Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:07-11-2015 Uruchomiony przez Jakub (2015-11-12 09:24:13) Run:2 Uruchomiony z C:\Users\Jakub\Downloads\FRTS Załadowane profile: UpdatusUser & Jakub & (Dostępne profile: UpdatusUser & Jakub) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => nie znaleziono Task: {1BB68C06-50EC-42E6-A2F5-6C0F2EEF92EC} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2053194998-3405878221-685674103-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {722D7488-46ED-4AEB-9622-46C3FF05EC95} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2053194998-3405878221-685674103-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Reg: reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Run" /f Reg: reg delete HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder /v "McAfee Parental Controls.lnk" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v HotKeysCmds /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v IgfxTray /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Persistence /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v TkBellExe /f CMD: type "C:\Program Files (x86)\Mozilla Firefox\B47960E2D889DD55984943B04E3AA048B479" C:\Program Files (x86)\Mozilla Firefox\B47960E2D889DD55984943B04E3AA048B479 C:\Program Files (x86)\Real C:\ProgramData\Real C:\Users\Jakub\AppData\Roaming\Real Reboot: ***************** HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758} => Wartość pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1BB68C06-50EC-42E6-A2F5-6C0F2EEF92EC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1BB68C06-50EC-42E6-A2F5-6C0F2EEF92EC}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2053194998-3405878221-685674103-1002 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2053194998-3405878221-685674103-1002" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{722D7488-46ED-4AEB-9622-46C3FF05EC95}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{722D7488-46ED-4AEB-9622-46C3FF05EC95}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2053194998-3405878221-685674103-1002 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeLogonTaskS-1-5-21-2053194998-3405878221-685674103-1002" => klucz pomyślnie usunięto ========= reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Run" /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder /v "McAfee Parental Controls.lnk" /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v HotKeysCmds /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v IgfxTray /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Persistence /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v TkBellExe /f ========= Operacja ukoäczona pomylnie. ========= Koniec Reg: ========= ========= type "C:\Program Files (x86)\Mozilla Firefox\B47960E2D889DD55984943B04E3AA048B479" ========= <<-sv-yv{r-z-or-rz}-n-||-J-P|z}|{r{;pynrh/Mz|vyyn;|t<}rsrr{pr:rvprH>/j;tr`rvpr5P|z}|{r{;v{rsnpr;{V]rs`rvpr6;trOn{pu5//6Hvs-5||;tr]rsa}r5/qnnr}|v{t;urnyur}|;}y|nqR{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/qnnr}|v{t;urnyur}|;}y|nqR{noyrq/9-snyr6Hvs-5||;tr]rsa}r5/qnnr}|v{t;urnyur}|;rvpr;r{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/qnnr}|v{t;urnyur}|;rvpr;r{noyrq/9-snyr6Hvs-5||;tr]rsa}r5/qnnr}|v{t;}|yvp;qnn`ozvv|{R{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/qnnr}|v{t;}|yvp;qnn`ozvv|{R{noyrq/9-snyr6Hvs-5||;tr]rsa}r5/||yxv;ryrzr;r{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/||yxv;ryrzr;r{noyrq/9-snyr6HP|z}|{r{;pynrh/Mz|vyyn;|t<||yxv
/j;tr`rvpr5P|z}|{r{;v{rsnpr;{VPnu_r}|r6;ozv_r}|-J-snyrHn-p-J-P|z}|{r{;pynrh/Mz|vyyn;|t<}p|z