Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:13-12-2015 Uruchomiony przez Zajcu (2015-12-15 21:42:00) Run:1 Uruchomiony z C:\Users\Zajcu\Downloads Załadowane profile: Zajcu (Dostępne profile: Zajcu) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: R2 IhPul; C:\Users\Zajcu\AppData\Roaming\TSv\TSvr.exe [580752 2015-12-08] (tsvr.com) R2 SSFK; C:\Program Files (x86)\SFK\SSFK.exe [170144 2015-11-27] (TODO: ) R2 WdMan; C:\ProgramData\OWdMO\WdMan.exe [333312 2015-12-04] (TFuns LIMITED) [Brak podpisu cyfrowego] R1 wfdrvr_vw_1_10_0_28; C:\Windows\System32\drivers\wfdrvr_vw_1_10_0_28.sys [57712 2015-10-30] (WF) ShortcutWithArgument: C:\Users\Zajcu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 <==== UWAGA ShortcutWithArgument: C:\Users\Zajcu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 <==== UWAGA ShortcutWithArgument: C:\Users\Zajcu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 <==== UWAGA ShortcutWithArgument: C:\Users\Zajcu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 <==== UWAGA ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 <==== UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://www.bing.com/search?q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} SearchScopes: HKU\S-1-5-21-108792187-3970147066-2546186400-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} SearchScopes: HKU\S-1-5-21-108792187-3970147066-2546186400-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872&q={searchTerms} SearchScopes: HKU\S-1-5-21-108792187-3970147066-2546186400-1001 -> {ielnksrch} URL = hxxp://www.bing.com/search?q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1447780180&z=63b9c9c17694e7c63dc0e46g5z2z9memam3t7b8b1g&from=cor&uid=GOODRAMXC40_1C9C074614D500571872 Edge HomeButtonPage: HKU\S-1-5-21-108792187-3970147066-2546186400-1001 -> hxxp://www.yoursites123.com/?type=hp&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Zajcu\AppData\Roaming\Mozilla\Firefox\Profiles\1i2oka09.default\extensions\defsearchp@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Zajcu\AppData\Roaming\Mozilla\Firefox\Profiles\1i2oka09.default\extensions\deskCutv2@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Zajcu\AppData\Roaming\Mozilla\Firefox\Profiles\1i2oka09.default\extensions\default_newtabff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Zajcu\AppData\Roaming\Mozilla\Firefox\Profiles\1i2oka09.default\extensions\yahooprotected@gmail.com StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-08-05] StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.yoursites123.com/?type=sc&ts=1450091433&z=63b01e0c44d89b9902b3448g7zfw3eeedtegfz4c7q&from=wpm07173&uid=GOODRAMXC40_1C9C074614D500571872 Task: {8A4F88D1-F17C-493D-A5FD-594E3E6137D7} - System32\Tasks\WordFly Auto Updater 1.10.0.28 Pending Update => C:\Program Files (x86)\WordFly_1.10.0.28\Update\WordflyAutoUpdateClient.exe <==== UWAGA Task: {A542D929-0022-4BE1-A15A-D3AB31892D6C} - System32\Tasks\WordFly Auto Updater 1.10.0.28 Core => C:\Program Files (x86)\WordFly_1.10.0.28\Update\WordflyAutoUpdateClient.exe <==== UWAGA HKLM-x32\...\Run: [] => [X] Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /v ProtectedHomepages /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /v ProtectedSearchScopes /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\OpenSearch" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.yoursites123.com" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\yoursites123.com" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.yoursites123.com" /f Reg: reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\yoursites123.com" /f DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software RemoveDirectory: C:\Program Files (x86)\SFK RemoveDirectory: C:\Program Files (x86)\WinZipper RemoveDirectory: C:\Program Files (x86)\WordFly_1.10.0.28 RemoveDirectory: C:\ProgramData\BSD RemoveDirectory: C:\ProgramData\gWMiniProg RemoveDirectory: C:\ProgramData\OWdMO RemoveDirectory: C:\ProgramData\TweakBit RemoveDirectory: C:\ProgramData\yWdMy RemoveDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper RemoveDirectory: C:\Users\Zajcu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome RemoveDirectory: C:\Users\Zajcu\AppData\Roaming\istartsurf RemoveDirectory: C:\Users\Zajcu\AppData\Roaming\TSv RemoveDirectory: C:\Users\Zajcu\AppData\Roaming\WinZipper C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\Users\Zajcu\Downloads\Realtek-driver-updater.exe C:\WINDOWS\SysWOW64\data.bin C:\WINDOWS\SysWOW64\pl.html C:\Windows\System32\drivers\wfdrvr_vw_1_10_0_28.sys CMD: netsh advfirewall reset EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. IhPul => serwis pomyślnie usunięto SSFK => serwis pomyślnie usunięto WdMan => serwis pomyślnie usunięto wfdrvr_vw_1_10_0_28 => Nie można zatrzymać usługi. wfdrvr_vw_1_10_0_28 => serwis pomyślnie usunięto C:\Users\Zajcu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Zajcu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Zajcu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Zajcu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => Wartość pomyślnie usunięto HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => Wartość pomyślnie usunięto HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\ielnksrch => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. HKU\S-1-5-21-108792187-3970147066-2546186400-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-21-108792187-3970147066-2546186400-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKU\S-1-5-21-108792187-3970147066-2546186400-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => klucz pomyślnie usunięto HKCR\CLSID\{ielnksrch} => klucz nie znaleziono. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono HKU\S-1-5-21-108792187-3970147066-2546186400-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main\\HomeButtonPage => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\defsearchp@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\deskCutv2@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\default_newtabff@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\yahooprotected@gmail.com => Wartość pomyślnie usunięto HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck" => klucz pomyślnie usunięto Nie można przenieść "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx" => Zaplanowany do przeniesienia przy restarcie. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command\\Default => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8A4F88D1-F17C-493D-A5FD-594E3E6137D7}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A4F88D1-F17C-493D-A5FD-594E3E6137D7}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\WordFly Auto Updater 1.10.0.28 Pending Update => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordFly Auto Updater 1.10.0.28 Pending Update" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A542D929-0022-4BE1-A15A-D3AB31892D6C}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A542D929-0022-4BE1-A15A-D3AB31892D6C}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\WordFly Auto Updater 1.10.0.28 Core => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordFly Auto Updater 1.10.0.28 Core" => klucz pomyślnie usunięto HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wartość pomyślnie usunięto ========= reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /v ProtectedHomepages /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /v ProtectedSearchScopes /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\OpenSearch" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= ========= reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.yoursites123.com" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= ========= reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\yoursites123.com" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= ========= reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.yoursites123.com" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= ========= reg delete "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\yoursites123.com" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= Koniec Reg: ========= HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz pomyślnie usunięto HKCU\Software\dobreprogramy => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\yoursites123Software => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\yoursites123Software => klucz pomyślnie usunięto niepowodzenie przy usuwaniu "C:\Program Files (x86)\SFK\SSFK.exe" => Zaplanowany do usunięcia przy restarcie. niepowodzenie przy usuwaniu "C:\Program Files (x86)\SFK" => Zaplanowany do usunięcia przy restarcie. "C:\Program Files (x86)\WinZipper" => pomyślnie usunięto. "C:\Program Files (x86)\WordFly_1.10.0.28" => nie znaleziono. "C:\ProgramData\BSD" => pomyślnie usunięto. "C:\ProgramData\gWMiniProg" => pomyślnie usunięto. "C:\ProgramData\OWdMO" => pomyślnie usunięto. "C:\ProgramData\TweakBit" => pomyślnie usunięto. "C:\ProgramData\yWdMy" => pomyślnie usunięto. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper" => nie znaleziono. "C:\Users\Zajcu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikacje Chrome" => pomyślnie usunięto. "C:\Users\Zajcu\AppData\Roaming\istartsurf" => pomyślnie usunięto. "C:\Users\Zajcu\AppData\Roaming\TSv" => pomyślnie usunięto. "C:\Users\Zajcu\AppData\Roaming\WinZipper" => pomyślnie usunięto. C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => pomyślnie przeniesiono C:\Users\Zajcu\Downloads\Realtek-driver-updater.exe => pomyślnie przeniesiono C:\WINDOWS\SysWOW64\data.bin => pomyślnie przeniesiono C:\WINDOWS\SysWOW64\pl.html => pomyślnie przeniesiono C:\Windows\System32\drivers\wfdrvr_vw_1_10_0_28.sys => pomyślnie przeniesiono ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= EmptyTemp: => 8.1 GB danych tymczasowych Usunięto. Rezultat przenoszenia plików przy restarcie (Tryb startu: Normal) (Data i godzina: 2015-12-15 21:44:29) "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx" => Nie można przenieść C:\Program Files (x86)\SFK\SSFK.exe => pomyślnie usunięto C:\Program Files (x86)\SFK => pomyślnie usunięto ==== Koniec Fixlog 21:44:29 ====