Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014 Ran by Marta at 2014-09-22 21:40:42 Run:1 Running from D:\Programy\# Zabezpieczenia\nowe 2014.09 Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 ttnfd; C:\Windows\System32\drivers\ttnfd.sys [58232 2014-09-04] (Term Tutor) R2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll [3541448 2014-09-16] () R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-09-13] (Cherished Technololgy LIMITED) R2 ttsvc; C:\Program Files (x86)\TermTutor\Service\ttsvc.exe [276048 2014-09-04] (Term Tutor) HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2640408 2014-08-26] () HKU\S-1-5-21-2195184045-3265951034-2981680463-1000\...\Run: [Google Update] => C:\Users\Marta\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2012-03-07] (Google Inc.) HKU\S-1-5-21-2195184045-3265951034-2981680463-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [146888 2014-08-21] (PC Utilities Software Limited) ShortcutWithArgument: C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Users\Marta\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.istartsurf.com/?type=sc&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 ShortcutWithArgument: C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 ShortcutWithArgument: C:\Users\Marta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 ShortcutWithArgument: C:\Users\Marta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} SearchScopes: HKLM-x32 - {7A2B24E3-FE2C-44B3-AB42-A646635E211C} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815&q={searchTerms} SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://startsear.ch/?aff=1&q={searchTerms} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={6A9E299C-827D-4072-BBFA-1DF8D14F8271}&mid=d940c8f5997247d0aa60d16d12990cc7-e6ff24eed6b55948f9ef0f68e18a000992eacfb6&lang=pl&ds=bm012&pr=sa&d=2012-05-26 22:16:01&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} BHO: TermTutor -> {6CB99040-7828-4C37-AC01-F15758F43E4D} -> C:\Program Files\TermTutor\IE\TermTutorClientIE.dll (Term Tutor) BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited) BHO-x32: TermTutor -> {6CB99040-7828-4C37-AC01-F15758F43E4D} -> C:\Program Files (x86)\TermTutor\IE\TermTutorClientIE.dll (Term Tutor) BHO-x32: IE5BarLauncherBHO Class -> {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} -> C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKLM-x32 - VShareToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File DPF: HKLM-x32 {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\istartsurf.xml FF HKLM-x32\...\Firefox\Extensions: [{B7082FAA-CB62-4872-9106-E42DD88EDE45}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF HKLM-x32\...\Firefox\Extensions: [bkmrksync@nokia.com] - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.1.9.799 FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Marta\AppData\Roaming\Mozilla\Firefox\Profiles\lbosaufd.default\extensions\faststartff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [termtutor@termtutor.com] - C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com CHR HomePage: Default -> hxxp://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815 CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hp&ts=1410632294&from=ild&uid=SAMSUNGXHM500JI_S20CJ9AZ410815" CHR Extension: (vshare plugin) - C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj [2012-03-07] CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\vShare.tv plugin\vshareplg.crx [2011-08-31] CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx [2011-08-31] CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-09-13] Task: {126B7EE4-6AF7-4E05-96B4-F1445EC79B9D} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [2014-08-21] (PC Utilities Software Limited) <==== ATTENTION Task: {1446443E-A3AE-42CE-B6D7-91441E5DC473} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-19] (Google Inc.) Task: {2484FE61-87CB-424B-8685-C09B509E04C9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000UA => C:\Users\Marta\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-07] (Google Inc.) Task: {345377DB-6D1B-4A0F-A6EC-DC9DAC472635} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-09-13] (AnyProtect.com) <==== ATTENTION Task: {A0265ABA-530F-4CAE-B140-24ABC23F3834} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-19] (Google Inc.) Task: {A1FAB000-2DB4-4AA4-8776-4B68DC76CB73} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-09-13] (AnyProtect.com) <==== ATTENTION Task: {D04062DF-6756-43EA-B73B-0E2417673151} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000Core => C:\Users\Marta\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-07] (Google Inc.) Task: {E02DBB35-2085-45B8-BEFE-D118B001B0D9} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\windows\TEMP\{302BDDF6-2260-4D5A-A1D5-D58CBB3FAB0A}.exe Task: {F2D93948-4F97-4EB7-81FC-D08B96158CD2} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe [2014-09-13] (AnyProtect.com) <==== ATTENTION Task: {F6EEF331-5FF3-4CF3-9FB8-8DCD1AE6C21C} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\windows\TEMP\{8524D000-6DA5-4274-9C6B-E40F8CEDA240}.exe Task: C:\windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\windows\TEMP\{302BDDF6-2260-4D5A-A1D5-D58CBB3FAB0A}.exe Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\windows\TEMP\{8524D000-6DA5-4274-9C6B-E40F8CEDA240}.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000Core.job => C:\Users\Marta\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000UA.job => C:\Users\Marta\AppData\Local\Google\Update\GoogleUpdate.exe CustomCLSID: HKU\S-1-5-21-2195184045-3265951034-2981680463-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Marta\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-2195184045-3265951034-2981680463-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Marta\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml C:\Program Files (x86)\Mozilla Firefox\extensions C:\Program Files (x86)\mozilla firefox\plugins C:\Program Files (x86)\SupTab C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 C:\ProgramData\IePluginServices C:\ProgramData\WindowsMangerProtect C:\Users\Marta\AppData\Local\*.tmp C:\Users\Marta\AppData\Roaming\ap_logs C:\Users\Marta\AppData\Roaming\aps.scan.quick.results C:\Users\Marta\AppData\Roaming\aps.scan.results C:\Users\Marta\AppData\Roaming\aps.uninstall.scan.results C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com C:\Users\Marta\AppData\Roaming\WebExtend C:\Users\Marta\Desktop\Optimizer Pro.lnk C:\Users\Marta\Documents\Optimizer Pro C:\Windows\System32\drivers\ttnfd.sys Folder: C:\Users\Marta\AppData\Roaming\Opera Software\Opera Stable\Extensions CMD: type "C:\Users\Marta\AppData\Roaming\Opera Software\Opera Stable\Preferences" Reg: reg query "HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command" /s Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: netsh advfirewall reset ***************** Processes closed successfully. ttnfd => Unable to stop service ttnfd => Service deleted successfully. 70e6ca8c => Service deleted successfully. IePluginServices => Service deleted successfully. ttsvc => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\vProt => value deleted successfully. HKU\S-1-5-21-2195184045-3265951034-2981680463-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully. HKU\S-1-5-21-2195184045-3265951034-2981680463-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => value deleted successfully. C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Marta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Marta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{7A2B24E3-FE2C-44B3-AB42-A646635E211C}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{7A2B24E3-FE2C-44B3-AB42-A646635E211C}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}" => Key deleted successfully. "HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CB99040-7828-4C37-AC01-F15758F43E4D}" => Key deleted successfully. "HKCR\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CB99040-7828-4C37-AC01-F15758F43E4D}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. "HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value deleted successfully. "HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55}" => Key deleted successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\istartsurf.xml => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45} => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\bkmrksync@nokia.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\avg@toolbar => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\faststartff@gmail.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\termtutor@termtutor.com => value deleted successfully. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj" => Key deleted successfully. C:\Program Files (x86)\vShare.tv plugin\vshareplg.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof" => Key deleted successfully. "C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx" => File/Directory not found. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma" => Key deleted successfully. C:\Users\Marta\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{126B7EE4-6AF7-4E05-96B4-F1445EC79B9D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{126B7EE4-6AF7-4E05-96B4-F1445EC79B9D}" => Key deleted successfully. C:\Windows\System32\Tasks\Optimizer Pro Schedule => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1446443E-A3AE-42CE-B6D7-91441E5DC473}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1446443E-A3AE-42CE-B6D7-91441E5DC473}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2484FE61-87CB-424B-8685-C09B509E04C9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2484FE61-87CB-424B-8685-C09B509E04C9}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000UA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000UA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{345377DB-6D1B-4A0F-A6EC-DC9DAC472635}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{345377DB-6D1B-4A0F-A6EC-DC9DAC472635}" => Key deleted successfully. C:\Windows\System32\Tasks\APSnotifierPP3 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A0265ABA-530F-4CAE-B140-24ABC23F3834}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0265ABA-530F-4CAE-B140-24ABC23F3834}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1FAB000-2DB4-4AA4-8776-4B68DC76CB73}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1FAB000-2DB4-4AA4-8776-4B68DC76CB73}" => Key deleted successfully. C:\Windows\System32\Tasks\APSnotifierPP1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D04062DF-6756-43EA-B73B-0E2417673151}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D04062DF-6756-43EA-B73B-0E2417673151}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000Core => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000Core" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E02DBB35-2085-45B8-BEFE-D118B001B0D9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E02DBB35-2085-45B8-BEFE-D118B001B0D9}" => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_HP_rmv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F2D93948-4F97-4EB7-81FC-D08B96158CD2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F2D93948-4F97-4EB7-81FC-D08B96158CD2}" => Key deleted successfully. C:\Windows\System32\Tasks\APSnotifierPP2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F6EEF331-5FF3-4CF3-9FB8-8DCD1AE6C21C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6EEF331-5FF3-4CF3-9FB8-8DCD1AE6C21C}" => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv" => Key deleted successfully. C:\windows\Tasks\APSnotifierPP1.job => Moved successfully. C:\windows\Tasks\APSnotifierPP2.job => Moved successfully. C:\windows\Tasks\APSnotifierPP3.job => Moved successfully. C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully. C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000Core.job => Moved successfully. C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2195184045-3265951034-2981680463-1000UA.job => Moved successfully. "HKU\S-1-5-21-2195184045-3265951034-2981680463-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => Key deleted successfully. "HKU\S-1-5-21-2195184045-3265951034-2981680463-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc" => Key deleted successfully. C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions => Moved successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. C:\Program Files (x86)\SupTab => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\Users\Marta\AppData\Local\*.tmp => Moved successfully. C:\Users\Marta\AppData\Roaming\ap_logs => Moved successfully. C:\Users\Marta\AppData\Roaming\aps.scan.quick.results => Moved successfully. C:\Users\Marta\AppData\Roaming\aps.scan.results => Moved successfully. C:\Users\Marta\AppData\Roaming\aps.uninstall.scan.results => Moved successfully. C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup => Moved successfully. C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com => Moved successfully. C:\Users\Marta\AppData\Roaming\WebExtend => Moved successfully. C:\Users\Marta\Desktop\Optimizer Pro.lnk => Moved successfully. C:\Users\Marta\Documents\Optimizer Pro => Moved successfully. C:\Windows\System32\drivers\ttnfd.sys => Moved successfully. ========================= Folder: C:\Users\Marta\AppData\Roaming\Opera Software\Opera Stable\Extensions ======================== Directory Not Found ========= type "C:\Users\Marta\AppData\Roaming\Opera Software\Opera Stable\Preferences" ========= ========= End of CMD: ========= ========= reg query "HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command (domy˜lny) REG_SZ "C:\Program Files (x86)\Opera\Launcher.exe" ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ====