Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 07-12-2016
Uruchomiony przez Dom (12-12-2016 16:09:29) Run:1
Uruchomiony z C:\Users\Dom\Desktop
Załadowane profile: Dom (Dostępne profile: Dom)
Tryb startu: Normal
==============================================
fixlist - zawartość:
*****************
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [win_en_77] => [X]
AutoConfigURL: [S-1-5-21-2293639786-2994818483-2183426564-1001] => hxxp://stoppblock.org/wpad.dat?4392482e72d26e5e142518eb8af879d514536945
ManualProxies: 0hxxp://stoppblock.org/wpad.dat?4392482e72d26e5e142518eb8af879d514536945
S3 Origin Client Service; "C:\Program Files (x86)\Origin\OriginClientService.exe" [X]
S2 Origin Web Helper Service; "C:\Program Files (x86)\Origin\OriginWebHelperService.exe" [X]
R1 UCGuard; C:\WINDOWS\System32\DRIVERS\ucguard.sys [81792 2016-08-02] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== UWAGA
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
2016-07-30 12:48 - 2016-07-30 12:48 - 7129600 _____ () C:\Users\Dom\AppData\Roaming\agent.dat
2016-07-30 12:48 - 2016-07-30 12:48 - 0067968 _____ () C:\Users\Dom\AppData\Roaming\Config.xml
2016-07-30 12:48 - 2016-07-30 12:48 - 2279413 _____ () C:\Users\Dom\AppData\Roaming\Freshlight.bin
2016-07-30 12:47 - 2016-07-30 12:48 - 0014400 _____ () C:\Users\Dom\AppData\Roaming\InstallationConfiguration.xml
2016-07-30 12:47 - 2016-07-30 12:47 - 0129024 _____ () C:\Users\Dom\AppData\Roaming\Installer.dat
2016-07-30 12:48 - 2016-07-30 12:48 - 0018432 _____ () C:\Users\Dom\AppData\Roaming\Main.dat
2016-07-30 12:48 - 2016-07-30 12:47 - 0683520 _____ () C:\Users\Dom\AppData\Roaming\MatHotex.exe
2016-07-30 12:48 - 2016-07-30 12:48 - 1903257 _____ () C:\Users\Dom\AppData\Roaming\MatHotex.tst
2016-07-30 12:48 - 2016-07-30 12:48 - 0005568 _____ () C:\Users\Dom\AppData\Roaming\md.xml
2016-07-30 12:48 - 2016-07-30 12:48 - 0126464 _____ () C:\Users\Dom\AppData\Roaming\noah.dat
Task: {014AE0B8-ECE3-4DB4-BF80-5B68E369F052} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== UWAGA
Task: C:\WINDOWS\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== UWAGA
C:\Program Files (x86)\UCBrowser
Task: {7878945C-058E-483B-BE81-EC762C0F86FF} - System32\Tasks\ComputerZLite => C:\Program Files (x86)\LdsLite\LdsLite.exe <==== UWAGA
C:\Program Files (x86)\LdsLite
Task: {5EA3EDBA-53A2-47E6-AE95-BC6E3BA18E65} - System32\Tasks\{FBDA17B3-D69F-4DF1-B7AA-55A6800E8C60} => pcalua.exe -a "C:\Program Files\SpaceSoundPro\uninstaller.exe"
C:\Program Files\SpaceSoundPro
WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA
ShortcutWithArgument: C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Dom\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabests.cc
ShortcutWithArgument: C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Dom\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabests.cc
ShortcutWithArgument: C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Dom\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://yeabests.cc
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://yeabests.cc
CMD: dir /a "C:\Program Files"
CMD: dir /a "C:\Program Files (x86)"
CMD: dir /a "C:\Program Files\Common Files\System"
CMD: dir /a "C:\Program Files (x86)\Common Files\System"
CMD: dir /a C:\ProgramData
CMD: dir /a C:\Users\Dom\AppData\Local
CMD: dir /a C:\Users\Dom\AppData\LocalLow
CMD: dir /a C:\Users\Dom\AppData\Roaming
Hosts:
RemoveProxy:
EmptyTemp:
*****************
Procesy zostały pomyślnie zamknięte.
Punkt przywracania został pomyślnie utworzony.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\win_en_77 => Wartość pomyślnie usunięto
HKU\S-1-5-21-2293639786-2994818483-2183426564-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => Wartość pomyślnie usunięto
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => Wartość pomyślnie usunięto
Origin Client Service => serwis pomyślnie usunięto
Origin Web Helper Service => serwis pomyślnie usunięto
UCGuard => Nie można zatrzymać usługi.
UCGuard => serwis pomyślnie usunięto
WinRing0_1_2_0 => serwis pomyślnie usunięto
C:\Users\Dom\AppData\Roaming\agent.dat => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\Config.xml => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\Freshlight.bin => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\InstallationConfiguration.xml => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\Installer.dat => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\Main.dat => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\MatHotex.exe => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\MatHotex.tst => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\md.xml => pomyślnie przeniesiono
C:\Users\Dom\AppData\Roaming\noah.dat => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{014AE0B8-ECE3-4DB4-BF80-5B68E369F052}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{014AE0B8-ECE3-4DB4-BF80-5B68E369F052}" => klucz pomyślnie usunięto
C:\WINDOWS\System32\Tasks\UCBrowserUpdater => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserUpdater" => klucz pomyślnie usunięto
C:\WINDOWS\Tasks\UCBrowserUpdater.job => pomyślnie przeniesiono
"C:\Program Files (x86)\UCBrowser" => nie znaleziono.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7878945C-058E-483B-BE81-EC762C0F86FF}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7878945C-058E-483B-BE81-EC762C0F86FF}" => klucz pomyślnie usunięto
C:\WINDOWS\System32\Tasks\ComputerZLite => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ComputerZLite" => klucz pomyślnie usunięto
"C:\Program Files (x86)\LdsLite" => nie znaleziono.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5EA3EDBA-53A2-47E6-AE95-BC6E3BA18E65}" => klucz pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EA3EDBA-53A2-47E6-AE95-BC6E3BA18E65}" => klucz pomyślnie usunięto
C:\WINDOWS\System32\Tasks\{FBDA17B3-D69F-4DF1-B7AA-55A6800E8C60} => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FBDA17B3-D69F-4DF1-B7AA-55A6800E8C60}" => klucz pomyślnie usunięto
"C:\Program Files\SpaceSoundPro" => nie znaleziono.
WMI_ActiveScriptEventConsumer_ASEC: <===== UWAGA => pomyślnie usunięto
C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Skrót - argument pomyślnie usunięto.
C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => Skrót - argument pomyślnie usunięto.
C:\Users\Dom\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk => Skrót - argument pomyślnie usunięto.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Skrót - argument pomyślnie usunięto.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Skrót - argument pomyślnie usunięto.
========= dir /a "C:\Program Files" =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\Program Files
10.12.2016 16:28
.
10.12.2016 16:28 ..
22.06.2016 17:09 7-Zip
26.09.2016 20:03 AMD
28.10.2016 18:28 ATI Technologies
14.09.2016 18:49 CanonBJ
10.12.2016 16:28 CCleaner
26.09.2016 20:03 Common Files
05.12.2016 21:19 DAEMON Tools Lite
10.12.2016 12:39 Defraggler
16.07.2016 12:45 174 desktop.ini
08.12.2016 09:25 GIMP 2
10.12.2016 12:29 Internet Explorer
03.11.2016 16:54 Java
26.09.2016 20:54 MSBuild
26.09.2016 20:54 Reference Assemblies
22.06.2016 15:40 Uninstall Information
27.09.2016 09:17 Windows Defender
12.10.2016 14:14 Windows Mail
28.10.2016 20:52 Windows Media Player
16.07.2016 12:47 Windows Multimedia Platform
26.09.2016 20:09 Windows NT
12.10.2016 14:14 Windows Photo Viewer
16.07.2016 12:47 Windows Portable Devices
16.07.2016 12:47 Windows Sidebar
09.12.2016 14:34 WindowsApps
16.07.2016 12:47 WindowsPowerShell
1 File(s) 174 bytes
26 Dir(s) 86˙719˙004˙672 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files (x86)" =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\Program Files (x86)
11.12.2016 15:32 .
11.12.2016 15:32 ..
26.09.2016 20:04 AMD
22.06.2016 16:20 ASM104xUSB3
23.11.2016 08:32 BRS
06.12.2016 17:35 Common Files
16.07.2016 12:45 174 desktop.ini
22.06.2016 16:03 Google
11.12.2016 15:32 InstallShield Installation Information
10.12.2016 12:29 Internet Explorer
13.11.2016 10:27 Java
08.12.2016 09:17 LibreOffice 5
16.07.2016 12:47 Microsoft.NET
13.11.2016 10:28 Mozilla Firefox
15.10.2016 19:57 Mozilla Maintenance Service
26.09.2016 20:54 MSBuild
23.11.2016 08:32 OpenAL
13.11.2016 10:28 OpenOffice.org 3
26.09.2016 20:54 Reference Assemblies
11.12.2016 15:32 Softronics
22.06.2016 16:15 VulkanRT
27.09.2016 09:17 Windows Defender
27.09.2016 09:17 Windows Mail
28.10.2016 20:52 Windows Media Player
16.07.2016 12:47 Windows Multimedia Platform
16.07.2016 12:47 Windows NT
12.10.2016 14:14 Windows Photo Viewer
16.07.2016 12:47 Windows Portable Devices
16.07.2016 12:47 Windows Sidebar
16.07.2016 12:47 WindowsPowerShell
13.11.2016 14:45 WinRAR
1 File(s) 174 bytes
30 Dir(s) 86˙718˙930˙944 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files\Common Files\System" =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\Program Files\Common Files\System
16.07.2016 23:04 .
16.07.2016 23:04 ..
16.07.2016 23:04 ado
16.07.2016 12:43 32˙256 DirectDB.dll
16.07.2016 23:04 en-US
16.07.2016 23:04 msadc
16.07.2016 23:04 Ole DB
16.07.2016 23:04 pl-PL
16.07.2016 12:42 867˙840 wab32.dll
16.07.2016 12:42 964˙096 wab32res.dll
3 File(s) 1˙864˙192 bytes
7 Dir(s) 86˙718˙935˙040 bytes free
========= Koniec CMD: =========
========= dir /a "C:\Program Files (x86)\Common Files\System" =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\Program Files (x86)\Common Files\System
16.07.2016 23:04 .
16.07.2016 23:04 ..
16.07.2016 23:04 ado
16.07.2016 12:43 28˙160 DirectDB.dll
16.07.2016 23:04 en-US
16.07.2016 23:04 msadc
29.09.2016 18:37 Ole DB
16.07.2016 23:04 pl-PL
16.07.2016 12:42 753˙152 wab32.dll
16.07.2016 12:42 964˙096 wab32res.dll
3 File(s) 1˙745˙408 bytes
7 Dir(s) 86˙718˙930˙944 bytes free
========= Koniec CMD: =========
========= dir /a C:\ProgramData =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\ProgramData
08.12.2016 15:41 .
08.12.2016 15:41 ..
30.10.2016 21:09 AMD
22.06.2016 16:14 ATI
16.08.2016 11:06 AVAST Software
04.07.2016 10:55 CanonBJ
23.11.2016 08:35 Codemasters
16.07.2016 12:47 Comms
05.12.2016 21:18 DAEMON Tools Lite
22.06.2016 21:36 Dane aplikacji [C:\ProgramData]
22.06.2016 21:36 Dokumenty [C:\Users\Public\Documents]
23.11.2016 08:35 DSS
13.09.2016 21:17 Electronic Arts
28.08.2016 14:41 GFACE
14.09.2016 18:39 HP
06.10.2016 19:39 IObit
22.06.2016 21:36 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu]
03.12.2016 22:29 Microsoft
26.09.2016 20:11 Microsoft OneDrive
03.11.2016 16:54 Oracle
04.12.2016 16:56 Origin
26.09.2016 20:03 Package Cache
22.06.2016 21:36 Pulpit [C:\Users\Public\Desktop]
26.09.2016 20:04 regid.1991-06.com.microsoft
23.06.2016 07:14 Riot Games
08.12.2016 15:41 SecuROM
16.07.2016 12:47 SoftwareDistribution
22.06.2016 21:36 Szablony [C:\ProgramData\Microsoft\Windows\Templates]
26.09.2016 20:10 USOPrivate
26.09.2016 20:10 USOShared
0 File(s) 0 bytes
30 Dir(s) 86˙718˙926˙848 bytes free
========= Koniec CMD: =========
========= dir /a C:\Users\Dom\AppData\Local =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\Users\Dom\AppData\Local
11.12.2016 16:07 .
11.12.2016 16:07 ..
22.06.2016 15:47 ActiveSync
28.10.2016 18:28 AMD
16.08.2016 11:06 Anerdward
17.09.2016 13:43 Apps
22.06.2016 16:14 ATI
22.06.2016 18:07 CEF
22.06.2016 16:04 Comms
26.09.2016 20:20 ConnectedDevicesPlatform
24.08.2016 15:14 CrashRpt
26.09.2016 20:02 Dane aplikacji [C:\Users\Dom\AppData\Local]
04.12.2016 16:47 Diagnostics
05.12.2016 21:19 Disc_Soft_Ltd
17.10.2016 17:35 ElevatedDiagnostics
08.12.2016 09:26 fontconfig
08.12.2016 09:26 gegl-0.2
04.11.2016 21:15 Google
26.09.2016 20:02 Historia [C:\Users\Dom\AppData\Local\Microsoft\Windows\History]
11.12.2016 21:14 166˙412 IconCache.db
08.12.2016 15:46 Microsoft
22.06.2016 15:58 MicrosoftEdge
25.11.2016 10:03 Mozilla
14.09.2016 18:08 Origin
03.12.2016 11:33 Packages
30.07.2016 11:57 Programs
22.06.2016 15:47 Publishers
08.12.2016 09:43 2˙082 recently-used.xbel
03.12.2016 22:30 17 resmon.resmoncfg
08.12.2016 15:41 Rockstar Games
27.08.2016 13:40 speech
22.06.2016 18:07 Steam
12.12.2016 16:09 Temp
16.08.2016 11:12 Tempfolder
26.09.2016 20:02 Temporary Internet Files [C:\Users\Dom\AppData\Local\Microsoft\Windows\INetCache]
22.06.2016 15:46 TileDataLayer
16.08.2016 11:41 UCBrowser
17.09.2016 13:43 Unity
06.11.2016 17:39 VirtualStore
28.08.2016 15:08 wf-launcher
3 File(s) 168˙511 bytes
37 Dir(s) 86˙718˙926˙848 bytes free
========= Koniec CMD: =========
========= dir /a C:\Users\Dom\AppData\LocalLow =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\Users\Dom\AppData\LocalLow
05.12.2016 18:21 .
05.12.2016 18:21 ..
28.10.2016 18:28 AMD
16.08.2016 11:12 Company
17.09.2016 15:12 Microsoft
03.11.2016 16:54 Oracle
03.11.2016 16:54 Sun
17.09.2016 15:12 Temp
17.09.2016 13:43 Unity
08.12.2016 08:03 uTorrent
0 File(s) 0 bytes
10 Dir(s) 86˙718˙926˙848 bytes free
========= Koniec CMD: =========
========= dir /a C:\Users\Dom\AppData\Roaming =========
Volume in drive C has no label.
Volume Serial Number is 46B4-4BEF
Directory of C:\Users\Dom\AppData\Roaming
12.12.2016 16:09 .
12.12.2016 16:09 ..
28.08.2010 21:43 96˙256 AdbWinApi.dll
28.08.2010 21:43 60˙928 AdbWinUsbApi.dll
22.06.2016 15:46 Adobe
22.06.2016 16:14 ATI
10.12.2016 16:29 DAEMON Tools Lite
28.06.2016 02:12 314˙434 EYapp.apk
11.08.2016 12:37 Grupa IMAGE
16.08.2016 11:12 Hemkajdoa
08.12.2016 09:18 LibreOffice
23.06.2016 09:22 LolClient
23.06.2016 09:23 Macromedia
01.07.2016 10:19 8˙284˙704 MaoHaWiFiSetup_262.exe
27.09.2016 16:59 Microsoft
30.06.2016 15:37 Milestone
15.10.2016 19:57 Mozilla
13.11.2016 10:28 OpenOffice.org
27.11.2016 18:51 Origin
16.08.2016 11:06 Profiles
23.06.2016 07:12 Riot Games
08.12.2016 15:10 SecuROM
27.08.2016 19:32 7˙616˙340 setup.apk
26.09.2016 20:12 Skype
03.11.2016 16:54 Sun
22.06.2016 17:52 TeamViewer
08.12.2016 16:42 TS3Client
30.07.2016 12:48 32˙038 uninstall_temp.ico
10.12.2016 16:29 uTorrent
30.08.2016 18:55 Wargaming.net
13.11.2016 14:45 WinRAR
6 File(s) 16˙404˙700 bytes
25 Dir(s) 86˙718˙922˙752 bytes free
========= Koniec CMD: =========
C:\Windows\System32\Drivers\etc\hosts => pomyślnie przeniesiono
Hosts pomyślnie przywrócono.
========= RemoveProxy: =========
HKU\S-1-5-21-2293639786-2994818483-2183426564-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => Wartość pomyślnie usunięto
HKU\S-1-5-21-2293639786-2994818483-2183426564-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => Wartość pomyślnie usunięto
========= Koniec RemoveProxy: =========
=========== EmptyTemp: ==========
BITS transfer queue => 3338048 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 66138796 B
Java, Flash, Steam htmlcache => 49165451 B
Windows/system/drivers => 75774 B
Edge => 9932679 B
Chrome => 228050492 B
Firefox => 7959409 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 4138 B
NetworkService => 0 B
Dom => 19427530 B
RecycleBin => 1933748 B
EmptyTemp: => 368.1 MB danych tymczasowych Usunięto.
================================
System wymagał restartu.
==== Koniec Fixlog 16:10:01 ====