Skocz do zawartości


Close Open
Close Open

zainfekowa

Dołączył: 26 lis 2015
Offline Ostatnio aktywny: lis 28 2015 00:57
-----

Moje posty

W temacie:Proszę o pomoc ComboFix, logi programu ratunku!!!

28 listopad 2015 - 00:35

dzięki bardzo :)


W temacie:Proszę o pomoc ComboFix, logi programu ratunku!!!

27 listopad 2015 - 20:31

fixlist:

http://wklej.org/id/1859552/



logi z frst

shortkuts:

http://wklej.org/id/1859998/

FRST:

http://wklej.org/id/1860003/

Additions:

http://wklej.org/id/1860004/


W temacie:Proszę o pomoc ComboFix, logi programu ratunku!!!

27 listopad 2015 - 00:45

addition:
http://wklej.org/id/1859233/

FRST:
http://wklej.org/id/1859234/

Shortkuts:
http://wklej.org/id/1859236/

Fixlog:

http://wklej.org/id/1859252/


W temacie:Proszę o pomoc ComboFix, logi programu ratunku!!!

26 listopad 2015 - 20:58


CodeIntegrity:
===================================
Date: 2015-11-20 18:13:18.130
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Sound+\SoundP.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-11-20 18:13:18.114
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Sound+\SoundP.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-11-20 18:12:34.244
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Sound+\SoundP.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-11-20 18:12:34.213
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Sound+\SoundP.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-11-20 18:12:34.172
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Sound+\SoundP.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-11-20 18:12:34.156
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Sound+\SoundP.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-08-17 21:46:41.975
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2015-08-17 21:46:41.733
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2015-08-17 21:46:41.640
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.

Date: 2015-08-17 21:46:41.482
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.


==================== Statystyki pamiêci ===========================

Procesor: Intel® Core™2 Duo CPU E6750 @ 2.66GHz
Procent pamiêci w u¿yciu: 68%
Ca³kowita pamiêæ fizyczna: 2044.91 MB
Dostêpna pamiêæ fizyczna: 645.14 MB
Ca³kowita pamiêæ wirtualna: 6134.72 MB
Dostêpna pamiêæ wirtualna: 4323.77 MB

==================== Dyski ================================

Drive c: () (Fixed) (Total:27.41 GB) (Free:1.44 GB) NTFS
Drive d: () (Fixed) (Total:159.96 GB) (Free:19.01 GB) NTFS
Drive e: (mobilNET) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS

==================== MBR & Tablica partycji ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: B1F7B5C5)
Partition 1: (Active) - (Size=45.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=27.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=160 GB) - (Type=OF Extended)

==================== Koniec Addition.txt ============================

Rezultat skanowania skrótów użytkowników (x86) Wersja:26-11-2015
Uruchomiony przez jacek (2015-11-26 19:29:59)
Uruchomiony z D:\Downloads
Tryb startu: Normal

==================== Skróty =============================

(Wybrane wejścia mogą zostać załączone w celu ich zresetowania lub usunięcia.)





Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 7.0.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Distiller.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 7.0 Professional.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Designer 7.0.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\PM_Designer.exe (InstallShield Software Corp.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2015b.lnk -> D:\Program Files\bin\matlab.exe (The MathWorks Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live ID.lnk -> C:\Program Files\Common Files\microsoft shared\Windows Live\SIGNINOPTIONS.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sothink PDF to DWG Converter\Sothink PDF to DWG Converter.lnk -> C:\Program Files\Sothink PDF to DWG Converter\pdf2dwg.exe (SourceTec Software Co., LTD)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sothink PDF to DWG Converter\Uninstall.lnk -> C:\Program Files\Sothink PDF to DWG Converter\uninst.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sothink PDF to DWG Converter\Website.lnk -> C:\Program Files\Sothink PDF to DWG Converter\Sothink PDF to DWG Converter.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\scilab-5.5.2\Scilab Console.lnk -> C:\Program Files\scilab-5.5.2\bin\Scilex.exe (Scilab Enterprises)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\scilab-5.5.2\Scilab on the Web.lnk -> C:\Program Files\scilab-5.5.2\scilabwebsite.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\scilab-5.5.2\scilab-5.5.2.lnk -> C:\Program Files\scilab-5.5.2\bin\WScilex.exe (Scilab Enterprises)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\scilab-5.5.2\Uninstall Scilab.lnk -> C:\Program Files\scilab-5.5.2\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ralink Wireless\Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Multimedia mobilNET\Multimedia mobilNET.lnk -> C:\Program Files\Multimedia mobilNET\Multimedia mobilNET.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Multimedia mobilNET\Uninstall.lnk -> C:\Program Files\Multimedia mobilNET\uninst.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\OneNote 2013.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTE.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Wyślij do programu OneNote 2013.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Narzędzia pakietu Office 2013\Office 2013 Upload Center.lnk -> C:\Program Files\Microsoft Office 15\root\office15\MSOUC.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Narzędzia pakietu Office 2013\Preferencje językowe pakietu Office 2013.lnk -> C:\Program Files\Microsoft Office 15\root\office15\SETLANG.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\GrooveIcon.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Certyfikat cyfrowy dla projektów VBA.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Diagnostyka pakietu Microsoft Office.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Office 2007 Ustawienia języka.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB\R2015b\Activate MATLAB R2015b.lnk -> D:\Program Files\bin\win32\activate_matlab.exe (The MathWorks, Inc)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB\R2015b\Deactivate MATLAB R2015b.lnk -> D:\Program Files\uninstall\bin\win32\deactivate_matlab.exe (The MathWorks, Inc)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB\R2015b\MATLAB R2015b.lnk -> D:\Program Files\bin\matlab.exe (The MathWorks Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\MathType Help.lnk -> C:\Program Files\MathType\MT6enu.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\MathType.lnk -> C:\Program Files\MathType\MathType.exe (Design Science, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe (Oracle Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HEXelon Free\HEXelon Free.lnk -> C:\Program Files\HEXelon Free\calculator.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HEXelon Free\Uninstall.lnk -> C:\Program Files\HEXelon Free\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HEXelon Free\www.HEXelon.com.lnk -> C:\Program Files\HEXelon Free\www.HEXelon.com.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic\Gothic.lnk -> D:\System\GOTHIC.EXE (Piranha Bytes Software GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DirectX Happy Uninstall\DirectX Happy Uninstall.lnk -> C:\Program Files\DirectX Happy Uninstall\DHU.exe (SuperFox Studio)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DirectX Happy Uninstall\FAQ_HELP.lnk -> C:\Program Files\DirectX Happy Uninstall\FAQ_HELP.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DirectX Happy Uninstall\Uninstall DirectX Happy Uninstall.lnk -> C:\Program Files\DirectX Happy Uninstall\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CompareDWG\CompareDWG Help.lnk -> C:\Program Files\Furix\CompareDWG\CompareDWG.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CompareDWG\CompareDWG program folder.lnk -> C:\Program Files\Furix\CompareDWG ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CompareDWG\Complete installation.lnk -> C:\Program Files\Furix\CompareDWG\Readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CompareDWG\Uninstall CompareDWG.lnk -> C:\Program Files\Furix\CompareDWG\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Catalyst Control Center.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Read Me.lnk -> C:\Program Files\Brother\Brmfl10b\RM10aPol.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Ustawienia skanera\Read Me.lnk -> C:\Program Files\Brother\Brmfl10b\ScanRead.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Ustawienia skanera\Scanner Utility.lnk -> C:\Program Files\Brother\Brmfl10b\BrScUtil.exe (Brother Industries Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterWMF\BetterWMF ARX folder.lnk -> C:\Program Files\Furix\BetterWMF ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterWMF\BetterWMF for AutoCAD LT.lnk -> C:\Program Files\Furix\BetterWMF\BClipbrd.exe (Furix bv)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterWMF\BetterWMF Help.lnk -> C:\Program Files\Furix\BetterWMF\BetterWMF.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterWMF\Uninstall BetterWMF.lnk -> C:\Program Files\Furix\BetterWMF\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Uninstall Tool.lnk -> C:\Program Files\Common Files\Autodesk Shared\Uninstall Tool\R1\UninstallTool.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Content Service\Content Service - Configuration Console.lnk -> C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.Admin.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Dołącz podpisy cyfrowe.lnk -> D:\a\AutoCAD 2013\AcSignApply.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Menedżer odnośników.lnk -> D:\a\AutoCAD 2013\AdRefMan.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Wsadowy kontroler standardów.lnk -> D:\a\AutoCAD 2013\DwgCheckStandards.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aide PDF to DXF Converter\Aide PDF to DXF Converter on the Web.lnk -> C:\Program Files\Aide PDF to DXF Converter\pdc.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aide PDF to DXF Converter\Aide PDF to DXF Converter.lnk -> C:\Program Files\Aide PDF to DXF Converter\pdc.exe (Aide CAD Systems Incorporated.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aide PDF to DXF Converter\Help.lnk -> C:\Program Files\Aide PDF to DXF Converter\help.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aide PDF to DXF Converter\Uninstall Aide PDF to DXF Converter.lnk -> C:\Program Files\Aide PDF to DXF Converter\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk -> C:\Windows\System32\NetProj.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center\360 Total Security\360 Total Security.lnk -> C:\Program Files\360\Total Security\QHSafeMain.exe (QIHU 360 SOFTWARE CO. LIMITED)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center\360 Total Security\Uninstall.lnk -> C:\Program Files\360\Total Security\Uninstall.exe ()
Shortcut: C:\Users\Default\Links\OneDrive.lnk -> C:\Program Files\Microsoft OneDrive\OneDriveSetup.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk -> C:\Program Files\Microsoft OneDrive\OneDriveSetup.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\Links\Desktop.lnk -> C:\Users\jacek\Desktop ()
Shortcut: C:\Users\jacek\Links\Downloads.lnk -> D:\Downloads ()
Shortcut: C:\Users\jacek\Links\OneDrive.lnk -> C:\Users\jacek\OneDrive ()
Shortcut: C:\Users\jacek\Desktop\Aide PDF to DXF Converter.lnk -> C:\Program Files\Aide PDF to DXF Converter\pdc.exe (Aide CAD Systems Incorporated.)
Shortcut: C:\Users\jacek\Desktop\Downloads — skrót.lnk -> D:\Users\0000\Downloads\Downloads.rar ()
Shortcut: C:\Users\jacek\Desktop\Katalog hali w technologii FF zeszyt 3 — skrót.lnk -> D:\Users\0000\Downloads\Katalog hali w technologii FF zeszyt 3.rar ()
Shortcut: C:\Users\jacek\Desktop\notepad — skrót.lnk -> C:\Windows\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\Desktop\Nowy folder (2) — skrót.lnk -> D:\Nowy folder\Nowy folder (2) ()
Shortcut: C:\Users\jacek\Desktop\osk — skrót.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\Desktop\Pobrane — skrót.lnk -> D:\Users\0000\Downloads ()
Shortcut: C:\Users\jacek\Desktop\WarThunder.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk -> C:\Users\jacek\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk -> C:\Users\jacek\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Windows\SendTo\Palm Powered™ Handheld.lnk -> C:\Program Files\palmOne\Instapp.exe (Brak pliku)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Aide PDF to DXF Converter.lnk -> C:\Program Files\Aide PDF to DXF Converter\pdc.exe (Aide CAD Systems Incorporated.)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\HEXelon Free.lnk -> C:\Program Files\HEXelon Free\calculator.exe ()
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -> C:\Users\jacek\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Catalyst Control Center.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MathApp.lnk -> D:\Program Files\Microsoft Mathematics\MathApp.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\osk — skrót.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Klawiatura ekranowa ułatwień dostępu.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\MathType.lnk -> D:\Program Files\MathType\MathType.exe (Design Science, Inc.)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Multimedia mobilNET.lnk -> C:\Program Files\Multimedia mobilNET\Multimedia mobilNET.exe ()
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Play withSIX.lnk -> D:\[ Najnowsze-Torrenty.pl ] Czlowiek.ze.stali.2013.TS.NAPISY PL\Nowy folder\withSIX-Play(2).exe (SIX Networks)
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\przelicznik jednostek.lnk -> D:\Users\0000\Downloads\Pobieranie\przelicznik jednostek.exe ()
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\RM-WIN.lnk -> D:\Nowy folder (3)\RM-Win_4.21\RM-Win\RM-WIN.EXE ()
Shortcut: C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\jacek\AppData\Roaming\Autodesk\AutoCAD 2013 — polski\R19.0\plk\Plotters\Plot Styles\Dodaj tabelę stylów wydruku.lnk -> D:\a\AutoCAD 2013\styshwiz.exe (Autodesk, Inc.)
Shortcut: C:\Users\jacek\AppData\Local\Microsoft\Windows\GameExplorer\{D2D89AFC-9906-4CA5-8807-EA561F3041DB}\PlayTasks\0\Zagraj.lnk -> D:\System\GOTHIC.EXE (Piranha Bytes Software GmbH)
Shortcut: C:\Users\jacek\AppData\Local\Microsoft\GFWLive\Logs\InstallLog.lnk -> C:\Users\jacek\AppData\Local\Microsoft\GFWLive\Install\Logs ()
Shortcut: C:\Users\jacek\AppData\Local\Microsoft\GFWLive\Install\Logs\ClientLog.lnk -> C:\Users\jacek\AppData\Local\Microsoft\GFWLive\Logs ()
Shortcut: C:\Users\Public\Desktop\360 Total Security.lnk -> C:\Program Files\360\Total Security\QHSafeMain.exe (QIHU 360 SOFTWARE CO. LIMITED)
Shortcut: C:\Users\Public\Desktop\Adobe Acrobat 7.0 Professional.lnk -> D:\Program Files\Acrobat\Acrobat.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\Public\Desktop\DirectX Happy Uninstall.lnk -> C:\Program Files\DirectX Happy Uninstall\DHU.exe (SuperFox Studio)
Shortcut: C:\Users\Public\Desktop\FriloSystemNext.lnk -> D:\New Folder\fril\Frilo.System.Next\FriloSystemNext.exe (Frilo Software GmbH)
Shortcut: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Public\Desktop\scilab-5.5.2.lnk -> C:\Program Files\scilab-5.5.2\bin\WScilex.exe (Scilab Enterprises)




ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.) -> -s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\Equation Conversion Manager.lnk -> C:\Program Files\MathType\Setup.exe (Design Science, Inc.) -> -OLEMGR
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\MathType Server.lnk -> C:\Program Files\MathType\MathType.exe (Design Science, Inc.) -> -server
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MathType 6\Remove MathType.lnk -> C:\Program Files\MathType\Setup.exe (Design Science, Inc.) -> -R
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe (Oracle Corporation) -> -tab about
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe (Oracle Corporation) -> -tab update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic\Usunięcie gry Gothic.lnk -> C:\Program Files\InstallShield Installation Information\{758A4269-70E5-4B11-B419-F692882408A9}\setup.exe (InstallShield Software Corporation) -> -l0x15 -uninst
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frilo\FriloSystemNext entfernen.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation) -> /x {F1209C94-2CCD-4EEB-902E-6F7CC76F5C94}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frilo\FriloSystemNext.lnk -> D:\New Folder\fril\Frilo.System.Next\FriloSystemNext.exe (Frilo Software GmbH) -> /S
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CompareDWG\CompareDWG in AutoCAD.lnk -> C:\Windows\hh.exe (Microsoft Corporation) -> "C:\Program Files\Furix\CompareDWG\CompareDWG.CHM::/comparedwg-documentation/installation-2.html"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center\Pomoc.lnk -> C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (ATI Technologies Inc.) -> Start Help -help
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\ControlCenter3.lnk -> C:\Program Files\Brother\ControlCenter3\BrCtrCen.exe (Brother Industries, Ltd.) -> /Model=DCP-J125
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Instalowanie diagnostyki.lnk -> C:\Program Files\Brother\Brmfl10b\Brinstck.exe (Brother Industries, Ltd.) -> DCP-J125
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Odinstaluj.lnk -> C:\Program Files\InstallShield Installation Information\{FB83EAC4-E3F6-4666-B45B-44522F2344B6}\setup.exe (Macrovision Corporation) -> -runfromtemp -l0x0015 UNINSTALL Reg=BH9e2_C1,Brother DCP-J125,USB
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Rejestracja On-Line.lnk -> C:\Program Files\Brother\Brmfl10b\Brolink\Brolink0.exe (Brother Industories, Ltd.) -> OLR_URL /mDCP-J125
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Status Monitor.lnk -> C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) -> Brother DCP-J125 Printer on USB001 /SHOW
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Ustawienia skanera\Skanery i aparaty fotograficzne.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ScannersAndCameras
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterWMF\BetterWMF for AutoCAD.lnk -> C:\Windows\hh.exe (Microsoft Corporation) -> "C:\Program Files\Furix\BetterWMF\BetterWMF.CHM::/betterwmf-documentation/installation/installation-autocad/index.html"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2014 - Polski (Polish)\Revit 2014 - Polski (Polish).lnk -> D:\Autodesk\Revit 2014\Revit.exe (Autodesk, Inc.) -> /language PLK
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2014 - Polski (Polish)\Revit Viewer 2014 - Polski (Polish).lnk -> D:\Autodesk\Revit 2014\Revit.exe (Autodesk, Inc.) -> /viewer /language PLK
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2014\License Transfer Utility - Revit 2014.lnk -> C:\Program Files\Common Files\Autodesk Shared\AdLM\R7\LTU.exe (Autodesk, Inc.) -> 829F1 2014.0.0.F -d SA -l en-US
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2014\Revit 2014.lnk -> D:\Autodesk\Revit 2014\Revit.exe (Autodesk, Inc.) -> /language ENU
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Revit 2014\Revit Viewer 2014.lnk -> D:\Autodesk\Revit 2014\Revit.exe (Autodesk, Inc.) -> /viewer /language ENU
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\AutoCAD 2013 – Polski (Polish).lnk -> C:\Windows\Installer\{5783F2D7-B001-0000-0002-0060B0CE6BBA}\Acad162_icon.exe () -> /product "ACAD" /language "pl-PL"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Narzędzie transferu licencji.lnk -> C:\Program Files\Common Files\Autodesk Shared\AdLM\R5\LTU.exe (Autodesk, Inc.) -> 001E1 2013.0.0.F -d SA -l pl-PL
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Przywróć ustawienia domyślne.lnk -> D:\a\AutoCAD 2013\AdMigrator.exe (Autodesk, Inc.) -> /reset /product "ACAD" /language "pl-PL"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Migracja ustawień niestandardowych\Eksportuj ustawienia programu AutoCAD 2013.lnk -> D:\a\AutoCAD 2013\AdMigrator.exe (Autodesk, Inc.) -> /e /product "ACAD" /language "pl-PL"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Migracja ustawień niestandardowych\Importuj ustawienia programu AutoCAD 2013.lnk -> D:\a\AutoCAD 2013\AdMigrator.exe (Autodesk, Inc.) -> /i /product "ACAD" /language "pl-PL"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\AutoCAD 2013 – Polski (Polish)\Migracja ustawień niestandardowych\Migracja z poprzedniej wersji.lnk -> D:\a\AutoCAD 2013\AdMigrator.exe (Autodesk, Inc.) -> /product "ACAD" /language "pl-PL"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wysyłanie do programu OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation) -> /tsr
ShortcutWithArgument: C:\Users\jacek\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\jacek\AppData\Roaming\Autodesk\AutoCAD 2013 — polski\R19.0\plk\Plotters\Dodaj ploter.lnk -> D:\a\AutoCAD 2013\addplwiz.exe (Autodesk, Inc.) -> /LANGUAGE pl-PL
ShortcutWithArgument: C:\Users\Public\Desktop\AutoCAD 2013 – Polski (Polish).lnk -> D:\a\AutoCAD 2013\acad.exe (Autodesk, Inc.) -> /product ACAD /language "pl-PL"
ShortcutWithArgument: C:\Users\Public\Desktop\Revit 2014 - Polski (Polish).lnk -> D:\Autodesk\Revit 2014\Revit.exe (Autodesk, Inc.) -> /language PLK
ShortcutWithArgument: C:\Users\Public\Desktop\Revit 2014.lnk -> D:\Autodesk\Revit 2014\Revit.exe (Autodesk, Inc.) -> /language ENU


InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Subtitle Edit\Help and Support\Online Help.url -> hxxp://www.nikse.dk/SubtitleEdit/Help
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Subtitle Edit\Help and Support\Strona WWW programu Subtitle Edit.url -> hxxp://www.nikse.dk/SubtitleEdit/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic\Strona domowa CD Projekt.url -> hxxp://www.cdprojekt.info
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CompareDWG\CompareDWG on the Web.url -> hxxp://www.furix.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Brother Creative Center.url -> "hxxp://www.brother.com/creativecenter/?WT.mc_id=AF"
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Podręczniki użytkownika w formacie PDF.url -> hxxp://solutions.brother.com/cgi-bin/solutions.cgi?MDL=mfc288&LNG=pl&SRC=DOC
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-J125\Pomoc online i często zadawane pytania (FAQ).url -> hxxp://solutions.brother.com/cgi-bin/solutions.cgi?MDL=mfc288&LNG=pl&SRC=FAQ
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetterWMF\BetterWMF on the Web.url -> hxxp://www.furix.com/
InternetURL: C:\Users\jacek\Favorites\Windows Live\Galeria gadżetów Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkID=70742
InternetURL: C:\Users\jacek\Favorites\Windows Live\Poczta usługi Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72681
InternetURL: C:\Users\jacek\Favorites\Windows Live\Programy usługi Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72700
InternetURL: C:\Users\jacek\Favorites\Windows Live\Windows Live Spaces.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72682
InternetURL: C:\Users\jacek\Favorites\MSN — witryny sieci Web\MSN Gospodarka.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68923
InternetURL: C:\Users\jacek\Favorites\MSN — witryny sieci Web\MSN Rozrywka.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68924
InternetURL: C:\Users\jacek\Favorites\MSN — witryny sieci Web\MSN Sport.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68921
InternetURL: C:\Users\jacek\Favorites\MSN — witryny sieci Web\MSN Technologie.url -> hxxp://go.microsoft.com/fwlink/?LinkId=55143
InternetURL: C:\Users\jacek\Favorites\MSN — witryny sieci Web\MSN Wideo.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68922
InternetURL: C:\Users\jacek\Favorites\MSN — witryny sieci Web\Portal MSN.url -> hxxp://go.microsoft.com/fwlink/?LinkId=54729
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Centrum bezpieczeństwa Microsoft.url -> hxxp://go.microsoft.com/fwlink/?LinkID=72887
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Dodatki programu Internet Explorer.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Microsoft Office Online.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72885
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Microsoft Technet.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72886
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Microsoft w Polsce.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72520
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Oryginalne oprogramowanie firmy Microsoft.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72900
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Strona główna programu Internet Explorer.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72186
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Strona główna systemu Windows.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72629
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\Technologia RSS.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72889
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\W domu.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72406
InternetURL: C:\Users\jacek\Favorites\Microsoft — witryny sieci Web\W pracy.url -> hxxp://go.microsoft.com/fwlink/?LinkId=72407
InternetURL: C:\Users\jacek\Favorites\Links for Polska\Bezpieczeństwo w trybie online.url -> hxxp://go.microsoft.com/fwlink/?LinkId=142211
InternetURL: C:\Users\jacek\Favorites\Links for Polska\Bezpieczny Internet.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129626
InternetURL: C:\Users\jacek\Favorites\Links for Polska\Kultura.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129625
InternetURL: C:\Users\jacek\Favorites\Links for Polska\Pogodynka.pl — oficjalny serwis pogodowy IMGW.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129624
InternetURL: C:\Users\jacek\Favorites\Links for Polska\Polska.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129622
InternetURL: C:\Users\jacek\Favorites\Links\Sugerowane witryny.url -> hxxps://ieonline.microsoft.com/#ieslice
InternetURL: C:\Users\jacek\Desktop\Make a 2L Coke Bottle Air Tank (Upgraded Version)johnnyq90459.URL -> hxxps://www.youtube.com/watch?v=P5hmX8DC7yk

==================== Koniec Shortcut.txt =============================

Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja:26-11-2015
Uruchomiony przez jacek (administrator) JACEK-KOMPUTER (26-11-2015 19:37:08)
Uruchomiony z D:\Downloads
Załadowane profile: jacek (Dostępne profile: jacek)
Platform: Microsoft Windows 7 Ultimate (X86) Język: Polski (Polska)
Internet Explorer Wersja 8 (Domyślna przeglądarka: FF)
Tryb startu: Normal
Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Procesy (filtrowane) =================

(Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\officeclicktorun.exe
() C:\ProgramData\DatacardService\HWDeviceService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Qihu Software Co. Limited) C:\Program Files\360\Total Security\safemon\QHWatchdog.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files\Multimedia mobilNET\Multimedia mobilNET.exe
(Akamai Technologies, Inc.) C:\Users\jacek\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\jacek\AppData\Local\Akamai\netsession_win.exe
(Ralink Technology, Corp.) C:\Program Files\Ralink\Common\RaUI.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_19_0_0_245.exe
(Microsoft Corporation) C:\Windows\System32\osk.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE


==================== Rejestr (filtrowane) ===========================

(Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.)

HKLM\...\Run: [QHSafeTray] => C:\Program Files\360\Total Security\safemon\QHSafeTray.exe [1474168 2015-11-12] (QIHU 360 SOFTWARE CO. LIMITED)
HKU\S-1-5-21-2488227506-879824950-2642440848-1000\...\Run: [uTorrent] => C:\Users\jacek\AppData\Roaming\uTorrent\uTorrent.exe [1822048 2015-10-10] (BitTorrent Inc.)
HKU\S-1-5-21-2488227506-879824950-2642440848-1000\...\Run: [Akamai NetSession Interface] => C:\Users\jacek\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2488227506-879824950-2642440848-1000\...\Policies\Explorer: []
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2012-02-07] (Autodesk, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk [2015-11-05]
ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk [2015-01-27]
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
Startup: C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wysyłanie do programu OneNote.lnk [2015-11-22]
ShortcutTarget: Wysyłanie do programu OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Ograniczenia - Chrome <======= UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA

==================== Internet (filtrowane) ====================

(Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.)

Tcpip\..\Interfaces\{2C40FAA4-D16C-4A0A-B282-42F03EC99AA2}: [NameServer] 212.2.96.51 212.2.96.52
Tcpip\..\Interfaces\{46A18A4D-AB39-4570-BDB7-D8B07CE82D5E}: [NameServer] 213.158.199.1 213.158.199.5
Tcpip\..\Interfaces\{53761580-177C-4B99-ABFC-0BD131B3D43C}: [NameServer] 213.158.199.1 213.158.199.5
Tcpip\..\Interfaces\{94C4B953-D584-4CFA-8CE5-AF7A14819744}: [NameServer] 213.158.199.1 213.158.199.5
Tcpip\..\Interfaces\{95A4E742-AB12-4E81-8292-059C96230A57}: [NameServer] 213.158.199.1 213.158.199.5

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKU\S-1-5-21-2488227506-879824950-2642440848-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Ograniczenia <======= UWAGA
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2488227506-879824950-2642440848-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2488227506-879824950-2642440848-1000 -> {ielnksrch} URL = hxxp://www.bing.com/search?q={searchTerms}
BHO: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> D:\Program Files\Acrobat\AcroIEFavClient.dll [2006-12-18] (Adobe Systems Incorporated)
BHO: FlashGetBHO -> {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} -> C:\Users\jacek\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll [2012-11-01] (Trend Media Group)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-11-22] (Microsoft Corporation)
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Acrobat\AcroIEFavClient.dll [2006-12-18] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-2488227506-879824950-2642440848-1000 -> Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Acrobat\AcroIEFavClient.dll [2006-12-18] (Adobe Systems Incorporated)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-11-22] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780
FF Homepage: hxxps://www.google.pl/webhp?hl=pl
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-28] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-11-22] (Microsoft Corporation)
FF Plugin HKU\S-1-5-21-2488227506-879824950-2642440848-1000: @tools.google.com/Google Update;version=3 -> C:\Users\jacek\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll [Brak pliku]
FF Plugin HKU\S-1-5-21-2488227506-879824950-2642440848-1000: @tools.google.com/Google Update;version=9 -> C:\Users\jacek\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll [Brak pliku]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2010-08-24] (BitComet)
FF HKLM\...\Firefox\Extensions: [WebProtection@360safe.com] - C:\Program Files\360\Total Security\safemon\webprotection_firefox
FF Extension: 360 Internet Protection - C:\Program Files\360\Total Security\safemon\webprotection_firefox [2015-11-20]

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2488227506-879824950-2642440848-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx

Opera:
=======
OPR Extension: (Magical Find) - C:\Users\jacek\AppData\Roaming\Opera Software\Opera Stable\Extensions\abeigmhanpbndgbmjdpjkbgecfecckgj [2015-08-17]
OPR Extension: (Opera Bookmarks Share Portal) - C:\Users\jacek\AppData\Roaming\Opera Software\Opera Stable\Extensions\gegdfeiahlfolhcfioipjlkombmgbakh [2015-09-16]
OPR Extension: (Opera Bookmarks Share Portal) - C:\Users\jacek\AppData\Roaming\Opera Software\Opera Stable\Extensions\oghkljobbhapacbahlneolfclkniiami [2015-03-06]

==================== Usługi (filtrowane) ========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [69632 2015-11-05] (Adobe Systems) [Brak podpisu cyfrowego]
R2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
S4 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [Brak podpisu cyfrowego]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [1895096 2015-10-13] (Microsoft Corporation)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1064312 2015-11-21] (Flexera Software LLC)
R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [264704 2010-11-16] () [Brak podpisu cyfrowego]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Brak podpisu cyfrowego]
S4 Multimedia mobilNET. RunOuc; C:\Program Files\Multimedia mobilNET\UpdateDog\ouc.exe [218624 2014-12-13] () [Brak podpisu cyfrowego]
R2 QHActiveDefense; C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe [903288 2015-11-12] (QIHU 360 SOFTWARE CO. LIMITED)
S4 RalinkRegistryWriter; C:\Program Files\Ralink\Common\RaRegistry.exe [372736 2011-11-14] (Ralink Technology, Corp.) [Brak podpisu cyfrowego]
S4 RaMediaServer; C:\Program Files\Ralink\Common\RaMediaServer.exe [625728 2011-08-18] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

===================== Sterowniki (filtrowane) ==========================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)

R3 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker.sys [122448 2015-11-12] (360.cn)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [66128 2015-11-12] (360.cn)
R1 360Box; C:\Windows\System32\DRIVERS\360Box.sys [204368 2015-11-12] (360.cn)
S3 360Camera; C:\Windows\System32\Drivers\360Camera.sys [34888 2015-11-12] (360.cn)
R1 360SelfProtection; C:\Windows\System32\drivers\360SelfProtection.sys [179152 2015-11-12] (360安全中心)
S3 athur; C:\Windows\System32\DRIVERS\athur.sys [1500160 2010-01-05] (Atheros Communications, Inc.)
R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV.sys [174672 2015-11-12] (360.cn)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [26168 2015-11-20] (Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [39992 2015-11-20] (Disc Soft Ltd)
R1 EfiMon; C:\Windows\System32\Drivers\Efimon.sys [23248 2015-11-12] (360.cn)
R0 HookPort; C:\Windows\System32\Drivers\Hookport.sys [60368 2015-11-12] (360安全中心)
R1 qutmdserv; C:\Windows\System32\DRIVERS\qutmdrv.sys [301264 2015-11-12] (360.cn)
R1 qutmipc; C:\Windows\system32\drivers\qutmipc.sys [53960 2015-11-12] (360.cn)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [329384 2015-11-26] (Duplex Secure Ltd.)
S2 adfs; Brak ImagePath
S1 ASPI32; Brak ImagePath
S3 catchme; \??\C:\Users\jacek\AppData\Local\Temp\catchme.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 PalmUSBD; system32\drivers\PalmUSBD.sys [X]
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]

==================== NetSvcs (filtrowane) ===================

(Załączenie wejścia w fixlist spowoduje jego usunięcie z rejestru. Powiązany plik nie zostanie przeniesiony, o ile nie zostanie załączony z osobna.)


==================== Jeden miesiąc - utworzone pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2015-11-26 18:19 - 2015-11-26 19:37 - 00000000 ____D C:\FRST
2015-11-26 17:10 - 2015-11-26 17:10 - 00001201 _____ C:\Users\jacek\Desktop\osk — skrót.lnk
2015-11-26 17:04 - 2015-11-26 17:04 - 00001078 _____ C:\Users\jacek\Desktop\notepad — skrót.lnk
2015-11-26 14:23 - 2015-11-26 06:30 - 00000000 ____D C:\Qoobox
2015-11-26 14:23 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2015-11-26 14:23 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2015-11-26 14:23 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-11-26 14:23 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-11-26 14:23 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-11-26 14:23 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2015-11-26 14:23 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2015-11-26 14:23 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2015-11-26 14:22 - 2015-11-26 06:29 - 00000000 ____D C:\Windows\erdnt
2015-11-26 14:20 - 2015-11-26 14:20 - 00000252 _____ C:\Users\jacek\Desktop\CFScript.txt
2015-11-26 06:30 - 2015-11-26 06:30 - 00024412 _____ C:\ComboFix.txt
2015-11-26 05:59 - 2015-11-26 05:59 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Everything
2015-11-26 05:59 - 2015-11-26 05:59 - 00000000 ____D C:\Program Files\Everything
2015-11-26 05:57 - 2015-11-26 18:38 - 00000969 _____ C:\Users\jacek\Desktop\WarThunder.lnk
2015-11-23 21:06 - 2015-11-26 16:58 - 00000000 ____D C:\Users\jacek\AppData\LocalLow\uTorrent
2015-11-23 14:01 - 2015-11-23 14:01 - 00000000 ____D C:\Users\jacek\AppData\Roaming\SOFiSTiK
2015-11-23 13:54 - 2015-11-23 13:54 - 02506752 _____ C:\Users\jacek\Documents\Projekt1Projekt1.rvt
2015-11-22 18:38 - 2015-11-22 18:43 - 00000000 ____D C:\Program Files\Google
2015-11-22 18:38 - 2015-11-22 18:38 - 00000000 ____D C:\Users\jacek\AppData\Local\Google
2015-11-22 18:38 - 2015-11-22 18:07 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-11-22 18:29 - 2015-11-22 18:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-11-22 18:23 - 2015-11-22 18:24 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-11-22 18:08 - 2015-11-22 18:09 - 00000000 ____D C:\Users\jacek\Documents\Notesy programu OneNote
2015-11-22 18:08 - 2015-11-22 18:08 - 00002062 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-11-22 18:08 - 2015-11-22 18:08 - 00002062 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-11-22 18:08 - 2015-11-22 18:08 - 00000000 ____D C:\Program Files\Microsoft OneDrive
2015-11-22 18:07 - 2015-11-22 18:07 - 00002162 _____ C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-11-22 18:07 - 2015-11-22 18:07 - 00000000 ___RD C:\Users\jacek\OneDrive
2015-11-22 18:07 - 2015-11-22 18:07 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-11-22 11:49 - 2015-11-22 11:49 - 02416640 _____ C:\Users\jacek\Documents\Projekt1.rvt
2015-11-22 00:52 - 2015-11-22 00:52 - 00001610 _____ C:\Users\Public\Desktop\Revit 2014 - Polski (Polish).lnk
2015-11-21 23:35 - 2015-11-21 23:38 - 00012288 _____ C:\Users\jacek\Documents\Project1(Recovery).rvt
2015-11-21 11:22 - 2015-11-21 11:22 - 00001150 _____ C:\Users\Public\Desktop\scilab-5.5.2.lnk
2015-11-21 11:22 - 2015-11-21 11:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\scilab-5.5.2
2015-11-21 11:18 - 2015-11-21 11:22 - 00000000 ____D C:\Program Files\scilab-5.5.2
2015-11-21 04:00 - 2015-11-21 04:00 - 00001610 _____ C:\Users\Public\Desktop\Revit 2014.lnk
2015-11-20 19:01 - 2015-11-20 19:01 - 00502998 _____ C:\Users\jacek\Desktop\CW_Calkowanie.pdf
2015-11-20 18:56 - 2015-11-20 18:56 - 00000000 ____D C:\Program Files\MSECache
2015-11-20 18:50 - 2015-11-20 18:50 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2015-11-20 18:47 - 2015-11-20 18:47 - 00039992 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtliteusbbus.sys
2015-11-20 18:46 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2015-11-20 18:46 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2015-11-20 18:46 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2015-11-20 18:46 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-11-20 18:46 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2015-11-20 18:46 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2015-11-20 18:46 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2015-11-20 18:46 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-11-20 18:45 - 2015-11-20 18:45 - 00026168 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2015-11-20 18:45 - 2015-11-20 18:45 - 00000917 _____ C:\Users\Public\Desktop\DirectX Happy Uninstall.lnk
2015-11-20 18:45 - 2015-11-20 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DirectX Happy Uninstall
2015-11-20 18:45 - 2015-11-20 18:45 - 00000000 ____D C:\Program Files\DirectX Happy Uninstall
2015-11-20 18:35 - 2015-11-20 18:39 - 00000000 ____D C:\Users\jacek\AppData\Roaming\360safe
2015-11-20 18:35 - 2015-11-20 18:35 - 00000000 ____D C:\Windows\Tasks\360Disabled
2015-11-20 18:34 - 2015-11-26 17:08 - 00000000 ____D C:\Users\jacek\AppData\LocalLow\360WD
2015-11-20 18:34 - 2015-11-20 18:34 - 00000000 ____D C:\Users\jacek\AppData\Roaming\360TotalSecurity
2015-11-20 18:34 - 2015-11-20 18:34 - 00000000 ____D C:\ProgramData\360TotalSecurity
2015-11-20 18:34 - 2015-11-12 16:10 - 00053960 _____ (360.cn) C:\Windows\system32\Drivers\qutmipc.sys
2015-11-20 18:33 - 2015-11-23 12:50 - 00000000 _RSHD C:\360SANDBOX
2015-11-20 18:33 - 2015-11-20 18:33 - 00001067 _____ C:\Users\Public\Desktop\360 Total Security.lnk
2015-11-20 18:33 - 2015-11-20 18:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center
2015-11-20 18:33 - 2015-11-12 16:10 - 00301264 _____ (360.cn) C:\Windows\system32\Drivers\qutmdrv.sys
2015-11-20 18:33 - 2015-11-12 16:10 - 00204368 _____ (360.cn) C:\Windows\system32\Drivers\360Box.sys
2015-11-20 18:33 - 2015-11-12 16:10 - 00179152 _____ (360安全中心) C:\Windows\system32\Drivers\360SelfProtection.sys
2015-11-20 18:33 - 2015-11-12 16:10 - 00174672 _____ (360.cn) C:\Windows\system32\Drivers\BAPIDRV.SYS
2015-11-20 18:33 - 2015-11-12 16:10 - 00122448 _____ (360.cn) C:\Windows\system32\Drivers\360AntiHacker.sys
2015-11-20 18:33 - 2015-11-12 16:10 - 00066128 _____ (360.cn) C:\Windows\system32\Drivers\360AvFlt.sys
2015-11-20 18:33 - 2015-11-12 16:10 - 00060368 _____ (360安全中心) C:\Windows\system32\Drivers\hookport.sys
2015-11-20 18:33 - 2015-11-12 16:10 - 00034888 _____ (360.cn) C:\Windows\system32\Drivers\360Camera.sys
2015-11-20 18:33 - 2015-11-12 16:10 - 00023248 _____ (360.cn) C:\Windows\system32\Drivers\efimon.sys
2015-11-20 18:32 - 2015-11-20 18:32 - 00000000 ____D C:\Program Files\360
2015-11-20 18:12 - 2015-11-20 18:12 - 00000000 ____D C:\Users\jacek\AppData\LocalLow\Company
2015-11-20 18:12 - 2015-11-20 18:12 - 00000000 ____D C:\Users\jacek\AppData\Local\Tempfolder
2015-11-20 18:12 - 2015-11-20 18:12 - 00000000 ____D C:\uninst
2015-11-20 17:51 - 2015-11-20 17:51 - 00000000 ____D C:\ProgramData\Zitenops
2015-11-19 13:23 - 2015-11-19 13:23 - 00000000 ____D C:\Users\jacek\AppData\Local\Experience Video
2015-11-19 13:21 - 2015-11-19 01:49 - 00000000 ____D C:\Users\jacek\AppData\Local\ospd_us_013010150
2015-11-19 02:10 - 2015-11-26 19:33 - 00000000 ____D C:\AdwCleaner
2015-11-18 09:04 - 2015-11-18 09:04 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlashGet3.7
2015-11-18 09:04 - 2015-11-18 09:04 - 00000000 ____D C:\Program Files\FlashGet Network
2015-11-17 21:02 - 2015-11-20 19:02 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Subtitle Edit
2015-11-17 21:02 - 2015-11-20 19:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Subtitle Edit
2015-11-17 21:01 - 2015-11-20 19:02 - 00000000 ____D C:\Users\jacek\AppData\Local\FalloffsPhilistine
2015-11-17 21:01 - 2015-11-20 18:30 - 00000098 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-11-17 20:32 - 2015-11-17 20:32 - 00000860 _____ C:\Users\jacek\Desktop\Nowy folder (2) — skrót.lnk
2015-11-17 20:27 - 2015-11-22 18:09 - 00149712 _____ C:\Users\jacek\AppData\Local\GDIPFONTCACHEV1.DAT
2015-11-17 20:20 - 2015-11-20 19:02 - 00000000 ____D C:\Program Files\CCleaner
2015-11-17 20:17 - 2015-11-20 18:49 - 00000000 ____D C:\ProgramData\360safe
2015-11-14 18:30 - 2015-11-14 18:30 - 00162625 _____ C:\Users\jacek\Documents\suwnica11_14.pdf
2015-11-14 18:17 - 2015-11-14 18:17 - 00159530 _____ C:\Users\jacek\Documents\34334333-Układ4.pdf
2015-11-14 18:13 - 2015-11-14 18:13 - 00154895 _____ C:\Users\jacek\Documents\rutjtun.pdf
2015-11-14 18:05 - 2015-11-14 18:05 - 00153453 _____ C:\Users\jacek\Documents\beeegagawfr-Układ4wfr-Układ4.pdf
2015-11-14 18:00 - 2015-11-14 18:00 - 10609750 _____ C:\Users\jacek\Documents\Binder1.pdf
2015-11-14 17:58 - 2015-11-14 17:58 - 00158592 _____ C:\Users\jacek\Documents\beeegagawfr_1_1_4766.sv$_1_1_9512.sv$-Układ4.pdf
2015-11-14 17:53 - 2015-11-14 17:53 - 00155097 _____ C:\Users\jacek\Documents\eytjr6j64rj.pdf
2015-11-14 17:52 - 2015-11-14 17:52 - 00155098 _____ C:\Users\jacek\Documents\beeegagawfr-Układ4beeegagawfr-Układ4beeegagawfr-Układ4.pdf
2015-11-14 17:50 - 2015-11-14 18:15 - 01126191 _____ C:\Users\jacek\Desktop\34334333.bak
2015-11-14 17:50 - 2015-11-14 17:50 - 00155149 _____ C:\Users\jacek\Documents\beeegagawfr-Układ4egagawfr-Układ4.pdf
2015-11-14 17:50 - 2015-11-14 17:50 - 00000199 ____H C:\Users\jacek\Documents\Rysunek1.dwl2
2015-11-14 17:50 - 2015-11-14 17:50 - 00000049 ____H C:\Users\jacek\Documents\Rysunek1.dwl
2015-11-14 17:50 - 2015-11-14 17:48 - 01174516 _____ C:\Users\jacek\Desktop\34334333.dwg
2015-11-14 17:47 - 2015-11-14 18:28 - 01030774 _____ C:\Users\jacek\Desktop\beeegagawfr_1_1_4766.sv$.dwg
2015-11-14 17:42 - 2015-11-14 17:42 - 00349902 _____ C:\Users\jacek\Desktop\przyklad_ii.pdf
2015-11-14 13:06 - 2015-11-14 13:06 - 00001902 _____ C:\Users\jacek\Documents\hhhh.wmf
2015-11-13 08:53 - 2015-11-13 08:53 - 00000000 ____D C:\Program Files\Clever Age
2015-11-13 08:22 - 2015-11-13 08:11 - 00000000 ____D C:\Users\jacek\AppData\Roaming\vlc
2015-11-13 08:08 - 2015-11-17 20:45 - 00000000 ____D C:\Program Files\Common Files\Real
2015-11-13 08:08 - 2015-11-13 08:08 - 00000000 ____D C:\Program Files\Real
2015-11-12 19:13 - 2015-11-12 19:10 - 00752519 _____ C:\Users\jacek\Desktop\beeegagawfrrr.bak
2015-11-12 19:10 - 2015-11-12 19:13 - 00944572 _____ C:\Users\jacek\Desktop\beeegagawfrrr.dwg
2015-11-12 18:37 - 2015-11-12 18:37 - 00058034 _____ C:\Users\jacek\Desktop\Wytyczne do proj hali SEM VI ver 2.pdf
2015-11-11 22:24 - 2015-11-23 16:47 - 00000000 ____D C:\Users\jacek\AppData\Local\Akamai
2015-11-10 15:27 - 2015-11-10 15:27 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Subversion
2015-11-10 15:27 - 2015-11-10 15:27 - 00000000 ____D C:\Users\jacek\AppData\Local\MathWorks
2015-11-10 15:26 - 2015-11-21 09:51 - 00000000 ____D C:\Users\jacek\Documents\MATLAB
2015-11-10 15:26 - 2015-11-10 15:26 - 00000000 ____D C:\Users\jacek\AppData\Roaming\MathWorks
2015-11-10 14:54 - 2015-11-10 15:26 - 00000933 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2015b.lnk
2015-11-10 14:54 - 2015-11-10 14:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB
2015-11-10 14:53 - 2015-11-26 17:00 - 00000490 _____ C:\Windows\Tasks\MATLAB R2015b Startup Accelerator.job
2015-11-10 14:53 - 2015-11-10 14:53 - 00000000 ____D C:\ProgramData\MathWorks
2015-11-09 22:57 - 2015-11-09 22:57 - 00000000 _____ C:\Users\jacek\w-ostatnizadanieslajd17.txt
2015-11-09 22:15 - 2015-11-09 22:15 - 00079867 _____ C:\Users\jacek\Documents\Okno graficzne numer 0.pdf
2015-11-09 22:14 - 2015-11-09 22:14 - 00125856 _____ C:\Users\jacek\Documents\3dplot.scg
2015-11-09 22:08 - 2015-11-09 22:08 - 00000000 _____ C:\Users\jacek\w-ostatniezadan.txt
2015-11-09 21:39 - 2015-11-21 11:52 - 00000940 _____ C:\Users\jacek\Documents\2gye.sce
2015-11-09 20:07 - 2015-11-09 20:07 - 00000146 _____ C:\Users\jacek\Documents\zapis.sce
2015-11-09 19:27 - 2015-11-09 19:30 - 00000270 _____ C:\Users\jacek\w-calki.txt
2015-11-09 18:21 - 2015-11-09 23:33 - 00000250 _____ C:\Users\jacek\Documents\calk3i.sce
2015-11-08 23:56 - 2015-11-08 23:56 - 00158707 _____ C:\Users\jacek\Documents\edffsaffaffa.pdf
2015-11-08 23:18 - 2015-11-09 18:19 - 00000137 _____ C:\Users\calki2.sce
2015-11-08 23:12 - 2015-11-08 23:12 - 00166552 _____ C:\Users\calki.scg
2015-11-08 23:04 - 2015-11-08 23:04 - 00000105 _____ C:\Users\jacek\Documents\calki.sce
2015-11-08 23:03 - 2015-11-08 23:03 - 00247112 _____ C:\Users\jacek\Documents\ttgddgg Układ1 (1).pdf
2015-11-06 00:16 - 2015-11-07 20:30 - 00162519 _____ C:\Users\jacek\Desktop\suwnicab.pdf
2015-11-05 23:29 - 2015-11-05 23:29 - 00053324 _____ C:\Users\jacek\Documents\beeegagawfr-Model.pdf
2015-11-05 20:05 - 2015-11-05 20:43 - 00001530 _____ C:\Users\Public\Documents\AcPro7_0_0.ini
2015-11-05 20:05 - 2015-11-05 20:24 - 00000095 _____ C:\Users\Public\Documents\AcPro7_0_0.sta
2015-11-05 20:04 - 2015-11-05 20:04 - 00000000 ____D C:\Users\jacek\AppData\Roaming\AdobeUM
2015-11-05 20:01 - 2015-11-05 20:01 - 00140550 _____ C:\Users\jacek\Documents\beeaaagawfr-Układ4.pdf
2015-11-05 19:42 - 2015-11-05 19:42 - 00000000 ____D C:\ProgramData\Adobe Systems
2015-11-05 19:41 - 2015-11-05 19:41 - 00000000 ____D C:\Program Files\Common Files\Adobe Systems Shared
2015-11-05 19:39 - 2015-11-05 20:23 - 00002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 7.0.lnk
2015-11-05 19:39 - 2015-11-05 20:23 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Designer 7.0.lnk
2015-11-05 19:39 - 2015-11-05 20:23 - 00002447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 7.0 Professional.lnk
2015-11-05 19:39 - 2015-11-05 20:03 - 00001558 _____ C:\Users\Public\Desktop\Adobe Acrobat 7.0 Professional.lnk
2015-11-05 19:39 - 2015-11-05 19:39 - 00000000 ____D C:\Users\Public\Documents\Adobe PDF
2015-11-05 18:10 - 2015-11-26 20:23 - 00000000 ____D C:\ProgramData\360Quarant
2015-11-05 18:10 - 2015-11-20 18:36 - 00000000 ____D C:\$360Section
2015-11-05 17:25 - 2015-11-05 17:25 - 00139680 _____ C:\Users\jacek\Documents\beeegagawfr-Układ4eegaga.pdf
2015-11-05 16:50 - 2015-11-05 16:50 - 00133961 _____ C:\Users\jacek\Documents\2-Układ4.pdf
2015-11-03 18:20 - 2015-11-03 18:20 - 00133300 _____ C:\Users\jacek\Documents\suwnicr-Układ3.pdf
2015-11-03 17:10 - 2015-11-03 17:10 - 00128547 _____ C:\Users\jacek\Documents\beeelka-Układ3.pdf
2015-11-02 00:39 - 2015-11-02 00:39 - 00009047 _____ C:\Users\jacek\Documents\beeegagawfr-Układ3aaa.pdf
2015-10-31 20:29 - 2015-11-14 18:37 - 00154579 _____ C:\Users\jacek\Documents\beeegagawfr-Układ4.pdf
2015-10-31 16:50 - 2015-10-31 16:50 - 00006693 _____ C:\Users\jacek\Documents\beeegagawfr-Układ3etg.pdf
2015-10-31 15:24 - 2015-10-31 15:24 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Ams
2015-10-31 15:21 - 2009-08-07 11:59 - 00233472 _____ (The cURL library, hxxp://curl.haxx.se/) C:\Windows\system32\libcurl.dll
2015-10-31 15:21 - 2007-03-17 11:56 - 00140288 _____ (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) C:\Windows\system32\pcre3.dll
2015-10-31 15:21 - 2007-03-17 11:56 - 00015872 _____ (GnuWin32 <hxxp://gnuwin32.sourceforge.net>) C:\Windows\system32\pcreposix3.dll
2015-10-31 15:21 - 2002-01-05 06:48 - 00974848 _____ (Microsoft Corporation) C:\Windows\system32\mfc70.dll
2015-10-31 15:21 - 2002-01-05 05:37 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msvcr70.dll
2015-10-29 10:50 - 2015-10-29 10:50 - 00000068 _____ C:\Users\jacek\Desktop\d***.txt
2015-10-29 09:18 - 2015-10-29 09:18 - 00000000 ____D C:\Users\jacek\AppData\Roaming\360SD
2015-10-27 10:38 - 2015-10-27 10:38 - 00027248 _____ (Connectify) C:\Windows\system32\Drivers\cnnctfy2.sys
2015-10-27 10:38 - 2015-10-27 10:05 - 00000000 ____D C:\Users\jacek\Desktop\Crack
2015-10-27 10:38 - 2011-11-18 00:41 - 00000371 _____ C:\Users\jacek\Desktop\Instructions.txt

==================== Jeden miesiąc - zmodyfikowane pliki i foldery ========

(Załączenie wejścia w fixlist spowoduje przeniesienie pliku/folderu.)

2015-11-26 19:44 - 2014-08-29 07:47 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-26 19:30 - 2009-07-14 05:34 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-26 19:30 - 2009-07-14 05:34 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-26 18:38 - 2015-10-17 13:53 - 00000999 _____ C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk
2015-11-26 18:38 - 2015-04-28 20:32 - 00000901 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-11-26 18:38 - 2005-01-02 09:27 - 00000913 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-26 18:20 - 2009-07-14 03:37 - 00000000 ____D C:\Windows
2015-11-26 16:58 - 2005-01-02 16:02 - 00000000 ____D C:\Users\jacek\AppData\Roaming\uTorrent
2015-11-26 16:56 - 2014-12-13 06:03 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2015-11-26 16:56 - 2014-08-26 08:08 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-11-26 16:56 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-26 16:56 - 2005-01-02 08:05 - 00000000 ____D C:\Users\jacek
2015-11-26 14:38 - 2009-07-14 03:03 - 60030976 _____ C:\Windows\system32\config\software.bak
2015-11-26 14:38 - 2009-07-14 03:03 - 18612224 _____ C:\Windows\system32\config\system.bak
2015-11-26 14:38 - 2009-07-14 03:03 - 00524288 _____ C:\Windows\system32\config\default.bak
2015-11-26 14:38 - 2009-07-14 03:03 - 00262144 _____ C:\Windows\system32\config\security.bak
2015-11-26 14:38 - 2009-07-14 03:03 - 00262144 _____ C:\Windows\system32\config\sam.bak
2015-11-26 14:33 - 2015-03-19 23:09 - 00000000 ____D C:\ProgramData\TEMP
2015-11-26 14:15 - 2005-01-02 16:00 - 00329384 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys
2015-11-26 13:58 - 2012-07-09 01:32 - 05834240 _____ C:\Users\jacek\Desktop\top_netinfo.exe
2015-11-26 13:58 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\ModemLogs
2015-11-26 06:28 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2015-11-26 05:57 - 2015-10-17 13:53 - 00000000 ____D C:\Users\jacek\AppData\Roaming\WarThunder
2015-11-25 19:26 - 2015-04-07 19:20 - 00000000 ____D C:\Users\jacek\AppData\Local\CrashDumps
2015-11-23 16:47 - 2014-09-18 01:53 - 00000000 ____D C:\ProgramData\FLEXnet
2015-11-23 16:47 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\registration
2015-11-23 13:03 - 2015-06-15 19:09 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Autodesk
2015-11-23 13:03 - 2015-06-15 19:09 - 00000000 ____D C:\ProgramData\Autodesk
2015-11-22 18:38 - 2005-01-02 17:38 - 00000000 ____D C:\Program Files\Microsoft Office
2015-11-22 18:06 - 2014-11-11 11:03 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2015-11-22 18:06 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-11-22 18:05 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf
2015-11-22 17:48 - 2009-07-14 05:33 - 02456112 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-22 00:52 - 2015-06-15 19:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2015-11-21 23:45 - 2015-06-15 19:28 - 00000000 ____D C:\Program Files\Autodesk
2015-11-21 09:39 - 2009-07-14 09:07 - 05925478 _____ C:\Windows\system32\perfh015.dat
2015-11-21 09:39 - 2009-07-14 09:07 - 01913032 _____ C:\Windows\system32\perfc015.dat
2015-11-21 09:39 - 2005-01-02 08:13 - 00006388 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-21 08:09 - 2015-06-15 19:33 - 00000000 ____D C:\Users\jacek\AppData\Local\Autodesk
2015-11-20 19:02 - 2015-04-22 20:21 - 00000000 ____D C:\Program Files\Common Files\Intel
2015-11-20 19:02 - 2015-04-07 20:16 - 00000000 ____D C:\Users\jacek\AppData\Roaming\FlashGetBHO
2015-11-20 19:02 - 2015-04-07 20:16 - 00000000 ____D C:\Users\jacek\AppData\Roaming\BITS
2015-11-20 19:02 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\AppCompat
2015-11-20 19:01 - 2014-08-26 10:06 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Notepad++
2015-11-20 19:01 - 2005-01-02 16:00 - 00000000 ____D C:\Users\jacek\AppData\Roaming\DAEMON Tools Lite
2015-11-20 18:55 - 2014-11-20 16:33 - 00000000 ____D C:\Users\jacek\AppData\Local\Disc_Soft_Ltd
2015-11-20 18:53 - 2015-10-13 04:20 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared
2015-11-20 18:51 - 2015-03-14 11:32 - 00000678 __RSH C:\ProgramData\ntuser.pol
2015-11-20 18:33 - 2015-10-17 14:28 - 00000000 ____D C:\Program Files\Common Files\AV
2015-11-20 18:27 - 2015-08-27 23:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-11-20 18:14 - 2005-01-02 09:27 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-11-20 03:04 - 2015-09-17 22:47 - 00075696 _____ C:\Users\jacek\Desktop\Nowy dokument dziennika.jnt
2015-11-19 05:34 - 2013-04-15 19:37 - 00000000 ____D C:\Users\jacek\AppData\Local\cache
2015-11-19 01:35 - 2014-10-18 07:45 - 00000173 _____ C:\Users\jacek\AppData\Local\msmathematics.qat.jacek
2015-11-17 20:54 - 2015-04-22 20:22 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2015-11-17 20:45 - 2014-09-18 18:40 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Real
2015-11-17 20:17 - 2014-08-26 16:50 - 00000000 ____D C:\Users\jacek\AppData\Local\AdFender
2015-11-17 20:13 - 2014-08-26 16:54 - 00000000 ____D C:\Program Files\WinRAR
2015-11-16 19:47 - 2015-01-27 02:12 - 00000000 ____D C:\ProgramData\Ralink
2015-11-16 19:41 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2015-11-16 19:29 - 2009-07-14 05:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-11-14 18:02 - 2014-08-30 07:27 - 00000000 ____D C:\Users\jacek\AppData\Local\Adobe
2015-11-14 17:52 - 2015-07-05 03:17 - 00000000 ____D C:\RM-Win_4.21
2015-11-12 18:42 - 2014-08-28 10:43 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Media Player Classic
2015-11-12 02:47 - 2015-10-04 20:54 - 00000000 ____D C:\Program Files\MpcStar
2015-11-12 02:38 - 2015-10-04 20:52 - 00000000 ____D C:\Program Files\BitComet
2015-11-11 22:24 - 2015-08-24 21:22 - 00000000 ____D C:\Autodesk
2015-11-10 18:44 - 2014-08-29 07:47 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-11-10 18:44 - 2014-08-29 07:47 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-11-10 15:59 - 2014-10-26 07:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic
2015-11-10 15:59 - 2014-10-14 19:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AirSnare
2015-11-10 15:59 - 2014-10-05 15:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
2015-11-10 15:59 - 2014-09-29 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DU Super Controler
2015-11-10 15:59 - 2012-04-08 00:41 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-08 23:32 - 2014-09-17 22:51 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-11-06 00:48 - 2015-10-13 05:11 - 00879628 _____ C:\Users\jacek\Desktop\beeegagawfr.dwg
2015-11-05 21:04 - 2015-10-17 14:36 - 00692764 _____ C:\Users\jacek\Desktop\beeegagawfr.bak
2015-11-05 20:05 - 2005-01-02 17:27 - 00000000 ____D C:\Users\jacek\AppData\Roaming\Adobe
2015-11-05 18:46 - 2005-01-02 16:51 - 00000000 ____D C:\ProgramData\Adobe
2015-11-05 18:22 - 2014-08-26 16:45 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-04 23:33 - 2015-07-23 23:13 - 00135054 _____ C:\Users\jacek\Documents\beeegagawfr-Układ3.pdf
2015-10-29 15:49 - 2015-10-17 13:58 - 00000000 ____D C:\ProgramData\Zonzap

==================== Pliki w katalogu głównym wybranych folderów =======

2015-04-14 17:28 - 2015-04-14 17:28 - 0004387 _____ () C:\Users\jacek\AppData\Roaming\1NnwukYoQ2tWXnzPPc
2014-10-05 15:05 - 2012-04-06 22:42 - 0000902 _____ () C:\Users\jacek\AppData\Roaming\burnaware.ini
2015-04-14 17:28 - 2015-04-14 17:28 - 0004387 _____ () C:\Users\jacek\AppData\Roaming\U0a5yO7Tih
2015-04-22 23:08 - 2015-04-22 23:08 - 0001503 _____ () C:\Users\jacek\AppData\Local\anzeige.htm
2015-04-22 23:14 - 2015-04-22 23:14 - 0000256 _____ () C:\Users\jacek\AppData\Local\flogx106.cfg
2015-04-22 20:30 - 2015-04-30 19:36 - 0001472 _____ () C:\Users\jacek\AppData\Local\FriloWebInfo.html
2014-10-18 07:45 - 2015-11-19 01:35 - 0000173 _____ () C:\Users\jacek\AppData\Local\msmathematics.qat.jacek
2014-12-07 15:09 - 2014-12-07 15:09 - 0003018 _____ () C:\Users\jacek\AppData\Local\recently-used.xbel
2015-01-04 04:05 - 2015-01-06 08:39 - 0007607 _____ () C:\Users\jacek\AppData\Local\Resmon.ResmonCfg
2015-11-17 21:01 - 2015-11-20 18:30 - 0000098 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Pliki do przeniesienia lub usunięcia:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


Niektóre pliki w TEMP:
====================
C:\Users\jacek\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(Brak automatycznej naprawy dla plików które nie przeszły weryfikacji.)

C:\Windows\explorer.exe => Plik podpisany cyfrowo
C:\Windows\system32\winlogon.exe => Plik podpisany cyfrowo
C:\Windows\system32\wininit.exe => Plik podpisany cyfrowo
C:\Windows\system32\svchost.exe => Plik podpisany cyfrowo
C:\Windows\system32\services.exe => Plik podpisany cyfrowo
C:\Windows\system32\User32.dll => Plik podpisany cyfrowo
C:\Windows\system32\userinit.exe => Plik podpisany cyfrowo
C:\Windows\system32\rpcss.dll => Plik podpisany cyfrowo
C:\Windows\system32\dnsapi.dll => Plik podpisany cyfrowo
C:\Windows\system32\Drivers\volsnap.sys => Plik podpisany cyfrowo


LastRegBack: 2015-11-20 03:10

==================== Koniec FRST.txt ============================

zrobilem ponownie i co tam widac?

W temacie:Proszę o pomoc ComboFix, logi programu ratunku!!!

26 listopad 2015 - 18:50

log z FRST
http://wklejto.pl/241255

# AdwCleaner v5.022 - Utworzono raport 26/11/2015 o 18:35:27
# Ostatnia aktualizacja 22/11/2015 przez Xplode
# Baza danych : 2015-11-22.2 [Serwer]
# System operacyjny : Windows 7 Ultimate (x86)
# Nazwa użytkownika : jacek - JACEK-KOMPUTER
# Lokalizacja programu : D:\Downloads\adwcleaner_5.022.exe
# Działanie : Skanuj
# Wsparcie : http://toolslib.net/forum

***** [ Usługi ] *****

Usługa znaleziono : WdsManPro
Usługa znaleziono : ihpmServer

***** [ Foldery ] *****

Folder znaleziono : C:\Program Files\SpaceSoundPro
Folder znaleziono : C:\Program Files\RayDld
Folder znaleziono : C:\Program Files\AmazingTab
Folder znaleziono : C:\Program Files\SpaceSoundPro
Folder znaleziono : C:\Program Files\gmsd_pl_005010152
Folder znaleziono : C:\Program Files\SpaceSondPro_v53.9388
Folder znaleziono : C:\ProgramData\1WMiniPro1
Folder znaleziono : C:\ProgramData\7WMiniPro7
Folder znaleziono : C:\ProgramData\QWMiniProQ
Folder znaleziono : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder znaleziono : C:\Users\jacek\AppData\Local\gmsd_pl_005010152
Folder znaleziono : C:\Users\jacek\AppData\Local\02AA6EBC-1447939299-DC11-8723-0011D8A408ED
Folder znaleziono : C:\Users\jacek\AppData\Local\02AA6EBC-1448045400-DC11-8723-0011D8A408ED
Folder znaleziono : C:\Users\jacek\AppData\Local\26129
Folder znaleziono : C:\Users\jacek\AppData\Local\Installer\Install_364
Folder znaleziono : C:\Users\jacek\AppData\LocalLow\SmartWeb
Folder znaleziono : C:\Users\jacek\AppData\Roaming\istartsurf
Folder znaleziono : C:\Users\jacek\AppData\Roaming\oursurfing
Folder znaleziono : C:\Users\jacek\AppData\Roaming\istartpageing
Folder znaleziono : C:\Users\Public\Documents\ShopperPro

***** [ Pliki ] *****

Plik znaleziono : C:\END
Plik znaleziono : C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\searchplugins\istartpageing.xml

***** [ DLL ] *****


***** [ Skróty ] *****

Skrót Zainfekowany : C:\Users\Public\Desktop\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\Desktop\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )

***** [ Zaplanowane zadania ] *****

Zadanie znaleziono : WarThunder sun
Zadanie znaleziono : WarThunder sat
Zadanie znaleziono : WarThunder24

***** [ Rejestr ] *****

Klucz znaleziono : HKCU\Software\Mozilla\Extends
Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
Wartość znaleziono : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [deskCutv2@gmail.com]
Klucz znaleziono : HKLM\SOFTWARE\Classes\AppID\{85198F55-85AC-498A-BFE4-BBC33840F4AB}
Klucz znaleziono : HKCU\Software\Classes\CLSID\{117270FA-48AC-45BB-9171-B63D1B42A910}
Klucz znaleziono : HKCU\Software\PRODUCTSETUP
Klucz znaleziono : HKLM\SOFTWARE\istartsurfSoftware
Klucz znaleziono : HKLM\SOFTWARE\WdsManPro
Klucz znaleziono : HKLM\SOFTWARE\RayDld
Klucz znaleziono : HKLM\SOFTWARE\ihpmserver
Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WarThunder
Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartpageing
Klucz znaleziono : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartpageing.com/?type=hp&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9
Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartpageing.com/?type=hp&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9
Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}
Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}
Dane wartości znaleziono : HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command [] - "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://www.istartsurf.com/?type=sc&ts=1448040617&z=5947fb2d0ee65de32e60bdbgcz0z5b6eaz2cbzct2t&from=cor&uid=ST3250410AS_6RY23RX9XXXX6RY23RX9

***** [ Przeglądarki internetowe ] *****

[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.newtab.url", "hxxp://www.istartpageing.com/newtab/?type=nt&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9");
[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.search.defaultenginename", "istartpageing");
[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.search.hiddenOneOffs", "DuckDuckGo,Encyklopedia PWN,istartpageing,Merlin,oursurfing");

########## EOF - C:\AdwCleaner\AdwCleaner[S12].txt - [6670 bajty] ##########

# AdwCleaner v5.022 - Utworzono raport 26/11/2015 o 18:35:27<br /># Ostatnia aktualizacja 22/11/2015 przez Xplode<br /># Baza danych : 2015-11-22.2 [Serwer]<br /># System operacyjny : Windows 7 Ultimate (x86)<br /># Nazwa użytkownika : jacek - JACEK-KOMPUTER<br /># Lokalizacja programu : D:\Downloads\adwcleaner_5.022.exe<br /># Działanie : Skanuj<br /># Wsparcie : http://toolslib.net/forum<br /><br />***** [ Usługi ] *****<br /><br />Usługa znaleziono : WdsManPro<br />Usługa znaleziono : ihpmServer<br /><br />***** [ Foldery ] *****<br /><br />Folder znaleziono : C:\Program Files\SpaceSoundPro<br />Folder znaleziono : C:\Program Files\RayDld<br />Folder znaleziono : C:\Program Files\AmazingTab<br />Folder znaleziono : C:\Program Files\SpaceSoundPro<br />Folder znaleziono : C:\Program Files\gmsd_pl_005010152<br />Folder znaleziono : C:\Program Files\SpaceSondPro_v53.9388<br />Folder znaleziono : C:\ProgramData\1WMiniPro1<br />Folder znaleziono : C:\ProgramData\7WMiniPro7<br />Folder znaleziono : C:\ProgramData\QWMiniProQ<br />Folder znaleziono : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP<br />Folder znaleziono : C:\Users\jacek\AppData\Local\gmsd_pl_005010152<br />Folder znaleziono : C:\Users\jacek\AppData\Local\02AA6EBC-1447939299-DC11-8723-0011D8A408ED<br />Folder znaleziono : C:\Users\jacek\AppData\Local\02AA6EBC-1448045400-DC11-8723-0011D8A408ED<br />Folder znaleziono : C:\Users\jacek\AppData\Local\26129<br />Folder znaleziono : C:\Users\jacek\AppData\Local\Installer\Install_364<br />Folder znaleziono : C:\Users\jacek\AppData\LocalLow\SmartWeb<br />Folder znaleziono : C:\Users\jacek\AppData\Roaming\istartsurf<br />Folder znaleziono : C:\Users\jacek\AppData\Roaming\oursurfing<br />Folder znaleziono : C:\Users\jacek\AppData\Roaming\istartpageing<br />Folder znaleziono : C:\Users\Public\Documents\ShopperPro<br /><br />***** [ Pliki ] *****<br /><br />Plik znaleziono : C:\END<br />Plik znaleziono : C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\searchplugins\istartpageing.xml<br /><br />***** [ DLL ] *****<br /><br /><br />***** [ Skróty ] *****<br /><br />Skrót Zainfekowany : C:\Users\Public\Desktop\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9 )<br />Skrót Zainfekowany : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9 )<br />Skrót Zainfekowany : C:\Users\jacek\Desktop\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9 )<br />Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9 )<br />Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9 )<br />Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9 )<br /><br />***** [ Zaplanowane zadania ] *****<br /><br />Zadanie znaleziono : WarThunder sun<br />Zadanie znaleziono : WarThunder sat<br />Zadanie znaleziono : WarThunder24<br /><br />***** [ Rejestr ] *****<br /><br />Klucz znaleziono : HKCU\Software\Mozilla\Extends<br />Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro<br />Wartość znaleziono : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [deskCutv2@gmail.com]<br />Klucz znaleziono : HKLM\SOFTWARE\Classes\AppID\{85198F55-85AC-498A-BFE4-BBC33840F4AB}<br />Klucz znaleziono : HKCU\Software\Classes\CLSID\{117270FA-48AC-45BB-9171-B63D1B42A910}<br />Klucz znaleziono : HKCU\Software\PRODUCTSETUP<br />Klucz znaleziono : HKLM\SOFTWARE\istartsurfSoftware<br />Klucz znaleziono : HKLM\SOFTWARE\WdsManPro<br />Klucz znaleziono : HKLM\SOFTWARE\RayDld<br />Klucz znaleziono : HKLM\SOFTWARE\ihpmserver<br />Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WarThunder<br />Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartpageing<br />Klucz znaleziono : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_<br />Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartpageing.com/?type=hp&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9<br />Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartpageing.com/?type=hp&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9<br />Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}<br />Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}<br />Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}<br />Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}<br />Dane wartości znaleziono : HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command [] - "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://www.istartsurf.com/?type=sc&amp;ts=1448040617&amp;z=5947fb2d0ee65de32e60bdbgcz0z5b6eaz2cbzct2t&amp;from=cor&amp;uid=ST3250410AS_6RY23RX9XXXX6RY23RX9<br /><br />***** [ Przeglądarki internetowe ] *****<br /><br />[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.newtab.url", "hxxp://www.istartpageing.com/newtab/?type=nt&amp;ts=1448513890&amp;z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&amp;from=cornl&amp;uid=st3250410as_6ry23rx9xxxx6ry23rx9");<br />[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.search.defaultenginename", "istartpageing");<br />[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.search.hiddenOneOffs", "DuckDuckGo,Encyklopedia PWN,istartpageing,Merlin,oursurfing");<br /><br />########## EOF - C:\AdwCleaner\AdwCleaner[S12].txt - [6670 bajty] ##########<br />

# AdwCleaner v5.022 - Utworzono raport 26/11/2015 o 18:35:27
# Ostatnia aktualizacja 22/11/2015 przez Xplode
# Baza danych : 2015-11-22.2 [Serwer]
# System operacyjny : Windows 7 Ultimate (x86)
# Nazwa użytkownika : jacek - JACEK-KOMPUTER
# Lokalizacja programu : D:\Downloads\adwcleaner_5.022.exe
# Działanie : Skanuj
# Wsparcie : http://toolslib.net/forum

***** [ Usługi ] *****

Usługa znaleziono : WdsManPro
Usługa znaleziono : ihpmServer

***** [ Foldery ] *****

Folder znaleziono : C:\Program Files\SpaceSoundPro
Folder znaleziono : C:\Program Files\RayDld
Folder znaleziono : C:\Program Files\AmazingTab
Folder znaleziono : C:\Program Files\SpaceSoundPro
Folder znaleziono : C:\Program Files\gmsd_pl_005010152
Folder znaleziono : C:\Program Files\SpaceSondPro_v53.9388
Folder znaleziono : C:\ProgramData\1WMiniPro1
Folder znaleziono : C:\ProgramData\7WMiniPro7
Folder znaleziono : C:\ProgramData\QWMiniProQ
Folder znaleziono : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder znaleziono : C:\Users\jacek\AppData\Local\gmsd_pl_005010152
Folder znaleziono : C:\Users\jacek\AppData\Local\02AA6EBC-1447939299-DC11-8723-0011D8A408ED
Folder znaleziono : C:\Users\jacek\AppData\Local\02AA6EBC-1448045400-DC11-8723-0011D8A408ED
Folder znaleziono : C:\Users\jacek\AppData\Local\26129
Folder znaleziono : C:\Users\jacek\AppData\Local\Installer\Install_364
Folder znaleziono : C:\Users\jacek\AppData\LocalLow\SmartWeb
Folder znaleziono : C:\Users\jacek\AppData\Roaming\istartsurf
Folder znaleziono : C:\Users\jacek\AppData\Roaming\oursurfing
Folder znaleziono : C:\Users\jacek\AppData\Roaming\istartpageing
Folder znaleziono : C:\Users\Public\Documents\ShopperPro

***** [ Pliki ] *****

Plik znaleziono : C:\END
Plik znaleziono : C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\searchplugins\istartpageing.xml

***** [ DLL ] *****


***** [ Skróty ] *****

Skrót Zainfekowany : C:\Users\Public\Desktop\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\Desktop\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )
Skrót Zainfekowany : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ( hxxp://www.istartpageing.com/?type=sc&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9 )

***** [ Zaplanowane zadania ] *****

Zadanie znaleziono : WarThunder sun
Zadanie znaleziono : WarThunder sat
Zadanie znaleziono : WarThunder24

***** [ Rejestr ] *****

Klucz znaleziono : HKCU\Software\Mozilla\Extends
Klucz znaleziono : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
Wartość znaleziono : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [deskCutv2@gmail.com]
Klucz znaleziono : HKLM\SOFTWARE\Classes\AppID\{85198F55-85AC-498A-BFE4-BBC33840F4AB}
Klucz znaleziono : HKCU\Software\Classes\CLSID\{117270FA-48AC-45BB-9171-B63D1B42A910}
Klucz znaleziono : HKCU\Software\PRODUCTSETUP
Klucz znaleziono : HKLM\SOFTWARE\istartsurfSoftware
Klucz znaleziono : HKLM\SOFTWARE\WdsManPro
Klucz znaleziono : HKLM\SOFTWARE\RayDld
Klucz znaleziono : HKLM\SOFTWARE\ihpmserver
Klucz znaleziono : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WarThunder
Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartpageing
Klucz znaleziono : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartpageing.com/?type=hp&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9
Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartpageing.com/?type=hp&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9
Klucz znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Dane wartości znaleziono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}
Klucz znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Dane wartości znaleziono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {33BB0A4E-99AF-4226-BDF6-49120163DE86}
Dane wartości znaleziono : HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command [] - "C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://www.istartsurf.com/?type=sc&ts=1448040617&z=5947fb2d0ee65de32e60bdbgcz0z5b6eaz2cbzct2t&from=cor&uid=ST3250410AS_6RY23RX9XXXX6RY23RX9

***** [ Przeglądarki internetowe ] *****

[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.newtab.url", "hxxp://www.istartpageing.com/newtab/?type=nt&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9");
[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.search.defaultenginename", "istartpageing");
[C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] znaleziono : user_pref("browser.search.hiddenOneOffs", "DuckDuckGo,Encyklopedia PWN,istartpageing,Merlin,oursurfing");

########## EOF - C:\AdwCleaner\AdwCleaner[S12].txt - [6670 bajty] ##########

# AdwCleaner v5.022 - Utworzono raport 26/11/2015 o 18:38:10
# Ostatnia aktualizacja 22/11/2015 przez Xplode
# Baza danych : 2015-11-22.2 [Serwer]
# System operacyjny : Windows 7 Ultimate (x86)
# Nazwa użytkownika : jacek - JACEK-KOMPUTER
# Lokalizacja programu : D:\Downloads\adwcleaner_5.022.exe
# Działanie : Usuń
# Wsparcie : http://toolslib.net/forum

***** [ Usługi ] *****

[-] Usługa usunięto : WdsManPro
[-] Usługa usunięto : ihpmServer

***** [ Foldery ] *****

[-] Folder usunięto : C:\Program Files\SpaceSoundPro
[-] Folder usunięto : C:\Program Files\RayDld
[-] Folder usunięto : C:\Program Files\AmazingTab
[!] Folder Nie usunięto : C:\Program Files\SpaceSoundPro
[-] Folder usunięto : C:\Program Files\gmsd_pl_005010152
[-] Folder usunięto : C:\Program Files\SpaceSondPro_v53.9388
[-] Folder usunięto : C:\ProgramData\1WMiniPro1
[-] Folder usunięto : C:\ProgramData\7WMiniPro7
[-] Folder usunięto : C:\ProgramData\QWMiniProQ
[-] Folder usunięto : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
[-] Folder usunięto : C:\Users\jacek\AppData\Local\gmsd_pl_005010152
[-] Folder usunięto : C:\Users\jacek\AppData\Local\02AA6EBC-1447939299-DC11-8723-0011D8A408ED
[-] Folder usunięto : C:\Users\jacek\AppData\Local\02AA6EBC-1448045400-DC11-8723-0011D8A408ED
[-] Folder usunięto : C:\Users\jacek\AppData\Local\26129
[-] Folder usunięto : C:\Users\jacek\AppData\Local\Installer\Install_364
[-] Folder usunięto : C:\Users\jacek\AppData\LocalLow\SmartWeb
[-] Folder usunięto : C:\Users\jacek\AppData\Roaming\istartsurf
[-] Folder usunięto : C:\Users\jacek\AppData\Roaming\oursurfing
[-] Folder usunięto : C:\Users\jacek\AppData\Roaming\istartpageing
[-] Folder usunięto : C:\Users\Public\Documents\ShopperPro

***** [ Pliki ] *****

[-] Plik usunięto : C:\END
[-] Plik usunięto : C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\searchplugins\istartpageing.xml

***** [ DLLs ] *****


***** [ Skróty ] *****

[-] Skrót wyleczono : C:\Users\Public\Desktop\Mozilla Firefox.lnk
[-] Skrót wyleczono : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Skrót wyleczono : C:\Users\jacek\Desktop\WarThunder.lnk
[-] Skrót wyleczono : C:\Users\jacek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder.lnk
[-] Skrót wyleczono : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk
[-] Skrót wyleczono : C:\Users\jacek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk

***** [ Zaplanowane zadania ] *****

[-] Zadanie usunięto : WarThunder sun
[-] Zadanie usunięto : WarThunder sat
[-] Zadanie usunięto : WarThunder24

***** [ Rejestr ] *****

[-] Klucz usunięto : HKCU\Software\Mozilla\Extends
[-] Klucz usunięto : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
[-] Wartość usunięto : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [deskCutv2@gmail.com]
[-] Klucz usunięto : HKLM\SOFTWARE\Classes\AppID\{85198F55-85AC-498A-BFE4-BBC33840F4AB}
[-] Klucz usunięto : HKCU\Software\Classes\CLSID\{117270FA-48AC-45BB-9171-B63D1B42A910}
[-] Klucz usunięto : HKCU\Software\PRODUCTSETUP
[-] Klucz usunięto : HKLM\SOFTWARE\istartsurfSoftware
[-] Klucz usunięto : HKLM\SOFTWARE\WdsManPro
[-] Klucz usunięto : HKLM\SOFTWARE\RayDld
[-] Klucz usunięto : HKLM\SOFTWARE\ihpmserver
[-] Klucz usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WarThunder
[-] Klucz usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartpageing
[-] Klucz usunięto : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
[-] Dane wartości przywrócono : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Dane wartości przywrócono : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Klucz usunięto : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Dane wartości przywrócono : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Klucz usunięto : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Dane wartości przywrócono : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Dane wartości przywrócono : HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command []

***** [ Przeglądarki internetowe ] *****

[-] [C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] usunięto : user_pref("browser.newtab.url", "hxxp://www.istartpageing.com/newtab/?type=nt&ts=1448513890&z=1511b120a1b349934636f71g2z1z8b0w2g9cab8tce&from=cornl&uid=st3250410as_6ry23rx9xxxx6ry23rx9");
[-] [C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] usunięto : user_pref("browser.search.defaultenginename", "istartpageing");
[-] [C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\rjez7bep.default-1443728688780\prefs.js] [Preference] usunięto : user_pref("browser.search.hiddenOneOffs", "DuckDuckGo,Encyklopedia PWN,istartpageing,Merlin,oursurfing");

*************************

:: "Tracing" klucze usunięta
:: Zresetowano ustawienia Winsock

########## EOF - C:\AdwCleaner\AdwCleaner[C11].txt - [5483 bajty] ##########