Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:05-03-2016 01 Uruchomiony przez Admin (2016-03-25 19:18:46) Run:1 Uruchomiony z C:\Users\Admin\Desktop\FRST ZaÅ‚adowane profile: Admin (DostÄ™pne profile: Admin) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: AppInit_DLLs-x32: C:\ProgramData\Lightzap\Can-Trax.dll => C:\ProgramData\Lightzap\Can-Trax.dll [320512 2015-11-28] () HKLM-x32\...\Run: [ApnTBMon] => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" HKU\S-1-5-21-2273012611-303174682-3880648035-1000\...\Run: [Gameo] => C:\Users\Admin\AppData\Roaming\Gameo\gameo.exe [42482176 2015-07-04] () Task: {0B42EA5C-ABD5-4288-81D3-F897D7D81160} - System32\Tasks\PC-Mechanic Maintenance => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe [2015-01-28] (Uniblue Systems Limited) Task: {12FB840A-516D-4C0D-815A-6C8DC22C81E0} - System32\Tasks\{FD5AE810-2139-4881-A66B-5A088D55CF93} => pcalua.exe -a C:\Users\Admin\Downloads\clamwin-0.98.7-setup_(www.programki.pl).exe -d C:\Users\Admin\Downloads Task: {2FFB3E57-8D29-4798-BD7D-1E17D2479AF6} - System32\Tasks\DNSKALAMAZOO => dnskalamazoo.exe <==== UWAGA Task: {4B1D622B-DF14-468B-9D62-54CEE03DCFA1} - \new_game_notification_service -> Brak pliku <==== UWAGA Task: {4FBC4ECC-270B-49B1-9A97-CBB7350CA088} - System32\Tasks\PC-Mechanic Subscription => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe [2015-01-28] (Uniblue Systems Limited) Task: {668DE9A9-58CF-49D9-87D1-3AA832C86B09} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== UWAGA Task: {76DD9942-C71D-4EEA-8396-F95DC772354B} - System32\Tasks\PC-Mechanic Startup => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe [2015-01-28] (Uniblue Systems Limited) Task: {8D89ADD1-71FD-4837-BD04-1A76E60C7784} - \Yahoo! Search -> Brak pliku <==== UWAGA Task: {B23C871F-F5E7-4AA5-A699-38867DE8F1F1} - \Yahoo! Search Updater -> Brak pliku <==== UWAGA Task: {E1AFD920-8078-4E2E-9787-73199C554D27} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe [2015-11-10] (Reimage ltd.) <==== UWAGA Task: {F70DFA71-3345-4C4C-A6AF-5D891F007912} - System32\Tasks\godzilla_shopper_helper_service => C:\Program Files (x86)\Godzilla Shopper\godzilla_shopper_helper_service.exe <==== UWAGA Task: {F9B7044B-C3B1-44A1-9357-04FA06BC6629} - \new_game_updating_service -> Brak pliku <==== UWAGA Task: C:\Windows\Tasks\godzilla_shopper_helper_service.job => C:\Program Files (x86)\Godzilla Shopper\godzilla_shopper_helper_service.exe <==== UWAGA Task: C:\Windows\Tasks\new_game_notification_service.job => C:\Program Files (x86)\new game\new_game_notification_service.exeG/url='hxxp:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='new game' /appid='73143' /srcid='2913' /bic='88ab7bbd29a2cfbab6c5a76d39948d0a' /verifier='7ca80c4d88f6116717d8ce6de10fe5d1' /installerversion='1.50.3.10' /statsdomain='hxxp:/stats.buildomserv.com/data.gif?' /errorsdomain='hxxp:/stats.buildomserv.com/data.gif?' /monetizationdomain='hxxp:/logs.buildomserv.com/monetization.gif <==== UWAGA Task: C:\Windows\Tasks\new_game_updating_service.job => C:\Program Files (x86)\new game\new_game_updating_service.exe© /campid=2913 /verid=1 /url=hxxp:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=new_game_updating_service /funurl=hxxp:/stats.buildomserv.com <==== UWAGA Task: C:\Windows\Tasks\PC-Mechanic Maintenance.job => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe Task: C:\Windows\Tasks\PC-Mechanic Startup.job => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe Task: C:\Windows\Tasks\PC-Mechanic Subscription.job => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe S2 APNMCP; "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe" [X] S3 cpuz134; \??\C:\Users\Admin\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] GroupPolicy: Ograniczenia - Chrome <======= UWAGA CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA CHR HomePage: Default -> hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSWwKIf0jRaXmSECqDhR3_S1HL-G6B4HLUqwfsieeCNTR8ViWaXyESVMiRUfb8mL2cpRp5O5qg8vlTQdLi_A3QTnwr-weV-7NQ1WfXyTG4A9mM6kYat6TtObboPPlCaGzpcFdSFLApx9g,, CHR StartupUrls: Default -> "hxxp://www.mysites123.com/?type=hp&ts=1452530008&z=acb9cad27bc97f5eb3a77b4g2z9w4o5w3c1e1e9e3b&from=amt&uid=st500dm002-1bd142_z2ayqqqaxxxxz2ayqqqa" CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSWwKIf0jRaXmSECqDhR3_S1HL-G6B4HLUqwfsieeCNTR8ViWaXyESVMiRUfb8mL2clMAWWuX5ai2bPJrmO66GgwCD0zh8Cv7RUsoXahXwxg-B9Iluz7tocuIg2Efej23IELNIlpnjfKA,,&q={searchTerms} CHR DefaultSearchKeyword: Default -> feed.sonic-search.com CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.interia.pl/#utm_source=instalki&utm_medium=installer&utm_campaign=instalki HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avast.com/AV772/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avast.com/AV772/search/web?q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avast.com/AV772/search/web?q={searchTerms} HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avast.com/AV772/ HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://search.avast.com/AV772/ HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSWwKIf0jRaXmSECqDhR3_S1HL-G6B4HLUqwfsieeCNTR8ViWaXyESVMiRUfb8mL2cydYP5POUdtvJZy4Mypu8uKOyVX_rKWf6I6_uYCcBfXeUJHJYi8n12wDOvBGI3a6PF04rFadAPzg,,&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms} SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSWwKIf0jRaXmSECqDhR3_S1HL-G6B4HLUqwfsieeCNTR8ViWaXyESVMiRUfb8mL2cydYP5POUdtvJZy4Mypu8uKOyVX_rKWf6I6_uYCcBfXeUJHJYi8n12wDOvBGI3a6PF04rFadAPzg,,&q={searchTerms} SearchScopes: HKLM-x32 -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms} SearchScopes: HKU\S-1-5-21-2273012611-303174682-3880648035-1000 -> DefaultScope {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms} SearchScopes: HKU\S-1-5-21-2273012611-303174682-3880648035-1000 -> D735241F7F874887B9EF63F4A7F61B79 URL = hxxp://www.bing.com/search?FORM=U218DF&PC=U218&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2273012611-303174682-3880648035-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://q.search-simple.com/?affID=pr_01ad000c-f598-40c5-9bfd-2bc7e87ec7be&q={searchTerms} SearchScopes: HKU\S-1-5-21-2273012611-303174682-3880648035-1000 -> {8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} URL = hxxps://search.avast.com/AV772/search/web?q={searchTerms} SearchScopes: HKU\S-1-5-21-2273012611-303174682-3880648035-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBPxn49PYmQ6e1krQXBFZY3csSWwKIf0jRaXmSECqDhR3_S1HL-G6B4HLUqwfsieeCNTR8ViWaXyESVMiRUfb8mL2cydYP5POUdtvJZy4Mypu8uKOyVX_rKWf6I6_uYCcBfXeUJHJYi8n12wDOvBGI3a6PF04rFadAPzg,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2273012611-303174682-3880648035-1000 -> {szukaj.gazeta.pl} URL = hxxp://szukaj.gazeta.pl/internet/0,0.html?slowo={searchTerms} FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF C:\Program Files\Essentware C:\Program Files\Reimage C:\Program Files\Symantec C:\Program Files\Common Files\Symantec Shared C:\Program Files (x86)\DNS Unlocker C:\Program Files (x86)\Godzilla Shopper C:\Program Files (x86)\Mozilla Firefox\my.cfg C:\Program Files (x86)\Mozilla Firefox\browser\defaults C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins C:\Program Files (x86)\Norton Internet Security C:\Program Files (x86)\Norton PC Checkup C:\Program Files (x86)\NortonInstaller C:\ProgramData\{08e235cf-712c-0} C:\ProgramData\{08e235cf-712c-1} C:\ProgramData\{1097c2c1-412c-0} C:\ProgramData\Essentware C:\ProgramData\f4f6b501 C:\ProgramData\Lightzap C:\ProgramData\Norton C:\ProgramData\NortonInstaller C:\ProgramData\Reimage Protector C:\ProgramData\Microsoft\Windows\GameExplorer\{A365DE48-2DF3-4EDA-8BE3-DA8483A23B25} C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kao - 2nd round (demo) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2 Ravia.eu C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton PC Checkup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair C:\rei C:\Users\Admin\AppData\Local\Ranktom.dat C:\Users\Admin\AppData\Local\AEFF2680-1452531350-11DD-920E-3085A98D4FF2 C:\Users\Admin\AppData\Local\AEFF2680-1452528769-11DD-920E-3085A98D4FF2 C:\Users\Admin\AppData\Local\Gameo C:\Users\Admin\AppData\Local\Steam\htmlcache C:\Users\Admin\AppData\Local\Microsoft\Windows\GameExplorer\{A365DE48-2DF3-4EDA-8BE3-DA8483A23B25} C:\Users\Admin\AppData\Roaming\*.* C:\Users\Admin\AppData\Roaming\Gameo C:\Users\Admin\AppData\Roaming\HTThread C:\Users\Admin\AppData\Roaming\Security Systems C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo.lnk C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duel of Champions Launcher\Duel of Champions Launcher Website.lnk C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage C:\Users\Admin\Desktop\Zdjecia\Kao - 2nd round (demo).lnk C:\Users\Admin\Downloads\6587.tmp C:\Users\Admin\Downloads\ReimageRepair.exe C:\Windows\system32\Drivers\NISx64 C:\Windows\system32\Drivers\NortonPCCheckupx64 C:\Windows\Reimage.ini DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy CMD: for /d %f in ("C:\Program Files (x86)\AEFF2680-*") do rd /s /q "%f" CMD: for /d %f in (C:\ProgramData\4bdbe351-*) do rd /s /q "%f" CMD: for /d %f in (C:\ProgramData\e7c2fe2e-*) do rd /s /q "%f" CMD: ipconfig /flushdns CMD: netsh advfirewall reset Hosts: EmptyTemp: ***************** Procesy zostaÅ‚y pomyÅ›lnie zamkniÄ™te. Punkt przywracania zostaÅ‚ pomyÅ›lnie utworzony. "C:\ProgramData\Lightzap\Can-Trax.dll" => Dane wartoÅ›ci pomyÅ›lnie usuniÄ™to. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ApnTBMon => Wartość nie znaleziono. HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Gameo => Wartość nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0B42EA5C-ABD5-4288-81D3-F897D7D81160} => klucz nie znaleziono. C:\Windows\System32\Tasks\PC-Mechanic Maintenance => nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC-Mechanic Maintenance => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{12FB840A-516D-4C0D-815A-6C8DC22C81E0}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12FB840A-516D-4C0D-815A-6C8DC22C81E0}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\{FD5AE810-2139-4881-A66B-5A088D55CF93} => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FD5AE810-2139-4881-A66B-5A088D55CF93}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2FFB3E57-8D29-4798-BD7D-1E17D2479AF6}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2FFB3E57-8D29-4798-BD7D-1E17D2479AF6}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\DNSKALAMAZOO => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DNSKALAMAZOO" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4B1D622B-DF14-468B-9D62-54CEE03DCFA1}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B1D622B-DF14-468B-9D62-54CEE03DCFA1}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\new_game_notification_service" => klucz pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4FBC4ECC-270B-49B1-9A97-CBB7350CA088} => klucz nie znaleziono. C:\Windows\System32\Tasks\PC-Mechanic Subscription => nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC-Mechanic Subscription => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{668DE9A9-58CF-49D9-87D1-3AA832C86B09}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{668DE9A9-58CF-49D9-87D1-3AA832C86B09}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\ReimageUpdater => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ReimageUpdater" => klucz pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76DD9942-C71D-4EEA-8396-F95DC772354B} => klucz nie znaleziono. C:\Windows\System32\Tasks\PC-Mechanic Startup => nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC-Mechanic Startup => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D89ADD1-71FD-4837-BD04-1A76E60C7784}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D89ADD1-71FD-4837-BD04-1A76E60C7784}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Search" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B23C871F-F5E7-4AA5-A699-38867DE8F1F1}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B23C871F-F5E7-4AA5-A699-38867DE8F1F1}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Search Updater" => klucz pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1AFD920-8078-4E2E-9787-73199C554D27} => klucz nie znaleziono. C:\Windows\System32\Tasks\Reimage Reminder => nie znaleziono. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Reimage Reminder => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F70DFA71-3345-4C4C-A6AF-5D891F007912}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F70DFA71-3345-4C4C-A6AF-5D891F007912}" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\System32\Tasks\godzilla_shopper_helper_service => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\godzilla_shopper_helper_service" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F9B7044B-C3B1-44A1-9357-04FA06BC6629}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9B7044B-C3B1-44A1-9357-04FA06BC6629}" => klucz pomyÅ›lnie usuniÄ™to "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\new_game_updating_service" => klucz pomyÅ›lnie usuniÄ™to C:\Windows\Tasks\godzilla_shopper_helper_service.job => pomyÅ›lnie przeniesiono C:\Windows\Tasks\new_game_notification_service.job => pomyÅ›lnie przeniesiono C:\Windows\Tasks\new_game_updating_service.job => pomyÅ›lnie przeniesiono C:\Windows\Tasks\PC-Mechanic Maintenance.job => nie znaleziono. C:\Windows\Tasks\PC-Mechanic Startup.job => nie znaleziono. C:\Windows\Tasks\PC-Mechanic Subscription.job => nie znaleziono. APNMCP => serwis nie znaleziono. cpuz134 => serwis pomyÅ›lnie usuniÄ™to C:\Windows\system32\GroupPolicy\Machine => pomyÅ›lnie przeniesiono C:\Windows\system32\GroupPolicy\GPT.ini => pomyÅ›lnie przeniesiono C:\Windows\SysWOW64\GroupPolicy\GPT.ini => pomyÅ›lnie przeniesiono "HKLM\SOFTWARE\Policies\Google" => klucz pomyÅ›lnie usuniÄ™to Chrome HomePage => pomyÅ›lnie usuniÄ™to Chrome StartupUrls => pomyÅ›lnie usuniÄ™to Chrome DefaultSearchURL => pomyÅ›lnie usuniÄ™to Chrome DefaultSearchKeyword => pomyÅ›lnie usuniÄ™to Chrome DefaultSuggestURL => pomyÅ›lnie usuniÄ™to HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Wartość pomyÅ›lnie przywrócono HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyÅ›lnie przywrócono HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => Wartość pomyÅ›lnie usuniÄ™to HKU\S-1-5-21-2273012611-303174682-3880648035-1000\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => Wartość pomyÅ›lnie usuniÄ™to HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie przywrócono "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\ielnksrch => klucz nie znaleziono. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{8C31F27B-BE8A-4e4b-A478-17760AF1F5D9}" => klucz pomyÅ›lnie usuniÄ™to HKCR\Wow6432Node\CLSID\{8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} => klucz nie znaleziono. HKU\S-1-5-21-2273012611-303174682-3880648035-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyÅ›lnie usuniÄ™to "HKU\S-1-5-21-2273012611-303174682-3880648035-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\D735241F7F874887B9EF63F4A7F61B79" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\D735241F7F874887B9EF63F4A7F61B79 => klucz nie znaleziono. "HKU\S-1-5-21-2273012611-303174682-3880648035-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => klucz nie znaleziono. "HKU\S-1-5-21-2273012611-303174682-3880648035-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8C31F27B-BE8A-4e4b-A478-17760AF1F5D9}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{8C31F27B-BE8A-4e4b-A478-17760AF1F5D9} => klucz nie znaleziono. "HKU\S-1-5-21-2273012611-303174682-3880648035-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{ielnksrch} => klucz nie znaleziono. "HKU\S-1-5-21-2273012611-303174682-3880648035-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{szukaj.gazeta.pl}" => klucz pomyÅ›lnie usuniÄ™to HKCR\CLSID\{szukaj.gazeta.pl} => klucz nie znaleziono. HKLM\Software\Mozilla\Firefox\Extensions\\sp@avast.com => Wartość pomyÅ›lnie usuniÄ™to HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF} => Wartość pomyÅ›lnie usuniÄ™to HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\sp@avast.com => Wartość pomyÅ›lnie usuniÄ™to C:\Program Files\Essentware => pomyÅ›lnie przeniesiono "C:\Program Files\Reimage" => nie znaleziono. C:\Program Files\Symantec => pomyÅ›lnie przeniesiono C:\Program Files\Common Files\Symantec Shared => pomyÅ›lnie przeniesiono C:\Program Files (x86)\DNS Unlocker => pomyÅ›lnie przeniesiono "C:\Program Files (x86)\Godzilla Shopper" => nie znaleziono. C:\Program Files (x86)\Mozilla Firefox\my.cfg => pomyÅ›lnie przeniesiono C:\Program Files (x86)\Mozilla Firefox\browser\defaults => pomyÅ›lnie przeniesiono C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins => pomyÅ›lnie przeniesiono C:\Program Files (x86)\Norton Internet Security => pomyÅ›lnie przeniesiono C:\Program Files (x86)\Norton PC Checkup => pomyÅ›lnie przeniesiono C:\Program Files (x86)\NortonInstaller => pomyÅ›lnie przeniesiono C:\ProgramData\{08e235cf-712c-0} => pomyÅ›lnie przeniesiono C:\ProgramData\{08e235cf-712c-1} => pomyÅ›lnie przeniesiono C:\ProgramData\{1097c2c1-412c-0} => pomyÅ›lnie przeniesiono C:\ProgramData\Essentware => pomyÅ›lnie przeniesiono C:\ProgramData\f4f6b501 => pomyÅ›lnie przeniesiono C:\ProgramData\Lightzap => pomyÅ›lnie przeniesiono C:\ProgramData\Norton => pomyÅ›lnie przeniesiono C:\ProgramData\NortonInstaller => pomyÅ›lnie przeniesiono C:\ProgramData\Reimage Protector => pomyÅ›lnie przeniesiono C:\ProgramData\Microsoft\Windows\GameExplorer\{A365DE48-2DF3-4EDA-8BE3-DA8483A23B25} => pomyÅ›lnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kao - 2nd round (demo) => pomyÅ›lnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metin2 Ravia.eu => pomyÅ›lnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton PC Checkup => pomyÅ›lnie przeniesiono "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair" => nie znaleziono. "C:\rei" => nie znaleziono. C:\Users\Admin\AppData\Local\Ranktom.dat => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Local\AEFF2680-1452531350-11DD-920E-3085A98D4FF2 => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Local\AEFF2680-1452528769-11DD-920E-3085A98D4FF2 => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Local\Gameo => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Local\Steam\htmlcache => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Local\Microsoft\Windows\GameExplorer\{A365DE48-2DF3-4EDA-8BE3-DA8483A23B25} => pomyÅ›lnie przeniesiono =========== "C:\Users\Admin\AppData\Roaming\*.*" ========== C:\Users\Admin\AppData\Roaming\agent.dat => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Roaming\Config.xml => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Roaming\ham.txt => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Roaming\Main.dat => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Roaming\md.xml => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Roaming\Moses.dat => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Roaming\shem.jpg => pomyÅ›lnie przeniesiono ========= Koniec -> "C:\Users\Admin\AppData\Roaming\*.*" ======== "C:\Users\Admin\AppData\Roaming\Gameo" => nie znaleziono. C:\Users\Admin\AppData\Roaming\HTThread => pomyÅ›lnie przeniesiono C:\Users\Admin\AppData\Roaming\Security Systems => pomyÅ›lnie przeniesiono "C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk" => nie znaleziono. C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk => pomyÅ›lnie przeniesiono "C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo.lnk" => nie znaleziono. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Duel of Champions Launcher\Duel of Champions Launcher Website.lnk => pomyÅ›lnie przeniesiono "C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta" => nie znaleziono. "C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk" => nie znaleziono. "C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo" => nie znaleziono. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage => pomyÅ›lnie przeniesiono C:\Users\Admin\Desktop\Zdjecia\Kao - 2nd round (demo).lnk => pomyÅ›lnie przeniesiono C:\Users\Admin\Downloads\6587.tmp => pomyÅ›lnie przeniesiono C:\Users\Admin\Downloads\ReimageRepair.exe => pomyÅ›lnie przeniesiono C:\Windows\system32\Drivers\NISx64 => pomyÅ›lnie przeniesiono C:\Windows\system32\Drivers\NortonPCCheckupx64 => pomyÅ›lnie przeniesiono C:\Windows\Reimage.ini => pomyÅ›lnie przeniesiono HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz pomyÅ›lnie usuniÄ™to HKCU\Software\dobreprogramy => klucz pomyÅ›lnie usuniÄ™to ========= for /d %f in ("C:\Program Files (x86)\AEFF2680-*") do rd /s /q "%f" ========= ========= Koniec CMD: ========= ========= for /d %f in (C:\ProgramData\4bdbe351-*) do rd /s /q "%f" ========= ========= Koniec CMD: ========= ========= for /d %f in (C:\ProgramData\e7c2fe2e-*) do rd /s /q "%f" ========= ========= Koniec CMD: ========= ========= ipconfig /flushdns ========= Konfiguracja IP systemu Windows Pomy˜lnie opr¢¾niono pami©† podr©czn¥ programu rozpoznawania nazw DNS. ========= Koniec CMD: ========= ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= C:\Windows\System32\Drivers\etc\hosts => pomyÅ›lnie przeniesiono Hosts pomyÅ›lnie przywrócono. EmptyTemp: => 8.3 GB danych tymczasowych UsuniÄ™to. System wymagaÅ‚ restartu. ==== Koniec Fixlog 19:36:30 ====