Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-09-2014 02 Ran by A&A at 2014-09-29 20:43:34 Run:1 Running from C:\Users\A&A\Desktop\ff Loaded Profile: A&A (Available profiles: A&A & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [46368 2013-11-11] (AVG Technologies) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed] S2 Crypkey License; crypserv.exe [X] U4 bdselfpr; S3 cpuz132; \??\C:\Users\euro\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [X] S3 cpuz134; \??\C:\Users\euro\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 cpuz135; \??\C:\Users\euro\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S1 NetworkX; \SystemRoot\system32\ckldrv.sys [X] S0 vmci; system32\DRIVERS\vmci.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] Task: {14917480-E5B0-4F87-AD22-E8FC844B19C6} - System32\Tasks\Express Files Updater => C:\Program Files (x86)\ExpressFiles\EFupdater.exe <==== ATTENTION Task: {44F23AFD-6271-46FB-9917-F1DF451EFD81} - System32\Tasks\AVG_SYS_TASK_0814av_DELETE => C:\ProgramData\Avg_Update_0814av\AVG-Secure-Search-Update_0814av.exe [2014-08-12] () Task: {A7B20965-6110-4556-8F39-5AA12FEB5E5D} - System32\Tasks\AVG_SYS_TASK_0814av => C:\ProgramData\Avg_Update_0814av\AVG-Secure-Search-Update_0814av.exe [2014-08-12] () Task: {DFB63B8F-040A-4729-A6C4-A22EF707F1B1} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION Task: C:\windows\Tasks\AVG_SYS_TASK_0814av.job => C:\ProgramData\Avg_Update_0814av\AVG-Secure-Search-Update_0814av.exe Task: C:\windows\Tasks\AVG_SYS_TASK_0814av_DELETE.job => C:\ProgramData\Avg_Update_0814av\AVG-Secure-Search-Update_0814av.exe HKLM\...\Run: [] => [X] HKU\S-1-5-21-3846476303-144707010-949530225-1006\...\Run: [ALLPlayer WiFi Remote] => C:\Program Files (x86)\ALLPlayer Remote\ALLPlayerRemoteControl.exe HKU\S-1-5-21-3846476303-144707010-949530225-1006\...\Run: [AVG-Secure-Search-Update_0214d] => C:\Users\A&A\AppData\Roaming\Avg_Update_0214d\AVG-Secure-Search-Update_0214d.exe /PROMPT /mid=c768cd (the data entry has 81 more characters). HKU\S-1-5-21-3846476303-144707010-949530225-1006\...\Run: [AVG-Secure-Search-Update_0814av] => C:\Users\A&A\AppData\Roaming\Avg_Update_0814av\AVG-Secure-Search-Update_0814av.exe [2775576 2014-08-12] () AppInit_DLLs-x32: => "" File Not Found ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=166 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear Toolbar: HKCU - No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File FF Plugin-x32: @ganymede/GanymedeNetPlugin,version=1.0 - C:\Program Files (x86)\Ganymede\Plugins\npganymedenet.dll No File FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\progra~2\mcafee\msc\npmcsn~1.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nation-secure-search.xml FF HKLM-x32\...\Firefox\Extensions: [bkmrksync@nokia.com] - C:\Program Files (x86)\Nokia\Nokia PC Suite 7\bkmrksync FF HKLM-x32\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-08-29] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-08-29] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-08-29] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-08-29] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-08-29] C:\Program Files (x86)\Mozilla Firefox\components C:\Program Files (x86)\Mozilla Firefox\plugins C:\Program Files (x86)\Mozilla Firefoxnation-secure-search.xml C:\ProgramData\*.bin C:\ProgramData\6fb0681fd9f5ce884c7c9b46a8e791bed15e4f84 C:\ProgramData\Avg_Update_0814av C:\ProgramData\MFAData C:\ProgramData\Temp C:\Users\A&A\AppData\Roaming\AVG C:\Users\A&A\AppData\Roaming\Avg_Update_0814av C:\Users\A&A\AppData\Roaming\nationzoom C:\Users\A&A\AppData\Roaming\QuickScan C:\Users\Administrator\AppData\Roaming\SmileysWeLove C:\Users\Default\AppData\Roaming\TuneUp Software C:\Windows\system32\drivers\avgtpx64.sys C:\Windows\SysWow64\Drivers\StarOpen.sys C:\Windows\SysWOW64\sqlite3.dll RemoveDirectory: C:\Users\Administrator\Desktop\Stare dane programu Firefox Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SqueakyChocolate, LLC UpdateChecker" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg query "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions" /s Reg: reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions" /s EmptyTemp: ***************** Processes closed successfully. avgtp => Service stopped successfully. avgtp => Service deleted successfully. StarOpen => Service deleted successfully. Crypkey License => Service deleted successfully. bdselfpr => Service deleted successfully. cpuz132 => Service deleted successfully. cpuz134 => Service deleted successfully. cpuz135 => Service deleted successfully. esgiguard => Service deleted successfully. NetworkX => Service deleted successfully. vmci => Service deleted successfully. VMnetAdapter => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{14917480-E5B0-4F87-AD22-E8FC844B19C6}" => Key not found. C:\Windows\System32\Tasks\Express Files Updater not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Express Files Updater" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44F23AFD-6271-46FB-9917-F1DF451EFD81}" => Key not found. C:\Windows\System32\Tasks\AVG_SYS_TASK_0814av_DELETE not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG_SYS_TASK_0814av_DELETE" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7B20965-6110-4556-8F39-5AA12FEB5E5D}" => Key not found. C:\Windows\System32\Tasks\AVG_SYS_TASK_0814av not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG_SYS_TASK_0814av" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DFB63B8F-040A-4729-A6C4-A22EF707F1B1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFB63B8F-040A-4729-A6C4-A22EF707F1B1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Program aktualizacji online firmy Adobe." => Key deleted successfully. C:\windows\Tasks\AVG_SYS_TASK_0814av.job not found. C:\windows\Tasks\AVG_SYS_TASK_0814av_DELETE.job not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-3846476303-144707010-949530225-1006\Software\Microsoft\Windows\CurrentVersion\Run\\ALLPlayer WiFi Remote => Value not found. HKU\S-1-5-21-3846476303-144707010-949530225-1006\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_0214d => Value not found. HKU\S-1-5-21-3846476303-144707010-949530225-1006\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_0814av => Value not found. "AppInit_DLLs-x32: => "" File Not Found" => Value Data not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive1" => Key not found. "HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive2" => Key not found. "HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive3" => Key not found. "HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key deleted successfully. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive1" => Key not found. "HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive2" => Key not found. "HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SkyDrive3" => Key not found. "HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} => value deleted successfully. "HKCR\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\FF Plugin-x32: @ganymede/GanymedeNetPlugin,version=1.0 - C:\Program Files (x86)\Ganymede\Plugins\npganymedenet.dll No File" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\progra~2\mcafee\msc\npmcsn~1.dll No File" => Key not found. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nation-secure-search.xml => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\bkmrksync@nokia.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\url_advisor@kaspersky.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\virtual_keyboard@kaspersky.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\content_blocker@kaspersky.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\anti_banner@kaspersky.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\online_banking@kaspersky.com => value deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dchlnpcodkpfdpacogkljefecpegganj" => Key deleted successfully. C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hakdifolhalapjijoafobooafbilfakh" => Key deleted successfully. C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hghkgaeecgjhjkannahfamoehjmkjail" => Key deleted successfully. C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh" => Key deleted successfully. C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pjldcfjmnllhmgjclecdnfampinooman" => Key deleted successfully. C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\components => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\plugins => Moved successfully. C:\Program Files (x86)\Mozilla Firefoxnation-secure-search.xml => Moved successfully. C:\ProgramData\*.bin => Moved successfully. C:\ProgramData\6fb0681fd9f5ce884c7c9b46a8e791bed15e4f84 => Moved successfully. "C:\ProgramData\Avg_Update_0814av" => File/Directory not found. C:\ProgramData\MFAData => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\A&A\AppData\Roaming\AVG => Moved successfully. "C:\Users\A&A\AppData\Roaming\Avg_Update_0814av" => File/Directory not found. C:\Users\A&A\AppData\Roaming\nationzoom => Moved successfully. C:\Users\A&A\AppData\Roaming\QuickScan => Moved successfully. C:\Users\Administrator\AppData\Roaming\SmileysWeLove => Moved successfully. C:\Users\Default\AppData\Roaming\TuneUp Software => Moved successfully. C:\Windows\system32\drivers\avgtpx64.sys => Moved successfully. C:\Windows\SysWow64\Drivers\StarOpen.sys => Moved successfully. C:\Windows\SysWOW64\sqlite3.dll => Moved successfully. "C:\Users\Administrator\Desktop\Stare dane programu Firefox" => removed successfully. ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SqueakyChocolate, LLC UpdateChecker" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg query "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0C4CC089-D306-440D-9772-464E226F6539} ButtonText REG_SZ &Klawiatura wirtualna CLSID REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} HotIcon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kbrd.ico Icon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kbrd.ico Default Visible REG_SZ YES ClsidExtension REG_SZ {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CCA281CA-C863-46ef-9331-5C8D4460577F} ButtonText REG_SZ @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 clsid REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} HotIcon REG_SZ C:\Program Files\Lenovo\Bluetooth Software\bt_hot_icon.ico Icon REG_SZ C:\Program Files\Lenovo\Bluetooth Software\bt_cold_icon.ico MenustatusBar REG_SZ @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4048 MenuText REG_SZ @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 Script REG_SZ C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm Default Visible REG_SZ Yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CCF151D8-D089-449F-A5A4-D9909053F20F} ButtonText REG_SZ &Sprawdzanie adres˘w internetowych CLSID REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} HotIcon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\logo.ico Icon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\logo.ico Default Visible REG_SZ YES ClsidExtension REG_SZ {CCF151D8-D089-449F-A5A4-D9909053F20F} ========= End of Reg: ========= ========= reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{0C4CC089-D306-440D-9772-464E226F6539} ButtonText REG_SZ &Klawiatura wirtualna CLSID REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} HotIcon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kbrd.ico Icon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kbrd.ico Default Visible REG_SZ YES ClsidExtension REG_SZ {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600} ButtonText REG_SZ @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 HotIcon REG_SZ C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll,201 Icon REG_SZ C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll,201 Default Visible REG_SZ Yes MenuText REG_SZ @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 CLSID REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} ClsidExtension REG_SZ {5F7B1267-94A9-47F5-98DB-E99415F33AEC} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49} KeyPath REG_SZ Yes ButtonText REG_SZ Wy˜lij do programu OneNote MenuText REG_SZ Wy˜lij &do programu OneNote ToolTip REG_SZ Wy˜lij do programu OneNote Default Visible REG_SZ Yes HotIcon REG_SZ C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll,103 Icon REG_SZ C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll,103 CLSID REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} ClsidExtension REG_SZ {48E73304-E1D6-4330-914C-F5F514E3486C} HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} CLSID REG_SZ {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} clsidExtension REG_SZ {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} Default Visible REG_SZ Yes Icon REG_SZ C:\windows\WindowsMobile\INetRepl.dll,210 HotIcon REG_SZ C:\windows\WindowsMobile\INetRepl.dll,211 ButtonText REG_SZ @C:\windows\WindowsMobile\INetRepl.dll,-222 (domy˜lny) REG_SZ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} CLSID REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} clsidExtension REG_SZ {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} MenuCustomize REG_SZ Tools MenuText REG_SZ @C:\windows\WindowsMobile\INetRepl.dll,-223 MenuStatusBar REG_SZ @C:\windows\WindowsMobile\INetRepl.dll,-224 (domy˜lny) REG_SZ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263} Icon REG_SZ C:\PROGRA~2\MICROS~1\Office12\REFBAR.ICO HotIcon REG_SZ C:\PROGRA~2\MICROS~1\Office12\REFBARH.ICO CLSID REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} BandCLSID REG_SZ {FF059E31-CC5A-4E2E-BF3B-96E929D65503} ButtonText REG_SZ Research Default Visible REG_SZ Yes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{CCA281CA-C863-46ef-9331-5C8D4460577F} ButtonText REG_SZ Wy˜lij do interfejsu Bluetooth clsid REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} HotIcon REG_SZ C:\Program Files\Lenovo\Bluetooth Software\bt_hot_icon.ico Icon REG_SZ C:\Program Files\Lenovo\Bluetooth Software\bt_cold_icon.ico MenustatusBar REG_SZ Wysyˆa bieľĄcĄ stron© do urzĄdzenia z interfejsem Bluetooth. MenuText REG_SZ Wy˜lij do urzĄdzenia &Bluetooth... Script REG_SZ C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm Default Visible REG_SZ Yes HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{CCF151D8-D089-449F-A5A4-D9909053F20F} ButtonText REG_SZ &Sprawdzanie adres˘w internetowych CLSID REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} HotIcon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\logo.ico Icon REG_SZ C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\logo.ico Default Visible REG_SZ YES ClsidExtension REG_SZ {CCF151D8-D089-449F-A5A4-D9909053F20F} ========= End of Reg: ========= EmptyTemp: => Removed 400.8 MB temporary data. The system needed a reboot. ==== End of Fixlog ====