Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 05-12-2016 Uruchomiony przez MAG (06-12-2016 19:16:37) Run:1 Uruchomiony z C:\Users\MAG\Desktop\usunąć Załadowane profile: MAG (Dostępne profile: MAG) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adva3d10] => C:\Users\MAG\AppData\Roaming\cdptcli\aeevispl.exe [524288 2015-12-04] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advavel9] => C:\Users\MAG\AppData\Roaming\cemaider\aeevispl.exe [524288 2016-01-12] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advp10_1] => C:\Users\MAG\AppData\Roaming\certtenc\amsiices.exe [524288 2016-02-05] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adsncapi] => C:\Users\MAG\AppData\Roaming\capicca\advaecsp.exe [524288 2016-02-08] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adsn3d32] => C:\Users\MAG\AppData\Roaming\catsosys\advaeter.exe [524288 2016-03-03] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adsnGSM7] => C:\Users\MAG\AppData\Roaming\catsosys\advaeter.exe [524288 2016-03-03] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adsnSCII] => C:\Users\MAG\AppData\Roaming\catsmapi\advabcd.exe [524288 2016-03-09] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adsnd3d9] => C:\Users\MAG\AppData\Roaming\Certwmdm\advaperf.exe [524288 2016-04-14] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advp0_43] => C:\Users\MAG\AppData\Roaming\cfgmdiag\amsikbox.exe [524288 2016-05-10] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advpfCdp] => C:\Users\MAG\AppData\Roaming\ChakgIME\amsiTVID.exe [524288 2016-06-14] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advpclen] => C:\Users\MAG\AppData\Roaming\charclb\amsianui.exe [524288 2016-07-12] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advpider] => C:\Users\MAG\AppData\Roaming\charis-2\amsianui.exe [524288 2016-07-15] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [aeevtlib] => C:\Users\MAG\AppData\Roaming\clbonfg\amstview.exe [524288 2016-09-20] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [amsilder] => C:\Users\MAG\AppData\Roaming\cmluutil\apdsrvps.exe [524288 2016-09-24] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adsntnet] => C:\Users\MAG\AppData\Roaming\cabitons\advaavrt.exe [524288 2016-10-17] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advad3d9] => C:\Users\MAG\AppData\Roaming\catsosys\advprypt.exe [524288 2016-11-08] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [adva8thk] => C:\Users\MAG\AppData\Roaming\catsosys\advprypt.exe [524288 2016-11-08] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advadxof] => C:\Users\MAG\AppData\Roaming\cdprtcli\aeevProv.exe [524288 2016-11-09] () HKU\S-1-5-21-2999985383-601964839-3280780558-1002\...\Run: [advaider] => C:\Users\MAG\AppData\Roaming\certtmgr\aeevwcli.exe [524288 2016-12-06] () C:\Users\MAG\AppData\Roaming\cdptcli C:\Users\MAG\AppData\Roaming\cemaider C:\Users\MAG\AppData\Roaming\certtenc C:\Users\MAG\AppData\Roaming\capicca C:\Users\MAG\AppData\Roaming\catsosys C:\Users\MAG\AppData\Roaming\catsmapi C:\Users\MAG\AppData\Roaming\Certwmdm C:\Users\MAG\AppData\Roaming\cfgmdiag C:\Users\MAG\AppData\Roaming\ChakgIME\amsiTVID.exe C:\Users\MAG\AppData\Roaming\charclb\amsianui.exe C:\Users\MAG\AppData\Roaming\charis-2\amsianui.exe C:\Users\MAG\AppData\Roaming\clbonfg\amstview.exe C:\Users\MAG\AppData\Roaming\cmluutil\apdsrvps.exe C:\Users\MAG\AppData\Roaming\cabitons\advaavrt.exe C:\Users\MAG\AppData\Roaming\cdprtcli\aeevProv.exe C:\Users\MAG\AppData\Roaming\certtmgr\aeevwcli.exe AppInit_DLLs: C:\Windows\system32\nvinitx.dll => Brak pliku AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => Brak pliku IFEO\MRT.exe: [Debugger] C:\Program Files (x86)\SearchesToYesbnd\_ALLOWDEL_27bfc\Gubed.exe -Yrrehs C:\Program Files (x86)\SearchesToYesbnd GroupPolicy: Ograniczenia <======= UWAGA HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Internet Explorer\Main,Start Page = SearchScopes: HKU\S-1-5-21-2999985383-601964839-3280780558-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2999985383-601964839-3280780558-1002 -> {FA9EC097-C43E-4767-866A-E31FA5272B20} URL = Edge HomeButtonPage: HKU\S-1-5-21-2999985383-601964839-3280780558-1002 -> hxxp://www.nuesearch.com/?type=hp&ts=1465910606&z=37c7bcedfe0fcd79fcd0425g1zfq5w1t1g7e5q4e5z&from=wpm0614&uid=TOSHIBAXMQ01ABD075_Y34TPQEDTXXY34TPQEDT FF DefaultSearchEngine: Mozilla\Firefox\Profiles\2263ujb8.default -> luck FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\2263ujb8.default -> luck FF SelectedSearchEngine: Mozilla\Firefox\Profiles\2263ujb8.default -> luck FF DefaultSearchEngine: Firefox\Firefox\Profiles\2263ujb8.default -> nice FF SearchEngineOrder.1: Firefox\Firefox\Profiles\2263ujb8.default -> nice FF SelectedSearchEngine: Firefox\Firefox\Profiles\2263ujb8.default -> nice R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [622080 2016-11-29] () [Brak podpisu cyfrowego] <==== UWAGA R2 Themes; C:\WINDOWS\system32\themeservice.dll [70656 2016-07-16] (Microsoft Corporation) [DependOnService: iThemes5]<==== UWAGA S2 NosemayP; C:\ProgramData\Nosemay\Nosemay.exe [400264 2016-05-30] () S2 NosemayU; "C:\Program Files (x86)\Nosemay\Update\NosemayUpdate.exe" [X] C:\Program Files (x86)\Nosemay C:\ProgramData\Nosemay Task: {1F357729-9984-4DAB-87F8-E84F39AF8EE7} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Brak pliku <==== UWAGA Task: {3DD526DA-F673-45CE-9002-14D1BC99DBD4} - System32\Tasks\NosemayUpdateTaskMachineCore => C:\Program Files (x86)\Nosemay\Update\NosemayUpdate.exe <==== UWAGA Task: {4E26A63E-55E5-48A4-9E07-B46D50710A89} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Brak pliku <==== UWAGA Task: {4E77BBE4-2C07-47A4-B58F-2A23B9C6D037} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Brak pliku <==== UWAGA Task: {52A92279-2FDA-4755-AAE5-DC6FE44B503B} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Brak pliku <==== UWAGA Task: {7617830F-3E2E-4E14-BC84-8D8F0FDDD5BD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Brak pliku <==== UWAGA Task: {7E519C3A-0D56-4C31-9AE4-5B2FBBD9429D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Brak pliku <==== UWAGA Task: {85097416-4841-491B-B87F-ABC07F723D5B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Brak pliku <==== UWAGA Task: {8BDB08BD-4D81-4A04-9149-8E9C34024CA0} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Brak pliku <==== UWAGA Task: {A1314326-5C03-448B-B853-3FA02E67EE70} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Brak pliku <==== UWAGA Task: {B1AD7971-CD5B-4CA2-AD61-92C25DD1FE39} - System32\Tasks\NosemayUpdateTaskMachineUA => C:\Program Files (x86)\Nosemay\Update\NosemayUpdate.exe <==== UWAGA Task: {D03E6501-354B-426D-9A6E-FAE0898D99BC} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Brak pliku <==== UWAGA Task: {D60BA628-7A6A-4E69-AB00-993837E0D6EB} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Brak pliku <==== UWAGA C:\Users\MAG\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Coldjob\Application\chrome.exe (Google Inc.) C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Coldjob\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Coldjob C:\Users\MAG\AppData\Local\Coldjob C:\Users\MAG\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk C:\Users\Public\Desktop\Mozilla Firefox.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\MAG\AppData\Local CMD: dir /a C:\Users\MAG\AppData\LocalLow CMD: dir /a C:\Users\MAG\AppData\Roaming Hosts: EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adva3d10 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advavel9 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advp10_1 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adsncapi => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adsn3d32 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adsnGSM7 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adsnSCII => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adsnd3d9 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advp0_43 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advpfCdp => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advpclen => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advpider => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\aeevtlib => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\amsilder => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adsntnet => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advad3d9 => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\adva8thk => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advadxof => Wartość pomyślnie usunięto HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Windows\CurrentVersion\Run\\advaider => Wartość pomyślnie usunięto C:\Users\MAG\AppData\Roaming\cdptcli => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\cemaider => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\certtenc => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\capicca => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\catsosys => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\catsmapi => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\Certwmdm => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\cfgmdiag => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\ChakgIME\amsiTVID.exe => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\charclb\amsianui.exe => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\charis-2\amsianui.exe => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\clbonfg\amstview.exe => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\cmluutil\apdsrvps.exe => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\cabitons\advaavrt.exe => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\cdprtcli\aeevProv.exe => pomyślnie przeniesiono C:\Users\MAG\AppData\Roaming\certtmgr\aeevwcli.exe => pomyślnie przeniesiono "C:\Windows\system32\nvinitx.dll" => Dane wartości pomyślnie usunięto. ",C:\WINDOWS\system32\nvinitx.dll" => Dane wartości nie znaleziono. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MRT.exe" => klucz pomyślnie usunięto "C:\Program Files (x86)\SearchesToYesbnd" => nie znaleziono. C:\WINDOWS\system32\GroupPolicy\Machine => pomyślnie przeniesiono C:\WINDOWS\system32\GroupPolicy\GPT.ini => pomyślnie przeniesiono C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => pomyślnie przeniesiono HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Wartość pomyślnie przywrócono HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono HKU\S-1-5-21-2999985383-601964839-3280780558-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie usunięto "HKU\S-1-5-21-2999985383-601964839-3280780558-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FA9EC097-C43E-4767-866A-E31FA5272B20}" => klucz pomyślnie usunięto HKCR\CLSID\{FA9EC097-C43E-4767-866A-E31FA5272B20} => klucz nie znaleziono. HKU\S-1-5-21-2999985383-601964839-3280780558-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main\\HomeButtonPage => Wartość pomyślnie usunięto Firefox DefaultSearchEngine pomyślnie usunięto Firefox SearchEngineOrder.1 pomyślnie usunięto Firefox SelectedSearchEngine pomyślnie usunięto Firefox DefaultSearchEngine pomyślnie usunięto Firefox SearchEngineOrder.1 pomyślnie usunięto Firefox SelectedSearchEngine pomyślnie usunięto iThemes5 => serwis pomyślnie usunięto hklm\System\CurrentControlSet\Services\Themes\\DependOnService => Wartość pomyślnie usunięto NosemayP => Nie można zatrzymać usługi. NosemayP => serwis pomyślnie usunięto NosemayU => serwis pomyślnie usunięto "C:\Program Files (x86)\Nosemay" => nie znaleziono. C:\ProgramData\Nosemay => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1F357729-9984-4DAB-87F8-E84F39AF8EE7}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F357729-9984-4DAB-87F8-E84F39AF8EE7}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3DD526DA-F673-45CE-9002-14D1BC99DBD4}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DD526DA-F673-45CE-9002-14D1BC99DBD4}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\NosemayUpdateTaskMachineCore => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NosemayUpdateTaskMachineCore" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4E26A63E-55E5-48A4-9E07-B46D50710A89}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E26A63E-55E5-48A4-9E07-B46D50710A89}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4E77BBE4-2C07-47A4-B58F-2A23B9C6D037}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E77BBE4-2C07-47A4-B58F-2A23B9C6D037}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{52A92279-2FDA-4755-AAE5-DC6FE44B503B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52A92279-2FDA-4755-AAE5-DC6FE44B503B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7617830F-3E2E-4E14-BC84-8D8F0FDDD5BD}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7617830F-3E2E-4E14-BC84-8D8F0FDDD5BD}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7E519C3A-0D56-4C31-9AE4-5B2FBBD9429D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E519C3A-0D56-4C31-9AE4-5B2FBBD9429D}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{85097416-4841-491B-B87F-ABC07F723D5B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85097416-4841-491B-B87F-ABC07F723D5B}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8BDB08BD-4D81-4A04-9149-8E9C34024CA0}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BDB08BD-4D81-4A04-9149-8E9C34024CA0}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1314326-5C03-448B-B853-3FA02E67EE70}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1314326-5C03-448B-B853-3FA02E67EE70}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B1AD7971-CD5B-4CA2-AD61-92C25DD1FE39}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1AD7971-CD5B-4CA2-AD61-92C25DD1FE39}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\NosemayUpdateTaskMachineUA => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NosemayUpdateTaskMachineUA" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D03E6501-354B-426D-9A6E-FAE0898D99BC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D03E6501-354B-426D-9A6E-FAE0898D99BC}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D60BA628-7A6A-4E69-AB00-993837E0D6EB}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D60BA628-7A6A-4E69-AB00-993837E0D6EB}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => klucz pomyślnie usunięto "C:\Users\MAG\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Coldjob\Application\chrome.exe (Google Inc.)" => nie znaleziono. "C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Coldjob\Application\chrome.exe (Google Inc.)" => nie znaleziono. C:\Program Files (x86)\Coldjob => pomyślnie przeniesiono C:\Users\MAG\AppData\Local\Coldjob => pomyślnie przeniesiono "C:\Users\MAG\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk" => nie znaleziono. C:\Users\Public\Desktop\Mozilla Firefox.lnk => pomyślnie przeniesiono C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => pomyślnie przeniesiono ========= dir /a "C:\Program Files" ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\Program Files 2016-11-08 10:10 . 2016-11-08 10:10 .. 2016-02-29 18:23 Bonjour 2016-09-24 04:11 Common Files 2016-09-24 04:11 CONEXANT 2016-07-16 12:45 174 desktop.ini 2014-09-21 20:12 HP 2016-09-24 04:11 Intel 2016-10-17 11:33 Internet Explorer 2016-11-08 10:10 iPod 2016-11-08 10:12 iTunes 2014-09-03 01:12 Microsoft Analysis Services 2014-12-26 02:10 Microsoft Office 2016-10-17 13:50 Microsoft Silverlight 2016-09-24 04:10 MSBuild 2016-09-24 04:12 NVIDIA Corporation 2016-09-24 04:10 Reference Assemblies 2015-03-28 15:04 Rossmann 2016-09-24 03:59 Synaptics 2013-11-19 11:34 Toshiba 2015-07-10 13:21 Uninstall Information 2016-09-24 04:43 Windows Defender 2016-10-17 11:33 Windows Mail 2016-11-08 11:35 Windows Media Player 2016-07-16 12:47 Windows Multimedia Platform 2016-09-24 04:50 Windows NT 2016-10-17 11:33 Windows Photo Viewer 2016-07-16 12:47 Windows Portable Devices 2016-07-16 12:47 Windows Sidebar 2016-12-03 18:34 WindowsApps 2016-07-16 12:47 WindowsPowerShell 2015-05-05 07:14 WinRAR 1 File(s) 174 bytes 31 Dir(s) 388˙262˙051˙840 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\Program Files (x86) 2016-12-06 19:16 . 2016-12-06 19:16 .. 2015-07-08 18:36 Adobe 2015-01-06 16:58 AGEIA Technologies 2016-03-30 08:14 Apple Software Update 2013-11-19 11:28 Atheros 2016-11-08 09:54 Bedhat 2013-11-19 11:27 Bluetooth Suite 2016-02-29 18:23 Bonjour 2015-12-28 21:05 CDex_140b9 2016-09-24 04:12 Common Files 2016-10-19 12:38 Cupduck 2016-07-16 12:45 174 desktop.ini 2013-11-19 11:22 DTS, Inc 2013-11-19 11:42 eBay 2016-03-24 12:59 Google 2016-07-12 10:59 InstallShield Installation Information 2013-11-19 11:12 Intel 2016-10-17 11:33 Internet Explorer 2016-12-06 17:10 Kaspersky Lab 2014-09-03 02:54 McAfee 2016-12-05 11:30 0 metadata 2014-09-03 01:12 Microsoft Analysis Services 2014-10-26 20:05 Microsoft ASP.NET 2014-09-03 01:12 Microsoft Office 2016-10-17 13:50 Microsoft Silverlight 2016-09-24 04:12 Microsoft.NET 2014-12-25 17:02 MiniToolR Solution Ltd 2016-03-21 23:35 Mozilla Firefox 2016-03-21 23:35 Mozilla Maintenance Service 2016-09-24 04:10 MSBuild 2015-01-30 22:15 Network Print Monitor 2016-09-24 04:12 NVIDIA Corporation 2015-06-16 19:08 Opera 2016-09-24 04:10 Reference Assemblies 2016-12-05 11:30 reports 2016-07-12 11:01 Samsung 2016-12-05 11:30 40 settings.dat 2013-09-11 23:32 Spotify 2016-10-19 12:37 1˙560˙800 SSFK.exe 2014-12-25 16:52 The.Sims.4.2014.Digital.Deluxe.CRACKv6-UPDATEv2-3DM 2013-11-19 12:19 TOSHIBA 2013-11-19 12:09 TOSHIBA Games 2013-11-19 11:42 Toshiba TEMPRO 2014-09-21 20:01 TP-LINK 2016-09-24 03:58 Uninstall Information 2013-11-19 12:07 WildGames 2013-11-19 11:42 WildTangent Games 2016-09-24 04:43 Windows Defender 2016-09-24 04:12 Windows Mail 2016-11-08 11:35 Windows Media Player 2016-07-16 12:47 Windows Multimedia Platform 2016-07-16 12:47 Windows NT 2016-10-17 11:33 Windows Photo Viewer 2016-07-16 12:47 Windows Portable Devices 2016-07-16 12:47 Windows Sidebar 2016-07-16 12:47 WindowsPowerShell 4 File(s) 1˙561˙014 bytes 53 Dir(s) 388˙262˙035˙456 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files\Common Files\System" ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\Program Files\Common Files\System 2016-07-16 23:04 . 2016-07-16 23:04 .. 2016-07-16 23:04 ado 2016-07-16 12:43 32˙256 DirectDB.dll 2016-09-24 04:30 en-US 2016-07-16 23:04 msadc 2016-09-24 04:11 Ole DB 2016-07-16 23:04 pl-PL 2016-07-16 12:42 867˙840 wab32.dll 2016-07-16 12:42 964˙096 wab32res.dll 3 File(s) 1˙864˙192 bytes 7 Dir(s) 388˙262˙035˙456 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files\System" ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\Program Files (x86)\Common Files\System 2016-07-16 23:04 . 2016-07-16 23:04 .. 2016-07-16 23:04 ado 2016-07-16 12:43 28˙160 DirectDB.dll 2016-09-24 04:30 en-US 2016-07-16 23:04 msadc 2016-10-17 11:33 Ole DB 2016-07-16 23:04 pl-PL 2016-07-16 12:42 753˙152 wab32.dll 2016-07-16 12:42 964˙096 wab32res.dll 3 File(s) 1˙745˙408 bytes 7 Dir(s) 388˙262˙035˙456 bytes free ========= Koniec CMD: ========= ========= dir /a C:\ProgramData ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\ProgramData 2016-12-06 19:16 . 2016-12-06 19:16 .. 2015-07-08 18:36 Adobe 2015-04-30 12:21 Apple 2015-04-30 12:23 Apple Computer 2016-07-16 12:47 Comms 2016-09-24 04:12 Conexant 2014-09-02 23:58 Dane aplikacji [C:\ProgramData] 2014-09-02 23:58 Dokumenty [C:\Users\Public\Documents] 2015-07-21 19:18 E1864A66-75E3-486a-BD95-D1B7D99A84A7 2016-11-08 12:39 fibfi 2016-12-01 11:13 ficfi 2016-11-08 09:53 hadga 2016-11-10 12:14 hbeha 2014-12-10 15:41 hps 2016-12-01 11:13 icfib 2013-11-19 11:20 Intel 2016-10-21 18:04 jcfic 2016-11-15 22:27 jdgjc 2016-12-06 19:16 Kaspersky Lab 2016-12-06 17:21 Kaspersky Lab Setup Files 2014-12-06 22:24 Local Settings 2014-09-03 02:54 McAfee 2014-09-02 23:58 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2016-11-08 09:54 Microsoft 2016-11-09 11:15 Microsoft Help 2016-09-24 04:55 Microsoft OneDrive 2014-09-03 01:44 Mozilla 2016-12-06 16:38 8˙192 ntuser.dat 2016-12-06 16:38 8˙192 ntuser.dat.LOG1 2016-12-06 16:38 0 ntuser.dat.LOG2 2016-12-06 16:38 65˙536 ntuser.dat{409dcc59-bb94-11e6-8620-a4db30fa5aba}.TM.blf 2016-12-06 16:38 524˙288 ntuser.dat{409dcc59-bb94-11e6-8620-a4db30fa5aba}.TMContainer00000000000000000001.regtrans-ms 2016-12-06 16:38 524˙288 ntuser.dat{409dcc59-bb94-11e6-8620-a4db30fa5aba}.TMContainer00000000000000000002.regtrans-ms 2016-09-24 11:17 266 ntuser.pol 2016-09-24 03:58 NVIDIA 2016-09-24 04:12 NVIDIA Corporation 2014-09-25 13:28 Origin 2015-02-12 22:43 Package Cache 2014-09-02 23:58 Pulpit [C:\Users\Public\Desktop] 2013-11-19 11:28 Qualcomm Atheros 2016-09-24 04:18 regid.1991-06.com.microsoft 2016-07-12 11:01 Samsung 2016-07-16 12:47 SoftwareDistribution 2013-11-19 11:22 SRS Labs 2014-09-02 23:58 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2014-12-10 15:13 tmp 2014-09-03 00:19 Toshiba 2014-09-03 00:18 ToshibaEurope 2016-12-01 11:14 ttff 2016-09-24 04:52 USOPrivate 2016-09-24 04:52 USOShared 2013-11-19 12:08 WildTangent 7 File(s) 1˙130˙762 bytes 46 Dir(s) 388˙262˙031˙360 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\MAG\AppData\Local ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\Users\MAG\AppData\Local 2016-12-06 19:16 . 2016-12-06 19:16 .. 2016-02-07 05:11 ActiveSync 2016-10-16 12:21 Adobe 2015-04-30 12:22 Apple 2016-03-30 08:09 Apple Computer 2016-11-08 12:40 Bedhat 2015-07-16 10:04 CEF 2015-08-30 22:36 Comms 2016-09-24 11:24 ConnectedDevicesPlatform 2016-06-14 14:23 Cupduck 2016-09-24 04:06 Dane aplikacji [C:\Users\MAG\AppData\Local] 2016-04-10 12:15 Diagnostics 2016-07-12 10:58 Downloaded Installations 2015-06-16 19:08 EmieBrowserModeList 2015-06-16 19:08 EmieSiteList 2015-06-16 19:08 EmieUserList 2016-02-12 07:41 F727A298-4DB4-456A-AC54-A93EA5F8554D 2016-10-19 12:44 Firefox 2016-11-11 07:18 Google 2015-06-03 06:46 GWX 2016-09-24 04:06 Historia [C:\Users\MAG\AppData\Local\Microsoft\Windows\History] 2016-12-06 17:21 153˙771 IconCache.db 2015-06-10 16:07 Intel_Corporation 2014-09-03 03:08 Macromedia 2016-09-25 09:19 Microsoft 2014-09-03 01:12 Microsoft Help 2015-09-24 11:11 MicrosoftEdge 2014-09-03 01:44 Mozilla 2015-10-17 13:04 NetworkTiles 2014-09-21 19:03 NVIDIA 2014-09-21 19:02 NVIDIA Corporation 2015-06-16 06:59 Opera Software 2016-12-03 18:32 Packages 2014-12-25 18:10 Programs 2015-08-30 22:37 Publishers 2016-07-12 11:03 Samsung 2016-12-06 19:16 Temp 2016-09-24 04:06 Temporary Internet Files [C:\Users\MAG\AppData\Local\Microsoft\Windows\INetCache] 2015-08-30 22:31 TileDataLayer 2014-09-03 00:18 TOSHIBA 2015-12-28 21:06 VirtualStore 1 File(s) 153˙771 bytes 41 Dir(s) 388˙262˙027˙264 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\MAG\AppData\LocalLow ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\Users\MAG\AppData\LocalLow 2015-07-16 10:07 . 2015-07-16 10:07 .. 2015-04-10 12:17 Adobe 2015-01-06 17:46 EmieBrowserModeList 2016-07-15 09:12 EmieSiteList 2016-07-15 09:12 EmieUserList 2015-03-28 14:32 Microsoft 2015-07-16 10:07 Temp 0 File(s) 0 bytes 8 Dir(s) 388˙262˙027˙264 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\MAG\AppData\Roaming ========= Volume in drive C is TI31202900A Volume Serial Number is 78F4-8EAA Directory of C:\Users\MAG\AppData\Roaming 2016-12-06 19:16 . 2016-12-06 19:16 .. 2015-07-08 18:52 Adobe 2016-03-30 08:26 Apple Computer 2016-12-06 19:16 cabitons 2016-12-06 19:16 cdprtcli 2016-12-06 19:16 certtmgr 2016-12-06 19:16 ChakgIME 2016-12-06 19:16 charclb 2016-12-06 19:16 charis-2 2016-12-06 19:16 clbonfg 2016-12-06 19:16 cmluutil 2016-10-19 12:38 Firefox 2014-12-26 02:19 GHISLER 2016-12-01 11:13 ibfib 2016-02-29 17:20 Identities 2016-02-02 00:38 KasperskyUpgradeLogs 2014-09-03 01:42 Macromedia 2014-12-26 02:19 MFP and Storage Server 2016-12-05 21:36 Microsoft 2014-09-03 01:44 Mozilla 2015-04-10 12:00 NVIDIA 2015-06-16 06:59 Opera Software 2016-07-12 11:03 Samsung 2014-12-17 22:21 Se 2016-09-19 18:13 setup1 2016-08-27 23:28 Skype 2015-03-22 17:59 sMedio 2015-01-19 18:24 Tweman 2014-09-03 01:08 WinRAR 0 File(s) 0 bytes 30 Dir(s) 388˙262˙023˙168 bytes free ========= Koniec CMD: ========= "C:\Windows\System32\Drivers\etc\hosts" => Nie można przenieść. Nie można przywrócić Hosts. =========== EmptyTemp: ========== BITS transfer queue => 32768 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12262521 B Java, Flash, Steam htmlcache => 69493 B Windows/system/drivers => 10819984 B Edge => 164395822 B Chrome => 0 B Firefox => 385569536 B Opera => 12787136 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 850631 B NetworkService => 15596 B MAG => 116585084 B RecycleBin => 0 B EmptyTemp: => 670.8 MB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 19:34:53 ====