Skocz do zawartości
  • 👋 Witaj na MPCForum!

    Przeglądasz forum jako gość, co oznacza, że wiele świetnych funkcji jest jeszcze przed Tobą! 😎

    • Pełny dostęp do działów i ukrytych treści
    • Możliwość pisania i odpowiadania w tematach
    • System prywatnych wiadomości
    • Zbieranie reputacji i rozwijanie swojego profilu
    • Członkostwo w jednej z największych społeczności graczy

    👉 Dołączenie zajmie Ci mniej niż minutę – a zyskasz znacznie więcej!

    Zarejestruj się teraz
  • 0

problem z Rosyjskimi natrętnymi programami.


MR.ZiomuuSs

Pytanie

Opublikowano

Witam. Wczoraj mój młodszy brat zainstalował jakiś program. Jednak instalator był w języku Rosyjskim, więc jak się można było spodziewać nie tylko to zainstalował -,- Po uruchomieniu komputera pokazuje się na chwilę kilka konsol. Jakieś Ruskie strony oblegają każdą przeglądarkę, co chwile coś ruskiego się instaluje (wszystkie programy mogące to powodować odinstalowałem). Nie wiem co się dzieje, proszę o pomoc ;-;

FRST.txt:

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by WOJT (administrator) on WOJT-KOMPUTER on 03-02-2015 10:41:40
Running from C:\Users\WOJT\Desktop\moje\FRST
Loaded Profiles: WOJT (Available profiles: WOJT & UpdatusUser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Polski (Polska)
Internet Explorer Version 9 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\Run: [thferblgac] => cmd /c start http://foretuned.com/
HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\RunOnce: [**>9B8 2 8=B5@=5B 2inf.net_startspeeddialmaker_chrome<*>] => "C:\Users\WOJT\AppData\Local\Temp\netB263.tmp.exe" --fromrunonce --partnertitle="Войти в интернет 2inf.net" --browser="chrome" <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\MountPoints2: K - K:\Install.exe
HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\MountPoints2: {231677e6-4e2c-11e4-8602-001d7daa2bab} - K:\Install.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKU\S-1-5-21-944672953-4028843236-912156999-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=156
SearchScopes: HKLM-x32 -> DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = 
SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> DefaultScope {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = http://go-search.ru/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {828B376B-F2F6-4778-928C-E29EC877535E} URL = http://www.google.com/cse?cx=partner-pub-0900663996874144:6813731868&ie=UTF-8&q={searchTerms}&sa=Search&ref=#gsc.tab=0&gsc.q={searchTerms}&gsc.page=1
SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = http://go-search.ru/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = http://go.mail.ru/search?q={SearchTerms}&fr=ntg
SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {szukaj.gazeta.pl} URL = http://szukaj.gazeta.pl/internet/0,0.html?slowo={searchTerms}
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\WOJT\AppData\Roaming\Mozilla\Firefox\Profiles\ffqkoyy7.default-1420461439169
FF DefaultSearchEngine: GoSearch
FF SelectedSearchEngine: GoSearch
FF Homepage: google.pl
FF Keyword.URL: hxxp://go.mail.ru/search?fr=ntg&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\WOJT\AppData\Roaming\Mozilla\Firefox\Profiles\ffqkoyy7.default-1420461439169\searchplugins\GoSearch.xml
FF SearchPlugin: C:\Users\WOJT\AppData\Roaming\Mozilla\Firefox\Profiles\ffqkoyy7.default-1420461439169\searchplugins\mailru.xml
FF SearchPlugin: C:\Users\WOJT\AppData\Roaming\Mozilla\Firefox\Profiles\ffqkoyy7.default-1420461439169\searchplugins\szukaj-gazeta-pl.xml

Chrome: 
=======
CHR HomePage: Default -> hxxp://mail.ru/cnt/10445?gp=blackbear5
CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=blackbear5", "hxxp://www.google.com"
CHR DefaultSearchKeyword: Default -> GoSearch
CHR DefaultSuggestURL: Default -> http://suggest.yandex.net/suggest-ff.cgi?part={searchTerms}
CHR Profile: C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-08]
CHR Extension: (Google Drive) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-08]
CHR Extension: (Google Search) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-08]
CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdknicmnhbaajdglbinpahhapghpakch [2015-02-02]
CHR Extension: (Mail.Ru) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\jedelkhanefmcnpappfhachbpnlhomai [2015-02-02]
CHR Extension: (Визуальные Закладки Mail.Ru) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pganlglbhgfjfgopijbhemcpbehjnpia [2015-02-02]
CHR Extension: (Gmail) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-08]
CHR HKLM-x32\...\Chrome\Extension: [gdknicmnhbaajdglbinpahhapghpakch] - No Path
CHR HKLM-x32\...\Chrome\Extension: [jedelkhanefmcnpappfhachbpnlhomai] - No Path
CHR HKLM-x32\...\Chrome\Extension: [pganlglbhgfjfgopijbhemcpbehjnpia] - No Path

Opera: 
=======
OPR StartupUrls: "hxxp://www.surfvox.com/"
OPR Extension: (Music с ВК) - C:\Users\WOJT\AppData\Roaming\Opera Software\Opera Stable\Extensions\lhbokblhneabjnphebnkelcfajmninoo [2015-02-02]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2015-01-17] (Tunngle.net GmbH)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-07] (Disc Soft Ltd)
R3 RTL85n64; C:\Windows\System32\DRIVERS\RTL85n64.sys [378368 2009-06-10] (Realtek)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 08:54 - 2015-02-03 08:54 - 00000584 _____ () C:\Windows\PFRO.log
2015-02-02 18:22 - 2015-02-02 18:36 - 90168102 _____ () C:\Users\WOJT\Downloads\skyre_09916928609916vanilla.zip
2015-02-02 18:22 - 2015-02-02 18:22 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Вoйти в Интeрнет 2inf.net
2015-02-02 18:18 - 2015-02-02 18:18 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-02-02 18:15 - 2015-02-02 18:15 - 00000000 ____D () C:\Users\WOJT\AppData\Local\MailRu
2015-02-02 18:14 - 2015-02-02 18:14 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Поиcк в Интeрнете
2015-02-02 18:12 - 2015-02-03 09:04 - 00000000 ____D () C:\Users\WOJT\AppData\Local\SystemDir
2015-02-02 18:12 - 2015-02-02 18:12 - 00003492 _____ () C:\Windows\System32\Tasks\nethost task
2015-02-02 18:09 - 2015-02-02 18:16 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Mail.Ru
2015-02-02 18:09 - 2015-02-02 18:09 - 00691080 _____ () C:\Users\WOJT\Downloads\skyrim script extender skse v 1 6 16.exe
2015-02-02 18:09 - 2015-02-02 18:09 - 00000000 ____D () C:\Users\WOJT\Downloads\skse_1_06_16
2015-02-02 17:02 - 2015-02-02 17:03 - 00011178 _____ () C:\Users\WOJT\Downloads\Władca pierścieni bitwa o śródziemie 2 król nazguli.iso.torrent
2015-02-02 11:55 - 2015-02-03 10:39 - 00000224 _____ () C:\Windows\setupact.log
2015-02-02 11:55 - 2015-02-02 11:55 - 00000000 _____ () C:\Windows\setuperr.log
2015-02-01 14:01 - 2015-02-03 10:11 - 00014006 _____ () C:\Windows\WindowsUpdate.log
2015-01-31 13:47 - 2015-01-31 13:48 - 00000000 ____D () C:\Users\WOJT\Documents\The Lord of the Rings - Conquest
2015-01-31 13:43 - 2015-01-31 13:43 - 00000000 _____ () C:\Windows\SysWOW64\Access.dat
2015-01-30 15:05 - 2015-01-31 14:01 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\Tunngle
2015-01-30 15:05 - 2015-01-31 14:01 - 00000000 ____D () C:\ProgramData\Tunngle
2015-01-30 15:05 - 2015-01-30 15:05 - 00000000 ____D () C:\Users\WOJT\Documents\Tunngle
2015-01-30 15:05 - 2015-01-30 15:05 - 00000000 ____D () C:\Users\Public\Documents\Tunngle
2015-01-30 15:05 - 2015-01-30 15:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2015-01-30 15:05 - 2015-01-30 15:05 - 00000000 ____D () C:\Program Files (x86)\Tunngle
2015-01-30 15:05 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys
2015-01-27 15:33 - 2015-01-27 15:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-26 14:03 - 2015-01-26 14:03 - 00000000 _____ () C:\permissions.yml
2015-01-26 14:02 - 2015-01-26 16:08 - 00000000 ____D () C:\world_the_end
2015-01-26 14:02 - 2015-01-26 16:08 - 00000000 ____D () C:\world_nether
2015-01-26 14:02 - 2015-01-26 16:08 - 00000000 ____D () C:\world
2015-01-26 14:02 - 2015-01-26 14:03 - 00000664 _____ () C:\server.properties
2015-01-26 14:02 - 2015-01-26 14:02 - 00002576 _____ () C:\help.yml
2015-01-26 14:02 - 2015-01-26 14:02 - 00001491 _____ () C:\bukkit.yml
2015-01-26 14:02 - 2015-01-26 14:02 - 00000623 _____ () C:\commands.yml
2015-01-26 14:02 - 2015-01-26 14:02 - 00000109 _____ () C:\banned-players.txt
2015-01-26 14:02 - 2015-01-26 14:02 - 00000109 _____ () C:\banned-ips.txt
2015-01-26 14:02 - 2015-01-26 14:02 - 00000000 ____D () C:\plugins
2015-01-26 14:02 - 2015-01-26 14:02 - 00000000 _____ () C:\white-list.txt
2015-01-26 14:02 - 2015-01-26 14:02 - 00000000 _____ () C:\ops.txt
2015-01-25 16:48 - 2015-01-28 15:03 - 00000000 ____D () C:\Users\WOJT\Documents\GTA San Andreas User Files
2015-01-25 16:31 - 2015-01-25 16:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2015-01-25 14:13 - 2015-01-25 14:13 - 00177612 _____ () C:\Users\WOJT\Downloads\Srodziemie _Cien_Mordoru_-_Middle-earth _Shadow_of_Mordor_ 2014 _[Multi10-PL]_[ iso]_[CODEX][Torrenty.org].torrent
2015-01-22 15:22 - 2015-01-22 15:22 - 06664704 _____ (Hazar & Co.) C:\Windows\SysWOW64\2.exe
2015-01-22 15:22 - 2015-01-22 15:22 - 00212992 _____ (SIMPLY THE WORST) C:\Windows\SysWOW64\1.exe
2015-01-18 14:48 - 2015-01-15 17:34 - 81935270 _____ () C:\4Fun4You.zip
2015-01-17 18:51 - 2015-01-17 18:51 - 00004522 _____ () C:\kowal.yml
2015-01-17 18:06 - 2015-01-17 18:06 - 00033039 _____ () C:\crash-2015-01-17_20.23.10-server.txt
2015-01-16 15:44 - 2015-01-16 15:48 - 19972709 _____ () C:\cb.jar
2015-01-16 15:21 - 2015-01-16 15:24 - 20610577 _____ () C:\craftbukkit.jar
2015-01-15 16:57 - 2015-01-15 16:57 - 00202201 _____ () C:\BetonQuest.jar
2015-01-15 16:44 - 2015-01-15 16:42 - 00420181 _____ () C:\ShowCaseStandalone.jar
2015-01-15 16:44 - 2013-12-11 00:07 - 00083463 _____ () C:\Sentry.jar
2015-01-14 17:26 - 2015-01-14 17:26 - 00000418 _____ () C:\config.yml
2015-01-14 17:21 - 2015-01-16 14:50 - 00955162 _____ () C:\Citizens.jar
2015-01-13 18:53 - 2015-01-13 18:53 - 00000005 _____ () C:\launcher_version.txt
2015-01-13 18:53 - 2015-01-13 18:53 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\.4fun4you
2015-01-11 16:18 - 2015-01-11 16:18 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Skyrim
2015-01-11 16:15 - 2015-01-11 16:15 - 211596192 _____ () C:\Pixelmon 3.0.4.zip
2015-01-08 16:42 - 2015-01-08 16:42 - 00000000 ____D () C:\conversations
2015-01-08 16:21 - 2015-02-02 18:15 - 00002189 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-08 16:21 - 2015-01-08 16:21 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-08 16:21 - 2015-01-08 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-08 16:21 - 2015-01-08 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-08 16:21 - 2015-01-08 16:21 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-08 16:20 - 2015-02-03 10:40 - 00001044 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-08 16:20 - 2015-02-03 09:30 - 00001048 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-08 16:20 - 2015-01-08 16:25 - 00004044 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-08 16:20 - 2015-01-08 16:25 - 00003792 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-06 16:25 - 2015-01-06 16:25 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Eclipse
2015-01-06 15:56 - 2015-02-03 10:41 - 00000000 ____D () C:\FRST
2015-01-06 15:15 - 2015-01-06 15:15 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\java
2015-01-05 14:01 - 2015-01-05 14:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2015-01-05 13:51 - 2015-01-05 13:51 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-03 10:41 - 2014-10-05 15:00 - 00000000 ___RD () C:\Users\WOJT\Desktop\moje
2015-02-03 10:39 - 2014-10-05 15:41 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-03 10:39 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 09:23 - 2014-11-13 15:11 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-02 18:31 - 2014-10-05 15:08 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\Skype
2015-02-02 18:17 - 2014-12-05 17:28 - 00000000 ____D () C:\Program Files (x86)\GMT-MAX.ORG
2015-02-02 18:15 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-02-02 17:38 - 2014-10-05 15:59 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\uTorrent
2015-02-02 16:30 - 2014-12-22 13:59 - 00000600 _____ () C:\Users\WOJT\AppData\Local\PUTTY.RND
2015-02-02 16:29 - 2014-12-22 14:02 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\FileZilla
2015-02-02 16:21 - 2014-10-05 15:26 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\.minecraft
2015-02-01 14:01 - 2014-10-07 15:31 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\DAEMON Tools Lite
2015-02-01 14:01 - 2014-10-05 17:25 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\TS3Client
2015-01-31 08:10 - 2009-07-14 05:45 - 00418416 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-30 15:35 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-30 15:20 - 2014-10-05 10:05 - 00109224 _____ () C:\Users\WOJT\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-28 17:31 - 2014-10-06 14:04 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\Moje pliki Bitwy o Śródziemie™ II
2015-01-27 16:44 - 2014-12-07 19:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-27 11:47 - 2014-10-05 15:05 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-01-25 16:48 - 2014-10-06 14:03 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-01-25 16:31 - 2014-10-19 13:45 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-25 15:25 - 2014-11-13 15:11 - 00003868 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-25 15:25 - 2014-10-05 11:40 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-25 15:25 - 2014-10-05 11:40 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-23 15:15 - 2014-12-14 16:50 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\GG
2015-01-22 15:23 - 2010-11-21 04:24 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-01-22 15:23 - 2010-11-21 04:24 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-01-22 15:23 - 2010-11-21 04:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2015-01-22 15:23 - 2010-11-21 04:24 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2015-01-22 15:23 - 2010-11-21 04:23 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2015-01-22 15:23 - 2009-07-14 05:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-22 15:23 - 2009-07-14 05:45 - 00016640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-16 15:42 - 2014-12-27 18:56 - 00000000 ____D () C:\Sv
2015-01-16 14:19 - 2009-07-14 06:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-13 18:53 - 2014-12-18 17:33 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Dino_Chiesa
2015-01-11 16:13 - 2014-12-13 12:52 - 00000000 ____D () C:\Users\WOJT\Documents\My Games
2015-01-08 16:22 - 2014-10-05 10:54 - 00000000 ____D () C:\Windows\Panther
2015-01-08 16:21 - 2014-12-07 16:21 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-08 16:09 - 2014-10-08 17:42 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-01-08 16:07 - 2014-10-05 15:05 - 00000000 ____D () C:\Users\WOJT\AppData\Roaming\Opera Software
2015-01-08 16:07 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-01-06 18:10 - 2011-04-12 14:21 - 00737242 _____ () C:\Windows\system32\perfh015.dat
2015-01-06 18:10 - 2011-04-12 14:21 - 00153930 _____ () C:\Windows\system32\perfc015.dat
2015-01-06 18:10 - 2009-07-14 06:13 - 01661232 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-05 14:01 - 2014-10-16 14:25 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-05 14:01 - 2014-10-16 14:25 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-05 14:01 - 2014-10-05 15:26 - 00000000 ____D () C:\ProgramData\Oracle

==================== Files in the root of some directories =======

2014-12-17 18:51 - 2014-12-18 18:27 - 0065994 _____ () C:\Users\WOJT\AppData\Roaming\bg.jpg
2014-12-07 15:57 - 2014-12-07 15:57 - 40068694 _____ () C:\Users\WOJT\AppData\Roaming\fpacked.exe
2014-12-18 16:28 - 2014-12-18 16:28 - 0015872 ___SH () C:\Users\WOJT\AppData\Roaming\Thumbs.db
2014-12-22 13:59 - 2015-02-02 16:30 - 0000600 _____ () C:\Users\WOJT\AppData\Local\PUTTY.RND

Some content of TEMP:
====================
C:\Users\WOJT\AppData\Local\Temp\1h6CHmKZ8eEn.exe
C:\Users\WOJT\AppData\Local\Temp\CShZmNza7kDp.exe
C:\Users\WOJT\AppData\Local\Temp\DbqGUflQXVRa.exe
C:\Users\WOJT\AppData\Local\Temp\E93UoQy0FUax.exe
C:\Users\WOJT\AppData\Local\Temp\eLhxyaktQpVn.exe
C:\Users\WOJT\AppData\Local\Temp\hp_9EA1.tmp.exe
C:\Users\WOJT\AppData\Local\Temp\iErsJHN7Lg6z.exe
C:\Users\WOJT\AppData\Local\Temp\Iu42IXauYOl4.exe
C:\Users\WOJT\AppData\Local\Temp\jCVdFGZ6gBmj.exe
C:\Users\WOJT\AppData\Local\Temp\JhAVKRo6beEi.exe
C:\Users\WOJT\AppData\Local\Temp\JZX9Ugpv9dZF.exe
C:\Users\WOJT\AppData\Local\Temp\MailRuUpdater.exe
C:\Users\WOJT\AppData\Local\Temp\n5th44euGaU3.exe
C:\Users\WOJT\AppData\Local\Temp\netB263.tmp.exe
C:\Users\WOJT\AppData\Local\Temp\netB265.tmp.exe
C:\Users\WOJT\AppData\Local\Temp\netB268.tmp.exe
C:\Users\WOJT\AppData\Local\Temp\netB26A.tmp.exe
C:\Users\WOJT\AppData\Local\Temp\tNad5OW8ikHT.exe
C:\Users\WOJT\AppData\Local\Temp\V3OkAfyRvH74.exe
C:\Users\WOJT\AppData\Local\Temp\vAU7rbBQC3Hf.exe
C:\Users\WOJT\AppData\Local\Temp\Z9ZnQMPLQveS.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-05 09:55

==================== End Of Log ============================

 

 

Addition.txt

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by WOJT at 2015-02-03 10:42:53
Running from C:\Users\WOJT\Desktop\moje\FRST
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

"Assassin's Creed IV - Black Flag" (HKLM-x32\...\{959CF39B-F3FA-4A80-AECF-8AF6BA639276}_is1) (Version: 1.01.0.0 - )
µTorrent (HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
4Story PL 4.4.142 (HKLM-x32\...\4Story_PL_is1) (Version: 4.4.142 - Gameforge4D GmbH)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Aktualizacje NVIDIA 1.7.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.7.12 - NVIDIA Corporation)
Assassin's Creed (R) III (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Assassin's Creed Revelations (HKLM-x32\...\{33A22B2D-55BA-4508-B767-BF2E9C21A73F}) (Version: 1.00 - Ubisoft)
Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Bitwa o Śródziemie™ (HKLM-x32\...\{3F290582-3F4E-4B96-009C-E0BABAA40C42}) (Version:  - )
Bitwa o Śródziemie™ II (HKLM-x32\...\{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
CPUID HWMonitor 1.25 (HKLM\...\CPUID HWMonitor_is1) (Version:  - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dead Island (HKLM-x32\...\Steam App 91310) (Version:  - Techland)
FileZilla Client 3.9.0.6 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
Gameforge Live 2.0.5 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.5 - Gameforge)
GameRanger (HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\GameRanger) (Version:  - GameRanger Technologies)
GG (HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\GG) (Version: 12 - GG Network S.A.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Gothic (HKLM-x32\...\{758A4269-70E5-4B11-B419-F692882408A9}) (Version: 1.08 - Piranha Bytes)
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java SE Development Kit 8 Update 25 (HKLM-x32\...\{32A3A4F4-B792-11D6-A78A-00B0D0180250}) (Version: 8.0.250.18 - Oracle Corporation)
LEGO - The Hobbit (HKLM-x32\...\TEVHT1RoZUhvYmJpdA==_is1) (Version: 1 - )
LEGO® Władca Pierścieni™ (HKLM-x32\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 35.0.1 (x86 pl) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 pl)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
NVIDIA Sterownik 3D Vision 296.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 296.39 - NVIDIA Corporation)
NVIDIA Sterownik dźwięku HD 1.3.12.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.12.0 - NVIDIA Corporation)
NVIDIA Sterownik graficzny 296.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 296.39 - NVIDIA Corporation)
NVIDIA Sterownik kontrolera 3D Vision 296.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 296.16 - NVIDIA Corporation)
OpenFM (HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\OpenFM) (Version: 2 - GG Network S.A.)
Opera Stable 27.0.1689.54 (HKLM-x32\...\Opera 27.0.1689.54) (Version: 27.0.1689.54 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.)
Panel sterowania NVIDIA 296.39 (Version: 296.39 - NVIDIA Corporation) Hidden
PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version:  - OVERKILL Software)
Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile PLK Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended PLK Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
S.K.I.L.L. - Special Force 2 (HKLM-x32\...\Special Force 2 Beta_is1) (Version:  - )
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.0.615 - Electronic Arts)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 8.51a - Ghisler Software GmbH)
Tropico 4 1.00 (HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\Tropico 4) (Version: 1.00 - Kalypso Media)
Tunngle (HKLM-x32\...\Tunngle_is1) (Version: Tunngle - Tunngle.net GmbH)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
Warcraft III (HKLM-x32\...\Warcraft III) (Version:  - Blizzard Entertainment)
WinRAR 5.11 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
Władca Pierścieni® - Podbój™ (HKLM-x32\...\{628C3D50-F524-4C49-A958-672CE7953756}) (Version: 1.0.0.1 - Electronic Arts)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-944672953-4028843236-912156999-1000_Classes\CLSID\{E68D0A55-3C40-4712-B90D-DCFA93FF2534}\InprocServer32 -> C:\Users\WOJT\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (GG Network S.A.)

==================== Restore Points  =========================

22-01-2015 15:23:18 Windows Update
25-01-2015 16:31:30 Installed GTA San Andreas
30-01-2015 14:44:23 Installed ProductName from default.wxl
02-02-2015 18:17:43 Removed Safari
02-02-2015 18:18:43 Removed Apple Software Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {16945688-3E29-4B34-9387-7F1450AF6EE3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {4274E0C7-50A3-4EB8-90B8-792ED4D0866A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08] (Google Inc.)
Task: {78630476-DF30-4A34-983B-AF2FE8E7F7A4} - System32\Tasks\nethost task => C:\Users\WOJT\AppData\Local\SystemDir\nethost.exe [2015-02-02] ()
Task: {81CE7936-6D2A-4216-B623-355CB1C37449} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {88D1A8C2-5B0A-4CB1-97FF-AC97C2383E91} - \{1B08680A-18D6-4B73-B11F-C837B0EBE073} No Task File <==== ATTENTION
Task: {94640D87-A1F5-4900-927A-30A0B70A83DA} - \{BFD1C5EF-92E1-4356-ABE3-3756EE6C3897} No Task File <==== ATTENTION
Task: {A83F96CA-32C3-463E-BF22-67C3026A1AD5} - \{AD554426-EBA7-433B-AF7F-FB2227ADE9C9} No Task File <==== ATTENTION
Task: {F8EA2CAC-491C-48D2-BC65-C2D386A5FDC6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-05-01 20:29 - 2014-05-01 20:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2014-12-12 23:25 - 2014-12-12 23:25 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1045.dll
2014-10-16 10:15 - 2014-10-16 10:15 - 00035328 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00091648 _____ () C:\Program Files (x86)\FileZilla FTP Client\libgcc_s_sjlj-1.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00892416 _____ () C:\Program Files (x86)\FileZilla FTP Client\libstdc++-6.dll
2015-01-27 11:47 - 2015-01-27 11:47 - 01408632 _____ () C:\Program Files (x86)\Opera\27.0.1689.54\libglesv2.dll
2015-01-27 11:47 - 2015-01-27 11:47 - 00219256 _____ () C:\Program Files (x86)\Opera\27.0.1689.54\libegl.dll
2015-01-27 11:47 - 2015-01-27 11:47 - 09510520 _____ () C:\Program Files (x86)\Opera\27.0.1689.54\pdf.dll
2015-01-25 15:25 - 2015-01-25 15:25 - 16844976 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll
2015-01-27 11:47 - 2015-01-27 11:47 - 00552056 _____ () C:\Program Files (x86)\Opera\27.0.1689.54\opera_crashreporter.exe

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: 4StoryPrePatch => D:\Program Files (x86)\GameforgeLive\Games\POL_pol\4Story\PrePatch.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: GG => "C:\Users\WOJT\AppData\Local\GG\Application\gghub.exe"
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-944672953-4028843236-912156999-500 - Administrator - Disabled)
Gość (S-1-5-21-944672953-4028843236-912156999-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-944672953-4028843236-912156999-1002 - Limited - Enabled)
UpdatusUser (S-1-5-21-944672953-4028843236-912156999-1003 - Limited - Enabled) => C:\Users\UpdatusUser
WOJT (S-1-5-21-944672953-4028843236-912156999-1000 - Administrator - Enabled) => C:\Users\WOJT

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Karta tunelowania Teredo firmy Microsoft
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/03/2015 10:41:35 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 10:39:54 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005.

Error: (02/03/2015 08:55:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 08:54:31 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005.

Error: (02/02/2015 03:38:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program javaw.exe w wersji 8.0.25.18 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji.

Identyfikator procesu: e24

Godzina rozpoczęcia: 01d03ef5d0f53990

Godzina zakończenia: 22

Ścieżka aplikacji: C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaw.exe

Identyfikator raportu: 22967891-aae9-11e4-b5de-001d7daa2bab

Error: (02/02/2015 03:36:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 03:34:27 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005.

Error: (02/02/2015 11:57:27 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/02/2015 11:55:47 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Aktywacja licencji systemu Windows nie powiodła się. Błąd 0x80070005.

Error: (02/01/2015 02:00:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (02/02/2015 06:23:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Usługa NVIDIA Stereoscopic 3D Driver Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1.

Error: (01/31/2015 09:41:47 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Poprzednie zamknięcie systemu przy 21:40:26 na ‎2015-‎01-‎31 było nieoczekiwane.

Error: (01/28/2015 03:46:06 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Poprzednie zamknięcie systemu przy 15:44:37 na ‎2015-‎01-‎28 było nieoczekiwane.

Error: (01/25/2015 05:40:24 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58}

Error: (01/19/2015 03:47:40 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Poprzednie zamknięcie systemu przy 15:44:21 na ‎2015-‎01-‎19 było nieoczekiwane.

Error: (01/09/2015 10:13:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi Windows Search z powodu następującego błędu: 
%%1053

Error: (01/09/2015 10:13:47 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Upłynął limit czasu (30000 ms) podczas oczekiwania na połączenie się z usługą Windows Search.

Error: (01/09/2015 10:13:17 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Usługa Windows Search niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. W przeciągu 30000 milisekund zostanie podjęta następująca czynność korekcyjna: Uruchom usługę ponownie.

Error: (01/09/2015 10:13:17 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Usługa Windows Search zakończyła działanie; wystąpił specyficzny dla niej błąd %%-1073473535.

Error: (01/08/2015 04:08:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Nie można uruchomić usługi Bufor wydruku z powodu następującego błędu: 
%%1069


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
Percentage of memory in use: 53%
Total physical RAM: 2047.55 MB
Available physical RAM: 957.92 MB
Total Pagefile: 4095.11 MB
Available Pagefile: 2694.57 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:127.99 GB) (Free:61.94 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:244.62 GB) (Free:91.37 GB) NTFS
Drive k: (GTA_SAN_ANDREAS) (CDROM) (Total:3.94 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 372.6 GB) (Disk ID: 00000001)
Partition 1: (Active) - (Size=128 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=244.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================

 

 

Shortcut.txt:

 

 

Users shortcut scan result (x64) Version: 01-02-2015
Ran by WOJT at 2015-02-03 10:44:23
Running from C:\Users\WOJT\Desktop\moje\FRST
Boot Mode: Normal
==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)



Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk -> C:\Program Files (x86)\Audacity\audacity.exe (The Audacity Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Co nowego w ostatniej wersji.lnk -> C:\Program Files\WinRAR\CoNowego.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Pomoc techniczna firmy Blizzard.lnk -> D:\Program Files (x86)\Warcraft III\TechSupport.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III - dezinstalacja.lnk -> C:\Program Files (x86)\Common Files\Blizzard Entertainment\Warcraft III\Uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III - edytor światów.lnk -> D:\Program Files (x86)\Warcraft III\World Editor.exe (Blizzard Entertainment)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III - rejestracja.lnk -> D:\Program Files (x86)\Warcraft III\Register Warcraft III.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III - The Frozen Throne - rejestracja.lnk -> D:\Program Files (x86)\Warcraft III\Register Frozen Throne.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III - The Frozen Throne.lnk -> D:\Program Files (x86)\Warcraft III\Frozen Throne.exe (Blizzard Entertainment)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III — dezinstalacja.lnk -> C:\Program Files (x86)\Common Files\Blizzard Entertainment\Warcraft III\Uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III — edytor światów.lnk -> D:\Program Files (x86)\Warcraft III\World Editor.exe (Blizzard Entertainment)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III — rejestracja.lnk -> D:\Program Files (x86)\Warcraft III\Register Warcraft III.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III\Warcraft III.lnk -> D:\Program Files (x86)\Warcraft III\Warcraft III.exe (Blizzard Entertainment)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle\Tunngle.lnk -> C:\Program Files (x86)\Tunngle\Tunngle.exe (Tunngle.net GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle\Uninstall Tunngle.lnk -> C:\Program Files (x86)\Tunngle\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\TeamSpeak 3 Client.lnk -> C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe (TeamSpeak Systems GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\Uninstall.lnk -> C:\Program Files (x86)\TeamSpeak 3 Client\Uninstall.exe (TeamSpeak Systems GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> D:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk -> C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games\GTA San Andreas\Play GTA San Andreas.lnk -> D:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games\GTA San Andreas\README.lnk -> D:\Program Files (x86)\Rockstar Games\GTA San Andreas\ReadMe\Readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Piranha Bytes\Gothic\Gothic.lnk -> D:\Program Files (x86)\Piranha Bytes\Gothic\System\Gothic.exe (Piranha Bytes)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Piranha Bytes\Gothic\Dokumentacja\Instrukcja użytkownika.lnk -> D:\Program Files (x86)\Piranha Bytes\Gothic\Instrukcja\instrukcja.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Piranha Bytes\Gothic\Dokumentacja\Plik CzytajTo.lnk -> D:\Program Files (x86)\Piranha Bytes\Gothic\Readme.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Piranha Bytes\Gothic\Dokumentacja\Pomoc techniczna offLine.lnk -> D:\Program Files (x86)\Piranha Bytes\Gothic\PomocOffline\index.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe (NVIDIA Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\GrooveIcon.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Certyfikat cyfrowy dla projektów VBA.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Diagnostyka pakietu Microsoft Office.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Office 2007 Ustawienia języka.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Narzędzia Microsoft Office\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit\Java Mission Control.lnk -> C:\Program Files (x86)\Java\jdk1.8.0_25\bin\jmc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javacpl.exe (Oracle Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live\Deinstalacja programu Gameforge Live.lnk -> D:\Program Files (x86)\GameforgeLive\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk -> C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe (FileZilla Project)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk -> C:\Program Files (x86)\FileZilla FTP Client\uninstall.exe (Tim Kosse)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Bitwa o Śródziemie™ II\Bitwa o Śródziemie™ II.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\lotrbfme2.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Bitwa o Śródziemie™ II\Edytor gry Bitwa o Śródziemie™ II.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\WorldBuilder.exe (Electronic Arts Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Bitwa o Śródziemie™ II\Pomoc techniczna.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\Support\European Help Files\EA_Help_Select.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Bitwa o Śródziemie™ II\Przeczytaj.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\Support\pl\Przeczytaj.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Bitwa o Śródziemie™ II\Usuń Bitwa o Śródziemie™ II.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\eauninstall.exe (Electronic Arts Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Bitwa o Śródziemie™\Bitwa o Śródziemie™.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\lotrbfme.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Bitwa o Śródziemie™\Edytor gry Bitwa o Śródziemie(tm).lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\WorldBuilder.exe (Electronic Arts)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Bitwa o Śródziemie™\Pomoc techniczna.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\Support\European Help Files\EA_Help_Select.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Bitwa o Śródziemie™\ReadMe.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\Support\pl\readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Bitwa o Śródziemie™\Usuń Bitwa o Śródziemie™.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\eauninstall.exe (Electronic Arts Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk -> C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk -> C:\Program Files (x86)\DAEMON Tools Lite\DT.gadget ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk -> C:\Program Files (x86)\DAEMON Tools Lite\SPTDinst-x64.exe (Duplex Secure Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\HWMonitor\HWMonitor.lnk -> C:\Program Files\CPUID\HWMonitor\HWMonitor.exe (CPUID)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\HWMonitor\Uninstall HWMonitor.lnk -> C:\Program Files\CPUID\HWMonitor\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\CPU-Z.lnk -> C:\Program Files\CPUID\CPU-Z\cpuz.exe (CPUID)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Edit CPU-Z Config File.lnk -> C:\Program Files\CPUID\CPU-Z\cpuz.ini ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Uninstall CPU-Z.lnk -> C:\Program Files\CPUID\CPU-Z\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed IV - Black Flag\Assassin's Creed IV - Black Flag.lnk -> D:\Games\Assassin's Creed IV - Black Flag\Launcher.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed IV - Black Flag\Manual.lnk -> D:\Games\Assassin's Creed IV - Black Flag\Support\Manual\English\AssassinsCreed.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed IV - Black Flag\Uninstall.lnk -> D:\Games\Assassin's Creed IV - Black Flag\Uninstall\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk -> C:\Windows\System32\NetProj.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\Windowspowershell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C62E4A21-177B-4FC5-902F-6129FD3C9C2F}\PlayTasks\0\Launch.lnk -> D:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\PlayTasks\3\Centrum Pomocy.lnk -> D:\Program Files (x86)\Electronic Arts\The Sims 3\Support\EA Help\Electronic_Arts_Technical_Support.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\PlayTasks\2\Umowa Użytkownika.lnk -> D:\Program Files (x86)\Electronic Arts\The Sims 3\Support\pl_EULA_DD.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\PlayTasks\1\Przeczytaj.lnk -> D:\Program Files (x86)\Electronic Arts\The Sims 3\Support\Przeczytaj.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\PlayTasks\0\Play.lnk -> D:\Program Files (x86)\Electronic Arts\The Sims 3\Game\Bin\Sims3Launcher.exe (EA.com)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{33B6BE1D-234F-437F-9F0F-9AF8FE826CAE}\PlayTasks\2\Pomoc techniczna.lnk -> D:\Program Files (x86)\Electronic Arts\Władca Pierścieni® - Podbój™\Support\EA Help\Electronic_Arts_Technical_Support.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{33B6BE1D-234F-437F-9F0F-9AF8FE826CAE}\PlayTasks\1\Plik Przeczytaj.lnk -> D:\Program Files (x86)\Electronic Arts\Władca Pierścieni® - Podbój™\Support\Przeczytaj.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{33B6BE1D-234F-437F-9F0F-9AF8FE826CAE}\PlayTasks\0\Play.lnk -> D:\Program Files (x86)\Electronic Arts\Władca Pierścieni® - Podbój™\Conquest.exe (Electronic Arts Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{0890289A-B5B2-4D76-9B15-204E744285B7}\PlayTasks\1\Manual.lnk -> C:\Program Files (x86)\Kalypso Media\Tropico 4\Manual.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{0890289A-B5B2-4D76-9B15-204E744285B7}\PlayTasks\0\Play.lnk -> C:\Program Files (x86)\Kalypso Media\Tropico 4\Tropico4.exe (Haemimont Games)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\Links\Desktop.lnk -> C:\Users\WOJT\Desktop ()
Shortcut: C:\Users\WOJT\Links\Downloads.lnk -> C:\Users\WOJT\Downloads ()
Shortcut: C:\Users\WOJT\Links\GG dysk.lnk -> C:\Users\WOJT\GG dysk ()
Shortcut: C:\Users\WOJT\Favorites\GG dysk.lnk -> C:\Users\WOJT\GG dysk ()
Shortcut: C:\Users\WOJT\Desktop\moje\Audacity.lnk -> C:\Program Files (x86)\Audacity\audacity.exe (The Audacity Team)
Shortcut: C:\Users\WOJT\Desktop\moje\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
Shortcut: C:\Users\WOJT\Desktop\moje\CPUID CPU-Z.lnk -> C:\Program Files\CPUID\CPU-Z\cpuz.exe (CPUID)
Shortcut: C:\Users\WOJT\Desktop\moje\CPUID HWMonitor.lnk -> C:\Program Files\CPUID\HWMonitor\HWMonitor.exe (CPUID)
Shortcut: C:\Users\WOJT\Desktop\moje\DAEMON Tools Lite.lnk -> C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
Shortcut: C:\Users\WOJT\Desktop\moje\FileZilla Client.lnk -> C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe (FileZilla Project)
Shortcut: C:\Users\WOJT\Desktop\moje\Gameforge Live.lnk -> D:\Program Files (x86)\GameforgeLive\GameforgeLive.exe ()
Shortcut: C:\Users\WOJT\Desktop\moje\GameRanger.lnk -> C:\Users\WOJT\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)
Shortcut: C:\Users\WOJT\Desktop\moje\GG.lnk -> C:\Users\WOJT\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)
Shortcut: C:\Users\WOJT\Desktop\moje\Notepad++.lnk -> C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO [email protected])
Shortcut: C:\Users\WOJT\Desktop\moje\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software)
Shortcut: C:\Users\WOJT\Desktop\moje\Safari.lnk -> C:\Windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe (No File)
Shortcut: C:\Users\WOJT\Desktop\moje\Skype.lnk -> C:\Windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe ()
Shortcut: C:\Users\WOJT\Desktop\moje\TeamSpeak 3 Client.lnk -> C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe (TeamSpeak Systems GmbH)
Shortcut: C:\Users\WOJT\Desktop\moje\Total Commander.lnk -> C:\totalcmd\TOTALCMD.EXE (Ghisler Software GmbH)
Shortcut: C:\Users\WOJT\Desktop\moje\Tunngle.lnk -> C:\Program Files (x86)\Tunngle\Tunngle.exe (Tunngle.net GmbH)
Shortcut: C:\Users\WOJT\Desktop\moje\Uplay.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe ()
Shortcut: C:\Users\WOJT\Desktop\moje\torrenty\µTorrent.lnk -> C:\Users\WOJT\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
Shortcut: C:\Users\WOJT\Desktop\moje\muzyka\muzyka — skrót.lnk -> C:\Users\WOJT\Desktop\moje\muzyka ()
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Assassin's Creed IV - Black Flag.lnk -> D:\Games\Assassin's Creed IV - Black Flag\Launcher.exe ()
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Battlefield 3.lnk -> D:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe (EA Digital Illusions CE AB)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Bitwa o Śródziemie™ II.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\lotrbfme2.exe ()
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Bitwa o Śródziemie™.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\lotrbfme.exe ()
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Gothic.lnk -> D:\Program Files (x86)\Piranha Bytes\Gothic\System\Gothic.exe (Piranha Bytes)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\LEGO - The Hobbit.lnk -> D:\Program Files (x86)\LEGO - The Hobbit\LEGOHobbit.exe (Warner Bros. Interactive Entertainment)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Origin.lnk -> D:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Steam.lnk -> D:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\The Sims™ 3.lnk -> D:\Program Files (x86)\Electronic Arts\The Sims 3\Game\Bin\Sims3Launcher.exe (EA.com)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Warcraft III - The Frozen Throne.lnk -> D:\Program Files (x86)\Warcraft III\Frozen Throne.exe (Blizzard Entertainment)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Warcraft III.lnk -> D:\Program Files (x86)\Warcraft III\Warcraft III.exe (Blizzard Entertainment)
Shortcut: C:\Users\WOJT\Desktop\moje\gry\Władca Pierścieni® - Podbój™.lnk -> D:\Program Files (x86)\Electronic Arts\Władca Pierścieni® - Podbój™\Conquest.exe (Electronic Arts Inc.)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk -> C:\Users\WOJT\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk -> C:\Users\WOJT\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenFM.lnk -> C:\Users\WOJT\AppData\Local\OpenFM\Application\openfm.exe ()
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Co nowego w ostatniej wersji.lnk -> C:\Program Files\WinRAR\CoNowego.txt ()
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Podręcznik RARa dla konsoli.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Pomoc WinRARa.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft\Uplay\Uninstall.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe ()
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft\Uplay\Uplay.lnk -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe ()
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Tunngle.lnk -> C:\Program Files (x86)\Tunngle\Tunngle.exe (Tunngle.net GmbH)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\GG.lnk -> C:\Users\WOJT\AppData\Local\GG\Application\ggapp.exe (GG Network S.A.)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\WOJT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software)
Shortcut: C:\Users\WOJT\AppData\Local\OpenFM\Application\openfm.lnk -> C:\Users\WOJT\AppData\Local\OpenFM\Application\openfm.exe ()
Shortcut: C:\Users\WOJT\AppData\Local\Microsoft\Windows\GameExplorer\{F67E0A94-0DA6-4B8D-A931-7D8C0725C863}\PlayTasks\0\Zagraj.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\lotrbfme.exe ()
Shortcut: C:\Users\WOJT\AppData\Local\Microsoft\Windows\GameExplorer\{DCC56F45-7A22-48AF-8DC3-87F602C0FAF3}\PlayTasks\0\Zagraj.lnk -> D:\Program Files (x86)\Warcraft III\Frozen Throne.exe (Blizzard Entertainment)
Shortcut: C:\Users\WOJT\AppData\Local\Microsoft\Windows\GameExplorer\{780FFB08-73E1-4C68-BEB9-F02C05F7098D}\PlayTasks\0\Zagraj.lnk -> D:\Program Files (x86)\Piranha Bytes\Gothic\System\Gothic.exe (Piranha Bytes)
Shortcut: C:\Users\WOJT\AppData\Local\Microsoft\Windows\GameExplorer\{32201955-EA5D-458D-91E8-F2BC31481210}\PlayTasks\0\Zagraj.lnk -> D:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe ()
Shortcut: C:\Users\WOJT\AppData\Local\Microsoft\Windows\GameExplorer\{0C01904D-98C5-43F3-B11C-0735CA19CA26}\PlayTasks\0\Zagraj.lnk -> D:\Program Files (x86)\Warcraft III\Warcraft III.exe (Blizzard Entertainment)
Shortcut: C:\Users\WOJT\AppData\Local\Microsoft\Windows\GameExplorer\{01F48DB4-C695-44FB-B8F9-BD629857C5F3}\PlayTasks\0\Zagraj.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\lotrbfme2.exe ()
Shortcut: C:\Users\WOJT\AppData\Local\GG\Application\gg.lnk -> C:\Users\WOJT\AppData\Local\GG\Application\gghub.exe (GG Network S.A.)


ShortcutWithArgument: C:\Users\WOJT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Вoйти в Интeрнeт 2inf.net.lnk -> C:\Users\WOJT\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт 2inf.net.exe () -> hxxp://2inf.net/?utm_source=startlink
ShortcutWithArgument: C:\Users\WOJT\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт 2inf.net.lnk -> C:\Users\WOJT\AppData\Local\Microsoft\Start Menu\Вoйти в Интeрнeт 2inf.net.exe () -> hxxp://2inf.net/?utm_source=startlink


ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games\GTA San Andreas\Uninstall GTA San Andreas.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Piranha Bytes\Gothic\Usuń grę Gothic.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{758A4269-70E5-4B11-B419-F692882408A9}\setup.exe" -l0x15
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /show
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Disable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /disable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Enable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /enable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javacpl.exe (Oracle Corporation) -> -tab about
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javacpl.exe (Oracle Corporation) -> -tab update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live\4Story.lnk -> D:\Program Files (x86)\GameforgeLive\GameforgeLive.exe () -> "D:\Program Files (x86)\GameforgeLive\Games\POL_pol\4Story\4Story.exe" -start FourStory
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live\S.K.I.L.L. - Special Force 2.lnk -> D:\Program Files (x86)\GameforgeLive\GameforgeLive.exe () -> "D:\Program Files (x86)\GameforgeLive\Games\POL_pol\S.K.I.L.L\DFUBG.exe" -start SKILL
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Bitwa o Śródziemie™ II\Rejestracja elektroniczna.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\Support\EReg.exe (Electronic Arts Inc.) -> "lotrbfme2.exe"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\Bitwa o Śródziemie™ II\Szukaj uaktualnień.lnk -> D:\Program Files (x86)\Electronic Arts\Bitwa o Śródziemie II\lotrbfme2.exe () -> GrabPatches
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Bitwa o Śródziemie™\Rejestracja elektroniczna.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\Support\EReg.exe (Electronic Arts Inc.) -> "lotrbfme.exe"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES\Bitwa o Śródziemie™\Szukaj uaktualnień.lnk -> D:\Program Files (x86)\EA GAMES\Bitwa o Śródziemie\lotrbfme.exe () -> GrabPatches
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\WOJT\Desktop\moje\4Story.lnk -> D:\Program Files (x86)\GameforgeLive\GameforgeLive.exe () -> "D:\Program Files (x86)\GameforgeLive\Games\POL_pol\4Story\4Story.exe" -start FourStory
ShortcutWithArgument: C:\Users\WOJT\Desktop\moje\gry\S.K.I.L.L. - Special Force 2.lnk -> D:\Program Files (x86)\GameforgeLive\GameforgeLive.exe () -> "D:\Program Files (x86)\GameforgeLive\Games\POL_pol\S.K.I.L.L\DFUBG.exe" -start SKILL
ShortcutWithArgument: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\WOJT\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk -> C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) -> /sendto:


InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle\Tunngle on the Web.url -> hxxp://www.Tunngle.net/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.url -> hxxp://support.steampowered.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games\GTA San Andreas\Register Online.url -> hxxp://www.rockstargames.com/register/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games\GTA San Andreas\Rockstar Games.url -> hxxp://www.rockstargames.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games\GTA San Andreas\Rockstar North Ltd.url -> hxxp://www.RockstarNorth.com
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Piranha Bytes\Gothic\Internet\www.piranhabytes.com.url -> hxxp://www.piranhabytes.com
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live\4Story online.url -> hxxp://pl.4story.gameforge.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live\Strona internetowa Gameforge Live.url -> hxxp://gfl.gameforge.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> hxxp://www.piriform.com/ccleaner
InternetURL: C:\Users\WOJT\Favorites\Mail.Ru Агент - используй для общения!.url -> hxxp://agent.mail.ru
InternetURL: C:\Users\WOJT\Favorites\Mail.Ru.url -> hxxp://www.mail.ru
InternetURL: C:\Users\WOJT\Favorites\Links for Polska\Bezpieczeństwo w trybie online.url -> hxxp://go.microsoft.com/fwlink/?LinkId=142211
InternetURL: C:\Users\WOJT\Favorites\Links for Polska\Bezpieczny Internet.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129626
InternetURL: C:\Users\WOJT\Favorites\Links for Polska\Kultura.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129625
InternetURL: C:\Users\WOJT\Favorites\Links for Polska\Pogodynka.pl — oficjalny serwis pogodowy IMGW.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129624
InternetURL: C:\Users\WOJT\Favorites\Links for Polska\Polska.pl.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129622
InternetURL: C:\Users\WOJT\Favorites\Links\Galeria obiektów Web Slice.url -> hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\WOJT\Favorites\Links\Sugerowane witryny.url -> https://ieonline.microsoft.com/#ieslice
InternetURL: C:\Users\WOJT\Favorites\Links\Интернет.url -> hxxp://2inf.net/?utm_source=favorites12
InternetURL: C:\Users\WOJT\Desktop\moje\gry\Dead Island.url -> steam://rungameid/91310
InternetURL: C:\Users\WOJT\Desktop\moje\gry\PAYDAY The Heist.url -> steam://rungameid/24240
InternetURL: C:\Users\WOJT\Desktop\moje\gry\Farming Simulator 15\2014年全部热门单机游戏及汉化下载.url -> hxxp://bbs.3dmgame.com/thread-4181441-1-1.html
InternetURL: C:\Users\WOJT\Desktop\moje\gry\Farming Simulator 15\www.3dmgame.com.url -> hxxp://www.3dmgame.com/

==================== End of log =============================

 

 

3 odpowiedzi na to pytanie

Rekomendowane odpowiedzi

Opublikowano

1. Pobierz http://speedy.sh/WT9RP/fixlist.txtumieść obok FRST i kliknij FIX. Po restarcie utworzy się fixlog, zapisz go w łatwo dostępnym miejscu (np na pulpicie) 

 

2. Pobierz unchecky.com, zainstaluj. Mało zasobożerny, nie spowalnia startu komputera. Pomaga w walce z adware.

 

3. W przypadku jeśli reklamy nadal będą zrób nowe logi FRST.

 

4. Dostarcz fixlog. 

Opublikowano


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015

Ran by WOJT at 2015-02-04 09:02:48 Run:2

Running from C:\Users\WOJT\Desktop\moje\FRST

Loaded Profiles: WOJT & UpdatusUser (Available profiles: WOJT & UpdatusUser)

Boot Mode: Normal

==============================================

 

Content of fixlist:

*****************

CloseProcesses:

HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\Run: [thferblgac] => cmd /c start http://foretuned.com/

HKU\S-1-5-21-944672953-4028843236-912156999-1000\...\RunOnce: [**>9B8 2 8=B5@=5B 2inf.net_startspeeddialmaker_chrome<*>] => "C:\Users\WOJT\AppData\Local\Temp\netB263.tmp.exe" --fromrunonce --partnertitle="Войти в интернет 2inf.net" --browser="chrome" <===== ATTENTION (Value Name with invalid characters)

HKU\S-1-5-21-944672953-4028843236-912156999-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=156

SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> DefaultScope {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = http://go-search.ru/search?q={searchTerms}

SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {828B376B-F2F6-4778-928C-E29EC877535E} URL = http://www.google.com/cse?cx=partner-pub-0900663996874144:6813731868&ie=UTF-8&q={searchTerms}&sa=Search&ref=#gsc.tab=0&gsc.q={searchTerms}&gsc.page=1

SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {A06ED961-D98F-4CF9-A89B-80AB11DB149C} URL = http://go-search.ru/search?q={searchTerms}

SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = http://go.mail.ru/search?q={SearchTerms}&fr=ntg

SearchScopes: HKU\S-1-5-21-944672953-4028843236-912156999-1000 -> {szukaj.gazeta.pl} URL = http://szukaj.gazeta.pl/internet/0,0.html?slowo={searchTerms}

FF DefaultSearchEngine: GoSearch

FF SelectedSearchEngine: GoSearch

FF SearchPlugin: C:\Users\WOJT\AppData\Roaming\Mozilla\Firefox\Profiles\ffqkoyy7.default-1420461439169\searchplugins\GoSearch.xml

CHR HomePage: Default -> hxxp://mail.ru/cnt/10445?gp=blackbear5

CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=blackbear5", "hxxp://www.google.com"

CHR DefaultSearchKeyword: Default -> GoSearch

CHR DefaultSuggestURL: Default -> http://suggest.yandex.net/suggest-ff.cgi?part={searchTerms}

CHR Extension: (Mail.Ru) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\jedelkhanefmcnpappfhachbpnlhomai [2015-02-02]

CHR Extension: (Визуальные Закладки Mail.Ru) - C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pganlglbhgfjfgopijbhemcpbehjnpia [2015-02-02]

OPR StartupUrls: "hxxp://www.surfvox.com/"

2015-02-02 18:22 - 2015-02-02 18:22 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Вoйти в Интeрнет 2inf.net

2015-02-02 18:15 - 2015-02-02 18:15 - 00000000 ____D () C:\Users\WOJT\AppData\Local\MailRu

2015-02-02 18:14 - 2015-02-02 18:14 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Поиcк в Интeрнете

2015-02-02 18:09 - 2015-02-02 18:16 - 00000000 ____D () C:\Users\WOJT\AppData\Local\Mail.Ru

Task: {88D1A8C2-5B0A-4CB1-97FF-AC97C2383E91} - \{1B08680A-18D6-4B73-B11F-C837B0EBE073} No Task File <==== ATTENTION

Task: {94640D87-A1F5-4900-927A-30A0B70A83DA} - \{BFD1C5EF-92E1-4356-ABE3-3756EE6C3897} No Task File <==== ATTENTION

Task: {A83F96CA-32C3-463E-BF22-67C3026A1AD5} - \{AD554426-EBA7-433B-AF7F-FB2227ADE9C9} No Task File <==== ATTENTION

InternetURL: C:\Users\WOJT\Favorites\Links\Интернет.url -> hxxp://2inf.net/?utm_source=favorites12

InternetURL: C:\Users\WOJT\Favorites\Mail.Ru Агент - используй для общения!.url -> hxxp://agent.mail.ru

InternetURL: C:\Users\WOJT\Favorites\Mail.Ru.url -> hxxp://www.mail.ru

 

EmptyTemp:

 

*****************

 

Processes closed successfully.

HKU\S-1-5-21-944672953-4028843236-912156999-1000\Software\Microsoft\Windows\CurrentVersion\Run\\thferblgac => value deleted successfully.

HKU\S-1-5-21-944672953-4028843236-912156999-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\**>9B8 2 8=B5@=5B 2inf.net_startspeeddialmaker_chrome<*> => Value Deleted Successfully.

HKU\S-1-5-21-944672953-4028843236-912156999-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.

HKU\S-1-5-21-944672953-4028843236-912156999-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.

"HKU\S-1-5-21-944672953-4028843236-912156999-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{828B376B-F2F6-4778-928C-E29EC877535E}" => Key deleted successfully.

HKCR\CLSID\{828B376B-F2F6-4778-928C-E29EC877535E} => Key not found.

"HKU\S-1-5-21-944672953-4028843236-912156999-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A06ED961-D98F-4CF9-A89B-80AB11DB149C}" => Key deleted successfully.

HKCR\CLSID\{A06ED961-D98F-4CF9-A89B-80AB11DB149C} => Key not found.

"HKU\S-1-5-21-944672953-4028843236-912156999-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}" => Key deleted successfully.

HKCR\CLSID\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} => Key not found.

"HKU\S-1-5-21-944672953-4028843236-912156999-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{szukaj.gazeta.pl}" => Key deleted successfully.

HKCR\CLSID\{szukaj.gazeta.pl} => Key not found.

Firefox DefaultSearchEngine deleted successfully.

Firefox SelectedSearchEngine deleted successfully.

C:\Users\WOJT\AppData\Roaming\Mozilla\Firefox\Profiles\ffqkoyy7.default-1420461439169\searchplugins\GoSearch.xml => Moved successfully.

Chrome HomePage deleted successfully.

Chrome StartupUrls deleted successfully.

Chrome DefaultSearchKeyword deleted successfully.

Chrome DefaultSuggestURL deleted successfully.

C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\jedelkhanefmcnpappfhachbpnlhomai => Moved successfully.

C:\Users\WOJT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pganlglbhgfjfgopijbhemcpbehjnpia => Moved successfully.

Opera StartupUrls deleted successfully.

C:\Users\WOJT\AppData\Local\Вoйти в Интeрнет 2inf.net => Moved successfully.

C:\Users\WOJT\AppData\Local\MailRu => Moved successfully.

C:\Users\WOJT\AppData\Local\Поиcк в Интeрнете => Moved successfully.

C:\Users\WOJT\AppData\Local\Mail.Ru => Moved successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{88D1A8C2-5B0A-4CB1-97FF-AC97C2383E91}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88D1A8C2-5B0A-4CB1-97FF-AC97C2383E91}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1B08680A-18D6-4B73-B11F-C837B0EBE073}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{94640D87-A1F5-4900-927A-30A0B70A83DA}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94640D87-A1F5-4900-927A-30A0B70A83DA}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BFD1C5EF-92E1-4356-ABE3-3756EE6C3897}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A83F96CA-32C3-463E-BF22-67C3026A1AD5}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A83F96CA-32C3-463E-BF22-67C3026A1AD5}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AD554426-EBA7-433B-AF7F-FB2227ADE9C9}" => Key deleted successfully.

C:\Users\WOJT\Favorites\Links\Интернет.url => Moved successfully.

C:\Users\WOJT\Favorites\Mail.Ru Агент - используй для общения!.url => Moved successfully.

C:\Users\WOJT\Favorites\Mail.Ru.url => Moved successfully.

EmptyTemp: => Removed 487.5 MB temporary data.

 

 

The system needed a reboot.

 

==== End of Fixlog 09:02:56 ====

Zarchiwizowany

Ten temat przebywa obecnie w archiwum. Dodawanie nowych odpowiedzi zostało zablokowane.

×
×
  • Dodaj nową pozycję...