cyfrowego] R2 cepyzuri; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\kns226E.tmp [474624 2017-02-21] () [Brak podpisu cyfrowego] R2 Convxxxx; C:\Users\oem\AppData\Roaming\cgjcg\UvConverter.exe [376832 2017-02-06] () [Brak podpisu cyfrowego] R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [162992 2017-02-17] () R2 mevucezu; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\kns8CB9.tmp [427520 2017-02-21] () [Brak podpisu cyfrowego] R2 sobubigo; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\kns7A9D.tmp [429056 2017-02-16] () [Brak podpisu cyfrowego] R2 venolici; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\kns5B5D.tmp [432640 2017-02-12] () [Brak podpisu cyfrowego] R2 vomiqyqy; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\kns7E86.tmp [421376 2017-02-19] () [Brak podpisu cyfrowego] R2 vunupehe; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\kns3CFF.tmp [386048 2017-02-17] () [Brak podpisu cyfrowego] R2 WinSAPSvc; C:\Users\oem\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-21] (TODO: ) [Brak podpisu cyfrowego] R2 zigipyro; C:\Users\oem\AppData\Local\1ED023C0-1487680745-11DD-BB38-10BF48B8C1EB\qnshC38F.tmp [158720 2015-12-26] () [Brak podpisu cyfrowego] S2 dykewulo; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\kns9D01.tmp [X] R2 gemeloki; C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844\prote927aa13-8b59-4155-bcc8-b9f29f322c0b.tmpfs [X] S2 MOJEMOJE; "E:\MOJE\MOJEMOJE.exe" 388837891c4f496ea6203a5f71b2a421 [X] S2 RóżneDokumenty; "E:\Dokumenty\RóżneDokumenty.exe" affe6dc7e5264e7e8e5695737342bee0 [X] S2 RóżneFotolia; "D:\Różne\RóżneFotolia.exe" 3e19779b2974487e881c2174c0562504 [X] S2 serverss; C:\Windows\Temp\5CD5.tmp [X] U0 aswVmm; Brak ImagePath S3 catchme; \??\C:\ComboFix\catchme.sys [X] S1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae64.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X] S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X] S2 MBAMChameleon; \SystemRoot\system32\drivers\MBAMChameleon.sys [X] S3 MBAMFarflt; \??\C:\Windows\system32\drivers\farflt.sys [X] S3 MBAMProtection; \??\C:\Windows\system32\drivers\mbam.sys [X] S3 MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [X] U3 uxldapod; \??\C:\Users\oem\AppData\Local\Temp\uxldapod.sys [X] <==== UWAGA C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe Encore CS6.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe Extension Manager CS6.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe Prelude CS6.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe SpeedGrade CS6.lnk Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: ipconfig /flushdns CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\oem\AppData\Local CMD: dir /a C:\Users\oem\AppData\LocalLow CMD: dir /a C:\Users\oem\AppData\Roaming Hosts: EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKU\S-1-5-21-642869367-1592473142-3323770084-1000_Classes\ChromeHTML => klucz pomyślnie usunięto "C:\Program Files (x86)\Cupface" => pomyślnie usunięto. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{611061C1-8DF3-433D-982C-092391135454} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{611061C1-8DF3-433D-982C-092391135454} => klucz pomyślnie usunięto C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\MailruSetup => pomyślnie przeniesiono HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\MailruSetup => klucz pomyślnie usunięto WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA => pomyślnie usunięto C:\Users\oem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Skrót - argument pomyślnie usunięto. C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Skrót - argument pomyślnie usunięto. C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7eacadfa43776aec\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\6dc87d5b8be063a4\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\oem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\361178be4aa3110f\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7E8C8C42-4906-4316-BC82-143C231CEECE} => Wartość pomyślnie usunięto HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1A8DF41A-B61C-434F-A328-9A27E08AC912} => Wartość pomyślnie usunięto HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B40BDFA0-A664-4803-AC8A-E44700CA8573} => Wartość pomyślnie usunięto "C:\Program Files (x86)\Firefox" => pomyślnie usunięto. HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\vh9ggz5t => klucz pomyślnie usunięto HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\\order vh9ggz5t => pomyślnie usunięto C:\Program Files (x86)\Clokisevuboly Reports => pomyślnie przeniesiono HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{7BCBF2F8-9E93-11E6-BA23-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{7BCBF2F8-9E93-11E6-BA23-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{D6A4F024-A5A8-11E6-9A93-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{D6A4F024-A5A8-11E6-9A93-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{5EBD559E-A5BA-11E6-B9FD-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{5EBD559E-A5BA-11E6-B9FD-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{FFC5BCD0-A5C1-11E6-B87D-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{FFC5BCD0-A5C1-11E6-B87D-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{73538FB6-AB7F-11E6-9B77-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{73538FB6-AB7F-11E6-9B77-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{C37C42DA-DC66-11E6-A37E-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{C37C42DA-DC66-11E6-A37E-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{0AAE96C8-DE2A-11E6-9E44-64006A5CFC35} => Wartość pomyślnie usunięto HKCR\CLSID\{0AAE96C8-DE2A-11E6-9E44-64006A5CFC35} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{036CBE24-DE3B-11E6-95A0-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{036CBE24-DE3B-11E6-95A0-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => klucz pomyślnie usunięto HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => klucz nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay => klucz pomyślnie usunięto HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => klucz nie znaleziono. C:\Windows\system32\GroupPolicy\Machine => pomyślnie przeniesiono C:\Windows\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono C:\Windows\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono C:\Windows\system32\GroupPolicy\User => pomyślnie przeniesiono HKLM\SOFTWARE\Policies\Google => klucz pomyślnie usunięto HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => klucz pomyślnie usunięto HKU\S-1-5-21-642869367-1592473142-3323770084-1000\SOFTWARE\Policies\Microsoft\Internet Explorer => klucz pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{58B532E2-DE3B-11E6-8BCE-64006A5CFC23} => Wartość pomyślnie usunięto HKCR\CLSID\{58B532E2-DE3B-11E6-8BCE-64006A5CFC23} => klucz nie znaleziono. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-642869367-1592473142-3323770084-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-642869367-1592473142-3323770084-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => Wartość pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto HKU\S-1-5-21-642869367-1592473142-3323770084-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto HKU\S-1-5-21-642869367-1592473142-3323770084-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKU\S-1-5-21-642869367-1592473142-3323770084-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => klucz pomyślnie usunięto HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => klucz nie znaleziono. Chrome HomePage => pomyślnie usunięto Chrome StartupUrls => pomyślnie usunięto Chrome DefaultSearchURL => pomyślnie usunięto Chrome DefaultSearchKeyword => pomyślnie usunięto HKLM\System\CurrentControlSet\Services\bilibili => klucz pomyślnie usunięto bilibili => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\cepyzuri => klucz pomyślnie usunięto cepyzuri => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\Convxxxx => klucz pomyślnie usunięto Convxxxx => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\FirefoxU => klucz pomyślnie usunięto FirefoxU => serwis pomyślnie usunięto mevucezu => serwis nie znaleziono. HKLM\System\CurrentControlSet\Services\sobubigo => klucz pomyślnie usunięto sobubigo => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\venolici => klucz pomyślnie usunięto venolici => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\vomiqyqy => klucz pomyślnie usunięto vomiqyqy => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\vunupehe => klucz pomyślnie usunięto vunupehe => serwis pomyślnie usunięto WinSAPSvc => Usługa pomyślnie zatrzymana. HKLM\System\CurrentControlSet\Services\WinSAPSvc => klucz pomyślnie usunięto WinSAPSvc => serwis pomyślnie usunięto zigipyro => serwis nie znaleziono. HKLM\System\CurrentControlSet\Services\dykewulo => klucz pomyślnie usunięto dykewulo => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\gemeloki => klucz pomyślnie usunięto gemeloki => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\MOJEMOJE => klucz pomyślnie usunięto MOJEMOJE => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\RóżneDokumenty => klucz pomyślnie usunięto RóżneDokumenty => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\RóżneFotolia => klucz pomyślnie usunięto RóżneFotolia => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\serverss => klucz pomyślnie usunięto serverss => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\aswVmm => klucz pomyślnie usunięto aswVmm => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\catchme => klucz pomyślnie usunięto catchme => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\ESProtectionDriver => klucz pomyślnie usunięto ESProtectionDriver => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\ew_hwusbdev => klucz pomyślnie usunięto ew_hwusbdev => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\ew_usbenumfilter => klucz pomyślnie usunięto ew_usbenumfilter => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\huawei_cdcacm => klucz pomyślnie usunięto huawei_cdcacm => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\huawei_enumerator => klucz pomyślnie usunięto huawei_enumerator => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\huawei_ext_ctrl => klucz pomyślnie usunięto huawei_ext_ctrl => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\huawei_wwanecm => klucz pomyślnie usunięto huawei_wwanecm => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\MBAMChameleon => klucz pomyślnie usunięto MBAMChameleon => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\MBAMFarflt => klucz pomyślnie usunięto MBAMFarflt => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\MBAMProtection => klucz pomyślnie usunięto MBAMProtection => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\MBAMWebProtection => klucz pomyślnie usunięto MBAMWebProtection => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\uxldapod => klucz pomyślnie usunięto uxldapod => serwis pomyślnie usunięto C:\Program Files (x86)\e927aa13-8b59-4155-bcc8-b9f29f322c0b1484938844 => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe Encore CS6.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe Extension Manager CS6.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe Prelude CS6.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS6\Adobe SpeedGrade CS6.lnk => pomyślnie przeniesiono ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= ipconfig /flushdns ========= Konfiguracja IP systemu Windows Pomy˜lnie opr˘ľniono pami©† podr©cznĄ programu rozpoznawania nazw DNS. ========= Koniec CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\Program Files 2017-02-17 23:38 . 2017-02-17 23:38 .. 2013-01-28 14:51 7-Zip 2016-03-19 15:26 Adobe 2012-12-21 19:57 ASUS 2016-10-29 08:58 Common Files 2013-01-09 14:39 Corel 2009-07-14 05:54 174 desktop.ini 2013-03-21 07:11 DVD Maker 2012-12-22 09:36 Google 2012-12-20 09:50 Intel 2017-02-04 12:00 Internet Explorer 2016-06-20 21:04 Java 2016-01-25 13:44 KMSnano 2017-01-20 20:00 LXI4ITSVJC 2016-12-24 11:15 Malwarebytes 2016-05-10 16:37 Microsoft Office 2014-12-01 10:56 Microsoft Silverlight 2013-02-13 11:38 Microsoft SQL Server 2009-07-14 06:32 MSBuild 2016-02-23 13:02 NVIDIA Corporation 2017-01-20 20:00 R24ILDVVAV 2012-12-20 09:46 Realtek 2009-07-14 06:32 Reference Assemblies 2012-12-22 12:14 Tablet 2012-12-22 12:14 TabletPlugins 2009-07-14 06:09 Uninstall Information 2017-02-03 20:52 vh9ggz5t 2013-03-21 07:11 Windows Defender 2013-03-21 07:11 Windows Journal 2014-05-15 07:18 Windows Live 2013-03-21 07:11 Windows Mail 2013-03-21 07:11 Windows Media Player 2012-12-20 09:37 Windows NT 2013-03-21 07:11 Windows Photo Viewer 2013-03-21 07:11 Windows Portable Devices 2016-10-29 09:31 Windows Sidebar 2012-12-22 10:56 WinRAR 1 plik(˘w) 174 bajt˘w 37 katalog(˘w) 117˙515˙866˙112 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\Program Files (x86) 2017-02-21 16:57 . 2017-02-21 16:57 .. 2017-01-20 19:59 0ddhdwim 2016-12-10 01:05 0ktpwyfg 2017-02-13 20:37 1jaz2inh 2017-01-22 20:56 1s2nd0fn 2016-11-07 17:16 2g9h28f1 2017-01-22 08:20 2u43cjuk 2017-01-10 20:42 32k33cdf 2016-11-11 09:32 360 2016-11-02 18:35 3ylghbrc 2016-11-22 22:29 6qh3dz1y 2016-11-01 19:44 7n6le65t 2017-01-03 16:54 8xe0v5k4 2016-10-19 21:40 a5a217b2-40da-4d70-ae27-166efeb42edc 2017-01-27 19:04 Adobe 2016-10-19 21:40 Apple Software Update 2017-01-22 20:56 ASUS 2017-01-22 21:33 Aterishwerwi 2017-01-20 20:03 b86pvy7z 2017-01-20 20:00 baidu 2017-02-21 16:54 BikaQRssReader 2017-02-14 22:03 bilibili 2016-12-28 20:14 bsq97ozk 2016-10-20 17:35 Carambis 2016-10-30 11:38 ChomikBox 2017-01-22 20:56 com.astg.asv1 2016-10-28 22:41 com.astg.cld1 2016-12-03 23:48 com.astg.dys1 2016-10-19 21:40 com.astg.inq1 2016-11-18 23:48 com.astg.ins1 2016-10-19 21:40 com.astg.mir1 2016-10-28 22:42 com.astg.pcs2 2016-10-19 21:40 com.astg.rst1 2016-10-28 22:41 com.astg.sty1 2016-11-03 23:42 com.astg.vs2 2016-10-30 11:38 com.astg.ws1 2017-01-20 20:49 Common Files 2016-10-19 21:40 Corel 2016-10-30 11:38 CorelDRAW 11 Trial Version 2017-02-14 20:02 cvbs0 2017-02-15 18:29 cvbs1 2017-02-15 22:29 cvbs2 2017-02-16 19:22 cvbs3 2017-02-16 21:19 cvbs4 2017-02-17 21:09 cvbs5 2017-02-17 23:42 cvbs6 2017-02-17 23:47 cvbs7 2017-02-21 12:08 cvbs8 2017-02-21 16:08 cvbs9 2009-07-14 05:54 174 desktop.ini 2016-10-19 21:40 epson 2016-11-30 21:31 Ercetheratebught 2016-10-28 22:42 EXPERTool 2016-12-29 00:15 f09er35s 2017-01-19 16:13 Fawelegehaght 2016-12-07 20:47 fzelt79j 2017-01-20 20:03 GCREC05.tmp 2017-01-22 20:54 Gipareedese Reports 2017-02-11 23:26 Google 2016-10-19 21:40 gs 2017-01-20 20:03 GUMEC91.tmp 2016-11-01 12:57 hzgzy8ma 2016-11-07 21:47 ig4me4xo 2017-01-22 21:57 INet 2016-11-11 09:41 InstallShield Installation Information 2017-01-20 20:03 Intel 2017-02-04 12:00 Internet Explorer 2016-11-03 23:42 ivo 2017-01-22 20:56 Jerqetainrutodom 2017-02-06 21:28 k5n4hznu 2017-02-03 20:53 l7c9u1a7 2016-10-19 21:40 Marvell 2016-10-29 07:35 McAfee 2017-01-20 20:02 114 metadata 2016-10-19 21:40 Microsoft SDKs 2016-10-28 22:42 Microsoft Silverlight 2016-10-28 22:41 Microsoft SkyDrive 2016-10-19 21:40 Microsoft SQL Server 2016-10-28 22:42 Microsoft Visual Studio 9.0 2016-11-13 00:50 Microsoft.NET 2017-02-20 16:43 MIO 2017-01-20 19:59 Momicultckerticult 2016-11-18 23:48 Monitor Calibration Wizard 2016-11-22 22:55 MSBuild 2016-10-19 21:40 MSECache 2016-11-22 22:55 mu2h48zp 2016-12-19 09:04 n91hhz4c 2016-11-22 22:36 Nernapyclermocult 2016-11-11 16:38 nexusfont 2016-10-19 21:40 NVIDIA Corporation 2017-02-13 20:54 o0asda6a 2016-11-03 17:13 OpenOffice 4 2016-11-03 17:13 OpenOffice.org 3 2016-12-03 23:48 Pfergh 2017-02-20 21:30 Pharudom 2016-11-18 19:33 Plernwardshefodom 2016-10-19 21:40 Podatnik.info 2016-10-19 21:40 QuickTime 2016-11-03 23:42 Rachunek 2016-11-18 23:48 Realtek 2016-10-19 21:40 Reference Assemblies 2017-02-18 22:11 reports 2016-11-03 17:27 ro7ts729 2017-02-21 16:54 40 settings.dat 2016-10-20 17:01 Skype 2017-01-22 21:33 Sony 2017-02-07 20:06 Steam 2017-01-22 21:33 Stkersethafige Verfier 2016-11-22 22:55 TabletPlugins 2016-10-19 21:40 Temp 2016-10-20 17:35 Tertocultthbecult 2016-11-18 23:48 Thibeward 2017-01-22 20:56 Thibeward_ 2016-11-17 21:19 ttv2723f 2016-10-19 21:40 Uninstall Information 2016-10-28 22:06 uvconvrx_00000000 2016-12-12 21:36 w6tmhbqp 2016-11-13 00:50 wfnkb0ym 2016-10-19 21:40 Windows Defender 2016-10-19 21:40 Windows Live 2016-10-19 21:40 Windows Mail 2016-10-19 21:40 Windows Media Player 2016-10-19 21:40 Windows NT 2016-10-19 21:40 Windows Photo Viewer 2016-10-19 21:40 Windows Portable Devices 2016-12-27 21:33 yb6mr4y7 2017-02-20 16:42 ypimrgzv 2016-11-08 16:24 Zaveprmsp 2017-01-20 20:02 Zuzach Engine 3 plik(˘w) 328 bajt˘w 127 katalog(˘w) 117˙515˙857˙920 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Program Files\Common Files\System" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\Program Files\Common Files\System 2016-10-28 22:06 . 2016-10-28 22:06 .. 2013-03-21 07:11 ado 2009-07-14 02:40 29˙184 DirectDB.dll 2009-07-14 18:55 en-US 2013-03-21 07:11 msadc 2013-03-21 07:11 Ole DB 2009-07-14 18:55 pl-PL 2011-10-01 06:45 886˙784 wab32.dll 2009-07-14 02:33 1˙098˙752 wab32res.dll 3 plik(˘w) 2˙014˙720 bajt˘w 7 katalog(˘w) 117˙515˙862˙016 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files\System" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\Program Files (x86)\Common Files\System 2013-03-21 07:11 . 2013-03-21 07:11 .. 2013-03-21 07:11 ado 2009-07-14 02:15 24˙064 DirectDB.dll 2009-07-14 18:55 en-US 2013-03-21 07:11 msadc 2013-03-21 07:11 Ole DB 2009-07-14 18:55 pl-PL 2011-10-01 05:37 708˙608 wab32.dll 2009-07-14 02:11 1˙098˙752 wab32res.dll 3 plik(˘w) 1˙831˙424 bajt˘w 7 katalog(˘w) 117˙515˙857˙920 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\ProgramData 2017-02-17 23:44 . 2017-02-17 23:44 .. 2014-10-02 07:55 11 .asv1sfi 2014-10-02 07:55 11 .cld1sfi 2014-10-02 07:56 11 .dys1sfi 2014-10-02 07:56 14 .inq1sfi 2014-10-02 07:56 11 .ins1sfi 2014-10-02 07:57 11 .mir1sfi 2014-10-02 07:57 16 .pcs2sfi 2014-10-02 07:57 14 .rst1sfi 2014-10-02 07:58 11 .sty1sfi 2014-10-02 07:58 11 .vs2sfi 2014-10-02 07:58 16 .ws1sfi 2016-11-01 16:14 Adobe 2014-02-21 10:08 ALM 2013-04-12 12:02 Apple 2014-02-14 10:01 Apple Computer 2009-07-14 06:08 Application Data [C:\ProgramData] 2014-10-21 07:30 Astute Graphics 2012-12-21 19:48 ASUS 2012-12-21 20:03 ASUS OC Profiles 2012-12-21 20:03 ASUS PowerControl Profiles 2016-10-28 22:41 AVAST Software 2016-10-19 21:40 Avg 2016-10-27 18:23 Avira 2013-02-20 08:18 Bitstream 2016-03-16 07:16 boost_interprocess 2016-11-11 09:39 CleanAndroid 2015-01-30 10:51 Corel 2014-11-27 15:07 CorelDRAW Graphics Suite X6 2015-11-19 10:06 DAEMON Tools Lite 2012-12-20 09:37 Dane aplikacji [C:\ProgramData] 2015-12-11 07:39 DatacardService 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2012-12-20 09:37 Dokumenty [C:\Users\Public\Documents] 2016-12-01 11:08 ehadh 2013-02-12 15:23 EliSoft 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2016-12-26 20:57 fjcfi 2013-06-24 09:33 Hewlett-Packard 2016-12-19 13:05 icfib 2017-01-20 18:32 ie8 2013-07-19 08:15 InstallMate 2012-12-20 21:38 InstallShield 2012-12-20 09:50 Intel 2016-10-19 21:39 IObit 2016-03-18 16:53 KONICA MINOLTA 2013-02-13 10:53 42 lscb.lc 2017-01-24 20:24 Malwarebytes 2016-10-29 07:51 McAfee 2012-12-20 09:37 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2016-10-28 22:34 Microsoft 2016-05-10 16:38 Microsoft Help 2013-02-25 12:46 Microsoft OneDrive 2016-03-22 14:36 MobileBrServ 2013-01-08 11:19 Mozilla 2017-02-21 12:07 NVIDIA 2016-02-23 13:03 NVIDIA Corporation 2016-06-20 21:04 Oracle 2016-02-26 07:40 Origin 2016-06-26 22:37 PACE Anti-Piracy 2016-10-27 18:22 Package Cache 2013-03-19 09:43 PITy 2015-09-27 11:44 PLAY ONLINE 2016-10-19 21:40 ProductData 2013-06-28 07:21 Protexis64 2012-12-20 09:37 Pulpit [C:\Users\Public\Desktop] 2014-02-19 09:51 regid.1986-12.com.adobe 2016-05-28 16:26 sessionn 2016-10-20 17:00 Skype 2015-10-25 16:48 Sony Corporation 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2012-12-20 09:37 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2013-03-21 16:27 TEMP 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2017-02-06 21:29 ttff 2012-12-20 09:37 Ulubione [C:\Users\Public\Favorites] 2016-12-26 20:58 VMware 2017-01-20 18:32 wintooll 2015-04-23 07:41 4˙864 zgedrojb.fyf 13 plik(˘w) 5˙043 bajt˘w 68 katalog(˘w) 117˙515˙849˙728 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\Users\oem\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\Users\oem\AppData\Local 2017-02-21 16:54 . 2017-02-21 16:54 .. 2017-02-18 21:31 1ED023C0-1487453456-11DD-BB38-10BF48B8C1EB 2017-02-18 21:31 1ED023C0-1487453469-11DD-BB38-10BF48B8C1EB 2017-02-18 21:31 1ED023C0-1487453473-11DD-BB38-10BF48B8C1EB 2017-02-18 22:06 1ED023C0-1487455586-11DD-BB38-10BF48B8C1EB 2017-02-18 22:06 1ED023C0-1487455587-11DD-BB38-10BF48B8C1EB 2017-02-19 12:01 1ED023C0-1487505699-11DD-BB38-10BF48B8C1EB 2017-02-19 12:01 1ED023C0-1487505700-11DD-BB38-10BF48B8C1EB 2017-02-19 12:01 1ED023C0-1487505702-11DD-BB38-10BF48B8C1EB 2017-02-19 12:01 1ED023C0-1487505704-11DD-BB38-10BF48B8C1EB 2017-02-19 21:32 1ED023C0-1487539957-11DD-BB38-10BF48B8C1EB 2017-02-19 21:32 1ED023C0-1487539962-11DD-BB38-10BF48B8C1EB 2017-02-19 21:33 1ED023C0-1487539985-11DD-BB38-10BF48B8C1EB 2017-02-20 17:03 1ED023C0-1487610181-11DD-BB38-10BF48B8C1EB 2017-02-20 22:01 1ED023C0-1487628082-11DD-BB38-10BF48B8C1EB 2017-02-21 12:38 1ED023C0-1487680682-11DD-BB38-10BF48B8C1EB 2017-02-21 12:17 Adobe 2016-11-29 21:24 1˙456 Adobe Save for Web 13.0 Prefs 2013-04-12 12:02 Apple 2013-04-12 12:03 Apple Computer 2017-02-11 23:26 Apps 2016-12-03 23:48 Arawese 2015-04-23 07:43 Carambis 2015-10-03 00:22 CEF 2013-06-28 07:21 ChomikBox 2016-10-19 21:40 Chonucklerbeward 2016-10-28 22:10 Coldold 2016-10-28 22:41 Cooves 2017-02-21 16:12 CrashDumps 2016-12-26 20:58 Cupface 2012-12-20 09:37 Dane aplikacji [C:\Users\oem\AppData\Local] 2017-02-11 23:26 Deployment 2016-11-18 23:48 Dercse 2017-01-30 23:33 Diagnostics 2016-11-22 22:55 Dogughttherjgh 2016-11-03 23:42 Dutdom 2016-12-23 11:32 ElevatedDiagnostics 2017-01-22 21:33 Etuieddinich 2016-12-26 20:59 Firefox 2013-05-13 13:40 fontconfig 2017-01-27 19:08 193˙632 GDIPFONTCACHEV1.DAT 2013-05-13 13:40 gegl-0.2 2017-02-11 23:26 Google 2017-01-20 19:59 Gropsycerjaly 2016-10-30 11:37 Herpiciqerry 2012-12-20 09:37 Historia [C:\Users\oem\AppData\Local\Microsoft\Windows\History] 2017-02-21 09:11 1˙452˙124 IconCache.db 2016-10-27 18:51 IIIQF 2016-01-11 16:02 Imposition Wizard 2016-04-26 19:56 IVONA_INST 2017-01-22 20:57 Kcetionchserent 2016-10-27 18:23 MailruSetup 2017-02-04 12:04 Microsoft 2016-01-27 16:32 Microsoft Help 2016-10-27 18:23 MzIzNTM1MzA= 2016-02-26 07:44 NVIDIA 2016-02-26 07:44 NVIDIA Corporation 2015-02-02 09:45 Opera Software 2012-12-22 12:17 PACE Anti-Piracy 2016-04-25 18:59 Programs 2016-02-25 10:03 PunkBuster 2017-01-20 20:02 Qapitain 2013-05-14 09:10 2˙842 recently-used.xbel 2017-01-30 23:18 17 resmon.resmoncfg 2016-05-26 22:11 Skype 2015-12-11 07:42 Sparta 2015-05-05 11:14 Steam 2012-12-22 12:17 STvYAyZaPhLE 2017-01-30 20:02 t5Za44SPXuU 2017-02-21 16:57 Temp 2016-10-19 22:34 Tempfolder 2012-12-20 09:37 Temporary Internet Files [C:\Users\oem\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2013-11-18 14:14 texturemate.com 2013-01-08 11:19 Thunderbird 2013-11-05 15:00 VirtualStore 2014-02-20 08:10 Windows Live 2013-02-25 12:51 Windows Live Writer 2016-11-13 00:50 Wodosytuniph 5 plik(˘w) 1˙650˙071 bajt˘w 74 katalog(˘w) 117˙515˙845˙632 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\Users\oem\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\Users\oem\AppData\LocalLow 2016-12-26 20:59 . 2016-12-26 20:59 .. 2012-12-22 10:31 Adobe 2013-04-12 12:02 Apple Computer 2017-02-04 12:29 Company 2016-10-19 21:40 IObit 2017-02-04 12:07 Microsoft 2017-02-20 16:44 Mozilla 2016-06-20 21:04 Oracle 2016-06-20 21:04 Sun 2016-03-10 06:39 Temp 0 plik(˘w) 0 bajt˘w 11 katalog(˘w) 117˙515˙849˙728 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\Users\oem\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A0D-5424 Katalog: C:\Users\oem\AppData\Roaming 2017-02-21 16:55 . 2017-02-21 16:55 .. 2016-11-11 09:33 360Login 2016-11-11 09:32 360mobilemgr 2016-11-11 09:35 360Quarant 2017-02-01 17:21 Adobe 2015-04-01 09:13 132 Adobe AIFF Format CC Prefs 2013-04-12 12:04 132 Adobe GIF Format CS6 Prefs 2014-04-24 10:33 132 Adobe IllExport Filter CC Prefs 2013-01-03 15:22 132 Adobe IllExport Filter CS6 Prefs 2017-01-24 23:58 132 Adobe PNG Format CC Prefs 2013-12-06 11:12 132 Adobe PNG Format CS6 Prefs 2015-05-25 08:09 132 Adobe Targa Format CC Prefs 2013-04-15 07:32 Apple Computer 2014-10-02 08:09 Astute Graphics 2014-06-30 10:42 Blender Foundation 2015-11-19 15:27 428 book.txt 2017-02-06 21:30 cgjcg 2016-11-01 11:24 charagh 2013-02-07 15:21 chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2016-11-11 09:39 CleanAndroid 2012-12-22 10:05 com.adobe.dmp.contentviewer 2016-03-24 11:58 com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1 2015-03-19 08:34 com.efile.epity2014 2013-01-09 14:41 Corel 2016-11-01 11:39 DAEMON Tools Lite 2014-03-31 07:42 Devalipi Software 2016-11-24 23:19 e-Deklaracje 2016-11-24 23:19 e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 2013-02-12 15:24 EliSoft 2016-02-12 10:41 EPSON 2013-02-13 10:04 EurekaLog 2016-11-11 14:06 FileZilla 2016-12-26 20:58 Firefox 2016-04-20 17:29 GofinDruki 2016-11-13 01:11 Gruktionreofise 2017-01-20 19:32 haeha 2014-05-06 10:01 2˙048 icon_settings470.sys 2012-12-20 09:37 Identities 2012-12-20 09:49 InstallShield 2012-12-20 09:55 Intel Corporation 2016-10-19 21:39 IObit 2017-01-20 20:19 Kiguly 2016-03-18 16:53 KONICA MINOLTA 2012-12-20 21:21 Macromedia 2009-07-14 19:09 Media Center Programs 2016-11-09 23:42 Microsoft 2015-02-02 09:47 MiniGet 2016-10-29 07:34 Misertain 2015-12-07 17:01 43˙008 Moses.dat 2013-08-16 06:35 Mozilla 2016-10-21 20:45 MyDesktop 2016-11-12 10:43 NexusFont 2012-12-22 10:33 NVIDIA 2016-11-03 17:14 OpenOffice 2013-04-17 10:19 OpenOffice.org 2015-02-02 09:45 Opera Software 2016-02-22 13:50 Origin 2016-06-26 22:37 PACE Anti-Piracy 2014-08-27 11:17 PC Remote 2017-02-18 21:10 PCFix 2014-01-27 08:24 PDAppFlex 2016-11-25 21:22 Phucusy 2015-11-19 15:26 4˙134 pic.jpg 2015-11-19 15:26 4˙134 pic1.jpg 2016-04-20 17:23 Podatnik.info 2017-01-22 21:33 Profiles 2013-07-17 11:47 Quite 2016-10-19 22:35 Reetegecoaqus 2016-11-25 21:22 Shvaied 2017-02-21 16:50 Skype 2015-10-25 16:49 Sony Corporation 2015-12-11 07:37 sparta111 2012-12-22 10:32 StageManager.BD092818F67280F4B42B04877600987F0111B594.1 2016-12-05 18:01 Stezogh 2016-06-20 21:04 Sun 2017-01-12 21:17 TeamViewer 2013-01-08 11:19 Thunderbird 2017-01-20 20:19 Torsparanupy 2017-01-25 16:23 Tudomclutother 2016-10-27 18:23 UrlControl_ 2017-01-23 21:54 Vvuckchvosh 2015-12-11 07:42 WarThunder 2016-10-21 20:55 183 WB.CFG 2016-11-08 16:48 Wecsereapa 2013-02-25 13:33 Windows Live Writer 2012-12-22 10:57 WinRAR 2017-02-21 12:06 WinSAPSvc 2017-02-21 16:55 WinSnare 2012-12-22 12:15 WTablet 13 plik(˘w) 54˙859 bajt˘w 77 katalog(˘w) 117˙515˙841˙536 bajt˘w wolnych ========= Koniec CMD: ========= C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono Hosts pomyślnie przywrócono. =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 53984396 B Java, Flash, Steam htmlcache => 100101824 B Windows/system/drivers => 49926613 B Edge => 0 B Chrome => 446166300 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 49912 B Public => 0 B ProgramData => 0 B systemprofile => 8429735 B systemprofile32 => 59309974 B LocalService => 115860 B NetworkService => 0 B oem => 179112564 B UpdatusUser => 0 B RecycleBin => 360058 B EmptyTemp: => 864 MB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 16:57:40 ====