Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-09-2014 Ran by Okurwiencze at 2014-10-01 11:19:38 Run:1 Running from D:\Instalki nowe\FRST Loaded Profile: Okurwiencze (Available profiles: Okurwiencze) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [186496 2014-03-21] () R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32288 2014-02-09] () <==== ATTENTION S2 savesenselive; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-01-26] (SaveSense) S3 savesenselivem; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-01-26] (SaveSense) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1146304 2014-05-13] (Crawler.com) R2 Update Surftastic; C:\Program Files (x86)\Surftastic\updateSurftastic.exe [111392 2014-02-21] () S2 WajamUpdaterV3; C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV3.exe [114176 2013-10-25] (Wajam) [File not signed] <==== ATTENTION R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [425104 2014-02-26] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] () S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed] S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [X] S2 Stereo Service; "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] Task: {05A0FAE9-9D7F-4D24-ABD1-25590ECCFAA3} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe Task: {08E8D64E-D573-4065-9CF9-001058C8D96E} - System32\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-5 => C:\Program Files (x86)\MediaPlayerplus\3d8c097a-d75d-43d1-aa88-eb4ad99df514-5.exe <==== ATTENTION Task: {167A22CF-12BD-4AEB-B647-14C94704C186} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-01-26] (SaveSense) <==== ATTENTION Task: {3C85AF43-996D-49CF-A242-C196C6EFC42A} - System32\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-4 => C:\Program Files (x86)\MediaPlayerplus\3d8c097a-d75d-43d1-aa88-eb4ad99df514-4.exe <==== ATTENTION Task: {4304EAE9-6DA2-4217-B2AE-4EFACA653EAE} - System32\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-1 => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe <==== ATTENTION Task: {44101BA9-CB5F-49AA-B6FF-5BD20A9C029A} - System32\Tasks\GoforFilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe <==== ATTENTION Task: {6560D23A-4774-450B-944B-9040DA94EB05} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-01-26] (SaveSense) <==== ATTENTION Task: {6C205B89-8665-42BE-BAB1-2BC198CE8DC6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-16] (Google Inc.) Task: {78D1EC06-217D-4057-A382-6705369252E6} - System32\Tasks\DSite => C:\Users\Okurwiencze\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe [2014-01-26] () <==== ATTENTION Task: {9A1302B4-A043-4F25-A971-FA06A6E17FD3} - System32\Tasks\AmiUpdXp => C:\Users\Okurwiencze\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION Task: {A4EB6967-A148-40CF-B69E-CC75818AD493} - System32\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-1 => C:\Program Files (x86)\Freeven Pro 1.3\Freeven Pro 1.3-codedownloader.exe <==== ATTENTION Task: {9F67F1BF-5D5A-4EF1-BFC8-5C41E551932E} - System32\Tasks\DriverToolkit Autorun => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe [2014-01-13] (Megaify Software Co., Ltd.) Task: {BBA7B92E-26EC-4BB9-A915-91C199B50760} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-16] (Google Inc.) Task: {CBF786C6-E815-4D3A-8B2B-D574443803C7} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION Task: {E368B25F-F29E-4B05-BC87-F99A88BD2D6D} - System32\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-4 => C:\Program Files (x86)\Freeven Pro 1.3\512823f1-87fd-4b5e-bf0a-0e1c683e9223-4.exe [2014-04-15] (Freeven) <==== ATTENTION Task: C:\Windows\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-1.job => C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-4.job => C:\Program Files (x86)\MediaPlayerplus\3d8c097a-d75d-43d1-aa88-eb4ad99df514-4.exe <==== ATTENTION Task: C:\Windows\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-5.job => C:\Program Files (x86)\MediaPlayerplus\3d8c097a-d75d-43d1-aa88-eb4ad99df514-5.exe <==== ATTENTION Task: C:\Windows\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-1.job => C:\Program Files (x86)\Freeven Pro 1.3\Freeven Pro 1.3-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-4.job => C:\Program Files (x86)\Freeven Pro 1.3\512823f1-87fd-4b5e-bf0a-0e1c683e9223-4.exe <==== ATTENTION Task: C:\Windows\Tasks\AmiUpdXp.job => C:\Users\Okurwiencze\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION Task: C:\Windows\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe Task: C:\Windows\Tasks\DSite.job => C:\Users\OKURWI~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION HKLM-x32\...\Run: [fst_de_7] => [X] AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found AppInit_DLLs: C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL => C:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll [2681648 2014-03-21] () AppInit_DLLs-x32: c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll => "c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll" File Not Found AppInit_DLLs-x32: c:\progra~2\optimi~1\optpro~1.dll => c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll [2961368 2014-03-21] () ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=sc&from=wpm0226&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&ts=1393412161 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software) -> hxxp://www.sweet-page.com/?type=sc&ts=1389823694&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK ShortcutWithArgument: C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1389823694&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK ShortcutWithArgument: C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=sc&from=wpm0226&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&ts=1393412161 ShortcutWithArgument: C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera12.15 1748.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software) -> hxxp://www.sweet-page.com/?type=sc&ts=1389823694&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=sc&from=wpm0226&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&ts=1393412161 ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\opera.exe (Opera Software) -> hxxp://www.sweet-page.com/?type=sc&ts=1389823694&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1402092449&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1402092449&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1402092449&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1402092449&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1389823694&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK SearchScopes: HKLM - {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = http://www.sweet-page.com/web/?type=ds&ts=1389823694&from=cor&uid=ST9320320AS_5SX4K3AKXXXX5SX4K3AK&q={searchTerms} SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna04ensW1Y9tWfcKY8_9HgKig_UQ7mxIYo82FlJl8EeQMAe2WF0m1GavOvyfDaV4QcyvPSFPDpodeKEwLNjXDzU4Ls1qwBFMFNJbfR608fJbE3eOmo2P-MGoxTUMD7qShw,,&q={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna04ensW1Y9tWfcKY8_9HgKig_UQ7mxIYo82FlJl8EeQMAe2WF0m1GavOvyfDaV4QcyvPSFPDpodeKEwLNjXDzU4Ls1qwBFMFNJbfR608fJbE3eOmo2P-MGoxTUMD7qSgA,,&q={searchTerms} SearchScopes: HKCU - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60327 BHO: Plus-HD-9.5 -> {11111111-1111-1111-1111-110511311166} -> C:\Program Files (x86)\Plus-HD-9.5\Plus-HD-9.5-bho64.dll (Plus HD) BHO: MediaPlayerplus -> {11111111-1111-1111-1111-110511421146} -> C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll (Freeven) BHO: Freeven Pro 1.3 -> {11111111-1111-1111-1111-110511421155} -> C:\Program Files (x86)\Freeven Pro 1.3\Freeven Pro 1.3-bho64.dll (Freeven) BHO: KINgCoupuon -> {56D3A495-004A-5305-3EC2-0C0D3D6E3D48} -> C:\ProgramData\KINgCoupuon\1CyZFc.x64.dll () BHO: KKingCoupion -> {6C277649-83C1-7382-6F9E-920426A91EFD} -> C:\ProgramData\KKingCoupion\SR8O97rf_.x64.dll () BHO-x32: No Name -> {11111111-1111-1111-1111-110411771118} -> No File BHO-x32: &Crawler Toolbar Helper -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} -> C:\Program Files (x86)\Crawler\Toolbar\ctbr.dll (Crawler.com) BHO-x32: KINgCoupuon -> {56D3A495-004A-5305-3EC2-0C0D3D6E3D48} -> C:\ProgramData\KINgCoupuon\1CyZFc.dll () BHO-x32: KKingCoupion -> {6C277649-83C1-7382-6F9E-920426A91EFD} -> C:\ProgramData\KKingCoupion\SR8O97rf_.dll () BHO-x32: No Name -> {84FF7BD6-B47F-46F8-9130-01B2696B36CB} -> No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files (x86)\Crawler\Toolbar\ctbr.dll (Crawler.com) Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - No File Handler-x32: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files (x86)\Crawler\Toolbar\ctbr.dll (Crawler.com) FF Plugin-x32: @tools.updaterss.com/SaveSenseLive Update;version=3 -> C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF Plugin-x32: @tools.updaterss.com/SaveSenseLive Update;version=9 -> C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File FF HKLM-x32\...\Firefox\Extensions: [ext@flashenhancer.com] - C:\Program Files (x86)\AmiExt\flashEnhancer\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home579.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home579\ff FF HKLM-x32\...\Firefox\Extensions: [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}] - C:\Program Files (x86)\Crawler\Toolbar\firefox FF HKCU\...\Firefox\Extensions: [freegames4357@BestOffers] - C:\Users\Okurwiencze\AppData\Roaming\Mozilla\Extensions\freegames4357@BestOffers FF HKCU\...\Firefox\Extensions: [speedtest4354@BestOffers] - C:\Users\Okurwiencze\AppData\Roaming\Mozilla\Extensions\speedtest4354@BestOffers FF HKCU\...\Firefox\Extensions: [{13b2a6cd-c8be-4191-a05b-b843a6b780cb}] - C:\Program Files (x86)\Re-markit\155.xpi FF HKCU\...\Firefox\Extensions: [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] - C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION! nointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION! C:\Program Files (x86)\Mozilla Firefox\searchplugins C:\Program Files (x86)\AmiExt C:\Program Files (x86)\Crawler C:\Program Files (x86)\DriverToolkit C:\Program Files (x86)\Freeven Pro 1.3 C:\Program Files (x86)\Google C:\Program Files (x86)\Iminent C:\Program Files (x86)\LPT C:\Program Files (x86)\MediaPlayerplus C:\Program Files (x86)\Mobogenie C:\Program Files (x86)\MyPC Backup C:\Program Files (x86)\Optimizer Pro C:\Program Files (x86)\Re-markit C:\Program Files (x86)\SaveSenseLive C:\Program Files (x86)\Spyware Terminator C:\Program Files (x86)\Surftastic C:\Program Files (x86)\Wajam C:\Program Files (x86)\WinZipper C:\ProgramData\26291a5eae6fc8d4 C:\ProgramData\KKingCoupion C:\ProgramData\ReoyalShOppERAPp C:\ProgramData\Spyware Terminator C:\ProgramData\TEMP C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper C:\Users\Okurwiencze\AppData\Local\{*} C:\Users\Okurwiencze\AppData\Local\Google C:\Users\Okurwiencze\AppData\Local\Mobogenie C:\Users\Okurwiencze\AppData\Roaming\DSite C:\Users\Okurwiencze\AppData\Roaming\Mozilla\Extensions C:\Users\Okurwiencze\AppData\Roaming\newnext.me C:\Users\Okurwiencze\AppData\Roaming\speedtest4354 C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Imperia Online.lnk C:\Users\Public\Desktop\Google Chrome.lnk C:\Users\Public\Desktop\Spyware Terminator 2012.lnk C:\Windows\pss\*.lnk.* C:\Windows\System32\DRIVERS\EsgScanner.sys C:\Windows\SysWow64\ZombieAlert.A222801BB6B4.2.6.80.dll C:\Windows\SysWow64\Drivers\StarOpen.sys DeleteKey: HKCU\Software\Google DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg DeleteKey: HKCU\Software\Microsoft\Internet Explorer\AboutURLs DeleteKey: HKCU\Software\Microsoft\Internet Explorer\Search DeleteKey: HKCU\Software\Microsoft\Internet Explorer\SearchURI DeleteKey: HKCU\Software\Microsoft\Internet Explorer\SearchUrl DeleteKey: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI DeleteKey: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl DeleteKey: HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs DeleteKey: HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main DeleteKey: HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search DeleteKey: HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI DeleteKey: HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchUrl CMD: sfc /scanfile=C:\Windows\system32\drivers\usbuhci.sys CMD: dir /a C:\Program Files CMD: dir /a C:\Program Files (x86) CMD: dir /a C:\Users\Okurwiencze\AppData\Local CMD: dir /a C:\Users\Okurwiencze\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. 70e6ca8c => Service deleted successfully. LPTSystemUpdater => Service deleted successfully. savesenselive => Service deleted successfully. savesenselivem => Service deleted successfully. ST2012_Svc => Service not found. Update Surftastic => Service stopped successfully. Update Surftastic => Service deleted successfully. WajamUpdaterV3 => Service deleted successfully. winzipersvc => Service deleted successfully. EsgScanner => Service deleted successfully. StarOpen => Service deleted successfully. SpyHunter 4 Service => Service deleted successfully. Stereo Service => Service deleted successfully. esgiguard => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{05A0FAE9-9D7F-4D24-ABD1-25590ECCFAA3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05A0FAE9-9D7F-4D24-ABD1-25590ECCFAA3}" => Key deleted successfully. C:\Windows\System32\Tasks\SpyHunter4Startup => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{08E8D64E-D573-4065-9CF9-001058C8D96E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08E8D64E-D573-4065-9CF9-001058C8D96E}" => Key deleted successfully. C:\Windows\System32\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-5 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\3d8c097a-d75d-43d1-aa88-eb4ad99df514-5" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{167A22CF-12BD-4AEB-B647-14C94704C186}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{167A22CF-12BD-4AEB-B647-14C94704C186}" => Key deleted successfully. C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3C85AF43-996D-49CF-A242-C196C6EFC42A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C85AF43-996D-49CF-A242-C196C6EFC42A}" => Key deleted successfully. C:\Windows\System32\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-4 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\3d8c097a-d75d-43d1-aa88-eb4ad99df514-4" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4304EAE9-6DA2-4217-B2AE-4EFACA653EAE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4304EAE9-6DA2-4217-B2AE-4EFACA653EAE}" => Key deleted successfully. C:\Windows\System32\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\3d8c097a-d75d-43d1-aa88-eb4ad99df514-1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{44101BA9-CB5F-49AA-B6FF-5BD20A9C029A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44101BA9-CB5F-49AA-B6FF-5BD20A9C029A}" => Key deleted successfully. C:\Windows\System32\Tasks\GoforFilesUpdate => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6560D23A-4774-450B-944B-9040DA94EB05}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6560D23A-4774-450B-944B-9040DA94EB05}" => Key deleted successfully. C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6C205B89-8665-42BE-BAB1-2BC198CE8DC6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C205B89-8665-42BE-BAB1-2BC198CE8DC6}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78D1EC06-217D-4057-A382-6705369252E6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78D1EC06-217D-4057-A382-6705369252E6}" => Key deleted successfully. C:\Windows\System32\Tasks\DSite => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9A1302B4-A043-4F25-A971-FA06A6E17FD3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A1302B4-A043-4F25-A971-FA06A6E17FD3}" => Key deleted successfully. C:\Windows\System32\Tasks\AmiUpdXp => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AmiUpdXp" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A4EB6967-A148-40CF-B69E-CC75818AD493}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4EB6967-A148-40CF-B69E-CC75818AD493}" => Key deleted successfully. C:\Windows\System32\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\512823f1-87fd-4b5e-bf0a-0e1c683e9223-1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9F67F1BF-5D5A-4EF1-BFC8-5C41E551932E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F67F1BF-5D5A-4EF1-BFC8-5C41E551932E}" => Key deleted successfully. C:\Windows\System32\Tasks\DriverToolkit Autorun => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DriverToolkit Autorun" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BBA7B92E-26EC-4BB9-A915-91C199B50760}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBA7B92E-26EC-4BB9-A915-91C199B50760}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CBF786C6-E815-4D3A-8B2B-D574443803C7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CBF786C6-E815-4D3A-8B2B-D574443803C7}" => Key deleted successfully. C:\Windows\System32\Tasks\LaunchApp => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchApp" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E368B25F-F29E-4B05-BC87-F99A88BD2D6D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E368B25F-F29E-4B05-BC87-F99A88BD2D6D}" => Key deleted successfully. C:\Windows\System32\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-4 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\512823f1-87fd-4b5e-bf0a-0e1c683e9223-4" => Key deleted successfully. C:\Windows\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-1.job => Moved successfully. C:\Windows\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-4.job => Moved successfully. C:\Windows\Tasks\3d8c097a-d75d-43d1-aa88-eb4ad99df514-5.job => Moved successfully. C:\Windows\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-1.job => Moved successfully. C:\Windows\Tasks\512823f1-87fd-4b5e-bf0a-0e1c683e9223-4.job => Moved successfully. C:\Windows\Tasks\AmiUpdXp.job => Moved successfully. C:\Windows\Tasks\DriverToolkit Autorun.job => Moved successfully. C:\Windows\Tasks\DSite.job => Moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_de_7 => value deleted successfully. "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll" => Value Data removed successfully. "C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL" => Value Data removed successfully. "c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll" => Value Data removed successfully. "c:\progra~2\optimi~1\optpro~1.dll" => Value Data removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk => Shortcut argument was removed successfully. C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera12.15 1748.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Opera.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}" => Key deleted successfully. "HKCR\CLSID\{460C3D19-B3D4-4964-A550-77D263B0CCCB}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}" => Key deleted successfully. "HKCR\CLSID\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully. "HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key deleted successfully. "HKCR\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511311166}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110511311166}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511421146}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110511421146}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511421155}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110511421155}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56D3A495-004A-5305-3EC2-0C0D3D6E3D48}" => Key deleted successfully. "HKCR\CLSID\{56D3A495-004A-5305-3EC2-0C0D3D6E3D48}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C277649-83C1-7382-6F9E-920426A91EFD}" => Key deleted successfully. "HKCR\CLSID\{6C277649-83C1-7382-6F9E-920426A91EFD}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411771118}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411771118}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key not found. "HKCR\Wow6432Node\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56D3A495-004A-5305-3EC2-0C0D3D6E3D48}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{56D3A495-004A-5305-3EC2-0C0D3D6E3D48}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C277649-83C1-7382-6F9E-920426A91EFD}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{6C277649-83C1-7382-6F9E-920426A91EFD}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. "HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value deleted successfully. "HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => Value not found. "HKCR\Wow6432Node\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" => Key not found. "HKCR\PROTOCOLS\Handler\tbr" => Key not found. "HKCR\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}" => Key not found. "HKCR\Wow6432Node\PROTOCOLS\Handler\tbr" => Key not found. "HKCR\Wow6432Node\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=3" => Key deleted successfully. C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll => Moved successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=9" => Key deleted successfully. C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. "HKCU\Software\MozillaPlugins\@lightspark.github.com/Lightspark;version=1" => Key deleted successfully. C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@flashenhancer.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaWatchV1home579.net => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => Value not found. HKCU\Software\Mozilla\Firefox\Extensions\\freegames4357@BestOffers => value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\speedtest4354@BestOffers => value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\{13b2a6cd-c8be-4191-a05b-b843a6b780cb} => value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2} => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKCU\SOFTWARE\Policies\Google" => Key deleted successfully. Wystapil blad podczas pr¢by usuniecia okreslonego elementu danych. Nie mozna odnalezc elementu. Wystapil blad podczas pr¢by usuniecia okreslonego elementu danych. Nie mozna odnalezc elementu. C:\Program Files (x86)\Mozilla Firefox\searchplugins => Moved successfully. C:\Program Files (x86)\AmiExt => Moved successfully. "C:\Program Files (x86)\Crawler" => File/Directory not found. C:\Program Files (x86)\DriverToolkit => Moved successfully. C:\Program Files (x86)\Freeven Pro 1.3 => Moved successfully. C:\Program Files (x86)\Google => Moved successfully. "C:\Program Files (x86)\Iminent" => File/Directory not found. C:\Program Files (x86)\LPT => Moved successfully. C:\Program Files (x86)\MediaPlayerplus => Moved successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. "C:\Program Files (x86)\MyPC Backup" => File/Directory not found. C:\Program Files (x86)\Optimizer Pro => Moved successfully. C:\Program Files (x86)\Re-markit => Moved successfully. C:\Program Files (x86)\SaveSenseLive => Moved successfully. "C:\Program Files (x86)\Spyware Terminator" => File/Directory not found. C:\Program Files (x86)\Surftastic => Moved successfully. C:\Program Files (x86)\Wajam => Moved successfully. C:\Program Files (x86)\WinZipper => Moved successfully. C:\ProgramData\26291a5eae6fc8d4 => Moved successfully. C:\ProgramData\KKingCoupion => Moved successfully. C:\ProgramData\ReoyalShOppERAPp => Moved successfully. "C:\ProgramData\Spyware Terminator" => File/Directory not found. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 => Moved successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012" => File/Directory not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper => Moved successfully. C:\Users\Okurwiencze\AppData\Local\{*} => Moved successfully. C:\Users\Okurwiencze\AppData\Local\Google => Moved successfully. C:\Users\Okurwiencze\AppData\Local\Mobogenie => Moved successfully. C:\Users\Okurwiencze\AppData\Roaming\DSite => Moved successfully. C:\Users\Okurwiencze\AppData\Roaming\Mozilla\Extensions => Moved successfully. C:\Users\Okurwiencze\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Okurwiencze\AppData\Roaming\speedtest4354 => Moved successfully. C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Moved successfully. C:\Users\Okurwiencze\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Imperia Online.lnk => Moved successfully. C:\Users\Public\Desktop\Google Chrome.lnk => Moved successfully. "C:\Users\Public\Desktop\Spyware Terminator 2012.lnk" => File/Directory not found. C:\Windows\pss\*.lnk.* => Moved successfully. C:\Windows\System32\DRIVERS\EsgScanner.sys => Moved successfully. C:\Windows\SysWow64\ZombieAlert.A222801BB6B4.2.6.80.dll => Moved successfully. C:\Windows\SysWow64\Drivers\StarOpen.sys => Moved successfully. HKCU\Software\Google => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Google => Key Deleted Successfully. HKLM\SOFTWARE\Wow6432Node\Google => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\Google => Key Deleted Successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder => Key Deleted Successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg => Key Deleted Successfully. HKCU\Software\Microsoft\Internet Explorer\AboutURLs => Key not found. HKCU\Software\Microsoft\Internet Explorer\Search => Key Deleted successfully. HKCU\Software\Microsoft\Internet Explorer\SearchURI => Key not found. HKCU\Software\Microsoft\Internet Explorer\SearchUrl => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl => Key not found. HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs => Key not found. HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main => Key not found. HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search => Key not found. HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes => Key not found. HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI => Key not found. HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchUrl => Key Deleted successfully. ========= sfc /scanfile=C:\Windows\system32\drivers\usbuhci.sys ========= Funkcja Ochrona zasob¢w systemu Windows nie moze wykonac zadanej operacji. ========= End of CMD: ========= ========= dir /a C:\Program Files ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: DCE1-5A38 Katalog: C:\ Nie mozna odnalezc pliku. Wolumin w stacji D to DATA Numer seryjny woluminu: 04F2-352C Katalog: D:\Instalki nowe\FRST Nie mozna odnalezc pliku. ========= End of CMD: ========= ========= dir /a C:\Program Files (x86) ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: DCE1-5A38 Katalog: C:\ Nie mozna odnalezc pliku. Wolumin w stacji D to DATA Numer seryjny woluminu: 04F2-352C Katalog: D:\Instalki nowe\FRST Katalog: D:\Instalki nowe\FRST Nie mozna odnalezc pliku. ========= End of CMD: ========= ========= dir /a C:\Users\Okurwiencze\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: DCE1-5A38 Katalog: C:\Users\Okurwiencze\AppData\Local 01.10.2014 11:21 . 01.10.2014 11:21 .. 25.08.2014 17:31 Adobe 15.01.2014 15:34 Anwendungsdaten [C:\Users\Okurwiencze\AppData\Local] 24.02.2014 00:45 Avg2014 11.08.2014 08:56 0 BIT1D40.tmp 16.01.2014 18:46 BonanzaDealsLive 16.01.2014 18:53 cache 28.04.2014 20:17 com 13.02.2014 19:46 CrashRpt 08.09.2014 20:05 CUSTPDF Writer 20.03.2014 11:35 Diagnostics 06.02.2014 14:34 DriverToolkit 17.01.2014 01:09 FLT 26.01.2014 21:48 64.136 GDIPFONTCACHEV1.DAT 07.06.2014 01:48 genienext 21.09.2014 03:46 1.968.532 IconCache.db 13.02.2014 18:58 Lollipop 22.02.2014 19:31 Macromedia 15.01.2014 20:11 MFAData 06.09.2014 23:52 Microsoft 02.02.2014 01:56 Microsoft Games 22.02.2014 19:30 Mozilla 21.02.2014 08:27 825.312 nsiCE25.tmp 27.05.2014 10:22 NVIDIA 11.03.2014 23:15 NVIDIA Corporation 15.01.2014 20:29 Opera 02.07.2014 19:55 Packages 15.01.2014 20:47 Programs 24.02.2014 00:59 SaveSense 26.01.2014 13:06 SaveSenseLive 15.01.2014 20:26 SearchProtect 16.02.2014 15:45 SmartFTP 16.02.2014 15:30 SmartFTP Client 5.0 Setup 16.01.2014 14:11 SRS Labs 06.06.2014 17:20 SwvUpdater 01.10.2014 11:21 Temp 15.01.2014 15:34 Temporary Internet Files [C:\Users\Okurwiencze\AppData\Local\Microsoft\Windows\Temporary Internet Files] 15.01.2014 15:34 Verlauf [C:\Users\Okurwiencze\AppData\Local\Microsoft\Windows\History] 05.02.2014 18:25 VirtualStore 21.03.2014 01:05 Wajam 4 plik(¢w) 2.857.980 bajt¢w 37 katalog(¢w) 23.833.972.736 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Okurwiencze\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: DCE1-5A38 Katalog: C:\Users\Okurwiencze\AppData\Roaming 01.10.2014 11:21 . 01.10.2014 11:21 .. 17.07.2014 16:25 .minecraft 27.05.2014 15:58 Activeris 06.02.2014 11:34 Adobe 20.02.2014 08:32 Allmyapps 24.02.2014 00:55 AVAST Software 15.01.2014 20:16 AVG2014 16.01.2014 00:13 CDXReader 15.01.2014 20:33 DAEMON Tools Lite 16.01.2014 00:06 DigitalSites 17.01.2014 01:07 DivX 15.01.2014 20:24 freegames111 13.02.2014 18:16 GoforFiles 15.01.2014 15:34 Identities 13.02.2014 18:08 IminentToolbar 06.09.2014 23:39 ipla 16.01.2014 00:13 LavFilters 16.01.2014 01:42 Macromedia 12.04.2011 09:54 Media Center Programs 14.06.2014 19:16 Microsoft 17.01.2014 01:07 MKKE 01.10.2014 11:21 Mozilla 03.02.2014 19:03 NVIDIA 15.01.2014 21:18 OpenCandy 26.01.2014 13:02 OpenOffice.org 15.01.2014 20:29 Opera 21.03.2014 01:06 Optimizer Pro 13.02.2014 18:58 PerformerSoft 09.03.2014 20:20 Samsung 26.01.2014 13:06 SaveSense 28.06.2014 00:26 Skype 16.02.2014 15:33 SmartFTP 26.02.2014 12:57 SupTab 07.06.2014 00:29 sweet-page 27.05.2014 16:04 systweak 15.01.2014 20:15 TuneUp Software 28.01.2014 22:34 ValueApps 01.10.2014 10:07 320 WB.CFG 26.01.2014 05:19 5 WBPU-TTL.DAT 11.04.2014 14:18 Winamp 15.01.2014 22:11 WinRAR 10.05.2014 23:52 WinZipper 2 plik(¢w) 325 bajt¢w 41 katalog(¢w) 23.834.497.024 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 1.6 GB temporary data. The system needed a reboot. ==== End of Fixlog ====