Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 10-10-2017 Uruchomiony przez Kamil Kowalczyk (10-10-2017 18:28:10) Run:1 Uruchomiony z C:\Users\Kamil Kowalczyk\Desktop Załadowane profile: Kamil Kowalczyk (Dostępne profile: Kamil Kowalczyk) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKLM\...\Winlogon: [Userinit] C:\Users\Kamil Kowalczyk\AppData\Local\Kometa\StartButton\kometastartvx64.exe,C:\windows\system32\userinit.exe, HKU\S-1-5-21-696178943-1244779741-494401308-1001\...\Run: [cqdbtbuhke] => explorer "hxxp://khovymush.ru/?utm_source=uoua03&utm_content=295e913c7eb43d006191a7eeee61c5ce&utm_term=D8E957798745964B948E3505AF0E8E8A&utm_d=20170321" <==== UWAGA HKU\S-1-5-21-696178943-1244779741-494401308-1001\...\Run: [Java x86 applicate] => C:\Users\Kamil Kowalczyk\AppData\Roaming\Java\x86-64bits Windows\Config-DefaultMain\SysUtils SDK v2.49\svhcost.exe [ ] () HKU\S-1-5-21-696178943-1244779741-494401308-1001\...\RunOnce: [Flash Inc.] => C:\Users\Kamil Kowalczyk\AppData\Roaming\Adobe\syssl.exe [509952 2017-10-03] () C:\Users\Kamil Kowalczyk\AppData\Roaming\Java C:\Users\Kamil Kowalczyk\AppData\Local\Kometa C:\Users\Kamil Kowalczyk\AppData\Roaming\Adobe\syssl.exe ShortcutTarget: Wysyłanie do programu OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Brak pliku) GroupPolicy: Ograniczenia <==== UWAGA GroupPolicy\User: Ograniczenia <==== UWAGA HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Internet Explorer\Main,Start Page = SearchScopes: HKU\S-1-5-21-696178943-1244779741-494401308-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-696178943-1244779741-494401308-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X] ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku C:\ProgramData\Microsoft\Windows\GameExplorer\{E48C0AD5-44D5-40E4-979C-F5EC3239172A}\PlayTasks\0\Play.lnk C:\Users\Kamil Kowalczyk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wysyłanie do programu OneNote.lnk DeleteKey: HKCU\Software\Google DeleteKey: HKCU\SOFTWARE\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Roaming\Java\x86-64bits Windows\Config-DefaultMain\SysUtils SDK v2.49\svhcost.exe VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Local\Kometa\StartButton\kometastartvx64.exe CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Kamil Kowalczyk\AppData\Local CMD: dir /a C:\Users\Kamil Kowalczyk\AppData\LocalLow CMD: dir /a C:\Users\Kamil Kowalczyk\AppData\Roaming CMD: netsh advfirewall reset Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} EmptyTemp:̩ ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Wartość pomyślnie przywrócono HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cqdbtbuhke => Wartość pomyślnie usunięto HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Java x86 applicate => Wartość pomyślnie usunięto HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Flash Inc. => Wartość pomyślnie usunięto C:\Users\Kamil Kowalczyk\AppData\Roaming\Java => pomyślnie przeniesiono "C:\Users\Kamil Kowalczyk\AppData\Local\Kometa" => nie znaleziono. C:\Users\Kamil Kowalczyk\AppData\Roaming\Adobe\syssl.exe => pomyślnie przeniesiono C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE => nie znaleziono. C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono C:\WINDOWS\system32\GroupPolicy\User => pomyślnie przeniesiono HKU\S-1-5-21-696178943-1244779741-494401308-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-696178943-1244779741-494401308-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto HKU\S-1-5-21-696178943-1244779741-494401308-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz pomyślnie usunięto HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. HKLM\System\CurrentControlSet\Services\ibtsiva => klucz pomyślnie usunięto ibtsiva => serwis pomyślnie usunięto HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => klucz pomyślnie usunięto HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => klucz nie znaleziono. C:\ProgramData\Microsoft\Windows\GameExplorer\{E48C0AD5-44D5-40E4-979C-F5EC3239172A}\PlayTasks\0\Play.lnk => pomyślnie przeniesiono C:\Users\Kamil Kowalczyk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wysyłanie do programu OneNote.lnk => pomyślnie przeniesiono HKCU\Software\Google => klucz pomyślnie usunięto HKCU\SOFTWARE\Google => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Google => klucz pomyślnie usunięto VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Roaming\Java\x86-64bits Windows\Config-DefaultMain\SysUtils SDK v2.49\svhcost.exe => nie znaleziono VirusTotal: C:\Users\Kamil Kowalczyk\AppData\Local\Kometa\StartButton\kometastartvx64.exe => nie znaleziono ========= dir /a "C:\Program Files" ========= Volume in drive C is OS Volume Serial Number is 1641-DF7F Directory of C:\Program Files 03.10.2017 23:51 . 03.10.2017 23:51 .. 10.03.2017 17:37 Adobe 29.07.2017 18:12 Common Files 29.07.2017 18:12 CONEXANT 23.06.2017 15:10 DAEMON Tools Lite 18.03.2017 23:01 174 desktop.ini 11.01.2017 16:04 DIFX 10.03.2017 17:56 Google 29.07.2017 18:12 Intel 13.09.2017 01:09 Internet Explorer 18.09.2017 15:55 Microsoft Office 14.03.2017 21:50 MPC-HC 29.07.2017 19:02 MSBuild 29.07.2017 19:02 Reference Assemblies 10.03.2017 15:18 Uninstall Information 29.06.2017 23:19 UNP 11.07.2017 07:47 Windows Defender 13.09.2017 01:09 Windows Mail 20.03.2017 06:00 Windows Media Player 18.03.2017 23:03 Windows Multimedia Platform 29.07.2017 18:18 Windows NT 13.09.2017 01:09 Windows Photo Viewer 18.03.2017 23:03 Windows Portable Devices 18.03.2017 23:03 Windows Security 18.03.2017 23:03 Windows Sidebar 10.10.2017 13:46 WindowsApps 18.03.2017 23:03 WindowsPowerShell 1 File(s) 174 bytes 27 Dir(s) 133˙129˙285˙632 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Volume in drive C is OS Volume Serial Number is 1641-DF7F Directory of C:\Program Files (x86) 29.09.2017 08:50 . 29.09.2017 08:50 .. 01.07.2017 18:23 2K Games 16.05.2017 17:46 Ad Muncher 28.04.2017 17:56 Adobe 01.07.2017 17:36 AGEIA Technologies 11.01.2017 16:03 AmUStor 16.09.2017 11:52 Armagetron Advanced 14.03.2017 16:28 ASUS 18.09.2017 15:56 Common Files 18.03.2017 23:01 174 desktop.ini 30.03.2017 12:59 Dropbox 16.09.2017 12:20 EA GAMES 11.01.2017 16:16 FarStone 10.03.2017 17:56 Google 11.01.2017 16:09 ICEpower 28.09.2017 21:54 InstallShield Installation Information 29.07.2017 18:12 Intel 13.09.2017 01:09 Internet Explorer 29.09.2017 08:50 KASHU 18.09.2017 15:55 Microsoft Analysis Services 18.09.2017 16:25 Microsoft Office 07.05.2017 18:58 Microsoft OneDrive 18.09.2017 16:25 Microsoft Visual Studio 8 18.09.2017 15:55 Microsoft.NET 18.09.2017 23:16 Mount Blade Warband 07.10.2017 12:52 Mozilla Firefox 23.06.2017 19:15 Mr DJ 29.07.2017 19:02 MSBuild 13.03.2017 08:43 NapiProjekt 01.07.2017 17:36 NVIDIA Corporation 14.09.2017 16:48 OpenAL 07.05.2017 21:51 OpenOffice 4 03.09.2017 12:29 PLAY INTERNET 27.09.2017 21:39 R.G. Mechanics 11.01.2017 16:03 Realtek 29.07.2017 19:02 Reference Assemblies 23.06.2017 15:12 Steam 03.04.2016 06:42 TeamViewer 27.09.2017 21:21 Ubisoft 11.07.2017 07:47 Windows Defender 13.09.2017 01:09 Windows Mail 20.03.2017 06:00 Windows Media Player 18.03.2017 23:03 Windows Multimedia Platform 18.03.2017 23:03 Windows NT 13.09.2017 01:09 Windows Photo Viewer 18.03.2017 23:03 Windows Portable Devices 18.03.2017 23:03 Windows Sidebar 18.03.2017 23:03 WindowsPowerShell 21.03.2017 14:05 WinRAR 1 File(s) 174 bytes 49 Dir(s) 133˙129˙285˙632 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files\Common Files\System" ========= Volume in drive C is OS Volume Serial Number is 1641-DF7F Directory of C:\Program Files\Common Files\System 20.03.2017 05:59 . 20.03.2017 05:59 .. 11.07.2017 07:47 ado 18.03.2017 22:59 32˙768 DirectDB.dll 20.03.2017 05:59 en-US 20.03.2017 05:59 msadc 20.03.2017 05:59 Ole DB 20.03.2017 05:59 pl-PL 18.03.2017 22:57 854˙528 wab32.dll 18.03.2017 22:57 964˙096 wab32res.dll 3 File(s) 1˙851˙392 bytes 7 Dir(s) 133˙129˙285˙632 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files\System" ========= Volume in drive C is OS Volume Serial Number is 1641-DF7F Directory of C:\Program Files (x86)\Common Files\System 18.09.2017 16:25 . 18.09.2017 16:25 .. 11.07.2017 07:47 ado 18.03.2017 22:59 27˙648 DirectDB.dll 20.03.2017 05:59 en-US 20.03.2017 05:59 msadc 18.09.2017 16:25 MSMAPI 18.09.2017 15:56 Ole DB 20.03.2017 05:59 pl-PL 18.03.2017 22:58 741˙888 wab32.dll 18.03.2017 22:58 964˙096 wab32res.dll 3 File(s) 1˙733˙632 bytes 8 Dir(s) 133˙129˙285˙632 bytes free ========= Koniec CMD: ========= ========= dir /a C:\ProgramData ========= Volume in drive C is OS Volume Serial Number is 1641-DF7F Directory of C:\ProgramData 18.09.2017 15:55 . 18.09.2017 15:55 .. 16.05.2017 17:46 Ad Muncher 28.04.2017 17:58 Adobe 11.01.2017 16:03 AmUStor 10.03.2017 15:28 APRP 01.08.2017 23:01 Armagetron 03.04.2016 06:33 ASUS WebStorage 16.07.2016 13:47 Comms 11.01.2017 15:58 Conexant 10.03.2017 16:05 CyberLink 23.06.2017 15:10 DAEMON Tools Lite 10.03.2017 15:25 Dane aplikacji [C:\ProgramData] 03.09.2017 12:29 DatacardService 23.06.2017 18:30 Dishonored 2 10.03.2017 15:25 Dokumenty [C:\Users\Public\Documents] 03.04.2016 06:35 Dropbox 11.01.2017 16:16 FarStone 11.03.2017 11:13 GOG.com 10.03.2017 19:47 Google 11.01.2017 16:21 install_clap 08.04.2017 16:31 Intel 03.04.2016 06:35 Kingsoft 07.05.2017 19:09 KMSAuto 09.06.2017 20:16 McAfee 10.03.2017 15:25 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 18.09.2017 15:55 Microsoft 18.09.2017 16:25 Microsoft Help 29.07.2017 18:19 Microsoft OneDrive 03.10.2017 23:47 Package Cache 03.09.2017 12:29 PLAY INTERNET 10.03.2017 15:25 Pulpit [C:\Users\Public\Desktop] 29.07.2017 18:14 regid.1986-12.com.adobe 18.09.2017 15:47 regid.1991-06.com.microsoft 11.01.2017 16:01 Roaming 18.03.2017 23:03 SoftwareDistribution 20.08.2017 13:44 Steam 10.03.2017 15:25 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 11.01.2017 16:22 Temp 10.03.2017 15:20 UIU 10.03.2017 14:30 USBChargerPlus 29.07.2017 18:18 USOPrivate 29.07.2017 18:18 USOShared 03.04.2016 06:33 WebStorage 10.03.2017 16:08 WildTangent 20.03.2017 06:01 WindowsHolographicDevices 0 File(s) 0 bytes 46 Dir(s) 133˙129˙281˙536 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\Kamil Kowalczyk\AppData\Local ========= System nie moľe odnale«† okre˜lonej ˜cieľki. ========= Koniec CMD: ========= ========= dir /a C:\Users\Kamil Kowalczyk\AppData\LocalLow ========= System nie moľe odnale«† okre˜lonej ˜cieľki. ========= Koniec CMD: ========= ========= dir /a C:\Users\Kamil Kowalczyk\AppData\Roaming ========= System nie moľe odnale«† okre˜lonej ˜cieľki. ========= Koniec CMD: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= ========= wevtutil el | Foreach-Object {wevtutil cl "$_"} ========= ========= Koniec Powershell: ========= =========== EmptyTemp: ========== BITS transfer queue => 8675328 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 98984828 B Java, Flash, Steam htmlcache => 896 B Windows/system/drivers => 9444193 B Edge => 28220665 B Chrome => 0 B Firefox => 407093582 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 31232 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 128 B LocalService => 0 B NetworkService => 428922 B Kamil Kowalczyk => 324205807 B RecycleBin => 13790873 B EmptyTemp: => 849.6 MB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 18:29:10 ====