Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 07-12-2016 Uruchomiony przez Dom (12-12-2016 16:09:29) Run:1 Uruchomiony z C:\Users\Dom\Desktop Załadowane profile: Dom (Dostępne profile: Dom) Tryb startu: Normal ============================================== fixlist - zawartość: ***************** CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [win_en_77] => [X] AutoConfigURL: [S-1-5-21-2293639786-2994818483-2183426564-1001] => hxxp://stoppblock.org/wpad.dat?4392482e72d26e5e142518eb8af879d514536945 ManualProxies: 0hxxp://stoppblock.org/wpad.dat?4392482e72d26e5e142518eb8af879d514536945 S3 Origin Client Service; "C:\Program Files (x86)\Origin\OriginClientService.exe" [X] S2 Origin Web Helper Service; "C:\Program Files (x86)\Origin\OriginWebHelperService.exe" [X] R1 UCGuard; C:\WINDOWS\System32\DRIVERS\ucguard.sys [81792 2016-08-02] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== UWAGA S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X] 2016-07-30 12:48 - 2016-07-30 12:48 - 7129600 _____ () C:\Users\Dom\AppData\Roaming\agent.dat 2016-07-30 12:48 - 2016-07-30 12:48 - 0067968 _____ () C:\Users\Dom\AppData\Roaming\Config.xml 2016-07-30 12:48 - 2016-07-30 12:48 - 2279413 _____ () C:\Users\Dom\AppData\Roaming\Freshlight.bin 2016-07-30 12:47 - 2016-07-30 12:48 - 0014400 _____ () C:\Users\Dom\AppData\Roaming\InstallationConfiguration.xml 2016-07-30 12:47 - 2016-07-30 12:47 - 0129024 _____ () C:\Users\Dom\AppData\Roaming\Installer.dat 2016-07-30 12:48 - 2016-07-30 12:48 - 0018432 _____ () C:\Users\Dom\AppData\Roaming\Main.dat 2016-07-30 12:48 - 2016-07-30 12:47 - 0683520 _____ () C:\Users\Dom\AppData\Roaming\MatHotex.exe 2016-07-30 12:48 - 2016-07-30 12:48 - 1903257 _____ () C:\Users\Dom\AppData\Roaming\MatHotex.tst 2016-07-30 12:48 - 2016-07-30 12:48 - 0005568 _____ () C:\Users\Dom\AppData\Roaming\md.xml 2016-07-30 12:48 - 2016-07-30 12:48 - 0126464 _____ () C:\Users\Dom\AppData\Roaming\noah.dat Task: {014AE0B8-ECE3-4DB4-BF80-5B68E369F052} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== UWAGA Task: C:\WINDOWS\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== UWAGA C:\Program Files (x86)\UCBrowser Task: {7878945C-058E-483B-BE81-EC762C0F86FF} - System32\Tasks\ComputerZLite => C:\Program Files (x86)\LdsLite\LdsLite.exe <==== UWAGA C:\Program Files (x86)\LdsLite Task: {5EA3EDBA-53A2-47E6-AE95-BC6E3BA18E65} - System32\Tasks\{FBDA17B3-D69F-4DF1-B7AA-55A6800E8C60} => pcalua.exe -a "C:\Program Files\SpaceSoundPro\uninstaller.exe" C:\Program Files\SpaceSoundPro WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA ShortcutWithArgument: C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Dom\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabests.cc ShortcutWithArgument: C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Dom\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabests.cc ShortcutWithArgument: C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Dom\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabests.cc ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://yeabests.cc CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Dom\AppData\Local CMD: dir /a C:\Users\Dom\AppData\LocalLow CMD: dir /a C:\Users\Dom\AppData\Roaming Hosts: RemoveProxy: EmptyTemp: ***************** Procesy zostały pomyślnie zamknięte. Punkt przywracania został pomyślnie utworzony. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\win_en_77 => Wartość pomyślnie usunięto HKU\S-1-5-21-2293639786-2994818483-2183426564-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => Wartość pomyślnie usunięto HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => Wartość pomyślnie usunięto Origin Client Service => serwis pomyślnie usunięto Origin Web Helper Service => serwis pomyślnie usunięto UCGuard => Nie można zatrzymać usługi. UCGuard => serwis pomyślnie usunięto WinRing0_1_2_0 => serwis pomyślnie usunięto C:\Users\Dom\AppData\Roaming\agent.dat => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\Config.xml => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\Freshlight.bin => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\InstallationConfiguration.xml => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\Installer.dat => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\Main.dat => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\MatHotex.exe => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\MatHotex.tst => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\md.xml => pomyślnie przeniesiono C:\Users\Dom\AppData\Roaming\noah.dat => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{014AE0B8-ECE3-4DB4-BF80-5B68E369F052}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{014AE0B8-ECE3-4DB4-BF80-5B68E369F052}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\UCBrowserUpdater => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserUpdater" => klucz pomyślnie usunięto C:\WINDOWS\Tasks\UCBrowserUpdater.job => pomyślnie przeniesiono "C:\Program Files (x86)\UCBrowser" => nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7878945C-058E-483B-BE81-EC762C0F86FF}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7878945C-058E-483B-BE81-EC762C0F86FF}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\ComputerZLite => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ComputerZLite" => klucz pomyślnie usunięto "C:\Program Files (x86)\LdsLite" => nie znaleziono. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5EA3EDBA-53A2-47E6-AE95-BC6E3BA18E65}" => klucz pomyślnie usunięto "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EA3EDBA-53A2-47E6-AE95-BC6E3BA18E65}" => klucz pomyślnie usunięto C:\WINDOWS\System32\Tasks\{FBDA17B3-D69F-4DF1-B7AA-55A6800E8C60} => pomyślnie przeniesiono "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FBDA17B3-D69F-4DF1-B7AA-55A6800E8C60}" => klucz pomyślnie usunięto "C:\Program Files\SpaceSoundPro" => nie znaleziono. WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA => pomyślnie usunięto C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Skrót - argument pomyślnie usunięto. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto. ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\Program Files 10.12.2016 16:28 . 10.12.2016 16:28 .. 22.06.2016 17:09 7-Zip 26.09.2016 20:03 AMD 28.10.2016 18:28 ATI Technologies 14.09.2016 18:49 CanonBJ 10.12.2016 16:28 CCleaner 26.09.2016 20:03 Common Files 05.12.2016 21:19 DAEMON Tools Lite 10.12.2016 12:39 Defraggler 16.07.2016 12:45 174 desktop.ini 08.12.2016 09:25 GIMP 2 10.12.2016 12:29 Internet Explorer 03.11.2016 16:54 Java 26.09.2016 20:54 MSBuild 26.09.2016 20:54 Reference Assemblies 22.06.2016 15:40 Uninstall Information 27.09.2016 09:17 Windows Defender 12.10.2016 14:14 Windows Mail 28.10.2016 20:52 Windows Media Player 16.07.2016 12:47 Windows Multimedia Platform 26.09.2016 20:09 Windows NT 12.10.2016 14:14 Windows Photo Viewer 16.07.2016 12:47 Windows Portable Devices 16.07.2016 12:47 Windows Sidebar 09.12.2016 14:34 WindowsApps 16.07.2016 12:47 WindowsPowerShell 1 File(s) 174 bytes 26 Dir(s) 86˙719˙004˙672 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\Program Files (x86) 11.12.2016 15:32 . 11.12.2016 15:32 .. 26.09.2016 20:04 AMD 22.06.2016 16:20 ASM104xUSB3 23.11.2016 08:32 BRS 06.12.2016 17:35 Common Files 16.07.2016 12:45 174 desktop.ini 22.06.2016 16:03 Google 11.12.2016 15:32 InstallShield Installation Information 10.12.2016 12:29 Internet Explorer 13.11.2016 10:27 Java 08.12.2016 09:17 LibreOffice 5 16.07.2016 12:47 Microsoft.NET 13.11.2016 10:28 Mozilla Firefox 15.10.2016 19:57 Mozilla Maintenance Service 26.09.2016 20:54 MSBuild 23.11.2016 08:32 OpenAL 13.11.2016 10:28 OpenOffice.org 3 26.09.2016 20:54 Reference Assemblies 11.12.2016 15:32 Softronics 22.06.2016 16:15 VulkanRT 27.09.2016 09:17 Windows Defender 27.09.2016 09:17 Windows Mail 28.10.2016 20:52 Windows Media Player 16.07.2016 12:47 Windows Multimedia Platform 16.07.2016 12:47 Windows NT 12.10.2016 14:14 Windows Photo Viewer 16.07.2016 12:47 Windows Portable Devices 16.07.2016 12:47 Windows Sidebar 16.07.2016 12:47 WindowsPowerShell 13.11.2016 14:45 WinRAR 1 File(s) 174 bytes 30 Dir(s) 86˙718˙930˙944 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files\Common Files\System" ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\Program Files\Common Files\System 16.07.2016 23:04 . 16.07.2016 23:04 .. 16.07.2016 23:04 ado 16.07.2016 12:43 32˙256 DirectDB.dll 16.07.2016 23:04 en-US 16.07.2016 23:04 msadc 16.07.2016 23:04 Ole DB 16.07.2016 23:04 pl-PL 16.07.2016 12:42 867˙840 wab32.dll 16.07.2016 12:42 964˙096 wab32res.dll 3 File(s) 1˙864˙192 bytes 7 Dir(s) 86˙718˙935˙040 bytes free ========= Koniec CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files\System" ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\Program Files (x86)\Common Files\System 16.07.2016 23:04 . 16.07.2016 23:04 .. 16.07.2016 23:04 ado 16.07.2016 12:43 28˙160 DirectDB.dll 16.07.2016 23:04 en-US 16.07.2016 23:04 msadc 29.09.2016 18:37 Ole DB 16.07.2016 23:04 pl-PL 16.07.2016 12:42 753˙152 wab32.dll 16.07.2016 12:42 964˙096 wab32res.dll 3 File(s) 1˙745˙408 bytes 7 Dir(s) 86˙718˙930˙944 bytes free ========= Koniec CMD: ========= ========= dir /a C:\ProgramData ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\ProgramData 08.12.2016 15:41 . 08.12.2016 15:41 .. 30.10.2016 21:09 AMD 22.06.2016 16:14 ATI 16.08.2016 11:06 AVAST Software 04.07.2016 10:55 CanonBJ 23.11.2016 08:35 Codemasters 16.07.2016 12:47 Comms 05.12.2016 21:18 DAEMON Tools Lite 22.06.2016 21:36 Dane aplikacji [C:\ProgramData] 22.06.2016 21:36 Dokumenty [C:\Users\Public\Documents] 23.11.2016 08:35 DSS 13.09.2016 21:17 Electronic Arts 28.08.2016 14:41 GFACE 14.09.2016 18:39 HP 06.10.2016 19:39 IObit 22.06.2016 21:36 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 03.12.2016 22:29 Microsoft 26.09.2016 20:11 Microsoft OneDrive 03.11.2016 16:54 Oracle 04.12.2016 16:56 Origin 26.09.2016 20:03 Package Cache 22.06.2016 21:36 Pulpit [C:\Users\Public\Desktop] 26.09.2016 20:04 regid.1991-06.com.microsoft 23.06.2016 07:14 Riot Games 08.12.2016 15:41 SecuROM 16.07.2016 12:47 SoftwareDistribution 22.06.2016 21:36 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 26.09.2016 20:10 USOPrivate 26.09.2016 20:10 USOShared 0 File(s) 0 bytes 30 Dir(s) 86˙718˙926˙848 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\Dom\AppData\Local ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\Users\Dom\AppData\Local 11.12.2016 16:07 . 11.12.2016 16:07 .. 22.06.2016 15:47 ActiveSync 28.10.2016 18:28 AMD 16.08.2016 11:06 Anerdward 17.09.2016 13:43 Apps 22.06.2016 16:14 ATI 22.06.2016 18:07 CEF 22.06.2016 16:04 Comms 26.09.2016 20:20 ConnectedDevicesPlatform 24.08.2016 15:14 CrashRpt 26.09.2016 20:02 Dane aplikacji [C:\Users\Dom\AppData\Local] 04.12.2016 16:47 Diagnostics 05.12.2016 21:19 Disc_Soft_Ltd 17.10.2016 17:35 ElevatedDiagnostics 08.12.2016 09:26 fontconfig 08.12.2016 09:26 gegl-0.2 04.11.2016 21:15 Google 26.09.2016 20:02 Historia [C:\Users\Dom\AppData\Local\Microsoft\Windows\History] 11.12.2016 21:14 166˙412 IconCache.db 08.12.2016 15:46 Microsoft 22.06.2016 15:58 MicrosoftEdge 25.11.2016 10:03 Mozilla 14.09.2016 18:08 Origin 03.12.2016 11:33 Packages 30.07.2016 11:57 Programs 22.06.2016 15:47 Publishers 08.12.2016 09:43 2˙082 recently-used.xbel 03.12.2016 22:30 17 resmon.resmoncfg 08.12.2016 15:41 Rockstar Games 27.08.2016 13:40 speech 22.06.2016 18:07 Steam 12.12.2016 16:09 Temp 16.08.2016 11:12 Tempfolder 26.09.2016 20:02 Temporary Internet Files [C:\Users\Dom\AppData\Local\Microsoft\Windows\INetCache] 22.06.2016 15:46 TileDataLayer 16.08.2016 11:41 UCBrowser 17.09.2016 13:43 Unity 06.11.2016 17:39 VirtualStore 28.08.2016 15:08 wf-launcher 3 File(s) 168˙511 bytes 37 Dir(s) 86˙718˙926˙848 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\Dom\AppData\LocalLow ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\Users\Dom\AppData\LocalLow 05.12.2016 18:21 . 05.12.2016 18:21 .. 28.10.2016 18:28 AMD 16.08.2016 11:12 Company 17.09.2016 15:12 Microsoft 03.11.2016 16:54 Oracle 03.11.2016 16:54 Sun 17.09.2016 15:12 Temp 17.09.2016 13:43 Unity 08.12.2016 08:03 uTorrent 0 File(s) 0 bytes 10 Dir(s) 86˙718˙926˙848 bytes free ========= Koniec CMD: ========= ========= dir /a C:\Users\Dom\AppData\Roaming ========= Volume in drive C has no label. Volume Serial Number is 46B4-4BEF Directory of C:\Users\Dom\AppData\Roaming 12.12.2016 16:09 . 12.12.2016 16:09 .. 28.08.2010 21:43 96˙256 AdbWinApi.dll 28.08.2010 21:43 60˙928 AdbWinUsbApi.dll 22.06.2016 15:46 Adobe 22.06.2016 16:14 ATI 10.12.2016 16:29 DAEMON Tools Lite 28.06.2016 02:12 314˙434 EYapp.apk 11.08.2016 12:37 Grupa IMAGE 16.08.2016 11:12 Hemkajdoa 08.12.2016 09:18 LibreOffice 23.06.2016 09:22 LolClient 23.06.2016 09:23 Macromedia 01.07.2016 10:19 8˙284˙704 MaoHaWiFiSetup_262.exe 27.09.2016 16:59 Microsoft 30.06.2016 15:37 Milestone 15.10.2016 19:57 Mozilla 13.11.2016 10:28 OpenOffice.org 27.11.2016 18:51 Origin 16.08.2016 11:06 Profiles 23.06.2016 07:12 Riot Games 08.12.2016 15:10 SecuROM 27.08.2016 19:32 7˙616˙340 setup.apk 26.09.2016 20:12 Skype 03.11.2016 16:54 Sun 22.06.2016 17:52 TeamViewer 08.12.2016 16:42 TS3Client 30.07.2016 12:48 32˙038 uninstall_temp.ico 10.12.2016 16:29 uTorrent 30.08.2016 18:55 Wargaming.net 13.11.2016 14:45 WinRAR 6 File(s) 16˙404˙700 bytes 25 Dir(s) 86˙718˙922˙752 bytes free ========= Koniec CMD: ========= C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono Hosts pomyślnie przywrócono. ========= RemoveProxy: ========= HKU\S-1-5-21-2293639786-2994818483-2183426564-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wartość pomyślnie usunięto HKU\S-1-5-21-2293639786-2994818483-2183426564-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wartość pomyślnie usunięto ========= Koniec RemoveProxy: ========= =========== EmptyTemp: ========== BITS transfer queue => 3338048 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 66138796 B Java, Flash, Steam htmlcache => 49165451 B Windows/system/drivers => 75774 B Edge => 9932679 B Chrome => 228050492 B Firefox => 7959409 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 6656 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 4138 B NetworkService => 0 B Dom => 19427530 B RecycleBin => 1933748 B EmptyTemp: => 368.1 MB danych tymczasowych Usunięto. ================================ System wymagał restartu. ==== Koniec Fixlog 16:10:01 ====