Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 14.03.2018 Uruchomiony przez byrdz (23-03-2018 15:02:47) Run:2 Uruchomiony z C:\Users\byrdz\Documents\FIX IT PLEASE Załadowane profile: byrdz (Dostępne profile: defaultuser0 & byrdz) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Native Instruments Homepage.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Massive\Native Instruments Homepage.lnk C:\Users\byrdz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazrog\Recabinet\Manual.lnk C:\Users\byrdz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazrog\Recabinet\Uninstall.lnk ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Brak pliku Task: {09B886FF-8099-4260-A05F-5802AEAD33D8} - System32\Tasks\dTRRfHQjsHOvbdt2 => rundll32 "C:\Program Files (x86)\LfFoujfjU\vJRmNI.dll",#1 Task: {CEFC37DF-45F8-422D-AE02-524CCA67331F} - System32\Tasks\qFbxfDUevnccZZ => rundll32 "C:\Program Files (x86)\jzVqtpDsXbLU2\EvfJfRbmLNDIf.dll",#1 Task: {EB593E33-0DC7-4D22-87F1-F1F330177DA5} - System32\Tasks\dIxshjfnsDsrepSSqPt2 => rundll32 "C:\Program Files (x86)\pidIvTaYsJowC\MczYPAT.dll",#1 Task: {FFDEAE73-39A9-4E12-8959-6F63B0386E8D} - System32\Tasks\WlbBJSMcknvngxNxC2 => rundll32 "C:\Program Files (x86)\mAUzXDPkZrvZtXzyunR\youRzsM.dll",#1 C:\Program Files (x86)\LfFoujfjU C:\Program Files (x86)\jzVqtpDsXbLU2 C:\Program Files (x86)\pidIvTaYsJowC C:\Program Files (x86)\mAUzXDPkZrvZtXzyunR Task: {18EBE0ED-1EAB-4776-BDFC-E8DFA3640784} - System32\Tasks\GoogleUpdateSecurityTaskMachine_AJ => C:\Users\byrdz\AppData\Roaming\4aa57c69cf284598ba2474ba12f54e45\HandlerExecution.exe [2018-03-22] () <==== UWAGA Task: {8BCC4E10-726F-4DA4-B219-6D2BE0E31FB2} - System32\Tasks\GoogleUpdateSecurityTaskMachine_YD => C:\Users\byrdz\AppData\Roaming\73179a203cf14340a078b0b2aacf6ba6\HandlerExecution.exe [2018-03-22] () <==== UWAGA Task: {A4C9CEF0-7528-4F97-B650-8F312A6116F1} - System32\Tasks\GoogleUpdateSecurityTaskMachine_OX => C:\Users\byrdz\AppData\Roaming\76cc55dd9a3740408c857ed0f23ff1bb\HandlerExecution.exe [2018-03-22] () <==== UWAGA Task: {E6E348A5-D695-46CB-88BC-4DDDA52CD080} - System32\Tasks\GoogleUpdateSecurityTaskMachine_LF => C:\Users\byrdz\AppData\Local\ca82a53784824e738c137e50727f8f1a\HandlerExecution.exe [2018-03-22] () <==== UWAGA Task: {A3D367BC-0B47-45F3-A9CB-CDB33A77C63B} - System32\Tasks\GoogleUpdateSecurityTaskMachine_FG => C:\ProgramData\e9bee0b438034d95b679fea1fd7dc782\HandlerExecution.exe [2018-03-22] () <==== UWAGA C:\Users\byrdz\AppData\Roaming\4aa57c69cf284598ba2474ba12f54e45 C:\Users\byrdz\AppData\Roaming\73179a203cf14340a078b0b2aacf6ba6 C:\Users\byrdz\AppData\Roaming\76cc55dd9a3740408c857ed0f23ff1bb C:\ProgramData\e9bee0b438034d95b679fea1fd7dc782 Task: {626CFDB1-5A99-4870-8752-C6117F6A7A62} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku <==== UWAGA Task: {662EABC6-8533-4A21-B365-DAE015B50537} - System32\Tasks\cmdsrv => C:\Browse\cmdsrvs.exe [2018-03-13] (Secrypt Inc.) C:\Browse GroupPolicy: Ograniczenia - Chrome <==== UWAGA S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S1 ebsktgnk; \??\C:\WINDOWS\system32\drivers\ebsktgnk.sys [X] S1 fqvefljg; \??\C:\WINDOWS\system32\drivers\fqvefljg.sys [X] S1 nkwpmper; \??\C:\WINDOWS\system32\drivers\nkwpmper.sys [X] S1 sldylynf; \??\C:\WINDOWS\system32\drivers\sldylynf.sys [X] S1 tcqhgvfw; \??\C:\WINDOWS\system32\drivers\tcqhgvfw.sys [X] 2018-03-22 15:34 - 2018-03-22 15:34 - 000000000 ____D C:\Program Files (x86)\yplCmHJcuoUn 2018-03-22 15:34 - 2018-03-22 15:34 - 000000000 ____D C:\Program Files (x86)\JwYYyjKjrIE 2018-03-22 15:07 - 2018-03-22 15:07 - 000000000 ____D C:\Program Files (x86)\pidIvTaYsJowCapgudtfmgq 2018-03-22 15:07 - 2018-03-22 15:07 - 000000000 ____D C:\Program Files (x86)\mAUzXDPkZrvZtXzyunRqnaqcoltor 2018-03-22 14:09 - 2018-03-22 14:09 - 000000000 ____D C:\Program Files (x86)\pidIvTaYsJowCwwpehuhwin 2018-03-22 14:09 - 2018-03-22 14:09 - 000000000 ____D C:\Program Files (x86)\mAUzXDPkZrvZtXzyunRytubqimuyg 2018-03-22 14:07 - 2018-03-22 14:09 - 000000000 ____D C:\Program Files (x86)\foldershare 2018-03-22 14:09 - 2018-03-22 15:45 - 000000000 ____D C:\Program Files\UEDT1PI04N 2018-03-22 14:35 - 2018-03-22 15:08 - 000000000 ____D C:\Users\byrdz\AppData\Local\yvxxOSvvvpXeZpQog 2018-03-22 14:09 - 2018-03-22 15:30 - 000000000 ____D C:\Users\byrdz\AppData\Roaming\j55dtnxuyah 2018-03-22 14:08 - 2018-03-22 15:19 - 000000000 ____D C:\Users\byrdz\AppData\Roaming\cpuminer 2018-03-22 14:08 - 2018-03-22 14:08 - 000000000 ____D C:\Users\byrdz\AppData\Roaming\gplyra 2018-03-22 14:06 - 2018-03-22 14:06 - 000000000 ____D C:\ProgramData\ef737cee-6357-1 2018-03-22 14:06 - 2018-03-22 14:06 - 000000000 ____D C:\ProgramData\ef737cee-3535-0 2018-03-22 14:09 - 2018-03-22 15:43 - 000000000 ____D C:\ProgramData\9d594f1d35 2018-03-22 14:07 - 2018-03-22 15:08 - 000000000 ____D C:\Applications Folder: C:\Users\Public\Documents\AdobeGC Folder: C:\WINDOWS\Microsoft Antimalware Folder: C:\WINDOWS\system32\config\SOFTWARE Folder: C:\Users\byrdz\AppData\Roaming\WidModule Folder: C:\Program Files (x86)\ON Tcpip\..\Interfaces\{5b7f5289-b6e9-46e5-bfee-e51b2047720e}: [NameServer] 82.163.142.8,95.211.158.136 CMD: ipconfig /flushdns CMD: netsh advfirewall reset Hosts: CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\byrdz\AppData\Local CMD: dir /a C:\Users\byrdz\AppData\LocalLow CMD: dir /a C:\Users\byrdz\AppData\Roaming Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Native Instruments Homepage.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Massive\Native Instruments Homepage.lnk => pomyślnie przeniesiono C:\Users\byrdz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazrog\Recabinet\Manual.lnk => pomyślnie przeniesiono C:\Users\byrdz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kazrog\Recabinet\Uninstall.lnk => pomyślnie przeniesiono "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw" => pomyślnie usunięto HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => nie znaleziono "HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => pomyślnie usunięto HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => nie znaleziono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{09B886FF-8099-4260-A05F-5802AEAD33D8}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09B886FF-8099-4260-A05F-5802AEAD33D8}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\dTRRfHQjsHOvbdt2 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dTRRfHQjsHOvbdt2" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEFC37DF-45F8-422D-AE02-524CCA67331F}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEFC37DF-45F8-422D-AE02-524CCA67331F}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\qFbxfDUevnccZZ => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\qFbxfDUevnccZZ" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EB593E33-0DC7-4D22-87F1-F1F330177DA5}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB593E33-0DC7-4D22-87F1-F1F330177DA5}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\dIxshjfnsDsrepSSqPt2 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dIxshjfnsDsrepSSqPt2" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FFDEAE73-39A9-4E12-8959-6F63B0386E8D}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFDEAE73-39A9-4E12-8959-6F63B0386E8D}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\WlbBJSMcknvngxNxC2 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WlbBJSMcknvngxNxC2" => pomyślnie usunięto C:\Program Files (x86)\LfFoujfjU => pomyślnie przeniesiono C:\Program Files (x86)\jzVqtpDsXbLU2 => pomyślnie przeniesiono C:\Program Files (x86)\pidIvTaYsJowC => pomyślnie przeniesiono C:\Program Files (x86)\mAUzXDPkZrvZtXzyunR => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{18EBE0ED-1EAB-4776-BDFC-E8DFA3640784}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18EBE0ED-1EAB-4776-BDFC-E8DFA3640784}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\GoogleUpdateSecurityTaskMachine_AJ => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateSecurityTaskMachine_AJ" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8BCC4E10-726F-4DA4-B219-6D2BE0E31FB2}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BCC4E10-726F-4DA4-B219-6D2BE0E31FB2}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\GoogleUpdateSecurityTaskMachine_YD => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateSecurityTaskMachine_YD" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4C9CEF0-7528-4F97-B650-8F312A6116F1}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4C9CEF0-7528-4F97-B650-8F312A6116F1}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\GoogleUpdateSecurityTaskMachine_OX => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateSecurityTaskMachine_OX" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E6E348A5-D695-46CB-88BC-4DDDA52CD080}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6E348A5-D695-46CB-88BC-4DDDA52CD080}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\GoogleUpdateSecurityTaskMachine_LF => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateSecurityTaskMachine_LF" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3D367BC-0B47-45F3-A9CB-CDB33A77C63B}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3D367BC-0B47-45F3-A9CB-CDB33A77C63B}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\GoogleUpdateSecurityTaskMachine_FG => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateSecurityTaskMachine_FG" => pomyślnie usunięto C:\Users\byrdz\AppData\Roaming\4aa57c69cf284598ba2474ba12f54e45 => pomyślnie przeniesiono C:\Users\byrdz\AppData\Roaming\73179a203cf14340a078b0b2aacf6ba6 => pomyślnie przeniesiono C:\Users\byrdz\AppData\Roaming\76cc55dd9a3740408c857ed0f23ff1bb => pomyślnie przeniesiono C:\ProgramData\e9bee0b438034d95b679fea1fd7dc782 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{626CFDB1-5A99-4870-8752-C6117F6A7A62}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{626CFDB1-5A99-4870-8752-C6117F6A7A62}" => pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => niepowodzenie przy usuwaniu. Odmowa dostępu. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{662EABC6-8533-4A21-B365-DAE015B50537}" => pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{662EABC6-8533-4A21-B365-DAE015B50537}" => pomyślnie usunięto C:\WINDOWS\System32\Tasks\cmdsrv => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cmdsrv" => pomyślnie usunięto C:\Browse => pomyślnie przeniesiono C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono "HKLM\System\CurrentControlSet\Services\gupdate" => pomyślnie usunięto gupdate => serwis pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\gupdatem" => pomyślnie usunięto gupdatem => serwis pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\ebsktgnk" => pomyślnie usunięto ebsktgnk => serwis pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\fqvefljg" => pomyślnie usunięto fqvefljg => serwis pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\nkwpmper" => pomyślnie usunięto nkwpmper => serwis pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\sldylynf" => pomyślnie usunięto sldylynf => serwis pomyślnie usunięto "HKLM\System\CurrentControlSet\Services\tcqhgvfw" => pomyślnie usunięto tcqhgvfw => serwis pomyślnie usunięto C:\Program Files (x86)\yplCmHJcuoUn => pomyślnie przeniesiono C:\Program Files (x86)\JwYYyjKjrIE => pomyślnie przeniesiono C:\Program Files (x86)\pidIvTaYsJowCapgudtfmgq => pomyślnie przeniesiono C:\Program Files (x86)\mAUzXDPkZrvZtXzyunRqnaqcoltor => pomyślnie przeniesiono C:\Program Files (x86)\pidIvTaYsJowCwwpehuhwin => pomyślnie przeniesiono C:\Program Files (x86)\mAUzXDPkZrvZtXzyunRytubqimuyg => pomyślnie przeniesiono C:\Program Files (x86)\foldershare => pomyślnie przeniesiono C:\Program Files\UEDT1PI04N => pomyślnie przeniesiono C:\Users\byrdz\AppData\Local\yvxxOSvvvpXeZpQog => pomyślnie przeniesiono C:\Users\byrdz\AppData\Roaming\j55dtnxuyah => pomyślnie przeniesiono C:\Users\byrdz\AppData\Roaming\cpuminer => pomyślnie przeniesiono C:\Users\byrdz\AppData\Roaming\gplyra => pomyślnie przeniesiono C:\ProgramData\ef737cee-6357-1 => pomyślnie przeniesiono C:\ProgramData\ef737cee-3535-0 => pomyślnie przeniesiono C:\ProgramData\9d594f1d35 => pomyślnie przeniesiono C:\Applications => pomyślnie przeniesiono ========================= Folder: C:\Users\Public\Documents\AdobeGC ======================== 2018-03-22 15:31 - 2018-03-22 15:31 - 000000330 ____A [646A83C89907BF1A7C8622A04DE7B552] () C:\Users\Public\Documents\AdobeGC\adobegc_a02904 ====== Koniec Folder: ====== ========================= Folder: C:\WINDOWS\Microsoft Antimalware ======================== 2018-03-22 14:26 - 2018-03-22 14:27 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Definition Updates 2018-03-22 14:26 - 2018-03-22 14:26 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Definition Updates\{47CEA7F9-B82A-4533-BFC1-4351A2823F26} 2018-03-22 14:26 - 2018-03-01 18:17 - 033187552 ____A [85D91E5C6053711D05C6096F8FEEA7C3] (Microsoft Corporation) C:\WINDOWS\Microsoft Antimalware\Definition Updates\{47CEA7F9-B82A-4533-BFC1-4351A2823F26}\mpasbase.vdm 2018-03-22 14:26 - 2018-03-22 13:28 - 004644584 ____A [F13B032282BF207234EC3108B2FEAC8D] (Microsoft Corporation) C:\WINDOWS\Microsoft Antimalware\Definition Updates\{47CEA7F9-B82A-4533-BFC1-4351A2823F26}\mpasdlta.vdm 2018-03-22 14:26 - 2018-03-01 18:17 - 060515552 ____A [B29B11807B08D7DAE57C4ADC09BB2E4B] (Microsoft Corporation) C:\WINDOWS\Microsoft Antimalware\Definition Updates\{47CEA7F9-B82A-4533-BFC1-4351A2823F26}\mpavbase.vdm 2018-03-22 14:26 - 2018-03-22 13:28 - 008828640 ____A [0968B75444AFEC7429386134FA4893F1] (Microsoft Corporation) C:\WINDOWS\Microsoft Antimalware\Definition Updates\{47CEA7F9-B82A-4533-BFC1-4351A2823F26}\mpavdlta.vdm 2018-03-22 14:26 - 2018-02-09 02:25 - 014453336 ____A [C80DF35BF0E3457CB71C2BC57644EE8F] (Microsoft Corporation) C:\WINDOWS\Microsoft Antimalware\Definition Updates\{47CEA7F9-B82A-4533-BFC1-4351A2823F26}\mpengine.dll 2018-03-22 14:26 - 2018-03-22 14:26 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Definition Updates\Backup 2018-03-22 14:26 - 2018-03-22 14:27 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Definition Updates\Updates 2018-03-22 14:26 - 2018-03-22 14:23 - 000058120 ____A [BF2513029E231BE96D82F7C3ABFF87F4] (Microsoft Corporation) C:\WINDOWS\Microsoft Antimalware\Definition Updates\Updates\MpKslb165de97.sys 2018-03-22 14:26 - 2018-03-22 14:32 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\LocalCopy 2018-03-22 14:26 - 2018-03-22 14:26 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Quarantine 2018-03-22 14:26 - 2018-03-22 14:32 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans 2018-03-22 14:26 - 2018-03-22 14:31 - 000000112 ____A [F411F5D10F54781242D3DCCD3E0C5F1F] () C:\WINDOWS\Microsoft Antimalware\Scans\MpDiag.bin 2018-03-22 14:27 - 2018-03-22 14:32 - 000180224 ____A [7712BA041B8B0BB423BF295F10932C71] () C:\WINDOWS\Microsoft Antimalware\Scans\mpenginedb.db 2018-03-22 14:31 - 2018-03-22 14:31 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry 2018-03-22 14:31 - 2018-03-22 14:32 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424 2018-03-22 14:32 - 2018-03-22 14:32 - 000001668 ____A [73324246C0E67DC65AF2232ABD92989C] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\0DFAE29A-F947-6492-61EF-CC58E059A684 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\2B029364-670E-B92E-1CB5-C4DDF5E35A37 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\31916878-7B8F-AC2B-DFC1-74D4340FCFCF 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\42CCAAB9-3813-EA51-DF03-AD81C0D873AF 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\5A877C38-9190-D720-38AC-41288B85F34F 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\63DFDEE6-1D97-19E3-3C0E-234FE4008136 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\75C3AE11-7CDE-357B-1D62-5DCA98AAD877 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\8EFEDD40-0BDA-F571-934F-8303EC4ABDD4 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\9949B37F-A428-B5C6-0714-4B9D7C3C6356 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\9B1610F2-3D6B-6CCE-6F70-36EDAAF51004 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\A3963CC1-3628-18C9-323D-896D0BEFC206 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\BD2B04D9-EA6A-C171-1E14-9C724591DC5B 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\C2CAF064-7835-F972-F9E9-822CE7C12749 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\CED62027-2D78-7EED-00A6-04A2B699AF55 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\D61EA19B-BE81-7DB2-9069-977653E360B5 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\DFB43BBB-049D-BCAF-32BB-50B3960E8A72 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\E0FF34DD-B1C3-5232-63AB-4D656F12DDC3 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\E1F1E991-ED74-EE31-3708-93C44C9112C6 2018-03-22 14:32 - 2018-03-22 14:32 - 000000094 ____A [AD9A18762B0CD194E0E4653287ACB8EE] () C:\WINDOWS\Microsoft Antimalware\Scans\FailTelemetry\6A2D9DB707AF3542AD23FD4F3A56D424\F69BF25C-5DE9-CDE3-0847-DBC95F187386 2018-03-22 14:26 - 2018-03-22 14:31 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\History 2018-03-22 14:31 - 2018-03-22 14:32 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Results 2018-03-22 14:31 - 2018-03-22 14:31 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Results\Quick 2018-03-22 14:31 - 2018-03-22 14:31 - 000023694 ____A [3FE15A0F416E9F1C234ABE367D49AA04] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Results\Quick\{C0C21A60-C08F-49F9-9AF6-F4DA599B1398} 2018-03-22 14:32 - 2018-03-22 14:32 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Results\Resource 2018-03-22 14:32 - 2018-03-22 14:32 - 000019806 ____A [0C7EA154D4A4DCF1CAF0697D84DFFB96] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Results\Resource\{B79D2D6A-AF07-4235-AD23-FD4F3A56D424} 2018-03-22 14:26 - 2018-03-22 14:32 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Service 2018-03-22 14:31 - 2018-03-22 14:32 - 000000002 ____A [F3B25701FE362EC84616A93A45CE9998] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Service\Detections.log 2018-03-22 14:32 - 2018-03-22 14:32 - 000000078 ____A [69B41003E20FAE3C669E8E5E503EA19D] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Service\History.Log 2018-03-22 14:31 - 2018-03-22 14:31 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Service\DetectionHistory 2018-03-22 14:31 - 2018-03-22 14:31 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Service\DetectionHistory\22 2018-03-22 14:31 - 2018-03-22 14:32 - 000002856 ____A [0679DB8F2233EE023BA66DA2C526ABBB] () C:\WINDOWS\Microsoft Antimalware\Scans\History\Service\DetectionHistory\22\23CF80C6-C8CB-4A39-8E49-437F56C42E2F 2018-03-22 14:26 - 2018-03-22 14:26 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Support 2018-03-22 14:26 - 2018-03-22 14:32 - 000001538 ____A [7C16B66D46ADBC30C78488BD7DEA2796] () C:\WINDOWS\Microsoft Antimalware\Support\MPDetection-03222018-142656.log 2018-03-22 14:26 - 2018-03-22 14:32 - 000158198 ____A [AD677AAE963EA34FCE05A3108C65D1B7] () C:\WINDOWS\Microsoft Antimalware\Support\MPLog-03222018-142656.log 2018-03-22 14:26 - 2018-03-22 14:32 - 004194304 ____A [C29EC07B4AB980EE96D46842DEDF947D] () C:\WINDOWS\Microsoft Antimalware\Support\MpWppTracing-03222018-142656-00000003-ffffffff.bin 2018-03-22 14:26 - 2018-03-22 14:32 - 000040902 ____A [2D73FDA0E5AE5EACE5349E061FFDF770] () C:\WINDOWS\Microsoft Antimalware\Support\msssWrapper.log 2018-03-22 14:26 - 2018-03-22 14:27 - 000000000 ____D [00000000000000000000000000000000] () C:\WINDOWS\Microsoft Antimalware\Tmp 2018-03-22 14:27 - 2018-03-22 14:27 - 000001578 ____A [44073F692F99D239CA6C043DEC3E8F70] () C:\WINDOWS\Microsoft Antimalware\Tmp\MpCmdRun.log ====== Koniec Folder: ====== ========================= Folder: C:\WINDOWS\system32\config\SOFTWARE ======================== C:\WINDOWS\system32\config\SOFTWARE => Plik ====== Koniec Folder: ====== ========================= Folder: C:\Users\byrdz\AppData\Roaming\WidModule ======================== 2018-03-22 14:07 - 2018-03-22 14:07 - 000000000 ____A [D41D8CD98F00B204E9800998ECF8427E] () C:\Users\byrdz\AppData\Roaming\WidModule\data.txt 2018-03-22 14:07 - 2018-03-22 14:08 - 000013438 ____A [373BD747C335B04DC9F82B72E16992F4] () C:\Users\byrdz\AppData\Roaming\WidModule\unins000.dat 2018-03-22 14:08 - 2018-03-22 14:08 - 001202385 ____A [CB92B5729637F3A29757149ABE6A7768] () C:\Users\byrdz\AppData\Roaming\WidModule\unins000.exe ====== Koniec Folder: ====== ========================= Folder: C:\Program Files (x86)\ON ======================== 2018-03-22 14:09 - 2017-12-14 07:42 - 000001860 ____A [DEB1B377008E7C7A9BC805B740245D6B] () C:\Program Files (x86)\ON\72417.exe.config 2018-03-22 14:07 - 2017-12-14 07:42 - 000001860 ____A [DEB1B377008E7C7A9BC805B740245D6B] () C:\Program Files (x86)\ON\73843.exe.config ====== Koniec Folder: ====== "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5b7f5289-b6e9-46e5-bfee-e51b2047720e}\\NameServer" => pomyślnie usunięto ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= Koniec CMD: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono Hosts pomyślnie przywrócono. ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is E458-3A05 Directory of C:\Program Files 23.03.2018 15:03