Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:17-12-2015 Uruchomiony przez Admin (2015-12-19 11:10:28) Run:1 Uruchomiony z C:\Users\Admin\Downloads Załadowane profile: UpdatusUser & Admin (Dostępne profile: UpdatusUser & Admin) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} HKU\S-1-5-21-305616459-1921965142-1483707717-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B HKU\S-1-5-21-305616459-1921965142-1483707717-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} SearchScopes: HKLM -> {89C89667-0D1F-4550-93BE-E0933A3BF058} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} SearchScopes: HKLM-x32 -> {545586A8-C5C1-48F8-91A4-5C73A645BBBD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-305616459-1921965142-1483707717-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} SearchScopes: HKU\S-1-5-21-305616459-1921965142-1483707717-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1450115549&z=21e223b3f0c97db3c281da1g7zccaefozzjcktmlma&from=wpm07173&uid=TOSHIBAXMK5065GSXN_Y0QUB1P5BXXY0QUB1P5B&q={searchTerms} SearchScopes: HKU\S-1-5-21-305616459-1921965142-1483707717-1001 -> {545586A8-C5C1-48F8-91A4-5C73A645BBBD} URL = SearchScopes: HKU\S-1-5-21-305616459-1921965142-1483707717-1001 -> {89C89667-0D1F-4550-93BE-E0933A3BF058} URL = BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL => Brak pliku FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\juy03p7e.default\extensions\defsearchp@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\juy03p7e.default\extensions\deskCutv2@gmail.com => nie znaleziono FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\juy03p7e.default\extensions\default_newtabff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\juy03p7e.default\extensions\yahooprotected@gmail.com HKLM\...\Run: [] => [X] HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-305616459-1921965142-1483707717-1000\...\Run: [] => [X] HKU\S-1-5-21-305616459-1921965142-1483707717-1000\...\RunOnce: [SysOff] => C:\Windows\SysWOW64\SYSPREP\ClosespV.exe HKU\S-1-5-21-305616459-1921965142-1483707717-1001\...\MountPoints2: {426a0e75-8601-11e5-884f-1c75087ab056} - E:\Startme.exe Task: {4EC95CF8-E4D6-48CA-BD30-7CB4C8C0AF66} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-08] (Lenovo) R2 HPSLPSVC; C:\Users\Admin\AppData\Local\Temp\7zS59C6\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [Brak podpisu cyfrowego] FirewallRules: [{8582E9FA-300A-4267-A93A-82632A5D6853}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zS59C6\hppiw.exe FirewallRules: [{BAC43470-0FFB-40DB-9ED8-5AD28FF1B060}] => (Allow) C:\Users\Admin\AppData\Local\Temp\7zS59C6\hppiw.exe Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo DeleteKey: HKLM\SOFTWARE\Wow6432Node\yoursites123Software RemoveDirectory: C:\Program Files (x86)\Lenovo RemoveDirectory: C:\ProgramData\JWMiniProJ RemoveDirectory: C:\Users\Admin\AppData\Local\Lenovo RemoveDirectory: C:\Windows\System32\Tasks\Lenovo C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Toshiba\Rejestracja gwarancji firmy Toshiba.lnk C:\Users\Admin\Documents\pliki\żeczy z pólpitó\Pliki instalacyjne Norton.lnk C:\Users\Admin\Documents\żeczy z pólpitó\Pliki instalacyjne Norton.lnk EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Skrót - argument pomyślnie przywrócono C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Public\Desktop\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Public\Desktop\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-305616459-1921965142-1483707717-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-305616459-1921965142-1483707717-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyślnie usunięto HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{89C89667-0D1F-4550-93BE-E0933A3BF058}" => klucz pomyślnie usunięto HKCR\CLSID\{89C89667-0D1F-4550-93BE-E0933A3BF058} => klucz nie znaleziono. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{545586A8-C5C1-48F8-91A4-5C73A645BBBD}" => klucz pomyślnie usunięto HKCR\Wow6432Node\CLSID\{545586A8-C5C1-48F8-91A4-5C73A645BBBD} => klucz nie znaleziono. HKU\S-1-5-21-305616459-1921965142-1483707717-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-21-305616459-1921965142-1483707717-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => klucz pomyślnie usunięto HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => klucz nie znaleziono. "HKU\S-1-5-21-305616459-1921965142-1483707717-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{545586A8-C5C1-48F8-91A4-5C73A645BBBD}" => klucz pomyślnie usunięto HKCR\CLSID\{545586A8-C5C1-48F8-91A4-5C73A645BBBD} => klucz nie znaleziono. "HKU\S-1-5-21-305616459-1921965142-1483707717-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{89C89667-0D1F-4550-93BE-E0933A3BF058}" => klucz pomyślnie usunięto HKCR\CLSID\{89C89667-0D1F-4550-93BE-E0933A3BF058} => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}" => klucz pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\defsearchp@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\deskCutv2@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\default_newtabff@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\yahooprotected@gmail.com => Wartość pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Wartość pomyślnie usunięto HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Wartość pomyślnie usunięto HKU\S-1-5-21-305616459-1921965142-1483707717-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => Wartość nie znaleziono. HKU\S-1-5-21-305616459-1921965142-1483707717-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SysOff => Wartość nie znaleziono. "HKU\S-1-5-21-305616459-1921965142-1483707717-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{426a0e75-8601-11e5-884f-1c75087ab056}" => klucz pomyślnie usunięto HKCR\CLSID\{426a0e75-8601-11e5-884f-1c75087ab056} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4EC95CF8-E4D6-48CA-BD30-7CB4C8C0AF66}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4EC95CF8-E4D6-48CA-BD30-7CB4C8C0AF66}" => klucz pomyślnie usunięto C:\windows\System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\Lenovo Customer Feedback Program 64" => klucz pomyślnie usunięto HPSLPSVC => Usługa pomyślnie zatrzymana. HPSLPSVC => serwis pomyślnie usunięto HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8582E9FA-300A-4267-A93A-82632A5D6853} => Wartość pomyślnie usunięto HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BAC43470-0FFB-40DB-9ED8-5AD28FF1B060} => Wartość pomyślnie usunięto ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz nie znaleziono. HKCU\Software\dobreprogramy => klucz nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\yoursites123Software => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\yoursites123Software => klucz pomyślnie usunięto "C:\Program Files (x86)\Lenovo" => pomyślnie usunięto. "C:\ProgramData\JWMiniProJ" => pomyślnie usunięto. "C:\Users\Admin\AppData\Local\Lenovo" => pomyślnie usunięto. "C:\Windows\System32\Tasks\Lenovo" => pomyślnie usunięto. C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Toshiba\Rejestracja gwarancji firmy Toshiba.lnk => pomyślnie przeniesiono C:\Users\Admin\Documents\pliki\żeczy z pólpitó\Pliki instalacyjne Norton.lnk => pomyślnie przeniesiono C:\Users\Admin\Documents\żeczy z pólpitó\Pliki instalacyjne Norton.lnk => pomyślnie przeniesiono EmptyTemp: => 2 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 11:12:58 ====