Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja:17-04-2016 01 Uruchomiony przez BOGUSLAW (2016-04-25 14:39:02) Run:2 Uruchomiony z E:\kB Załadowane profile: BOGUSLAW (Dostępne profile: BOGUSLAW) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: FF Plugin-x32: @ei.RadioRage_4j.com/Plugin -> C:\Program Files (x86)\RadioRage_4jEI\Installr\1.bin\NP4jEISB.dll [2012-07-31] (RadioRage) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll => Brak pliku BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll => Brak pliku BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll => Brak pliku BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll => Brak pliku BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll => Brak pliku BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll => Brak pliku ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll Brak pliku ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll Brak pliku ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll Brak pliku ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll Brak pliku ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll Brak pliku ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll Brak pliku ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll Brak pliku ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll Brak pliku ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll Brak pliku ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\BOGUSLAW\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll Brak pliku Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> Brak pliku <==== UWAGA Task: {40689133-6C95-4ED3-8D70-E84773F8CF1A} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> Brak pliku <==== UWAGA Task: {AB2BC3D5-FA57-4E61-BC3C-BCF9F9865701} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> Brak pliku <==== UWAGA Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> Brak pliku <==== UWAGA Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> Brak pliku <==== UWAGA Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> Brak pliku <==== UWAGA HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\...\Run: [] => [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 massfilter; system32\DRIVERS\massfilter.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] DisableService: PLAY ONLINE. RunOuc DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKCU\Software\Google\Chrome DeleteKey: HKLM\SOFTWARE\Mozilla\Firefox\Extensions DeleteKey: HKLM\SOFTWARE\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google\Chrome DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions C:\Program Files (x86)\GUTFD9.tmp C:\Program Files (x86)\RadioRage_4jEI C:\Users\BOGUSLAW\AppData\Local\{EE467084-2CE9-48B6-80EC-14D677F96A0F} C:\Users\BOGUSLAW\AppData\Local\Google\Chrome CMD: netsh advfirewall reset Reg: reg query HKLM\SYSTEM\CurrentControlSet\Services\Tosrfcom /s Reg: reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Reg: reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run File: C:\Program Files\TOSHIBA\PasswordUtility\TOSDCR.exe File: C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe File: C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe File: C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. "HKLM\Software\Wow6432Node\MozillaPlugins\@ei.RadioRage_4j.com/Plugin" => klucz pomyślnie usunięto C:\Program Files (x86)\RadioRage_4jEI\Installr\1.bin\NP4jEISB.dll => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}" => klucz pomyślnie usunięto "HKCR\CLSID\{73455575-E40C-433C-9784-C78DC7761455}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}" => klucz pomyślnie usunięto "HKCR\CLSID\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}" => klucz pomyślnie usunięto "HKCR\CLSID\{E33CF602-D945-461A-83F0-819F76A199F8}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{73455575-E40C-433C-9784-C78DC7761455}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{E33CF602-D945-461A-83F0-819F76A199F8}" => klucz pomyślnie usunięto "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1" => klucz pomyślnie usunięto "HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => klucz pomyślnie usunięto "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2" => klucz pomyślnie usunięto "HKCR\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}" => klucz pomyślnie usunięto "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3" => klucz pomyślnie usunięto "HKCR\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}" => klucz pomyślnie usunięto "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4" => klucz pomyślnie usunięto "HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => klucz pomyślnie usunięto "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5" => klucz pomyślnie usunięto "HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => klucz pomyślnie usunięto "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => klucz pomyślnie usunięto "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}" => klucz pomyślnie usunięto "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}" => klucz pomyślnie usunięto "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => klucz pomyślnie usunięto "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5" => klucz pomyślnie usunięto "HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40689133-6C95-4ED3-8D70-E84773F8CF1A}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40689133-6C95-4ED3-8D70-E84773F8CF1A}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AB2BC3D5-FA57-4E61-BC3C-BCF9F9865701}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB2BC3D5-FA57-4E61-BC3C-BCF9F9865701}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector" => klucz pomyślnie usunięto "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc" => klucz pomyślnie usunięto HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Wartość pomyślnie usunięto ewusbnet => serwis pomyślnie usunięto massfilter => serwis pomyślnie usunięto ZTEusbmdm6k => serwis pomyślnie usunięto ZTEusbnet => serwis pomyślnie usunięto ZTEusbnmea => serwis pomyślnie usunięto ZTEusbser6k => serwis pomyślnie usunięto PLAY ONLINE. RunOuc => usługę wyłączono HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => klucz pomyślnie usunięto HKCU\Software\Google\Chrome => klucz nie znaleziono. HKLM\SOFTWARE\Mozilla\Firefox\Extensions => klucz pomyślnie usunięto HKLM\SOFTWARE\Google => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Google => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Google\Chrome => niepowodzenie przy usuwaniu w pierwszym podejściu (ErrorCode: C0000121), zobacz kolejną linię. HKLM\SOFTWARE\Wow6432Node\Google\Chrome => klucz pomyślnie usunięto HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions => klucz pomyślnie usunięto C:\Program Files (x86)\GUTFD9.tmp => pomyślnie przeniesiono C:\Program Files (x86)\RadioRage_4jEI => pomyślnie przeniesiono C:\Users\BOGUSLAW\AppData\Local\{EE467084-2CE9-48B6-80EC-14D677F96A0F} => pomyślnie przeniesiono C:\Users\BOGUSLAW\AppData\Local\Google\Chrome => pomyślnie przeniesiono ========= netsh advfirewall reset ========= Ok. ========= Koniec CMD: ========= ========= reg query HKLM\SYSTEM\CurrentControlSet\Services\Tosrfcom /s ========= HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tosrfcom Start REG_DWORD 0x3 Type REG_DWORD 0x1 ErrorControl REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tosrfcom\Parameters Enable REG_DWORD 0x1 ========= Koniec Reg: ========= ========= reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run IgfxTray REG_SZ C:\windows\system32\igfxtray.exe HotKeysCmds REG_SZ C:\windows\system32\hkcmd.exe Persistence REG_SZ C:\windows\system32\igfxpers.exe RtHDVCpl REG_SZ C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s SynTPEnh REG_EXPAND_SZ %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe TPwrMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE HSON REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\TBS\HSON.exe TCrdMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe IntelWireless REG_SZ "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray TFPUPWDBankService REG_SZ C:\Program Files\TOSHIBA\TFPU\TFPUPWDBank.exe /start TFPUService REG_SZ C:\Program Files\TOSHIBA\TFPU\TFPUTaskMonitor.exe /start Teco REG_EXPAND_SZ "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r TosSENotify REG_EXPAND_SZ C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe ThpSrv REG_SZ C:\windows\system32\thpsrv /logon TosWaitSrv REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe TosVolRegulator REG_SZ C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe TosNC REG_EXPAND_SZ %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe TosReelTimeMonitor REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe Toshiba TEMPRO REG_SZ C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe Toshiba Registration REG_SZ C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe ========= Koniec Reg: ========= ========= reg query HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run ========= HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run Adobe Reader Speed Launcher REG_SZ "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" NBAgent REG_SZ "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart IMSS REG_SZ "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" TOSDCR REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\PasswordUtility\TOSDCR.exe TWebCamera REG_EXPAND_SZ "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun ITSecMng REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START ToshibaServiceStation REG_SZ "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 TSleepSrv REG_EXPAND_SZ %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe TSUScheduler REG_EXPAND_SZ %ProgramFiles(x86)%\TOSHIBA\Sync Utility\TosSyncScheduler.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\OptionalComponents ========= Koniec Reg: ========= ========================= File: C:\Program Files\TOSHIBA\PasswordUtility\TOSDCR.exe ======================== "C:\Program Files\TOSHIBA\PasswordUtility\TOSDCR.exe" => nie znaleziono. ====== Koniec File: ====== ========================= File: C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ======================== "C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" => nie znaleziono. ====== Koniec File: ====== ========================= File: C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe ======================== Plik podpisany cyfrowo MD5: CE7648AF53E26CEB484F54866F195328 Data utworzenia i modyfikacji: 2007-08-28 19:30 - 2007-08-28 19:30 Rozmiar: 0169296 Atrybuty: ----A Firma: Wewnętrzna nazwa: Oryginalna nazwa: Produkt: Opis: Plik Wersja: Produkt Wersja: Prawa autorskie: ====== Koniec File: ====== ========================= File: C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ======================== Plik podpisany cyfrowo MD5: B9FBE2C4DE9A72E8997697C8D5CAD009 Data utworzenia i modyfikacji: 2009-07-22 22:40 - 2009-07-22 22:40 Rozmiar: 0083336 Atrybuty: ----A Firma: TOSHIBA CORPORATION Wewnętrzna nazwa: ItSecMng Oryginalna nazwa: ItSecMng.exe Produkt: Bluetooth Stack for Windows by Toshiba Opis: IT Security Manager for Toshiba Stack Plik Wersja: 7, 0, 9722, 1 Produkt Wersja: 7, 0, 0, 0 Prawa autorskie: Copyright c 2007 - 2009 TOSHIBA CORPORATION ====== Koniec File: ====== EmptyTemp: => 1.3 GB danych tymczasowych Usunięto. System wymagał restartu. ==== Koniec Fixlog 14:39:56 ====