Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-09-2014 01 Ran by Owner at 2014-09-08 12:54:09 Run:4 Running from C:\Users\Owner\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (APN LLC.) C:\Users\Owner\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe (APN LLC.) C:\Users\Owner\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-08-29] (APN LLC.) HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1942424 2014-08-29] (APN) IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe Task: {0C523F11-E1D2-4FA6-A799-2ABE20AD35CB} - \APSnotifierPP1 No Task File <==== ATTENTION Task: {0DB7EF00-D191-488A-AC2C-BD3858B8CA0D} - System32\Tasks\PC Cleaner Schedule => C:\Program Files (x86)\PC Cleaner\PCCLauncher.exe Task: {6896F8EA-950C-4BD2-8348-9D5A38F6BE2F} - \APSnotifierPP2 No Task File <==== ATTENTION Task: {BE78A481-8D24-4A14-B26D-7ED25A3F45E6} - \APSnotifierPP3 No Task File <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?tpid=ORJ-SPE&o=APN11406&pf=V7&trgb=IE&p2=^BBE^OSJ000^YY^CA&gct=hp&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^CA&apn_dbr=ie_11.0.9600.17239&apn_uid=4D1963BE-45F3-4BF6-8DD7-9752213D0E16&itbv=12.15.5.30&doi=2014-08-23&psv=&pt=tb StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=cmi_14_24_ie&cd=2XzuyEtN2Y1L1Qzu0AtD0BtA0C0CyEyE0A0EzzyDyC0DtB0FtN0D0Tzu0SzzzyyBtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEyB0F0FyBtCyEtAtGzyzytCtDtG0B0FyD0EtGyDtC0FyEtGtB0E0D0D0D0Czz0AtCtD0CtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByC0Czz0E0FzzzztGyC0ByByCtG0CyE0AtDtGtB0D0BtBtGyByB0AzztAtB0F0EyEzytBtC2Q&cr=298421677&ir= SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=cmi_14_24_ie&cd=2XzuyEtN2Y1L1Qzu0AtD0BtA0C0CyEyE0A0EzzyDyC0DtB0FtN0D0Tzu0SzzzyyBtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEyB0F0FyBtCyEtAtGzyzytCtDtG0B0FyD0EtGyDtC0FyEtGtB0E0D0D0D0Czz0AtCtD0CtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByC0Czz0E0FzzzztGyC0ByByCtG0CyE0AtDtGtB0D0BtBtGyByB0AzztAtB0F0EyEzytBtC2Q&cr=298421677&ir= SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=123&itype=n&ver=13072&tm=405&src=ds&p={searchTerms} SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=123&itype=n&ver=13072&tm=405&src=ds&p={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=cmi_14_24_ie&cd=2XzuyEtN2Y1L1Qzu0AtD0BtA0C0CyEyE0A0EzzyDyC0DtB0FtN0D0Tzu0SzzzyyBtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEyB0F0FyBtCyEtAtGzyzytCtDtG0B0FyD0EtGyDtC0FyEtGtB0E0D0D0D0Czz0AtCtD0CtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByC0Czz0E0FzzzztGyC0ByByCtG0CyE0AtDtGtB0D0BtBtGyByB0AzztAtB0F0EyEzytBtC2Q&cr=298421677&ir= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=cmi_14_24_ie&cd=2XzuyEtN2Y1L1Qzu0AtD0BtA0C0CyEyE0A0EzzyDyC0DtB0FtN0D0Tzu0SzzzyyBtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEyB0F0FyBtCyEtAtGzyzytCtDtG0B0FyD0EtGyDtC0FyEtGtB0E0D0D0D0Czz0AtCtD0CtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByC0Czz0E0FzzzztGyC0ByByCtG0CyE0AtDtGtB0D0BtBtGyByB0AzztAtB0F0EyEzytBtC2Q&cr=298421677&ir= SearchScopes: HKCU - {7DDBF870-FD43-4FED-80D6-D0D9AD0CB8C3} URL = http://www.search.ask.com/web?tpid=ORJ-SPE&o=APN11406&pf=V7&p2=^BBE^OSJ000^YY^CA&gct=&itbv=12.15.5.30&apn_uid=4D1963BE-45F3-4BF6-8DD7-9752213D0E16&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^CA&apn_dbr=ie_11.0.9600.17239&doi=2014-08-23&trgb=IE&q={searchTerms}&psv=&pt=tb SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={65864BAE-1CE7-4EEF-8EA6-AC675D831FA4}&mid=861191289cd347d3ab4ab91405788bb8-29cf90d90ef2d6b9d678849a91a3293d0812fa2c&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-08-04 10:39:06&v=18.1.8.643&pid=safeguard&sg=&sap=dsp&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=123&itype=n&ver=13072&tm=405&src=ds&p={searchTerms} BHO: Search App by Ask -> {4F524A2D-5350-4500-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport_x64.dll (APN LLC.) BHO-x32: Search App by Ask -> {4F524A2D-5350-4500-76A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll (APN LLC.) Toolbar: HKLM - Search App by Ask - {4F524A2D-5350-4500-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Search App by Ask - {4F524A2D-5350-4500-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll (APN LLC.) FF StartMenuInternet: FIREFOX.EXE - firefox.exe FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml C:\Users\Owner\AppData\Local\Google\Chrome\User Data\default C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\9lpjozou.default C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\oneyyiv1.default-1375743666646 C:\Users\Owner\Desktop\Obraski na czat\lusia\super_emoty\Shortcut to erde.lnk C:\Users\Owner\Desktop\New folder (2)\DCIM - Shortcut.lnk C:\Users\Owner\Downloads\k,NzE0MDM5MjgsNDc5MjAwODU=,f,z5zsovwo.gif — skrót.lnk C:\Users\Owner\Music\Muzyka\JERZY PIOTROWSKI - Zloty kamien.lnk C:\Users\Owner\Music\Muzyka\JERZY PIOTROWSKI - Zloty kamien — skrót.lnk RemoveDirectory: C:\Users\Owner\Downloads\FRST-OlderVersion Tcpip\..\Interfaces\{70923415-8B08-4621-AAF7-24D755899993}: [NameServer] 208.69.150.250,208.69.150.252 Tcpip\..\Interfaces\{7AAF003C-5C30-4B24-A12B-E93C23612AB6}: [NameServer] 208.69.150.250,208.69.150.252 Tcpip\..\Interfaces\{7DB77D31-0516-44A0-AFC3-DC1E540D62E7}: [NameServer] 208.69.150.250,208.69.150.252 Tcpip\..\Interfaces\{90726EF4-EAEA-4483-87C7-EE239CC129BA}: [NameServer] 208.69.150.250,208.69.150.252 Tcpip\..\Interfaces\{942371D0-17CD-4B8A-80FC-F5AD84230A7C}: [NameServer] 208.69.150.250,208.69.150.252 Tcpip\..\Interfaces\{9B858825-D2C6-4E27-85F0-FD19BE87EB6D}: [NameServer] 208.69.150.250,208.69.150.252 Tcpip\..\Interfaces\{D8015D14-D582-42D5-92FF-B44C5DDFD1D1}: [NameServer] 208.69.150.250,208.69.150.252 Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\Main" /v "bProtector Start Page" /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {4c60e5ab-5c68-4c59-abaa-885010b24b32} / f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {77f5fe49-12e3-4cf5-abb4-d993a0164d9e} / f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {d2cf9842-af95-48cd-b873-bfbb48cd7f5e} / f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {da7a20cf-bef4-4342-ad78-0240fdf87055} / f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes" /v bProtectorDefaultScope" /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1248F259-004C-4A7D-8FDE-CBB26DAEBEA2}" /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{36A406DB-5AD9-4A3C-B35E-ECCBD63EDCC5}" /f Reg: reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: del /q C:\Users\Owner\Desktop\fix*.txt Reboot: ***************** [7180] C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe => Process closed successfully. [8896] C:\Users\Owner\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe => Process closed successfully. [7492] C:\Users\Owner\AppData\Local\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr_x64.exe => Process closed successfully. APNMCP => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ApnTBMon => value deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0C523F11-E1D2-4FA6-A799-2ABE20AD35CB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C523F11-E1D2-4FA6-A799-2ABE20AD35CB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0DB7EF00-D191-488A-AC2C-BD3858B8CA0D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DB7EF00-D191-488A-AC2C-BD3858B8CA0D}" => Key deleted successfully. C:\Windows\System32\Tasks\PC Cleaner Schedule => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Cleaner Schedule" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6896F8EA-950C-4BD2-8348-9D5A38F6BE2F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6896F8EA-950C-4BD2-8348-9D5A38F6BE2F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BE78A481-8D24-4A14-B26D-7ED25A3F45E6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE78A481-8D24-4A14-B26D-7ED25A3F45E6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => Key deleted successfully. "HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7DDBF870-FD43-4FED-80D6-D0D9AD0CB8C3}" => Key deleted successfully. "HKCR\CLSID\{7DDBF870-FD43-4FED-80D6-D0D9AD0CB8C3}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => Key deleted successfully. "HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}" => Key deleted successfully. "HKCR\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5350-4500-76A7-7A786E7484D7}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{4F524A2D-5350-4500-76A7-7A786E7484D7} => value deleted successfully. "HKCR\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{4F524A2D-5350-4500-76A7-7A786E7484D7} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}" => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml => Moved successfully. C:\Users\Owner\AppData\Local\Google\Chrome\User Data\default => Moved successfully. C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\9lpjozou.default => Moved successfully. C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\oneyyiv1.default-1375743666646 => Moved successfully. C:\Users\Owner\Desktop\Obraski na czat\lusia\super_emoty\Shortcut to erde.lnk => Moved successfully. C:\Users\Owner\Desktop\New folder (2)\DCIM - Shortcut.lnk => Moved successfully. C:\Users\Owner\Downloads\k,NzE0MDM5MjgsNDc5MjAwODU=,f,z5zsovwo.gif — skrót.lnk => Moved successfully. C:\Users\Owner\Music\Muzyka\JERZY PIOTROWSKI - Zloty kamien.lnk => Moved successfully. C:\Users\Owner\Music\Muzyka\JERZY PIOTROWSKI - Zloty kamien — skrót.lnk => Moved successfully. "C:\Users\Owner\Downloads\FRST-OlderVersion" => removed successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{70923415-8B08-4621-AAF7-24D755899993}\\NameServer => value deleted successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7AAF003C-5C30-4B24-A12B-E93C23612AB6}\\NameServer => value deleted successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7DB77D31-0516-44A0-AFC3-DC1E540D62E7}\\NameServer => value deleted successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{90726EF4-EAEA-4483-87C7-EE239CC129BA}\\NameServer => value deleted successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{942371D0-17CD-4B8A-80FC-F5AD84230A7C}\\NameServer => value deleted successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9B858825-D2C6-4E27-85F0-FD19BE87EB6D}\\NameServer => value deleted successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8015D14-D582-42D5-92FF-B44C5DDFD1D1}\\NameServer => value deleted successfully. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\Main" /v "bProtector Start Page" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {4c60e5ab-5c68-4c59-abaa-885010b24b32} / f ========= ERROR: Invalid syntax. Type "REG DELETE /?" for usage. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {77f5fe49-12e3-4cf5-abb4-d993a0164d9e} / f ========= ERROR: Invalid syntax. Type "REG DELETE /?" for usage. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {d2cf9842-af95-48cd-b873-bfbb48cd7f5e} / f ========= ERROR: Invalid syntax. Type "REG DELETE /?" for usage. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\URLSearchHooks" /v {da7a20cf-bef4-4342-ad78-0240fdf87055} / f ========= ERROR: Invalid syntax. Type "REG DELETE /?" for usage. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes" /v bProtectorDefaultScope" /f ========= ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1248F259-004C-4A7D-8FDE-CBB26DAEBEA2}" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{36A406DB-5AD9-4A3C-B35E-ECCBD63EDCC5}" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2696247456-811157038-2453434591-1000\Software\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= del /q C:\Users\Owner\Desktop\fix*.txt ========= ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ====