Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:09-01-2015 Uruchomiony przez Łukasz (2016-02-10 19:29:12) Run:2 Uruchomiony z C:\Users\Łukasz\Downloads Załadowane profile: Łukasz (Dostępne profile: Łukasz) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: Task: {20519E68-28A8-4A03-9CE2-2A38254549B3} - System32\Tasks\Chromium => C:\Users\UKASZ~1\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE Task: {2113A336-37FF-4CC3-84B0-B3DF09415BB2} - System32\Tasks\Folding@HomeStatsUpload => C:\Folding@HomeCPU\FAHStatsUploader.exe [2009-06-08] () Task: {3C8AD0B7-AE90-49BB-95FA-360472757917} - System32\Tasks\{AB3DC6E0-374D-45D6-8FC2-74BEB7F4D1A3} => pcalua.exe -a C:\Users\Łukasz\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=adks <==== UWAGA Task: {C675EC1D-EC18-4DA4-9DCB-72210696C1EB} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-12-17] (AVAST Software) Task: {F8C053F2-2DA8-41E3-AB84-115F7D0FF40D} - System32\Tasks\ConcussingSeasonerV2 => Rundll32.exe SoullessnessPin.dll,main 7 1 <==== UWAGA Task: C:\Windows\Tasks\Chromium.job => C:\Users\UKASZ~1\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Brak pliku HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-2466319396-4157294396-1527453628-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_15_38_orgnl¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dpl%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0BzytDyByB0EtByE0DtDyDtN0D0Tzu0StCtAyDtBtN1L2XzutAtFtCtAtFtAtFtCtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2S0ByB0AtB0EyEzztAtGtC0AzzyCtGyEyB0CtBtGzyyBtCtBtG0D0B0D0E0C0C0CyEzyyD0F0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtBzy0F0F0FtBtDtGtAtBzyzztGyEtA0D0AtGzz0D0A0BtG0A0DyEtB0CyCyByEyDyBtD0C2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzyzztB%26cr%3D627881398%26a%3Dhdr_s_15_38_orgnl%26os%3DWindows%2B8.1 SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_dnldastr_15_26¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0BzytDyByB0EtByE0DtDyDtN0D0Tzu0StCtByBtDtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StCtDyCtB0FzztA0EtGtAyDtDyEtG0AyBtB0AtGyEtByCzytGtB0D0ByCtB0DyDzzyEtDzytA2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0FyB0BtDtBtDtBtGyB0AyDtDtGyEzy0AtDtGzy0E0AyEtGtCyDyDyEzyzztAyDtA0FyE0C2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzztDtD%26cr%3D865094644%26a%3Dwncy_dnldastr_15_26%26os%3DWindows 8.1&p={searchTerms} SearchScopes: HKLM -> {6E82A80A-AE16-45B4-86AA-6C82E9516F5E} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_15_38_orgnl¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0BzytDyByB0EtByE0DtDyDtN0D0Tzu0StCtAyDtBtN1L2XzutAtFtCtAtFtAtFtCtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2S0ByB0AtB0EyEzztAtGtC0AzzyCtGyEyB0CtBtGzyyBtCtBtG0D0B0D0E0C0C0CyEzyyD0F0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtBzy0F0F0FtBtDtGtAtBzyzztGyEtA0D0AtGzz0D0A0BtG0A0DyEtB0CyCyByEyDyBtD0C2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzyzztB%26cr%3D627881398%26a%3Dhdr_s_15_38_orgnl%26os%3DWindows%2B8.1&p={searchTerms} SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_24¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0BzytDyByB0EtByE0DtDyDtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyByB0C0BzztDzyyCtGyCzyyDyDtGtCtCzztBtGtDyD0DyDtGtC0AtC0EyEtAzyyDtA0Czyzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0AtC0CyDtC0EzytAtGzz0EzztAtGyEtAtD0DtG0AyEyEyDtG0AtDyD0FyD0BtByEyEtA0AtC2QtN0A0LzuyE%26cr%3D1539620490%26a%3Dwny_ir_15_24%26os%3DWindows 8.1&p={searchTerms} SearchScopes: HKU\S-1-5-21-2466319396-4157294396-1527453628-1001 -> DefaultScope {6E82A80A-AE16-45B4-86AA-6C82E9516F5E} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_15_38_orgnl¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0BzytDyByB0EtByE0DtDyDtN0D0Tzu0StCtAyDtBtN1L2XzutAtFtCtAtFtAtFtCtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2S0ByB0AtB0EyEzztAtGtC0AzzyCtGyEyB0CtBtGzyyBtCtBtG0D0B0D0E0C0C0CyEzyyD0F0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtBzy0F0F0FtBtDtGtAtBzyzztGyEtA0D0AtGzz0D0A0BtG0A0DyEtB0CyCyByEyDyBtD0C2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzyzztB%26cr%3D627881398%26a%3Dhdr_s_15_38_orgnl%26os%3DWindows%2B8.1&p={searchTerms} SearchScopes: HKU\S-1-5-21-2466319396-4157294396-1527453628-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-2466319396-4157294396-1527453628-1001 -> {6E82A80A-AE16-45B4-86AA-6C82E9516F5E} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_15_38_orgnl¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dpl%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0BzytDyByB0EtByE0DtDyDtN0D0Tzu0StCtAyDtBtN1L2XzutAtFtCtAtFtAtFtCtN1L1Czu1M1Q1CtCyDtN1L1G1B1V1N2Y1L1Qzu2S0ByB0AtB0EyEzztAtGtC0AzzyCtGyEyB0CtBtGzyyBtCtBtG0D0B0D0E0C0C0CyEzyyD0F0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtBzy0F0F0FtBtDtGtAtBzyzztGyEtA0D0AtGzz0D0A0BtG0A0DyEtB0CyCyByEyDyBtD0C2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzyzztB%26cr%3D627881398%26a%3Dhdr_s_15_38_orgnl%26os%3DWindows%2B8.1&p={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe CHR HKLM\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2466319396-4157294396-1527453628-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx C:\ProgramData\*.log C:\Users\Łukasz\AppData\Local\*.tmp C:\Users\Łukasz\AppData\Roaming\*.* C:\Users\Łukasz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\3c2f5dbd57bb3f49\Chromium.lnk C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\SendTo\??????@Mail.ru.lnk C:\Users\Łukasz\Desktop\DUNE2000 — skrót.lnk C:\Users\Łukasz\Desktop\LOD.lnk C:\Users\Łukasz\Downloads\aspsetup.exe C:\Users\Łukasz\Downloads\sh-remover.exe RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\Folding@HomeCPU RemoveDirectory: C:\Program Files\Common Files\AV\avast! Antivirus RemoveDirectory: C:\ProgramData\AVAST Software RemoveDirectory: C:\ProgramData\Temp RemoveDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games RemoveDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digital Image Recovery RemoveDirectory: C:\Users\Łukasz\AppData\Local\{F9D1CF8D-DD79-A335-B0E1-86DD94897A45} RemoveDirectory: C:\Users\Łukasz\AppData\Local\ConcussingSeasoner RemoveDirectory: C:\Users\Łukasz\AppData\Local\Opera Software RemoveDirectory: C:\Users\Łukasz\AppData\Local\Systweak RemoveDirectory: C:\Users\Łukasz\AppData\Roaming\Opera Software RemoveDirectory: C:\Users\Łukasz\AppData\Roaming\Systweak RemoveDirectory: C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macgo Windows Blu-ray Player RemoveDirectory: C:\Users\Łukasz\Desktop\Stare dane programu Firefox RemoveDirectory: C:\Windows\System32\Tasks\AVAST Software DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes CMD: netsh advfirewall reset EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{20519E68-28A8-4A03-9CE2-2A38254549B3}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20519E68-28A8-4A03-9CE2-2A38254549B3}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\Chromium => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Chromium" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2113A336-37FF-4CC3-84B0-B3DF09415BB2}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2113A336-37FF-4CC3-84B0-B3DF09415BB2}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\Folding@HomeStatsUpload => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Folding@HomeStatsUpload" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C8AD0B7-AE90-49BB-95FA-360472757917}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C8AD0B7-AE90-49BB-95FA-360472757917}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\{AB3DC6E0-374D-45D6-8FC2-74BEB7F4D1A3} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AB3DC6E0-374D-45D6-8FC2-74BEB7F4D1A3}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C675EC1D-EC18-4DA4-9DCB-72210696C1EB}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C675EC1D-EC18-4DA4-9DCB-72210696C1EB}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\AVAST Software\Avast settings backup => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F8C053F2-2DA8-41E3-AB84-115F7D0FF40D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8C053F2-2DA8-41E3-AB84-115F7D0FF40D}" => klucz pomyślnie usunięto C:\Windows\System32\Tasks\ConcussingSeasonerV2 => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConcussingSeasonerV2" => klucz pomyślnie usunięto C:\Windows\Tasks\Chromium.job => pomyślnie przeniesiono MBAMSwissArmy => serwis pomyślnie usunięto "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => klucz pomyślnie usunięto HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => klucz nie znaleziono. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-2466319396-4157294396-1527453628-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}" => klucz pomyślnie usunięto HKCR\CLSID\{2f23ab71-4ac6-41f2-a955-ea576e553146} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6E82A80A-AE16-45B4-86AA-6C82E9516F5E}" => klucz pomyślnie usunięto HKCR\CLSID\{6E82A80A-AE16-45B4-86AA-6C82E9516F5E} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}" => klucz pomyślnie usunięto HKCR\CLSID\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A} => klucz nie znaleziono. HKU\S-1-5-21-2466319396-4157294396-1527453628-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-21-2466319396-4157294396-1527453628-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyślnie usunięto HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKU\S-1-5-21-2466319396-4157294396-1527453628-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6E82A80A-AE16-45B4-86AA-6C82E9516F5E}" => klucz pomyślnie usunięto HKCR\CLSID\{6E82A80A-AE16-45B4-86AA-6C82E9516F5E} => klucz nie znaleziono. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Wartość pomyślnie przywrócono "HKLM\SOFTWARE\Google\Chrome\Extensions\ajcmdlkeklfmbjffnlofgfkjcnpfckab" => klucz pomyślnie usunięto "HKU\S-1-5-21-2466319396-4157294396-1527453628-1001\SOFTWARE\Google\Chrome\Extensions\ajcmdlkeklfmbjffnlofgfkjcnpfckab" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ajcmdlkeklfmbjffnlofgfkjcnpfckab" => klucz pomyślnie usunięto =========== "C:\ProgramData\*.log" ========== C:\ProgramData\Temp.log => pomyślnie przeniesiono C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log => pomyślnie przeniesiono C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log => pomyślnie przeniesiono C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log => pomyślnie przeniesiono C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log => pomyślnie przeniesiono C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log => pomyślnie przeniesiono ========= Koniec -> "C:\ProgramData\*.log" ======== =========== "C:\Users\Łukasz\AppData\Local\*.tmp" ========== C:\Users\Łukasz\AppData\Local\nsd4F96.tmp => pomyślnie przeniesiono C:\Users\Łukasz\AppData\Local\nse9FA.tmp => pomyślnie przeniesiono C:\Users\Łukasz\AppData\Local\nspB5B.tmp => pomyślnie przeniesiono ========= Koniec -> "C:\Users\Łukasz\AppData\Local\*.tmp" ======== =========== "C:\Users\Łukasz\AppData\Roaming\*.*" ========== C:\Users\Łukasz\AppData\Roaming\apachesrvin.vbs => pomyślnie przeniesiono C:\Users\Łukasz\AppData\Roaming\burnaware.ini => pomyślnie przeniesiono C:\Users\Łukasz\AppData\Roaming\die.bat => pomyślnie przeniesiono C:\Users\Łukasz\AppData\Roaming\Setup72494.exe => pomyślnie przeniesiono C:\Users\Łukasz\AppData\Roaming\WB.CFG => pomyślnie przeniesiono ========= Koniec -> "C:\Users\Łukasz\AppData\Roaming\*.*" ======== C:\Users\Łukasz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\3c2f5dbd57bb3f49\Chromium.lnk => pomyślnie przeniesiono =========== "C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\SendTo\??????@Mail.ru.lnk" ========== C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\SendTo\МойМир@Mail.ru.lnk => pomyślnie przeniesiono ========= Koniec -> "C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\SendTo\??????@Mail.ru.lnk" ======== C:\Users\Łukasz\Desktop\DUNE2000 — skrót.lnk => pomyślnie przeniesiono C:\Users\Łukasz\Desktop\LOD.lnk => pomyślnie przeniesiono C:\Users\Łukasz\Downloads\aspsetup.exe => pomyślnie przeniesiono C:\Users\Łukasz\Downloads\sh-remover.exe => pomyślnie przeniesiono "C:\AdwCleaner" => pomyślnie usunięto. "C:\Folding@HomeCPU" => pomyślnie usunięto. "C:\Program Files\Common Files\AV\avast! Antivirus" => pomyślnie usunięto. "C:\ProgramData\AVAST Software" => pomyślnie usunięto. "C:\ProgramData\Temp" => pomyślnie usunięto. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Games" => pomyślnie usunięto. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Digital Image Recovery" => pomyślnie usunięto. "C:\Users\Łukasz\AppData\Local\{F9D1CF8D-DD79-A335-B0E1-86DD94897A45}" => pomyślnie usunięto. "C:\Users\Łukasz\AppData\Local\ConcussingSeasoner" => pomyślnie usunięto. "C:\Users\Łukasz\AppData\Local\Opera Software" => pomyślnie usunięto. "C:\Users\Łukasz\AppData\Local\Systweak" => pomyślnie usunięto. "C:\Users\Łukasz\AppData\Roaming\Opera Software" => pomyślnie usunięto. "C:\Users\Łukasz\AppData\Roaming\Systweak" => pomyślnie usunięto. "C:\Users\Łukasz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macgo Windows Blu-ray Player" => pomyślnie usunięto. "C:\Users\Łukasz\Desktop\Stare dane programu Firefox" => pomyślnie usunięto. "C:\Windows\System32\Tasks\AVAST Software" => pomyślnie usunięto. HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz pomyślnie usunięto HKCU\Software\dobreprogramy => klucz nie znaleziono. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => klucz pomyślnie usunięto HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software => klucz pomyślnie usunięto HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => klucz pomyślnie usunięto HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes => klucz pomyślnie usunięto HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => klucz pomyślnie usunięto ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= EmptyTemp: => 1.7 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 19:30:54 ====