Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:07-11-2015 Uruchomiony przez Jakub (2015-11-12 09:24:13) Run:2 Uruchomiony z C:\Users\Jakub\Downloads\FRTS Załadowane profile: UpdatusUser & Jakub & (Dostępne profile: UpdatusUser & Jakub) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => nie znaleziono Task: {1BB68C06-50EC-42E6-A2F5-6C0F2EEF92EC} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2053194998-3405878221-685674103-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {722D7488-46ED-4AEB-9622-46C3FF05EC95} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2053194998-3405878221-685674103-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Reg: reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Run" /f Reg: reg delete HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder /v "McAfee Parental Controls.lnk" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v HotKeysCmds /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v IgfxTray /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Persistence /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v TkBellExe /f CMD: type "C:\Program Files (x86)\Mozilla Firefox\B47960E2D889DD55984943B04E3AA048B479" C:\Program Files (x86)\Mozilla Firefox\B47960E2D889DD55984943B04E3AA048B479 C:\Program Files (x86)\Real C:\ProgramData\Real C:\Users\Jakub\AppData\Roaming\Real Reboot: ***************** HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758} => Wartość pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1BB68C06-50EC-42E6-A2F5-6C0F2EEF92EC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1BB68C06-50EC-42E6-A2F5-6C0F2EEF92EC}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2053194998-3405878221-685674103-1002 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2053194998-3405878221-685674103-1002" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{722D7488-46ED-4AEB-9622-46C3FF05EC95}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{722D7488-46ED-4AEB-9622-46C3FF05EC95}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2053194998-3405878221-685674103-1002 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeLogonTaskS-1-5-21-2053194998-3405878221-685674103-1002" => klucz pomyślnie usunięto ========= reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Run" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKU\S-1-5-21-2053194998-3405878221-685674103-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder /v "McAfee Parental Controls.lnk" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v HotKeysCmds /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v IgfxTray /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Persistence /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v TkBellExe /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= type "C:\Program Files (x86)\Mozilla Firefox\B47960E2D889DD55984943B04E3AA048B479" ========= <<-sv-yv{r-z-or-rz}-n-||-J-P|z}|{r{;pynrh/Mz|vyyn;|t<}rsrr{pr:rvprH>/j;tr`rvpr5P|z}|{r{;v{rsnpr;{V]rs`rvpr6;trOn{pu5//6Hvs-5||;tr]rsa}r5/qnnr}|v{t;urnyur}|;}y|nqR{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/qnnr}|v{t;urnyur}|;}y|nqR{noyrq/9-snyr6Hvs-5||;tr]rsa}r5/qnnr}|v{t;urnyur}|;rvpr;r{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/qnnr}|v{t;urnyur}|;rvpr;r{noyrq/9-snyr6Hvs-5||;tr]rsa}r5/qnnr}|v{t;}|yvp;qnn`ozvv|{R{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/qnnr}|v{t;}|yvp;qnn`ozvv|{R{noyrq/9-snyr6Hvs-5||;tr]rsa}r5/||yxv;ryrzr;r{noyrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/||yxv;ryrzr;r{noyrq/9-snyr6HP|z}|{r{;pynrh/Mz|vyyn;|t<||yxv/j;tr`rvpr5P|z}|{r{;v{rsnpr;{VPnu_r}|r6;ozv_r}|-J-snyrHn-p-J-P|z}|{r{;pynrh/Mz|vyyn;|t<}p|z/j;tr`rvpr5P|z}|{r{;v{rsnpr;{Vcrv|{P|z}nn|6Hn-v{s|-J-P|z}|{r{;pynrh/Mz|vyyn;|t<r/j;tr`rvpr5P|z}|{r{;v{rsnpr;{VebYN}}V{s|6Hvs-5p;p|z}nr5v{s|;rv|{9-/A>/6-KJ-=-33----||;tr]rsa}r5/}v{nyy;vt{nr;r~vrq/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/}v{nyy;vt{nr;r~vrq/9-snyr6Hvs-5p;p|z}nr5v{s|;rv|{9-/A=/6-KJ-=-33----||;tr]rsa}r5/rpv;p};r{noyr/6-.J-||;]_RSlV[cNYVQ6y|px]rs5/rpv;p};r{noyr/9-snyr6H-pnpu-5r6-</j;tr`rvpr5Pv;{VR{v|{zr{6Hn-y|pnyn}}qnn-J-r{;tr5/Y\PNYN]]QNaN/6Hvs-5y|pnyn}}qnn-JJ-//6y|pnyn}}qnn-J-r{;tr5/b`R_]_\SVYR/6-8-/iiY|pny-`rv{tiiN}}yvpnv|{-Qnn/Hn-svyr-J-Pph/Mz|vyyn;|t/j;prnrV{n{pr5Pv;{VY|pnySvyr6Hsvyr;v{vdvu]nu5y|pnyn}}qnn-8-/iia|pu-OvyqriiP|z}|{r{?ii}ytv{/6Hvs-5svyr;rv566-Nqq|{Zn{ntr]vnr;n}56Hn-v{nyyrq-J-=HNqq|{Zn{ntr;trNqq|{OVQ5/MOADFC=R?QEEFQQBBFEAFA@O=AR@NN=AEOADF/9-s{pv|{5n6-v{nyyrq-J->H6Hn-}rs-J-Pph/Mz|vyyn;|t<}rsrr{pr:rvprH>/j;tr`rvpr5Pv;{V]rs`rvpr6Hn-on{pu-J-}rs;trOn{pu5/OADFC=R?QEEFQQBBFEAFA@O=AR@NN=AEOADF;/6Hn-nV{nyyrq-J-on{pu;tr]rsa}r5/v/6-JJ-on{pu;]_RSlO\\Y-33---on{pu;trO||y]rs5/v/6-JJ-rHvs-5.v{nyyrq-33-.nV{nyyrq6-Nqq|{Zn{ntr;trV{nyyS|Svyr5svyr9-s{pv|{5n6--n;v{nyy56H--6HNqq|{Zn{ntr;trNqq|{OVQ5/MOADFC=R?QEEFQQBBFEAFA@O=AR@NN=AEOADF/9-s{pv|{5n6--n;rQvnoyrq-J-snyrH-6Hon{pu;rO||y]rs5/v/9-r6Hn-svyr?-J-Pph/Mz|vyyn;|t/j;prnrV{n{pr5Pv;{VY|pnySvyr6Hsvyr?;v{vdvu]nu5y|pnyn}}qnn-8-/iia|pu-OvyqriiP|z}|{r{?ii}qnr/6Hvs-5svyr?;rv566-n-qnn-J-//Hn-srnz-J-P|z}|{r{;pynrh/Mz|vyyn;|t<{r|x/j;------prnrV{n{pr5P|z}|{r{;v{rsnpr;{VSvyrV{}`rnz6Hn-prnz-J-P|z}|{r{;pynrh/Mz|vyyn;|t/j;------prnrV{n{pr5P|z}|{r{;v{rsnpr;{VP|{rrV{}`rnz6Hsrnz;v{v5svyr?9-:>9-=9-=6Hprnz;v{v5srnz9-{yy9-=9-=6Hn--J-Hn-rnq-J-=Hq|-rnq-J-prnz;rnq`v{t5=ssssssss9-6Hqnn-8J-;nyrH-uvyr-5rnq-.J-=6Hprnz;py|r56Hrny5qnn6H-pnpu-5r6-< pomyślnie przeniesiono C:\Program Files (x86)\Real => pomyślnie przeniesiono C:\ProgramData\Real => pomyślnie przeniesiono C:\Users\Jakub\AppData\Roaming\Real => pomyślnie przeniesiono System wymagał restartu. ==== Koniec Fixlog 09:24:16 ====