Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:14-12-2015 Uruchomiony przez Ola (2015-12-15 13:53:42) Run:1 Uruchomiony z C:\Users\Ola\Desktop\FRST Załadowane profile: Ola (Dostępne profile: Ola) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: R1 {fef7f75c-f985-4250-96f9-8183cd04238b}Gw64; C:\Windows\System32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}Gw64.sys [44696 2014-09-15] (StdLib) R1 {fef7f75c-f985-4250-96f9-8183cd04238b}w64; C:\Windows\System32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}w64.sys [44696 2014-09-16] (StdLib) R2 IhPul; C:\Users\Ola\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: ) R2 WdMan; C:\ProgramData\4WdM4\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] GroupPolicy: Ograniczenia - Chrome <======= UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA ShortcutWithArgument: C:\Users\Ola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 <==== UWAGA ShortcutWithArgument: C:\Users\Ola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.omniboxes.com/?type=sc&ts=1448348101&z=523b69bf34d70293944c0e1g0zfzbbcc3zbb9gegee&from=ient07031&uid=KINGSTONXSV300S37A120G_50026B72410DB662 <==== UWAGA ShortcutWithArgument: C:\Users\Ola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.omniboxes.com/?type=sc&ts=1448348101&z=523b69bf34d70293944c0e1g0zfzbbcc3zbb9gegee&from=ient07031&uid=KINGSTONXSV300S37A120G_50026B72410DB662 <==== UWAGA ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.omniboxes.com/?type=sc&ts=1448348101&z=523b69bf34d70293944c0e1g0zfzbbcc3zbb9gegee&from=ient07031&uid=KINGSTONXSV300S37A120G_50026B72410DB662 <==== UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.delta-homes.com/web/?type=ds&ts=1418204911&from=wpm12103&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.delta-homes.com/web/?type=ds&ts=1418204911&from=wpm12103&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1450162454&z=e841f9fab298aba217473aeg1zbwce4gfq9o7zfqco&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450162454&z=e841f9fab298aba217473aeg1zbwce4gfq9o7zfqco&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?type=ds&ts=1418204911&from=wpm12103&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} SearchScopes: HKLM-x32 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\.DEFAULT -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\S-1-5-19 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\S-1-5-19 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\S-1-5-20 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\S-1-5-20 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\S-1-5-21-1119756383-1426237223-1916157764-1001 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\S-1-5-21-1119756383-1426237223-1916157764-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1119756383-1426237223-1916157764-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1119756383-1426237223-1916157764-1001 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://al.redisearch.com/web?type=ds&ts=1433243477&from=zzgbkk123&uid=kingstonxsv300s37a120g_50026b72410db662&z=b8cc37a4e0aba318e44d336g5zec4cco9z2caz5b9m&bst=1&bsv=11019(KB3049563)&q={searchTerms} SearchScopes: HKU\S-1-5-21-1119756383-1426237223-1916157764-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} BHO-x32: Brak nazwy -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> Brak pliku BHO-x32: Middle Rush -> {d00ab4cc-662c-40b6-a85f-d53086f4bb16} -> C:\Program Files (x86)\Middle Rush\Extensions\d00ab4cc-662c-40b6-a85f-d53086f4bb16.dll => Brak pliku StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1450162454&z=e841f9fab298aba217473aeg1zbwce4gfq9o7zfqco&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 FF HKLM-x32\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\ntn0gl8d.default\extensions\detgdp@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [quick_searchff@gmail.com] - C:\Users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\ntn0gl8d.default\extensions\quick_searchff@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [sweetsearch@gmail.com] - C:\Users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\ntn0gl8d.default\extensions\sweetsearch@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\ntn0gl8d.default\extensions\arthurj8283@gmail.com FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\ntn0gl8d.default\extensions\default_newtabff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\ntn0gl8d.default\extensions\yahooprotected@gmail.com StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1450162454&z=e841f9fab298aba217473aeg1zbwce4gfq9o7zfqco&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 CHR HomePage: Default -> hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 CHR StartupUrls: Default -> "hxxp://www.yoursites123.com/?type=hp&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662" CHR DefaultSearchURL: Default -> hxxp://www.yoursites123.com/web/?type=ds&ts=1449816669&z=f062091e8a0e939293eba04g0z0z5tdb8g6qcq4q7t&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662&q={searchTerms} CHR DefaultSearchKeyword: Default -> yoursites123 CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-05-22] StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1450162454&z=e841f9fab298aba217473aeg1zbwce4gfq9o7zfqco&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.yoursites123.com/?type=sc&ts=1450162454&z=e841f9fab298aba217473aeg1zbwce4gfq9o7zfqco&from=ient07021&uid=KINGSTONXSV300S37A120G_50026B72410DB662 Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] BootExecute: autocheck autochk * sdnclean64.exe CustomCLSID: HKU\S-1-5-21-1119756383-1426237223-1916157764-1001_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\AutoCAD Architecture 2010\acad.exe /Automation => Brak pliku CustomCLSID: HKU\S-1-5-21-1119756383-1426237223-1916157764-1001_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\AutoCAD Architecture 2010\acad.exe => Brak pliku Task: {2ECAA6AA-0C20-4928-81E0-78DBEEB99F1A} - System32\Tasks\{2CB8BBA1-D0D7-4BF9-A7BA-AC31584F796B} => pcalua.exe -a "C:\Program Files (x86)\Picexa\uninstall.exe" Task: {80EB4C99-1C6A-4534-852D-8B9515F1891B} - \AppCloudUpdater -> Brak pliku <==== UWAGA Task: {BC0744ED-5867-47C1-BB77-3289A93BC70D} - System32\Tasks\{CEB78C73-6D91-4B37-BF78-8A7181E8E962} => pcalua.exe -a D:\AC14-POL32\AC14-POL32.exe -d D:\AC14-POL32 Task: {F62E284D-4228-4FF0-A646-4C972C15A6BF} - System32\Tasks\{E584B8FC-FCCC-4FD8-855D-28AFA126A404} => pcalua.exe -a "C:\Program Files\AutoCAD Architecture 2010\acad.exe" -d "C:\Program Files\AutoCAD Architecture 2010\UserDataCache\" -c /ld "C:\Program Files\AutoCAD Architecture 2010\AecBase.dbx" /p "AutoCAD Architecture (jednostki metryczne)" DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software RemoveDirectory: C:\Program Files (x86)\SFK RemoveDirectory: C:\Program Files (x86)\WinZipper RemoveDirectory: C:\ProgramData\4WdM4 RemoveDirectory: C:\ProgramData\9WMiniPro9 RemoveDirectory: C:\ProgramData\TEMP RemoveDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper RemoveDirectory: C:\Users\Ola\AppData\Roaming\TSv RemoveDirectory: C:\Users\Ola\AppData\Roaming\WinZipper C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\Users\Ola\Downloads\sh-remover.exe C:\Users\Ola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Reader XI.lnk C:\Users\Ola\Desktop\PROGRAMY\Adobe Reader XI.lnk C:\Users\Ola\Desktop\PROGRAMY\AppSafe.lnk C:\Users\Ola\Desktop\PROGRAMY\Picexa.lnk C:\Users\Public\Desktop\Post Win10 Spybot-install.exe C:\Windows\System32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}Gw64.sys C:\Windows\System32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}w64.sys RemoveDirectory: C:\Windows\SysWOW64\pl4.exe RemoveDirectory: C:\Windows\SysWOW64\pl.html CMD: netsh advfirewall reset EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. {fef7f75c-f985-4250-96f9-8183cd04238b}Gw64 => Nie można zatrzymać usługi. {fef7f75c-f985-4250-96f9-8183cd04238b}Gw64 => serwis pomyślnie usunięto {fef7f75c-f985-4250-96f9-8183cd04238b}w64 => Nie można zatrzymać usługi. {fef7f75c-f985-4250-96f9-8183cd04238b}w64 => serwis pomyślnie usunięto IhPul => serwis pomyślnie usunięto SSFK => Nie można zatrzymać usługi. SSFK => serwis pomyślnie usunięto WdMan => serwis pomyślnie usunięto C:\Windows\system32\GroupPolicy\Machine => pomyślnie przeniesiono C:\Windows\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono "HKLM\SOFTWARE\Policies\Google" => klucz pomyślnie usunięto C:\Users\Ola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Ola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Ola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Public\Desktop\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => klucz nie znaleziono. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => klucz pomyślnie usunięto HKCR\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => klucz nie znaleziono. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => klucz pomyślnie usunięto HKCR\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => klucz nie znaleziono. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => klucz pomyślnie usunięto HKCR\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => klucz nie znaleziono. HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyślnie usunięto HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => klucz pomyślnie usunięto HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => klucz nie znaleziono. "HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => klucz pomyślnie usunięto HKCR\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => klucz nie znaleziono. "HKU\S-1-5-21-1119756383-1426237223-1916157764-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => klucz pomyślnie usunięto HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d00ab4cc-662c-40b6-a85f-d53086f4bb16}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{d00ab4cc-662c-40b6-a85f-d53086f4bb16}" => klucz pomyślnie usunięto HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\detgdp@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\quick_searchff@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\sweetsearch@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\arthurj8283@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\default_newtabff@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\yahooprotected@gmail.com => Wartość pomyślnie usunięto HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono Chrome HomePage => pomyślnie usunięto Chrome StartupUrls => pomyślnie usunięto Chrome DefaultSearchURL => pomyślnie usunięto Chrome DefaultSearchKeyword => pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck" => klucz pomyślnie usunięto Nie można przenieść "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx" => Zaplanowany do przeniesienia przy restarcie. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon => klucz nie znaleziono. hklm\System\CurrentControlSet\Control\Session Manager\\BootExecute => Wartość pomyślnie przywrócono "HKU\S-1-5-21-1119756383-1426237223-1916157764-1001_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}" => klucz pomyślnie usunięto "HKU\S-1-5-21-1119756383-1426237223-1916157764-1001_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2ECAA6AA-0C20-4928-81E0-78DBEEB99F1A}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2ECAA6AA-0C20-4928-81E0-78DBEEB99F1A}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{2CB8BBA1-D0D7-4BF9-A7BA-AC31584F796B} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2CB8BBA1-D0D7-4BF9-A7BA-AC31584F796B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{80EB4C99-1C6A-4534-852D-8B9515F1891B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80EB4C99-1C6A-4534-852D-8B9515F1891B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AppCloudUpdater" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC0744ED-5867-47C1-BB77-3289A93BC70D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC0744ED-5867-47C1-BB77-3289A93BC70D}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{CEB78C73-6D91-4B37-BF78-8A7181E8E962} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CEB78C73-6D91-4B37-BF78-8A7181E8E962}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F62E284D-4228-4FF0-A646-4C972C15A6BF}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F62E284D-4228-4FF0-A646-4C972C15A6BF}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{E584B8FC-FCCC-4FD8-855D-28AFA126A404} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E584B8FC-FCCC-4FD8-855D-28AFA126A404}" => klucz pomyślnie usunięto HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz pomyślnie usunięto HKCU\Software\dobreprogramy => klucz pomyślnie usunięto HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\yoursites123Software => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\yoursites123Software => klucz pomyślnie usunięto niepowodzenie przy usuwaniu "C:\Program Files (x86)\SFK\SSFK.exe" => Zaplanowany do usunięcia przy restarcie. niepowodzenie przy usuwaniu "C:\Program Files (x86)\SFK" => Zaplanowany do usunięcia przy restarcie. "C:\Program Files (x86)\WinZipper" => pomyślnie usunięto. "C:\ProgramData\4WdM4" => pomyślnie usunięto. "C:\ProgramData\9WMiniPro9" => pomyślnie usunięto. "C:\ProgramData\TEMP" => pomyślnie usunięto. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper" => nie znaleziono. "C:\Users\Ola\AppData\Roaming\TSv" => pomyślnie usunięto. "C:\Users\Ola\AppData\Roaming\WinZipper" => nie znaleziono. C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => pomyślnie przeniesiono C:\Users\Ola\Downloads\sh-remover.exe => pomyślnie przeniesiono C:\Users\Ola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Reader XI.lnk => pomyślnie przeniesiono C:\Users\Ola\Desktop\PROGRAMY\Adobe Reader XI.lnk => pomyślnie przeniesiono C:\Users\Ola\Desktop\PROGRAMY\AppSafe.lnk => pomyślnie przeniesiono C:\Users\Ola\Desktop\PROGRAMY\Picexa.lnk => pomyślnie przeniesiono C:\Users\Public\Desktop\Post Win10 Spybot-install.exe => pomyślnie przeniesiono C:\Windows\System32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}Gw64.sys => pomyślnie przeniesiono C:\Windows\System32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}w64.sys => pomyślnie przeniesiono "C:\Windows\SysWOW64\pl4.exe" => Plik "C:\Windows\SysWOW64\pl.html" => Plik ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= EmptyTemp: => 715.5 MB danych tymczasowych Usunięto. Rezultat przenoszenia plików przy restarcie (Tryb startu: Normal) (Data i godzina: 2015-12-15 13:55:08) "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx" => Nie można przenieść C:\Program Files (x86)\SFK\SSFK.exe => pomyślnie usunięto C:\Program Files (x86)\SFK => pomyślnie usunięto ==== Koniec Fixlog 13:55:08 ====