Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:09-12-2015 Uruchomiony przez Slawomir (2015-12-09 22:59:32) Run:1 Uruchomiony z C:\Users\Slawomir\Downloads ZaÅ‚adowane profile: Slawomir (DostÄ™pne profile: Slawomir) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: R2 IhPul; C:\Users\Slawomir\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: ) R2 WdMan; C:\ProgramData\tWdMt\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] ShortcutWithArgument: C:\Users\Slawomir\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 <==== UWAGA ShortcutWithArgument: C:\Users\Slawomir\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 <==== UWAGA ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 <==== UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} SearchScopes: HKU\S-1-5-21-3747367151-4080275244-1175166767-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} SearchScopes: HKU\S-1-5-21-3747367151-4080275244-1175166767-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9&q={searchTerms} SearchScopes: HKU\S-1-5-21-3747367151-4080275244-1175166767-1001 -> {E8DC851D-7E83-48B0-93E7-5F9290CC82B5} URL = StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1449648227&z=af18cc88cb265af796564d7gez5z2t5qbz4b3o1gfb&from=ient07021&uid=ST500LT012-1DG142_W3PEN0N9XXXXW3PEN0N9 CHR HomePage: Default -> gazeta.allplayer.org/ CHR HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efhdjkbfpoohkmfaldijcpbnmbpefpkb] - C:\Program Files (x86)\ALLPlayer\AllPlayer.crx CHR HKLM-x32\...\Chrome\Extension: [efhdjkbfpoohkmfaldijcpbnmbpefpkb] - C:\Program Files (x86)\ALLPlayer\AllPlayer.crx HKLM\...\Run: [WavesSvc] => "C:\Program Files\Realtek\Audio\HDA\WavesSvc64.exe" Task: {17107572-2329-4D6C-A423-1F0C7F4D8651} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA Task: {23B03DE9-680A-4EAE-A236-0FB22450AFBE} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA Task: {27513359-B4F8-4893-BD58-BD791970C28D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA Task: {2BDF76F6-4028-4838-8B41-29827793E26B} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA Task: {3166B31A-2F69-48A1-AB59-9CE86CAF4C9F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA Task: {4667AD38-9430-4B2A-995F-472D190642F5} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA Task: {9F3D9ABF-F132-4318-BE37-06F5CD1FF18C} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {B150F8DE-12B7-4938-9C4C-9C46F561DBBF} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA Task: {CE74D58A-A2E2-4B5F-880D-89C8A8C0D5CF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA Task: {D3E22CBA-38A4-4030-B39D-8CAC75434F90} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA Task: {DCB07C8E-3643-44D5-9706-FB1B67ACCF8B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA Task: {DE83BA88-6CE7-4028-9278-44427DD98DCD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\SFK C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\ProgramData\{AA6BF06E-316C-487A-9BC2-5F06A43C56B1} C:\ProgramData\gWMiniProg C:\ProgramData\lWdMl C:\ProgramData\tWdMt C:\Users\Slawomir\AppData\Roaming\eCyber C:\Users\Slawomir\AppData\Roaming\istartsurf C:\Users\Slawomir\AppData\Roaming\TSv C:\Users\Slawomir\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Picexa.lnk C:\WINDOWS\SysWOW64\data.bin C:\WINDOWS\SysWOW64\pl.html Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f CMD: type "C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" CMD: type "C:\Windows\System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent" EmptyTemp: ***************** Procesy zostaÅ‚y pomyÅ›lnie zamkniÄ™te. Punkt przywracania zostaÅ‚ pomyÅ›lnie utworzony. IhPul => serwis pomyÅ›lnie usuniÄ™to SSFK => Nie można zatrzymać usÅ‚ugi. SSFK => serwis pomyÅ›lnie usuniÄ™to WdMan => serwis pomyÅ›lnie usuniÄ™to C:\Users\Slawomir\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. C:\Users\Slawomir\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. C:\Users\Public\Desktop\Google Chrome.lnk => Skrót - argument pomyÅ›lnie usuniÄ™to. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie przywrócono "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E8DC851D-7E83-48B0-93E7-5F9290CC82B5}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{E8DC851D-7E83-48B0-93E7-5F9290CC82B5} => klucz nie znaleziono. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wartość pomyÅ›lnie przywrócono Chrome HomePage => pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-3747367151-4080275244-1175166767-1001\SOFTWARE\Google\Chrome\Extensions\efhdjkbfpoohkmfaldijcpbnmbpefpkb" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efhdjkbfpoohkmfaldijcpbnmbpefpkb" => klucz pomyÅ›lnie usuniÄ™to HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\WavesSvc => Wartość pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17107572-2329-4D6C-A423-1F0C7F4D8651}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17107572-2329-4D6C-A423-1F0C7F4D8651}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{23B03DE9-680A-4EAE-A236-0FB22450AFBE}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{23B03DE9-680A-4EAE-A236-0FB22450AFBE}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27513359-B4F8-4893-BD58-BD791970C28D}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27513359-B4F8-4893-BD58-BD791970C28D}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2BDF76F6-4028-4838-8B41-29827793E26B}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2BDF76F6-4028-4838-8B41-29827793E26B}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3166B31A-2F69-48A1-AB59-9CE86CAF4C9F}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3166B31A-2F69-48A1-AB59-9CE86CAF4C9F}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4667AD38-9430-4B2A-995F-472D190642F5}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4667AD38-9430-4B2A-995F-472D190642F5}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F3D9ABF-F132-4318-BE37-06F5CD1FF18C}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F3D9ABF-F132-4318-BE37-06F5CD1FF18C}" => klucz pomyÅ›lnie usuniÄ™to C:\WINDOWS\System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Office\Office 15 Subscription Heartbeat" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B150F8DE-12B7-4938-9C4C-9C46F561DBBF}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B150F8DE-12B7-4938-9C4C-9C46F561DBBF}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE74D58A-A2E2-4B5F-880D-89C8A8C0D5CF}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE74D58A-A2E2-4B5F-880D-89C8A8C0D5CF}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D3E22CBA-38A4-4030-B39D-8CAC75434F90}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3E22CBA-38A4-4030-B39D-8CAC75434F90}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DCB07C8E-3643-44D5-9706-FB1B67ACCF8B}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DCB07C8E-3643-44D5-9706-FB1B67ACCF8B}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE83BA88-6CE7-4028-9278-44427DD98DCD}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE83BA88-6CE7-4028-9278-44427DD98DCD}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => klucz pomyÅ›lnie usuniÄ™to C:\Program Files (x86)\Mozilla Firefox => pomyÅ›lnie przeniesiono C:\Program Files (x86)\SFK => pomyÅ›lnie przeniesiono C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => pomyÅ›lnie przeniesiono C:\ProgramData\{AA6BF06E-316C-487A-9BC2-5F06A43C56B1} => pomyÅ›lnie przeniesiono C:\ProgramData\gWMiniProg => pomyÅ›lnie przeniesiono C:\ProgramData\lWdMl => pomyÅ›lnie przeniesiono C:\ProgramData\tWdMt => pomyÅ›lnie przeniesiono C:\Users\Slawomir\AppData\Roaming\eCyber => pomyÅ›lnie przeniesiono C:\Users\Slawomir\AppData\Roaming\istartsurf => pomyÅ›lnie przeniesiono C:\Users\Slawomir\AppData\Roaming\TSv => pomyÅ›lnie przeniesiono C:\Users\Slawomir\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Picexa.lnk => pomyÅ›lnie przeniesiono C:\WINDOWS\SysWOW64\data.bin => pomyÅ›lnie przeniesiono C:\WINDOWS\SysWOW64\pl.html => pomyÅ›lnie przeniesiono ========= reg delete HKCU\Software\Mozilla /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= type "C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" ========= Odmowa dost©pu. ========= Koniec CMD: ========= ========= type "C:\Windows\System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent" ========= McAfee \McAfee\McAfee Auto Maintenance Task Agent IgnoreNew true true false false false PT10M PT1H true true true true false true false false P1D P2D false true PT72H 7 {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} System LeastPrivilege ========= Koniec CMD: ========= EmptyTemp: => 238.3 MB danych tymczasowych UsuniÄ™to. System wymagaÅ‚ restartu. ==== Koniec Fixlog 23:01:40 ====