Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:13-04-2016 Uruchomiony przez Ewelina (2016-04-15 18:45:34) Run:1 Uruchomiony z C:\Users\Ewelina\Desktop Załadowane profile: Ewelina (Dostępne profile: Ewelina) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [dtmcfg] => C:\Pliki Systemowe\Nod\x94\dtmcfg\dtmcfg.exe [1304576 2010-05-31] (Dyzmond Software) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\...\Run: [spoolsv32] => "C:\WINDOWS\system32\javaw.exe" -jar "C:\Users\Ewelina\AppData\Roaming\Win32\spoolsv32.jar" HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\...\Run: [Mobile Partner] => C:\Michał\net\Huawei E5372\Huawei E5372 HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\...\Policies\system: [DisableLockWorkstation] 0 S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation) Task: {15975FC2-5B99-4383-9B25-15AA19F9F119} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA Task: {2A6FA746-EB11-4570-BC22-469993C1013D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA Task: {2CC9561D-3A76-422E-92E2-DBDC12D77442} - System32\Tasks\{C92E8478-8A1B-4260-9F34-2208E48FC04A} => pcalua.exe -a C:\Users\Ewelina\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor Task: {4A346F29-9A1F-4170-AC6C-548A483D37ED} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA Task: {56D6AF1C-2A8A-43EF-B32A-C049B9BA6982} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe Task: {5D81EFE7-157C-49DF-B9B2-CB0B8AE380CC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA Task: {68FB1AAE-B47A-4277-BF97-BD96C0E382F1} - System32\Tasks\{AF6DA228-E8C6-41F2-940A-CC5D7D3BB0F7} => pcalua.exe -a "C:\Users\Ewelina\AppData\Local\Europa Casino\internalEuropaSetupUninstall1389109868205_7f2d9b_pl.exe" -c /executeuninstall /trafficsource='caver3' /profile='nasdec' /userid='BEC57A6FA8B94421BD22FA925046BB5FUI' /skinid='new' Task: {768779C3-5474-4F17-8989-F74DD1E20EC8} - System32\Tasks\{DD7B7164-27AC-4565-B9B1-D33BD5CD1E95} => pcalua.exe -a "C:\Users\Ewelina\AppData\Local\Casino Tropez\internalTropezSetupUninstall1389092744832_b8b35_pl.exe" -c /executeuninstall /trafficsource='nokws' /profile='main' /userid='EBD63FB308FA42E59D2AEE043035711FUI' /skinid='new_icons' Task: {78A79BB3-898C-46DA-ACC9-5A0CBD07FB60} - System32\Tasks\{479D3E8A-4F12-4A79-B087-431F2D86E932} => pcalua.exe -a E:\autorun.exe -d E:\ Task: {7EB1AF35-A4DA-46EF-80E2-D19D9B1832C3} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA Task: {8A98AC78-7436-4386-8301-97D7C461D66F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA Task: {8D866BB0-ABE6-4A6D-985F-F037221E770D} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA Task: {B4FA2981-E0F1-40DD-B0E9-5C30DFEAD341} - System32\Tasks\{6DA83E79-4B81-4235-A50B-1D8136A9B60E} => pcalua.exe -a "C:\Program Files (x86)\Image-Line\Shared\uninstall.exe" Task: {B670F1A1-0469-4E73-9A91-20E4CEFD8BC2} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA Task: {C5487043-BFB8-4950-833D-4BF8EEF66485} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA Task: {C74D8655-68A6-44B6-AFDD-2027ADD4043B} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA Task: {C89D345F-6F07-4E63-96CF-6DDC6A140EFC} - System32\Tasks\{76BA7823-6504-4749-AEC9-8988F970AAE7} => pcalua.exe -a D:\SETUP.EXE -d D:\ Task: {CEA24034-8B61-4300-8876-9CCDD8BD91B7} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA Task: {D3374684-E6B4-4A61-9A0F-4DB8AB6165FA} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon Task: {D52743E4-45F4-4984-8789-94B094663400} - System32\Tasks\{7E90E837-52B3-4B5D-81F4-081969A70FA1} => pcalua.exe -a "C:\Users\Ewelina\Desktop\Tibia Map Installer.exe" -d C:\Users\Ewelina\Desktop Task: {D56326A5-290B-483F-A72B-A5CAD07C844A} - System32\Tasks\{DC67236D-08AD-4A49-A111-21C533702C4F} => pcalua.exe -a "C:\Program Files (x86)\Common Files\myCuteBuddy\Bootstrapper{4.wfBHCKiGLgWE12.102}.exe" Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\napinsp.dll" Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\pnrpnsp.dll" Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\pnrpnsp.dll" Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)UWAGA: LibraryPath powinno kierować na "%SystemRoot%\System32\winrnr.dll" CustomCLSID: HKU\S-1-5-21-1292469835-3904043757-2447316924-1001_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> Brak ścieżki do pliku ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => Brak pliku ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => Brak pliku ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => Brak pliku ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => Brak pliku GroupPolicy: Ograniczenia - Chrome <======= UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={F6612E51-E9EF-489D-8641-0BFF948889D6}&mid=7a80442b378d47cca1dcf1c0c2f5592d-5233c8df0424be70114540273ff17c4401ab22ac&lang=en&ds=AVG&coid=avgtbavg&cmpid=0216piz&pr=fr&d=2016-04-13 15:09:02&v=4.2.9.726&pid=wtu&sg=&sap=hp SearchScopes: HKU\S-1-5-21-1292469835-3904043757-2447316924-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={F6612E51-E9EF-489D-8641-0BFF948889D6}&mid=7a80442b378d47cca1dcf1c0c2f5592d-5233c8df0424be70114540273ff17c4401ab22ac&lang=en&ds=AVG&coid=avgtbavg&cmpid=0216piz&pr=fr&d=2016-04-13 15:09:02&v=4.2.9.726&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-1292469835-3904043757-2447316924-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={F6612E51-E9EF-489D-8641-0BFF948889D6}&mid=7a80442b378d47cca1dcf1c0c2f5592d-5233c8df0424be70114540273ff17c4401ab22ac&lang=en&ds=AVG&coid=avgtbavg&cmpid=0216piz&pr=fr&d=2016-04-13 15:09:02&v=4.2.9.726&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-1292469835-3904043757-2447316924-1001 -> {F2E48B17-78B7-406A-BE47-7FB63603E514} URL = BHO: Brak nazwy -> {89BDDABE-B308-89D1-AB93-14E8F6D8CDB3} -> Brak pliku DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy DeleteKey: HKCU\Software\Google DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKCU\Software\Mozilla DeleteKey: HKCU\Software\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Google DeleteKey: HKLM\SOFTWARE\Mozilla DeleteKey: HKLM\SOFTWARE\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\mozilla.org DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "DAEMON Tools Lite" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v RGSC /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v AlcoholAutomount /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "BIL Start" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v spoolsv32 /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v vilanscr.exe /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "CnxMon.exe " /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "EA Core" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v MyCuteBuddy /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Cudanv /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v HotKeysCmds /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v IgfxTray /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Persistence /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v egui /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v "Adobe Reader Speed Launcher" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v CLMLServer_For_P2G8 /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v CLVirtualDrive /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v "Intel AppUp(SM) center" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v RemoteControl10 /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v SunJavaUpdateSched /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v WinPatrol /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v "BIL Start" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v dtmcfg /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v vProt /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder /v "McAfee Security Scan Plus.lnk" /f C:\Program Files (x86)\fwmdpwclxd C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ivo C:\Users\Ewelina\AppData\Local\nsq925.tmp C:\Users\Ewelina\AppData\Local\Google C:\Users\Ewelina\AppData\Local\Mozilla C:\Users\Ewelina\AppData\Local\Sparta C:\Users\Ewelina\AppData\Roaming\*.* C:\Users\Ewelina\AppData\Roaming\Nature C:\Users\Ewelina\AppData\Roaming\PDEs C:\Users\Ewelina\AppData\Roaming\Pipe Organ C:\Users\Ewelina\AppData\Roaming\Mozilla C:\Users\Ewelina\AppData\Roaming\sparta111 C:\Users\Ewelina\AppData\Roaming\WarThunder C:\Users\Ewelina\AppData\Roaming\Win32 C:\Users\Ewelina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk C:\Users\Ewelina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk C:\Users\Ewelina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta C:\Users\Ewelina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tibia Map Viewer C:\Users\Ewelina\Documents\Bajki dla dzieci\YTD Video Downloader.lnk C:\Users\Ewelina\Documents\MAGIX\Video_deluxe_MX_Download_Version\Pokaz zdjęć z muzyką.lnk C:\Users\Ewelina\Documents\MAGIX\Video_deluxe_MX_Download_Version\_TV Anti Cropping.LNK C:\WINDOWS\msdownld.tmp C:\WINDOWS\system32\drivers\mbam.sys C:\WINDOWS\system32\drivers\mwac.sys C:\WINDOWS\SysWOW64\HRUPPROG.TXT C:\WINDOWS\SysWOW64\HRUPPROG.EXIT Hosts: CMD: netsh advfirewall reset EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\dtmcfg => Wartość pomyślnie usunięto "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" => klucz pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\BtvStack => Wartość pomyślnie usunięto HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\Software\Microsoft\Windows\CurrentVersion\Run\\spoolsv32 => Wartość pomyślnie usunięto HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Mobile Partner => Wartość pomyślnie usunięto HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => Wartość pomyślnie usunięto MBAMProtector => serwis pomyślnie usunięto MBAMWebAccessControl => serwis pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15975FC2-5B99-4383-9B25-15AA19F9F119}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15975FC2-5B99-4383-9B25-15AA19F9F119}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A6FA746-EB11-4570-BC22-469993C1013D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A6FA746-EB11-4570-BC22-469993C1013D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2CC9561D-3A76-422E-92E2-DBDC12D77442}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2CC9561D-3A76-422E-92E2-DBDC12D77442}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{C92E8478-8A1B-4260-9F34-2208E48FC04A} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C92E8478-8A1B-4260-9F34-2208E48FC04A}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4A346F29-9A1F-4170-AC6C-548A483D37ED}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A346F29-9A1F-4170-AC6C-548A483D37ED}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{56D6AF1C-2A8A-43EF-B32A-C049B9BA6982}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56D6AF1C-2A8A-43EF-B32A-C049B9BA6982}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\SAgent => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SAgent" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5D81EFE7-157C-49DF-B9B2-CB0B8AE380CC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D81EFE7-157C-49DF-B9B2-CB0B8AE380CC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68FB1AAE-B47A-4277-BF97-BD96C0E382F1}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68FB1AAE-B47A-4277-BF97-BD96C0E382F1}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{AF6DA228-E8C6-41F2-940A-CC5D7D3BB0F7} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AF6DA228-E8C6-41F2-940A-CC5D7D3BB0F7}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{768779C3-5474-4F17-8989-F74DD1E20EC8}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{768779C3-5474-4F17-8989-F74DD1E20EC8}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{DD7B7164-27AC-4565-B9B1-D33BD5CD1E95} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DD7B7164-27AC-4565-B9B1-D33BD5CD1E95}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78A79BB3-898C-46DA-ACC9-5A0CBD07FB60}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78A79BB3-898C-46DA-ACC9-5A0CBD07FB60}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{479D3E8A-4F12-4A79-B087-431F2D86E932} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{479D3E8A-4F12-4A79-B087-431F2D86E932}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7EB1AF35-A4DA-46EF-80E2-D19D9B1832C3}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7EB1AF35-A4DA-46EF-80E2-D19D9B1832C3}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A98AC78-7436-4386-8301-97D7C461D66F}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A98AC78-7436-4386-8301-97D7C461D66F}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D866BB0-ABE6-4A6D-985F-F037221E770D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D866BB0-ABE6-4A6D-985F-F037221E770D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B4FA2981-E0F1-40DD-B0E9-5C30DFEAD341}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4FA2981-E0F1-40DD-B0E9-5C30DFEAD341}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{6DA83E79-4B81-4235-A50B-1D8136A9B60E} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6DA83E79-4B81-4235-A50B-1D8136A9B60E}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B670F1A1-0469-4E73-9A91-20E4CEFD8BC2}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B670F1A1-0469-4E73-9A91-20E4CEFD8BC2}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5487043-BFB8-4950-833D-4BF8EEF66485}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5487043-BFB8-4950-833D-4BF8EEF66485}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C74D8655-68A6-44B6-AFDD-2027ADD4043B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C74D8655-68A6-44B6-AFDD-2027ADD4043B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C89D345F-6F07-4E63-96CF-6DDC6A140EFC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C89D345F-6F07-4E63-96CF-6DDC6A140EFC}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{76BA7823-6504-4749-AEC9-8988F970AAE7} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{76BA7823-6504-4749-AEC9-8988F970AAE7}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEA24034-8B61-4300-8876-9CCDD8BD91B7}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEA24034-8B61-4300-8876-9CCDD8BD91B7}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D3374684-E6B4-4A61-9A0F-4DB8AB6165FA}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3374684-E6B4-4A61-9A0F-4DB8AB6165FA}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D52743E4-45F4-4984-8789-94B094663400}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D52743E4-45F4-4984-8789-94B094663400}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{7E90E837-52B3-4B5D-81F4-081969A70FA1} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7E90E837-52B3-4B5D-81F4-081969A70FA1}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D56326A5-290B-483F-A72B-A5CAD07C844A}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D56326A5-290B-483F-A72B-A5CAD07C844A}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{DC67236D-08AD-4A49-A111-21C533702C4F} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DC67236D-08AD-4A49-A111-21C533702C4F}" => klucz pomyślnie usunięto Winsock: Catalog5 000000000001\\LibraryPath => pomyślnie przywrócono (%SystemRoot%\system32\napinsp.dll) Winsock: Catalog5 000000000002\\LibraryPath => pomyślnie przywrócono (%SystemRoot%\system32\pnrpnsp.dll) Winsock: Catalog5 000000000003\\LibraryPath => pomyślnie przywrócono (%SystemRoot%\system32\pnrpnsp.dll) Winsock: Catalog5 000000000004\\LibraryPath => pomyślnie przywrócono (%SystemRoot%\system32\NLAapi.dll) Winsock: Catalog5 000000000005\\LibraryPath => pomyślnie przywrócono (%SystemRoot%\System32\mswsock.dll) Winsock: Catalog5 000000000006\\LibraryPath => pomyślnie przywrócono (%SystemRoot%\System32\winrnr.dll) "HKU\S-1-5-21-1292469835-3904043757-2447316924-1001_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}" => klucz pomyślnie usunięto "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay1" => klucz pomyślnie usunięto HKCR\CLSID\{E68D0A50-3C40-4712-B90D-DCFA93FF2534} => klucz nie znaleziono. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay2" => klucz pomyślnie usunięto HKCR\CLSID\{E68D0A51-3C40-4712-B90D-DCFA93FF2534} => klucz nie znaleziono. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay3" => klucz pomyślnie usunięto HKCR\CLSID\{E68D0A52-3C40-4712-B90D-DCFA93FF2534} => klucz nie znaleziono. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay4" => klucz pomyślnie usunięto HKCR\CLSID\{E68D0A53-3C40-4712-B90D-DCFA93FF2534} => klucz nie znaleziono. C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => klucz pomyślnie usunięto "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => klucz pomyślnie usunięto "HKU\S-1-5-21-1292469835-3904043757-2447316924-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F2E48B17-78B7-406A-BE47-7FB63603E514}" => klucz pomyślnie usunięto HKCR\CLSID\{F2E48B17-78B7-406A-BE47-7FB63603E514} => klucz nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{89BDDABE-B308-89D1-AB93-14E8F6D8CDB3}" => klucz pomyślnie usunięto HKCR\CLSID\{89BDDABE-B308-89D1-AB93-14E8F6D8CDB3} => klucz nie znaleziono. HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => klucz nie znaleziono. HKCU\Software\dobreprogramy => klucz nie znaleziono. HKCU\Software\Google => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Google => klucz pomyślnie usunięto HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => klucz pomyślnie usunięto HKCU\Software\Mozilla => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Mozilla => klucz pomyślnie usunięto HKCU\Software\MozillaPlugins => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\MozillaPlugins => klucz pomyślnie usunięto HKLM\SOFTWARE\Google => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Google => klucz pomyślnie usunięto HKLM\SOFTWARE\Mozilla => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Mozilla => klucz pomyślnie usunięto HKLM\SOFTWARE\MozillaPlugins => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\MozillaPlugins => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Google => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\Google => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Mozilla => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\Mozilla => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\mozilla.org => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\mozilla.org => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => klucz pomyślnie usunięto HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => klucz pomyślnie usunięto ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "DAEMON Tools Lite" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v RGSC /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v AlcoholAutomount /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "BIL Start" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v spoolsv32 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v vilanscr.exe /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "CnxMon.exe " /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "EA Core" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v MyCuteBuddy /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Cudanv /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v HotKeysCmds /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v IgfxTray /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v Persistence /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v egui /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v "Adobe Reader Speed Launcher" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v CLMLServer_For_P2G8 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v CLVirtualDrive /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v "Intel AppUp(SM) center" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v RemoteControl10 /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v SunJavaUpdateSched /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v WinPatrol /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v "BIL Start" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v dtmcfg /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v vProt /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder /v "McAfee Security Scan Plus.lnk" /f ========= Operacja ukoäczona pomy˜lnie. ========= Koniec Reg: ========= C:\Program Files (x86)\fwmdpwclxd => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ivo => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Local\nsq925.tmp => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Local\Google => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Local\Mozilla => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Local\Sparta => pomyślnie przeniesiono =========== "C:\Users\Ewelina\AppData\Roaming\*.*" ========== C:\Users\Ewelina\AppData\Roaming\glide_wrapper.zbag.ini => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\npb32.pas => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\o.exe => pomyślnie przeniesiono ========= Koniec -> "C:\Users\Ewelina\AppData\Roaming\*.*" ======== C:\Users\Ewelina\AppData\Roaming\Nature => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\PDEs => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\Pipe Organ => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\Mozilla => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\sparta111 => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\WarThunder => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\Win32 => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta => pomyślnie przeniesiono C:\Users\Ewelina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tibia Map Viewer => pomyślnie przeniesiono C:\Users\Ewelina\Documents\Bajki dla dzieci\YTD Video Downloader.lnk => pomyślnie przeniesiono C:\Users\Ewelina\Documents\MAGIX\Video_deluxe_MX_Download_Version\Pokaz zdjęć z muzyką.lnk => pomyślnie przeniesiono C:\Users\Ewelina\Documents\MAGIX\Video_deluxe_MX_Download_Version\_TV Anti Cropping.LNK => pomyślnie przeniesiono C:\WINDOWS\msdownld.tmp => pomyślnie przeniesiono C:\WINDOWS\system32\drivers\mbam.sys => pomyślnie przeniesiono C:\WINDOWS\system32\drivers\mwac.sys => pomyślnie przeniesiono C:\WINDOWS\SysWOW64\HRUPPROG.TXT => pomyślnie przeniesiono C:\WINDOWS\SysWOW64\HRUPPROG.EXIT => pomyślnie przeniesiono C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono Hosts pomyślnie przywrócono. ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= EmptyTemp: => 1 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 18:49:28 ====