Fix result of Farbar Recovery Scan Tool (x64) Version: 04-10-2016 Ran by Zbigniew Niewiński (08-10-2016 15:01:55) Run:1 Running from C:\Users\Zbigniew Niewiński\Downloads Loaded Profiles: Zbigniew Niewiński (Available Profiles: Zbigniew Niewiński) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [Tv-Plug-In] => "C:\Program Files (x86)\Tv-Plug-In\Tv-Plug-In.exe" nogui Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk [2016-10-05] S2 0287211475661876mcinstcleanup; C:\Users\Zbigniew Niewiński\AppData\Local\Temp\0287211475661876mcinst.exe [883024 2016-10-05] (McAfee, Inc.) Task: {618B4918-D369-42FF-98AA-C6EF921DFF78} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {75D36573-B885-4FEB-B62F-B962E1E0CB5F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe Task: {91215154-BDC7-4178-B2A6-C6F994E8853B} - System32\Tasks\Microsoft\Windows\SystemRestore\FreeVPN => C:\Users\Zbigniew Niewiński\AppData\Roaming\FreeVPN\FreeVPN.exe <==== ATTENTION CustomCLSID: HKU\S-1-5-21-2006376192-134370331-1719292346-1002_Classes\CLSID\{56568F08-AD1D-8C3D-9F6F-A29DFB1849C0}\InprocServer32 -> C:\Users\Zbigniew Niewiński\AppData\Roaming\WildTangent\WildTangent Games\App\Settings\OnlineProducts.ini () CustomCLSID: HKU\S-1-5-21-2006376192-134370331-1719292346-1002_Classes\CLSID\{7F291FC0-AA13-D0FF-58AF-745564016CFD}\InprocServer32 -> C:\Users\Zbigniew Niewiński\AppData\Roaming\Raptr\data\zbigol1\config\xmpp-caps.inf () HKU\S-1-5-21-2006376192-134370331-1719292346-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.gazeta.pl/0,0.html?p=182&d=20160304 CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fcoadmpfijfcmokecmkgolhbaeclfage] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx DeleteKey: HKCU\Software\Mozilla DeleteKey: HKCU\Software\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Mozilla DeleteKey: HKLM\SOFTWARE\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins RemoveDirectory: C:\Program Files\ByteFence RemoveDirectory: C:\Program Files\McAfee RemoveDirectory: C:\Program Files (x86)\McAfee RemoveDirectory: C:\ProgramData\McAfee RemoveDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen RemoveDirectory: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911 RemoveDirectory: C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo RemoveDirectory: C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GetGo Software C:\ProgramData\*.* C:\Users\Zbigniew Niewiński\AppData\Roaming\*.* C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GetGo Download Manager.lnk C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo.lnk C:\Users\Zbigniew Niewiński\AppData\Roaming\Raptr\data\zbigol1\config\xmpp-caps.inf C:\Users\Zbigniew Niewiński\AppData\Roaming\WildTangent\WildTangent Games\App\Settings\OnlineProducts.ini C:\Users\Zbigniew Niewiński\Documents\decryptor.exe C:\Users\Zbigniew Niewiński\Documents\uid.txt C:\Users\Zbigniew Niewiński\Documents\Corel\Próbki CorelDRAW X6\target.lnk C:\Users\Zbigniew Niewiński\Downloads\*-dp*.exe StartBatch: netsh advfirewall reset attrib -r -h -s "C:\Files encrypted.txt" /s attrib -r -h -s "D:\Files encrypted.txt" /s del /q /s "C:\Files encrypted.txt" del /q /s "D:\Files encrypted.txt" EndBatch: EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Tv-Plug-In => value not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk => not found. 0287211475661876mcinstcleanup => service not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{618B4918-D369-42FF-98AA-C6EF921DFF78}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{618B4918-D369-42FF-98AA-C6EF921DFF78}" => key removed successfully C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVGPCTuneUp_Task_BkGndMaintenance" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{75D36573-B885-4FEB-B62F-B962E1E0CB5F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75D36573-B885-4FEB-B62F-B962E1E0CB5F}" => key removed successfully C:\WINDOWS\System32\Tasks\MirageAgent => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MirageAgent" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{91215154-BDC7-4178-B2A6-C6F994E8853B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{91215154-BDC7-4178-B2A6-C6F994E8853B}" => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\SystemRestore\FreeVPN => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SystemRestore\FreeVPN" => key removed successfully "HKU\S-1-5-21-2006376192-134370331-1719292346-1002_Classes\CLSID\{56568F08-AD1D-8C3D-9F6F-A29DFB1849C0}" => key removed successfully "HKU\S-1-5-21-2006376192-134370331-1719292346-1002_Classes\CLSID\{7F291FC0-AA13-D0FF-58AF-745564016CFD}" => key removed successfully HKU\S-1-5-21-2006376192-134370331-1719292346-1002\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fcoadmpfijfcmokecmkgolhbaeclfage" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki" => key removed successfully HKCU\Software\Mozilla => key not found. HKCU\Software\MozillaPlugins => could not remove at first attempt (ErrorCode: C0000121), see next line. HKCU\Software\MozillaPlugins => key removed successfully HKLM\SOFTWARE\Mozilla => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Mozilla => key removed successfully HKLM\SOFTWARE\MozillaPlugins => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\MozillaPlugins => key removed successfully HKLM\SOFTWARE\Wow6432Node\Mozilla => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\Mozilla => key removed successfully HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => key removed successfully "C:\Program Files\ByteFence" => removed successfully. "C:\Program Files\McAfee" => removed successfully. "C:\Program Files (x86)\McAfee" => not found. "C:\ProgramData\McAfee" => removed successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen" => removed successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911" => removed successfully. "C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo" => not found. "C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GetGo Software" => removed successfully. =========== "C:\ProgramData\*.*" ========== C:\ProgramData\encfiles.log => moved successfully C:\ProgramData\encinfo.jpg => moved successfully C:\ProgramData\uid.txt => moved successfully ========= End -> "C:\ProgramData\*.*" ======== =========== "C:\Users\Zbigniew Niewiński\AppData\Roaming\*.*" ========== C:\Users\Zbigniew Niewiński\AppData\Roaming\Installer.dat => moved successfully C:\Users\Zbigniew Niewiński\AppData\Roaming\LogFile.txt => moved successfully C:\Users\Zbigniew Niewiński\AppData\Roaming\uid.txt => moved successfully ========= End -> "C:\Users\Zbigniew Niewiński\AppData\Roaming\*.*" ======== C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GetGo Download Manager.lnk => moved successfully C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk => moved successfully "C:\Users\Zbigniew Niewiński\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo.lnk" => not found. "C:\Users\Zbigniew Niewiński\AppData\Roaming\Raptr\data\zbigol1\config\xmpp-caps.inf" => not found. C:\Users\Zbigniew Niewiński\AppData\Roaming\WildTangent\WildTangent Games\App\Settings\OnlineProducts.ini => moved successfully C:\Users\Zbigniew Niewiński\Documents\decryptor.exe => moved successfully C:\Users\Zbigniew Niewiński\Documents\uid.txt => moved successfully C:\Users\Zbigniew Niewiński\Documents\Corel\Próbki CorelDRAW X6\target.lnk => moved successfully =========== "C:\Users\Zbigniew Niewiński\Downloads\*-dp*.exe" ========== not found ========= End -> "C:\Users\Zbigniew Niewiński\Downloads\*-dp*.exe" ======== ========= Batch: ========= Ok. Deleted file - C:\AMD\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Config\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Images\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1028\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1031\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1033\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1036\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1040\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1041\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1042\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\1049\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\2052\Files encrypted.txt Deleted file - C:\AMD\AMD-Catalyst-14.4-64Bit-Win8.1-Win8-Win7-WHQL-Aug\Packages\Apps\VC10RTx64\vcredist_x64\3082\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-15.12-amdas4-win8.1-64bit\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-15.12-amd_sata-win8.1-64bit\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-15.12-smbusamd-win8.1-64bit\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-16.3.2-amdas4-win8.1-64bit\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-16.3.2-amd_sata-win8.1-64bit\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-16.3.2-smbusamd-win8.1-64bit\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-16.7.3-amdas4-win8.1-64bit-160728\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-16.7.3-amd_sata-win8.1-64bit-160728\Files encrypted.txt Deleted file - C:\AMD\Packages\Drivers\Radeon-Crimson-16.7.3-smbusamd-win8.1-64bit-160728\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-15.12-MinimalSetup_web\Config\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-15.12-MinimalSetup_web\Images\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-15.12-Win8.1-64Bit\Config\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-15.12-Win8.1-64Bit\Images\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-16.3.2-MinimalSetup_web\Config\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-16.3.2-MinimalSetup_web\Images\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-16.7.3-MinimalSetup-160728_web\Config\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-16.7.3-MinimalSetup-160728_web\Images\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-16.7.3-Win8.1-64Bit\Config\Files encrypted.txt Deleted file - C:\AMD\Radeon-Crimson-16.7.3-Win8.1-64Bit\Images\Files encrypted.txt Deleted file - C:\AMD\WHQL-64Bit-Radeon-Software-Crimson-16.1.1-Win10-Win8.1-Win7-Feb12\Config\Files encrypted.txt Deleted file - C:\AMD\WHQL-64Bit-Radeon-Software-Crimson-16.1.1-Win10-Win8.1-Win7-Feb12\Images\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\common\images\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\common\js\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\bg\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\cs\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\da\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\de\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\el\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\en\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\es\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\et\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\fi\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\fr\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\hr\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\hu\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\it\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\lt\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\lv\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\nl\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\no\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\pl\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\pt\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\ro\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\sr\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\sv\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\install\html\tr\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\logs\Files encrypted.txt Deleted file - C:\Games\World_of_Tanks\res\gui\flash\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\common\images\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\html\cs\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\html\de\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\html\en\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\html\es\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\html\fr\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\html\pl\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\install\html\tr\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\logs\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\res\Files encrypted.txt Deleted file - C:\Games\World_of_Warships\res\gui\flash\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Desilva\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Grafiki Lasowice\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Grafiki Lasowice\PAŤDZIERNIK\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Grafiki Lasowice\rozliczenia\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Grafiki Lasowice\SIERPIEă\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Grafiki Lasowice\WRZESIEă\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\GRAFIKI ZBYSZEK\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\GRUDZIEă\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\Kielce komunia Pauliny\100SSCAM\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\LISTOPAD\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\LUTY\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\OpenOffice.org 3.4.1 (pl) Installation Files\readmes\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\PAŤDZIERNIK\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\PAŤDZIERNIK\GRAFIKI ANIA\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\SIERPIEă\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\STYCZEă\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\W\Files encrypted.txt Deleted file - C:\priv and instalki\Grafiki\WRZESIEă\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\CZERWIEC\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\Desilva\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\GRAFIKI ANIA\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\Grafiki Lasowice\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\Grafiki Lasowice\PAŤDZIERNIK\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\Grafiki Lasowice\rozliczenia\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\Grafiki Lasowice\SIERPIEă\Files encrypted.txt Deleted file - C:\priv1 and instalki\Grafiki\Grafiki Lasowice\WRZESIEă\Files encrypted.txt Deleted file - C:\priv1 and instalki\Music\Files encrypted.txt Deleted file - C:\priv1 and instalki\Nowy folder\Files encrypted.txt Deleted file - C:\priv1 and instalki\Nowy folder\CZERWIEC\Files encrypted.txt Deleted file - C:\priv1 and instalki\Nowy folder\DZIAťKA\Files encrypted.txt Deleted file - C:\priv1 and instalki\Nowy folder\KWIECIEă\Files encrypted.txt Deleted file - C:\priv1 and instalki\Nowy folder\Maj\Files encrypted.txt Deleted file - C:\priv1 and instalki\Pendrive\Files encrypted.txt Deleted file - C:\priv1 and instalki\Z telefonu\Files encrypted.txt Deleted file - C:\SWSetup\7ZIP\Files encrypted.txt Deleted file - C:\SWSetup\CustTweak\Files encrypted.txt Deleted file - C:\SWSetup\CyberMS\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKCard\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\FAQ\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\QUICK_INSTALL_GUIDE\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Arabic\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\English\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\French\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\German\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Hebrew\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Hungarian\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Italian\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Japanese\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Korean\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Portuguese\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Simplified_Chinese\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Spanish\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Traditional_Chinese\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\README\WIN8\Turkish\images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKNetWork\UTILIZE_DUAL_MAC_GUIDE\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Config\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Images\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1028\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1031\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1033\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1036\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1040\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1041\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1042\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\1049\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\2052\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx64\vcredist_x64\3082\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1028\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1031\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1033\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1036\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1040\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1041\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1042\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\1049\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\2052\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Apps\VC10RTx86\vcredist_x86\3082\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Drivers\SBDrv\a4acpi\W8\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Drivers\SBDrv\a4acpi\W864A\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Drivers\SBDrv\hseries\AHCI\W8\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Drivers\SBDrv\hseries\AHCI\W864A\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Drivers\SBDrv\hseries\UsbFilter\W8\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HKVGAK\Packages\Drivers\SBDrv\hseries\UsbFilter\W864A\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HPePrint\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HPePrint\src\32bit\Win32\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\HPePrint\src\64bit\x64\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\SynTP\WinWDF\x64\Files encrypted.txt Deleted file - C:\SWSetup\Drivers\SynTP\WinWDF\x86\Files encrypted.txt Deleted file - C:\SWSetup\ESUW8\Files encrypted.txt Deleted file - C:\SWSetup\HPQStar\Files encrypted.txt Deleted file - C:\SWSetup\HPQStar\src\HPQuickStart\Files encrypted.txt Deleted file - C:\SWSetup\P2Go\Files encrypted.txt Deleted file - C:\SWSetup\P2Go\ToolDocs\Files encrypted.txt Deleted file - C:\SWSetup\sp62310\Files encrypted.txt Deleted file - C:\SWSetup\sp64444\Files encrypted.txt Deleted file - C:\SWSetup\sp64445\WinWDF\x64\Files encrypted.txt Deleted file - C:\SWSetup\sp64445\WinWDF\x86\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\FAQ\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\QUICK_INSTALL_GUIDE\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Arabic\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\English\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\French\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\German\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Hebrew\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Hungarian\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Italian\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Japanese\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Korean\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Portuguese\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Simplified_Chinese\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Spanish\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Traditional_Chinese\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\README\WIN8\Turkish\images\Files encrypted.txt Deleted file - C:\SWSetup\sp64446\UTILIZE_DUAL_MAC_GUIDE\Files encrypted.txt Deleted file - C:\SWSetup\sp65793\Files encrypted.txt Deleted file - C:\SWSetup\sp66604\Files encrypted.txt Deleted file - C:\SWSetup\WinLive\Files encrypted.txt Deleted file - D:\recovery\Files encrypted.txt ========= End of Batch: ========= =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 34306141 B Java, Flash, Steam htmlcache => 506 B Windows/system/drivers => 1237321 B Edge => 0 B Chrome => 11821535 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 0 B LocalService => 824 B NetworkService => 0 B Zbigniew Niewiński => 15527360 B RecycleBin => 0 B EmptyTemp: => 68 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 15:12:06 ====