Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 10-10-2017
Uruchomiony przez Kamil Kowalczyk (10-10-2017 18:28:10) Run:1
Uruchomiony z C:\Users\Kamil Kowalczyk\Desktop
Załadowane profile: Kamil Kowalczyk (Dostępne profile: Kamil Kowalczyk)
Tryb startu: Normal
==============================================
fixlist - zawartość:
*****************
CloseProcesses:
CreateRestorePoint:
HKLM\...\Winlogon: [Userinit] C:\Users\Kamil Kowalczyk\AppData\Local\Kometa\StartButton\kometastartvx64.exe,C:\windows\system32\userinit.exe,
HKU\S-1-5-21-696178943-1244779741-494401308-1001\...\Run: [cqdbtbuhke] => explorer "hxxp://khovymush.ru/?utm_source=uoua03&utm_content=295e913c7eb43d006191a7eeee61c5ce&utm_term=D8E957798745964B948E3505AF0E8E8A&utm_d=20170321" <==== UWAGA
HKU\S-1-5-21-696178943-1244779741-494401308-1001\...\Run: [Java x86 applicate] => C:\Users\Kamil Kowalczyk\AppData\Roaming\Java\x86-64bits Windows\Config-DefaultMain\SysUtils SDK v2.49\svhcost.exe [ ] ()
HKU\S-1-5-21-696178943-1244779741-494401308-1001\...\RunOnce: [Flash Inc.] => C:\Users\Kamil Kowalczyk\AppData\Roaming\Adobe\syssl.exe [509952 2017-10-03] ()
C:\Users\Kamil Kowalczyk\AppData\Roaming\Java
C:\Users\Kamil Kowalczyk\AppData\Local\Kometa
C:\Users\Kamil Kowalczyk\AppData\Roaming\Adobe\syssl.exe
ShortcutTarget: Wysyłanie do programu OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Brak pliku)
GroupPolicy: Ograniczenia <==== UWAGA
GroupPolicy\User: Ograniczenia <==== UWAGA
HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKU\S-1-5-21-696178943-1244779741-494401308-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-696178943-1244779741-494401308-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku
C:\ProgramData\Microsoft\Windows\GameExplorer\{E48C0AD5-44D5-40E4-979C-F5EC3239172A}\PlayTasks\0\Play.lnk
C:\Users\Kamil Kowalczyk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wysyłanie do programu OneNote.lnk
DeleteKey: HKCU\Software\Google
DeleteKey: HKCU\SOFTWARE\Google
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google
VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Roaming\Java\x86-64bits Windows\Config-DefaultMain\SysUtils SDK v2.49\svhcost.exe
VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Local\Kometa\StartButton\kometastartvx64.exe
CMD: dir /a "C:\Program Files"
CMD: dir /a "C:\Program Files (x86)"
CMD: dir /a "C:\Program Files\Common Files\System"
CMD: dir /a "C:\Program Files (x86)\Common Files\System"
CMD: dir /a C:\ProgramData
CMD: dir /a C:\Users\Kamil Kowalczyk\AppData\Local
CMD: dir /a C:\Users\Kamil Kowalczyk\AppData\LocalLow
CMD: dir /a C:\Users\Kamil Kowalczyk\AppData\Roaming
CMD: netsh advfirewall reset
Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
EmptyTemp:̩
*****************
Procesy zostały pomyślnie zamknięte.
Punkt przywracania został pomyślnie utworzony.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Wartość pomyślnie przywrócono
HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cqdbtbuhke => Wartość pomyślnie usunięto
HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Java x86 applicate => Wartość pomyślnie usunięto
HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Flash Inc. => Wartość pomyślnie usunięto
C:\Users\Kamil Kowalczyk\AppData\Roaming\Java => pomyślnie przeniesiono
"C:\Users\Kamil Kowalczyk\AppData\Local\Kometa" => nie znaleziono.
C:\Users\Kamil Kowalczyk\AppData\Roaming\Adobe\syssl.exe => pomyślnie przeniesiono
C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE => nie znaleziono.
C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono
C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono
C:\WINDOWS\system32\GroupPolicy\User => pomyślnie przeniesiono
HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono
HKU\S-1-5-21-696178943-1244779741-494401308-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto
HKU\S-1-5-21-696178943-1244779741-494401308-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz pomyślnie usunięto
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono.
HKLM\System\CurrentControlSet\Services\ibtsiva => klucz pomyślnie usunięto
ibtsiva => serwis pomyślnie usunięto
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => klucz pomyślnie usunięto
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => klucz nie znaleziono.
C:\ProgramData\Microsoft\Windows\GameExplorer\{E48C0AD5-44D5-40E4-979C-F5EC3239172A}\PlayTasks\0\Play.lnk => pomyślnie przeniesiono
C:\Users\Kamil Kowalczyk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wysyłanie do programu OneNote.lnk => pomyślnie przeniesiono
HKCU\Software\Google => klucz pomyślnie usunięto
HKCU\SOFTWARE\Google => klucz nie znaleziono.
HKLM\SOFTWARE\Wow6432Node\Google => klucz pomyślnie usunięto
VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Roaming\Java\x86-64bits Windows\Config-DefaultMain\SysUtils SDK v2.49\svhcost.exe => nie znaleziono
VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Local\Kometa\StartButton\kometastartvx64.exe => nie znaleziono
========= dir /a "C:\Program Files" =========
Volume in drive C is OS
Volume Serial Number is 1641-DF7F
Directory of C:\Program Files
03.10.2017 23:51
.
03.10.2017 23:51 ..
10.03.2017 17:37 Adobe
29.07.2017 18:12 Common Files
29.07.2017 18:12 CONEXANT
23.06.2017 15:10 DAEMON Tools Lite
18.03.2017 23:01 174 desktop.ini
11.01.2017 16:04 DIFX
10.03.2017 17:56 Google
29.07.2017 18:12 Intel
13.09.2017 01:09 Internet Explorer
18.09.2017 15:55 Microsoft Office
14.03.2017 21:50 MPC-HC
29.07.2017 19:02 MSBuild
29.07.2017 19:02 Reference Assemblies
10.03.2017 15:18 Uninstall Information
29.06.2017 23:19 UNP
11.07.2017 07:47 Windows Defender
13.09.2017 01:09 Windows Mail
20.03.2017 06:00 Windows Media Player
18.03.2017 23:03 Windows Multimedia Platform
29.07.2017 18:18 Windows NT
13.09.2017 01:09 Windows Photo Viewer
18.03.2017 23:03 Windows Portable Devices
18.03.2017 23:03 Windows Security
18.03.2017 23:03 Windows Sidebar
10.10.2017 13:46 WindowsApps
18.03.2017 23:03 WindowsPowerShell
1 File(s) 174 bytes
27 Dir(s) 133˙129˙285˙632 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files (x86)" =========
Volume in drive C is OS
Volume Serial Number is 1641-DF7F
Directory of C:\Program Files (x86)
29.09.2017 08:50 .
29.09.2017 08:50 ..
01.07.2017 18:23 2K Games
16.05.2017 17:46 Ad Muncher
28.04.2017 17:56 Adobe
01.07.2017 17:36 AGEIA Technologies
11.01.2017 16:03 AmUStor
16.09.2017 11:52 Armagetron Advanced
14.03.2017 16:28 ASUS
18.09.2017 15:56 Common Files
18.03.2017 23:01 174 desktop.ini
30.03.2017 12:59 Dropbox
16.09.2017 12:20 EA GAMES
11.01.2017 16:16 FarStone
10.03.2017 17:56 Google
11.01.2017 16:09 ICEpower
28.09.2017 21:54 InstallShield Installation Information
29.07.2017 18:12 Intel
13.09.2017 01:09 Internet Explorer
29.09.2017 08:50 KASHU
18.09.2017 15:55 Microsoft Analysis Services
18.09.2017 16:25 Microsoft Office
07.05.2017 18:58 Microsoft OneDrive
18.09.2017 16:25 Microsoft Visual Studio 8
18.09.2017 15:55 Microsoft.NET
18.09.2017 23:16 Mount Blade Warband
07.10.2017 12:52 Mozilla Firefox
23.06.2017 19:15 Mr DJ
29.07.2017 19:02 MSBuild
13.03.2017 08:43 NapiProjekt
01.07.2017 17:36 NVIDIA Corporation
14.09.2017 16:48 OpenAL
07.05.2017 21:51 OpenOffice 4
03.09.2017 12:29 PLAY INTERNET
27.09.2017 21:39 R.G. Mechanics
11.01.2017 16:03 Realtek
29.07.2017 19:02 Reference Assemblies
23.06.2017 15:12 Steam
03.04.2016 06:42 TeamViewer
27.09.2017 21:21 Ubisoft
11.07.2017 07:47 Windows Defender
13.09.2017 01:09 Windows Mail
20.03.2017 06:00 Windows Media Player
18.03.2017 23:03 Windows Multimedia Platform
18.03.2017 23:03 Windows NT
13.09.2017 01:09 Windows Photo Viewer
18.03.2017 23:03 Windows Portable Devices
18.03.2017 23:03 Windows Sidebar
18.03.2017 23:03 WindowsPowerShell
21.03.2017 14:05 WinRAR
1 File(s) 174 bytes
49 Dir(s) 133˙129˙285˙632 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files\Common Files\System" =========
Volume in drive C is OS
Volume Serial Number is 1641-DF7F
Directory of C:\Program Files\Common Files\System
20.03.2017 05:59 .
20.03.2017 05:59 ..
11.07.2017 07:47 ado
18.03.2017 22:59 32˙768 DirectDB.dll
20.03.2017 05:59 en-US
20.03.2017 05:59 msadc
20.03.2017 05:59 Ole DB
20.03.2017 05:59 pl-PL
18.03.2017 22:57 854˙528 wab32.dll
18.03.2017 22:57 964˙096 wab32res.dll
3 File(s) 1˙851˙392 bytes
7 Dir(s) 133˙129˙285˙632 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files (x86)\Common Files\System" =========
Volume in drive C is OS
Volume Serial Number is 1641-DF7F
Directory of C:\Program Files (x86)\Common Files\System
18.09.2017 16:25 .
18.09.2017 16:25 ..
11.07.2017 07:47 ado
18.03.2017 22:59 27˙648 DirectDB.dll
20.03.2017 05:59 en-US
20.03.2017 05:59 msadc
18.09.2017 16:25 MSMAPI
18.09.2017 15:56 Ole DB
20.03.2017 05:59 pl-PL
18.03.2017 22:58 741˙888 wab32.dll
18.03.2017 22:58 964˙096 wab32res.dll
3 File(s) 1˙733˙632 bytes
8 Dir(s) 133˙129˙285˙632 bytes free
========= Koniec CMD: =========
========= dir /a C:\ProgramData =========
Volume in drive C is OS
Volume Serial Number is 1641-DF7F
Directory of C:\ProgramData
18.09.2017 15:55 .
18.09.2017 15:55 ..
16.05.2017 17:46 Ad Muncher
28.04.2017 17:58 Adobe
11.01.2017 16:03 AmUStor
10.03.2017 15:28 APRP
01.08.2017 23:01 Armagetron
03.04.2016 06:33 ASUS WebStorage
16.07.2016 13:47 Comms
11.01.2017 15:58 Conexant
10.03.2017 16:05 CyberLink
23.06.2017 15:10 DAEMON Tools Lite
10.03.2017 15:25 Dane aplikacji [C:\ProgramData]
03.09.2017 12:29 DatacardService
23.06.2017 18:30 Dishonored 2
10.03.2017 15:25 Dokumenty [C:\Users\Public\Documents]
03.04.2016 06:35 Dropbox
11.01.2017 16:16 FarStone
11.03.2017 11:13 GOG.com
10.03.2017 19:47 Google
11.01.2017 16:21 install_clap
08.04.2017 16:31 Intel
03.04.2016 06:35 Kingsoft
07.05.2017 19:09 KMSAuto
09.06.2017 20:16 McAfee
10.03.2017 15:25 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu]
18.09.2017 15:55 Microsoft
18.09.2017 16:25 Microsoft Help
29.07.2017 18:19 Microsoft OneDrive
03.10.2017 23:47 Package Cache
03.09.2017 12:29 PLAY INTERNET
10.03.2017 15:25 Pulpit [C:\Users\Public\Desktop]
29.07.2017 18:14 regid.1986-12.com.adobe
18.09.2017 15:47 regid.1991-06.com.microsoft
11.01.2017 16:01 Roaming
18.03.2017 23:03 SoftwareDistribution
20.08.2017 13:44 Steam
10.03.2017 15:25 Szablony [C:\ProgramData\Microsoft\Windows\Templates]
11.01.2017 16:22 Temp
10.03.2017 15:20 UIU
10.03.2017 14:30 USBChargerPlus
29.07.2017 18:18 USOPrivate
29.07.2017 18:18 USOShared
03.04.2016 06:33 WebStorage
10.03.2017 16:08 WildTangent
20.03.2017 06:01 WindowsHolographicDevices
0 File(s) 0 bytes
46 Dir(s) 133˙129˙281˙536 bytes free
========= Koniec CMD: =========
========= dir /a C:\Users\Kamil Kowalczyk\AppData\Local =========
System nie moľe odnale«† okrelonej cieľki.
========= Koniec CMD: =========
========= dir /a C:\Users\Kamil Kowalczyk\AppData\LocalLow =========
System nie moľe odnale«† okrelonej cieľki.
========= Koniec CMD: =========
========= dir /a C:\Users\Kamil Kowalczyk\AppData\Roaming =========
System nie moľe odnale«† okrelonej cieľki.
========= Koniec CMD: =========
========= netsh advfirewall reset =========
Ok.
========= Koniec CMD: =========
========= wevtutil el | Foreach-Object {wevtutil cl "$_"} =========
========= Koniec Powershell: =========
=========== EmptyTemp: ==========
BITS transfer queue => 8675328 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 98984828 B
Java, Flash, Steam htmlcache => 896 B
Windows/system/drivers => 9444193 B
Edge => 28220665 B
Chrome => 0 B
Firefox => 407093582 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 31232 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 0 B
NetworkService => 428922 B
Kamil Kowalczyk => 324205807 B
RecycleBin => 13790873 B
EmptyTemp: => 849.6 MB danych tymczasowych Usunięto.
================================
System wymagał restartu.
==== Koniec Fixlog 18:29:10 ====