Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-09-2014 Ran by Bobek at 2014-09-10 18:53:17 Run:2 Running from C:\Users\Bobek\Desktop\FRS Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: EmptyTemp: R2 d0e87c27; c:\Program Files (x86)\SW-Booster\AssistantSvc.dll [174928 2014-09-06] () [File not signed] R2 f1f78e38; c:\ProgramData\WinSpeed\WinSpeedSvc.dll [186192 2014-08-24] () [File not signed] R2 Update trolatunt; C:\Program Files (x86)\trolatunt\updatetrolatunt.exe [323360 2014-08-05] () R2 Util trolatunt; C:\Program Files (x86)\trolatunt\bin\utiltrolatunt.exe [323360 2014-08-05] () S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service [X] R1 {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64; C:\Windows\System32\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64.sys [61112 2014-07-21] (StdLib) R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}w64; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys [61120 2014-06-20] (StdLib) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] HKU\S-1-5-21-555694070-2704252721-650672022-1001\...\Run: [LiveSupport] => "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log AppInit_DLLs: C:\PROGRA~3\WinSpeed\WINSPE~1.DLL => C:\ProgramData\WinSpeed\WinSpeed_x64.dll [4304896 2014-08-24] () AppInit_DLLs: C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL => C:\Program Files (x86)\SW-Booster\Assistant_x64.dll [4210176 2014-09-06] () AppInit_DLLs-x32: c:\progra~3\winspeed\winspeed.dll => c:\ProgramData\WinSpeed\WinSpeed.dll [4127232 2014-08-24] () AppInit_DLLs-x32: c:\progra~2\sw-boo~1\assist~1.dll => c:\Program Files (x86)\SW-Booster\Assistant.dll [4296192 2014-09-06] () Task: {05D3ADF8-CE9A-4055-A096-309A2A4674EC} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-7 No Task File <==== ATTENTION Task: {084C8F1A-2E78-430F-ADA1-2C8B82EE08E0} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-3 No Task File <==== ATTENTION Task: {192D2401-A40C-4F45-91C2-0E0517BD0EDF} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {24568D78-9A9C-4CDC-970C-085D23BB9062} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-6 No Task File <==== ATTENTION Task: {3E7FE32C-41D9-43ED-9647-2B18AF9C46DF} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-2 No Task File <==== ATTENTION Task: {61A0D17A-4EE0-4B60-94AE-05E5615B2128} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {6802742F-4C28-4F2A-BD57-C6F9303AF642} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-5_user No Task File <==== ATTENTION Task: {81659E09-3D80-4823-A99B-AB219F27A085} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-4 No Task File <==== ATTENTION Task: {A8176A55-FCBE-4637-B317-F8A88CD832F0} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION Task: {E265FCDD-A1FD-4BD4-A2F1-6CB2B9BAC123} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-5 No Task File <==== ATTENTION Task: {E3CD8524-11B9-4622-B51C-8918B40C3AD4} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-1 No Task File <==== ATTENTION Task: {E57B6BBE-F340-4B37-B308-F8296965D490} - \88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-11 No Task File <==== ATTENTION Task: {FE510951-41DE-4787-BE21-3C328FBE813E} - System32\Tasks\SW-Booster-S-792098896 => c:\programdata\trusted publisher\sw-booster\SW-Booster.exe [2013-09-06] () <==== ATTENTION Task: C:\Windows\Tasks\SW-Booster-S-792098896.job => c:\programdata\trusted publisher\sw-booster\SW-Booster.exe <==== ATTENTION GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ShortcutWithArgument: C:\Users\Bobek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 ShortcutWithArgument: C:\Users\Bobek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 ShortcutWithArgument: C:\Users\Bobek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=a12834-386&apn_uid=0471563149454403&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=a12834-386&apn_uid=0471563149454403&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409996866&from=wpc&uid=SAMSUNGXHD502HJ_S20BJ9AZ407378&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=a12834-386&apn_uid=0471563149454403&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} BHO: YYoUtubeAdBloceke -> {3bcd3670-a43d-4c97-b26c-52bb0681bbe2} -> C:\Program Files (x86)\YYoUtubeAdBloceke\SzK2uA6boZ2LOs.x64.dll () BHO: tperifecctucoUpoon -> {77D615B8-2E98-F959-C446-9B9CE5299EEF} -> C:\ProgramData\tperifecctucoUpoon\d6K.x64.dll () BHO: pRiCCechop -> {c561f6d7-a9d0-41ac-b055-eca900b58b9b} -> C:\Program Files (x86)\pRiCCechop\1eBzEahhdxcxYC.x64.dll () BHO: piricaeciHoop -> {e335ae00-2ef1-4198-80ec-fed4694b68b7} -> C:\Program Files (x86)\piricaeciHoop\UnOVOebpR7QvXg.x64.dll () BHO: CoollSaLaeCoupon -> {F324BF5E-B7D0-58BC-98F8-330489556625} -> C:\ProgramData\CoollSaLaeCoupon\BCsk.x64.dll () BHO-x32: YYoUtubeAdBloceke -> {3bcd3670-a43d-4c97-b26c-52bb0681bbe2} -> C:\Program Files (x86)\YYoUtubeAdBloceke\SzK2uA6boZ2LOs.dll () BHO-x32: tperifecctucoUpoon -> {77D615B8-2E98-F959-C446-9B9CE5299EEF} -> C:\ProgramData\tperifecctucoUpoon\d6K.dll () BHO-x32: pRiCCechop -> {c561f6d7-a9d0-41ac-b055-eca900b58b9b} -> C:\Program Files (x86)\pRiCCechop\1eBzEahhdxcxYC.dll () BHO-x32: piricaeciHoop -> {e335ae00-2ef1-4198-80ec-fed4694b68b7} -> C:\Program Files (x86)\piricaeciHoop\UnOVOebpR7QvXg.dll () BHO-x32: CoollSaLaeCoupon -> {F324BF5E-B7D0-58BC-98F8-330489556625} -> C:\ProgramData\CoollSaLaeCoupon\BCsk.dll () Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" C:\Program Files (x86)\trolatunt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BananaMt2 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader C:\Users\Administrator C:\Users\Gość C:\Users\Bobek\AppData\Local\Chromatic Browser C:\Users\Bobek\AppData\Local\Comodo C:\Users\Bobek\AppData\Local\Google\Chrome C:\Users\Bobek\AppData\Local\Torch C:\Users\Bobek\AppData\Roaming\Mozilla C:\Users\Bobek\AppData\Roaming\Systweak C:\Users\Bobek\Downloads\yet_another_cleaner_reh.exe C:\Users\Bobek\Downloads\yet_another_cleaner_gam.exe C:\Users\Public\Desktop\EZDownloader.lnk C:\Windows\pss\MyPC Backup.lnk.Startup C:\Windows\System32\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64.sys C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys C:\Windows\SysWOW64\GroupPolicy\GPT.INI Folder: C:\Windows\SysWOW64\X86 Folder: C:\Windows\SysWOW64\AMD64 Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Bobek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk" /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ***************** Processes closed successfully. d0e87c27 => Service deleted successfully. f1f78e38 => Service deleted successfully. Update trolatunt => Service deleted successfully. Util trolatunt => Service deleted successfully. gupdate => Service deleted successfully. gupdatem => Service deleted successfully. WindowsMangerProtect => Service deleted successfully. {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64 => Service stopped successfully. {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64 => Service deleted successfully. {a3f28269-ad17-41a8-b032-3e0313ef8979}w64 => Service stopped successfully. {a3f28269-ad17-41a8-b032-3e0313ef8979}w64 => Service deleted successfully. esgiguard => Service deleted successfully. gdrv => Service deleted successfully. HKU\S-1-5-21-555694070-2704252721-650672022-1001\Software\Microsoft\Windows\CurrentVersion\Run\\LiveSupport => value deleted successfully. "C:\PROGRA~3\WinSpeed\WINSPE~1.DLL" => Value Data removed successfully. "C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL" => Value Data removed successfully. "c:\progra~3\winspeed\winspeed.dll" => Value Data removed successfully. "c:\progra~2\sw-boo~1\assist~1.dll" => Value Data removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{05D3ADF8-CE9A-4055-A096-309A2A4674EC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05D3ADF8-CE9A-4055-A096-309A2A4674EC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-7" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{084C8F1A-2E78-430F-ADA1-2C8B82EE08E0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{084C8F1A-2E78-430F-ADA1-2C8B82EE08E0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{192D2401-A40C-4F45-91C2-0E0517BD0EDF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{192D2401-A40C-4F45-91C2-0E0517BD0EDF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{24568D78-9A9C-4CDC-970C-085D23BB9062}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24568D78-9A9C-4CDC-970C-085D23BB9062}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-6" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3E7FE32C-41D9-43ED-9647-2B18AF9C46DF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E7FE32C-41D9-43ED-9647-2B18AF9C46DF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{61A0D17A-4EE0-4B60-94AE-05E5615B2128}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{61A0D17A-4EE0-4B60-94AE-05E5615B2128}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6802742F-4C28-4F2A-BD57-C6F9303AF642}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6802742F-4C28-4F2A-BD57-C6F9303AF642}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-5_user" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{81659E09-3D80-4823-A99B-AB219F27A085}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81659E09-3D80-4823-A99B-AB219F27A085}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-4" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A8176A55-FCBE-4637-B317-F8A88CD832F0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8176A55-FCBE-4637-B317-F8A88CD832F0}" => Key deleted successfully. C:\Windows\System32\Tasks\LaunchSignup => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E265FCDD-A1FD-4BD4-A2F1-6CB2B9BAC123}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E265FCDD-A1FD-4BD4-A2F1-6CB2B9BAC123}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-5" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E3CD8524-11B9-4622-B51C-8918B40C3AD4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3CD8524-11B9-4622-B51C-8918B40C3AD4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E57B6BBE-F340-4B37-B308-F8296965D490}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E57B6BBE-F340-4B37-B308-F8296965D490}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\88f9d0a7-0d4d-4e1a-9e5c-3dba1727a592-11" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FE510951-41DE-4787-BE21-3C328FBE813E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE510951-41DE-4787-BE21-3C328FBE813E}" => Key deleted successfully. C:\Windows\System32\Tasks\SW-Booster-S-792098896 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SW-Booster-S-792098896" => Key deleted successfully. C:\Windows\Tasks\SW-Booster-S-792098896.job => Moved successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. C:\Users\Bobek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Bobek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Bobek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully. "HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully. "HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3bcd3670-a43d-4c97-b26c-52bb0681bbe2}" => Key deleted successfully. "HKCR\CLSID\{3bcd3670-a43d-4c97-b26c-52bb0681bbe2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77D615B8-2E98-F959-C446-9B9CE5299EEF}" => Key deleted successfully. "HKCR\CLSID\{77D615B8-2E98-F959-C446-9B9CE5299EEF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c561f6d7-a9d0-41ac-b055-eca900b58b9b}" => Key deleted successfully. "HKCR\CLSID\{c561f6d7-a9d0-41ac-b055-eca900b58b9b}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e335ae00-2ef1-4198-80ec-fed4694b68b7}" => Key deleted successfully. "HKCR\CLSID\{e335ae00-2ef1-4198-80ec-fed4694b68b7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F324BF5E-B7D0-58BC-98F8-330489556625}" => Key deleted successfully. "HKCR\CLSID\{F324BF5E-B7D0-58BC-98F8-330489556625}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3bcd3670-a43d-4c97-b26c-52bb0681bbe2}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{3bcd3670-a43d-4c97-b26c-52bb0681bbe2}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77D615B8-2E98-F959-C446-9B9CE5299EEF}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{77D615B8-2E98-F959-C446-9B9CE5299EEF}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c561f6d7-a9d0-41ac-b055-eca900b58b9b}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{c561f6d7-a9d0-41ac-b055-eca900b58b9b}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e335ae00-2ef1-4198-80ec-fed4694b68b7}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{e335ae00-2ef1-4198-80ec-fed4694b68b7}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F324BF5E-B7D0-58BC-98F8-330489556625}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{F324BF5E-B7D0-58BC-98F8-330489556625}" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully. "HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}" => Key not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys" => Key deleted successfully. C:\Program Files (x86)\trolatunt => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BananaMt2 => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader => Moved successfully. C:\Users\Administrator => Moved successfully. C:\Users\Gość => Moved successfully. C:\Users\Bobek\AppData\Local\Chromatic Browser => Moved successfully. C:\Users\Bobek\AppData\Local\Comodo => Moved successfully. C:\Users\Bobek\AppData\Local\Google\Chrome => Moved successfully. C:\Users\Bobek\AppData\Local\Torch => Moved successfully. C:\Users\Bobek\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Bobek\AppData\Roaming\Systweak => Moved successfully. C:\Users\Bobek\Downloads\yet_another_cleaner_reh.exe => Moved successfully. C:\Users\Bobek\Downloads\yet_another_cleaner_gam.exe => Moved successfully. C:\Users\Public\Desktop\EZDownloader.lnk => Moved successfully. C:\Windows\pss\MyPC Backup.lnk.Startup => Moved successfully. C:\Windows\System32\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64.sys => Moved successfully. C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys => Moved successfully. C:\Windows\SysWOW64\GroupPolicy\GPT.INI => Moved successfully. ========================= Folder: C:\Windows\SysWOW64\X86 ======================== ====== End of Folder: ====== ========================= Folder: C:\Windows\SysWOW64\AMD64 ======================== ====== End of Folder: ====== ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Bobek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk" /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= EmptyTemp: => Removed 5.6 GB temporary data. The system needed a reboot. ==== End of Fixlog ====