Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:09-12-2015 Uruchomiony przez Zuzanna (2015-12-09 17:17:06) Run:1 Uruchomiony z C:\Users\Zuzanna\Downloads Załadowane profile: Zuzanna (Dostępne profile: Zuzanna) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: R2 IhPul; C:\Users\Zuzanna\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: ) R2 WdMan; C:\ProgramData\tWdMt\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] S1 wfdrvr_vw_1_10_0_28; system32\drivers\wfdrvr_vw_1_10_0_28.sys [X] ShortcutWithArgument: C:\Users\Zuzanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 <==== UWAGA ShortcutWithArgument: C:\Users\Zuzanna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 <==== UWAGA ShortcutWithArgument: C:\Users\Zuzanna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 <==== UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1447961168&z=acdbe4dd161e92fa45b4404g2z9z0mctbqbe9b3w3b&from=cor&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1449659058&z=3df4eaf379b008bea0941c0g0z4z3t5q9w1tdebw5w&from=ient07021&uid=KINGSTONXSV300S37A240G_50026B775708A5F4 FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Zuzanna\AppData\Roaming\Mozilla\Firefox\Profiles\bnqkxdrh.default\extensions\defsearchp@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Zuzanna\AppData\Roaming\Mozilla\Firefox\Profiles\bnqkxdrh.default\extensions\deskCutv2@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Zuzanna\AppData\Roaming\Mozilla\Firefox\Profiles\bnqkxdrh.default\extensions\default_newtabff@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Zuzanna\AppData\Roaming\Mozilla\Firefox\Profiles\bnqkxdrh.default\extensions\yahooprotected@gmail.com => nie znaleziono HKU\S-1-5-21-1379735399-1450969573-2400207767-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1379735399-1450969573-2400207767-1001\...\Policies\Explorer: [] CustomCLSID: HKU\S-1-5-21-1379735399-1450969573-2400207767-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2015\Inventor Server\Bin\TestServer.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1379735399-1450969573-2400207767-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2015\Inventor Server\Bin\TestServer.dll => Brak pliku CustomCLSID: HKU\S-1-5-21-1379735399-1450969573-2400207767-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2015\Inventor Server\Bin\TestServer.dll => Brak pliku Task: {7D687F2C-6642-40D5-9306-704222F4CF50} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe C:\Program Files (x86)\SFK C:\Program Files (x86)\WordFly_1.10.0.28 C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\ProgramData\9WMiniPro9 C:\ProgramData\Pokki C:\ProgramData\tWdMt C:\ProgramData\vWdMv C:\Users\Zuzanna\AppData\Local\SweetLabs App Platform C:\Users\Zuzanna\AppData\Roaming\TSv C:\Users\Zuzanna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Picexa.lnk Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla\Thunderbird /f EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. IhPul => serwis pomyślnie usunięto SSFK => Nie można zatrzymać usługi. SSFK => serwis pomyślnie usunięto WdMan => serwis pomyślnie usunięto wfdrvr_vw_1_10_0_28 => serwis pomyślnie usunięto C:\Users\Zuzanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Zuzanna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Zuzanna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyślnie usunięto HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\defsearchp@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\deskCutv2@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\default_newtabff@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\yahooprotected@gmail.com => Wartość pomyślnie usunięto HKU\S-1-5-21-1379735399-1450969573-2400207767-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Wartość pomyślnie usunięto HKU\S-1-5-21-1379735399-1450969573-2400207767-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Wartość pomyślnie usunięto "HKU\S-1-5-21-1379735399-1450969573-2400207767-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}" => klucz pomyślnie usunięto "HKU\S-1-5-21-1379735399-1450969573-2400207767-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}" => klucz pomyślnie usunięto "HKU\S-1-5-21-1379735399-1450969573-2400207767-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7D687F2C-6642-40D5-9306-704222F4CF50}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D687F2C-6642-40D5-9306-704222F4CF50}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\DolbySelectorTask => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DolbySelectorTask" => klucz pomyślnie usunięto C:\Program Files (x86)\SFK => pomyślnie przeniesiono C:\Program Files (x86)\WordFly_1.10.0.28 => pomyślnie przeniesiono C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => pomyślnie przeniesiono C:\ProgramData\9WMiniPro9 => pomyślnie przeniesiono "C:\ProgramData\Pokki" => nie znaleziono. C:\ProgramData\tWdMt => pomyślnie przeniesiono C:\ProgramData\vWdMv => pomyślnie przeniesiono "C:\Users\Zuzanna\AppData\Local\SweetLabs App Platform" => nie znaleziono. C:\Users\Zuzanna\AppData\Roaming\TSv => pomyślnie przeniesiono C:\Users\Zuzanna\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Picexa.lnk => pomyślnie przeniesiono ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla\Thunderbird /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= EmptyTemp: => 299.2 MB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 17:17:26 ====