Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-12-2014 Ran by DOM at 2014-12-02 10:33:01 Run:1 Running from C:\Users\DOM\Desktop\scnay Loaded Profiles: UpdatusUser & DOM (Available profiles: UpdatusUser & DOM) Boot Mode: Normal ============================================== Content of fixlist: ***************** R1 {df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64; C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys [48776 2014-11-29] (StdLib) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) S3 catchme; \??\C:\1234aa.exe168021\catchme.sys [X] HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 -> {CAAF45EA-FED9-4150-A588-64A3DD21CE05} URL = http://startsear.ch/?aff=1&src=sp&cf=078e0ab0-9927-11e1-bb33-dca971544231&q={searchTerms} SearchScopes: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001 -> {CAAF45EA-FED9-4150-A588-64A3DD21CE05} URL = http://startsear.ch/?aff=1&src=sp&cf=078e0ab0-9927-11e1-bb33-dca971544231&q={searchTerms} Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File Task: {108BEE63-2766-4082-94F9-A61E192C52BD} - System32\Tasks\{B7E75CE9-1262-4690-AA0A-5B03EA04AA5B} => D:\PowerPoint\Microsoft Office PowerPoint 2007 PL.exe Task: {27D837BC-2143-491D-AAB6-043871D9C48A} - System32\Tasks\{A749C1FF-4F43-4E34-8BB2-9E0759156C2F} => D:\PowerPoint\Microsoft Office PowerPoint 2007 PL.exe Task: {56C2E152-8EE1-4DF0-B489-E3118A984267} - System32\Tasks\{B1419125-866F-4406-8442-C3CA4BF07D48} => D:\NARUTOSGNTS\GAME.exe Task: {5A1E3B8E-1DD6-4885-A917-1AF56E4BDD58} - System32\Tasks\{E0BAC9A1-853D-4B28-B3A8-4814E0F48583} => C:\PROGRAMY\SubEdit-Player\subedit.exe Task: {78C543BB-5491-46F2-B572-B618DDB772C4} - System32\Tasks\Symantec\Norton Error Analyzer 18.6.0.29 => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\SymErr.exe Task: {8FD4B633-27C6-4D34-904B-870C7AC40493} - System32\Tasks\{8E82E1DF-2265-4724-9017-FBDF336CF588} => D:\SpellForce - CieÅ„ Feniksa\spellforce.exe Task: {AFA14807-B62A-44BB-98BB-5394FC2D9302} - System32\Tasks\{64097DB9-622C-4BED-A5F5-946A01432E4B} => D:\NARUTOSGNTS\Dolphin.exe Task: {CC3B5B95-0F13-4475-AC8E-CB14D3680AA5} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-12225A02\EPM.exe Task: {CC94F45D-CB75-4B11-B3B7-CE2E3CA684B0} - System32\Tasks\{3844D976-0EC0-498F-9D35-5DA155B9BDEF} => D:\NARUTOSGNTS\GAME.exe Task: {D3A1BC40-F056-4BA3-B1CE-AFE331FF2774} - System32\Tasks\Symantec\Norton Error Processor 18.6.0.29 => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\SymErr.exe Task: {D632650A-7DB2-49F0-AFD0-6E6E31BA5068} - System32\Tasks\{280B954B-E01B-4065-B48E-30F2D5F04042} => D:\NARUTOSGNTS\Dolphin.exe Task: {DADCEB1A-04AA-4007-BC0E-A6B622E9928D} - System32\Tasks\{1A45A83B-276F-46FB-8DF6-E3587F1EA7DD} => D:\Sniper Elite III\Sniper Elite 3\bin\SniperElite3.exe Task: {E73E0127-3400-4A10-8C53-34120909C727} - System32\Tasks\{D46EF293-11F6-406A-A7F4-140C0A7D2BBF} => D:\SpellForce - CieÅ„ Feniksa\spellforce.exe Task: {E7F3B44A-8828-4797-804E-3A60B5B45784} - System32\Tasks\{1D3E57E1-D932-47F5-B65F-65A564596CB6} => D:\SpellForce - CieÅ„ Feniksa\spellforce.exe CHR HKLM-x32\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\DOM\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2013-02-03] CHR HKLM-x32\...\Chrome\Extension: [gpicboiclhmnllnjdcfcffifpoaebgkm] - C:\Program Files (x86)\Freecorder extension\Freecorder.crx [2012-10-13] FF Plugin HKU\S-1-5-21-1480235242-2075340924-4091109271-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File C:\Program Files\Freecorder extension x64 C:\Program Files (x86)\Freecorder extension C:\Program Files (x86)\Hold Page C:\Users\DOM\AppData\Local\CRE C:\Users\DOM\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\DOM\AppData\Local\WMTools Downloaded Files C:\Users\DOM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton C:\Users\DOM\AppData\Roaming\Thinstall C:\Users\DOM\Downloads\*(*)-dp*.exe C:\Users\DOM\Downloads\Niepotwierdzony*.crdownload C:\Users\DOM\Downloads\wlsetup*.exe C:\Users\UpdatusUser\Desktop\*.lnk C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Run /f Reg: reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome" /f CMD: for /d %f in (C:\Users\DOM\AppData\Local\{*}) do rd /s /q "%f" CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\DOM\AppData\Local CMD: dir /a C:\Users\DOM\AppData\LocalLow CMD: dir /a C:\Users\DOM\AppData\Roaming ***************** {df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64 => Service stopped successfully. {df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64 => Service deleted successfully. AppMgmt => Service deleted successfully. catchme => Service deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key not found. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key deleted successfully. "HKCR\CLSID\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. "HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{108BEE63-2766-4082-94F9-A61E192C52BD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{108BEE63-2766-4082-94F9-A61E192C52BD}" => Key deleted successfully. C:\Windows\System32\Tasks\{B7E75CE9-1262-4690-AA0A-5B03EA04AA5B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B7E75CE9-1262-4690-AA0A-5B03EA04AA5B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27D837BC-2143-491D-AAB6-043871D9C48A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27D837BC-2143-491D-AAB6-043871D9C48A}" => Key deleted successfully. C:\Windows\System32\Tasks\{A749C1FF-4F43-4E34-8BB2-9E0759156C2F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A749C1FF-4F43-4E34-8BB2-9E0759156C2F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{56C2E152-8EE1-4DF0-B489-E3118A984267}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56C2E152-8EE1-4DF0-B489-E3118A984267}" => Key deleted successfully. C:\Windows\System32\Tasks\{B1419125-866F-4406-8442-C3CA4BF07D48} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B1419125-866F-4406-8442-C3CA4BF07D48}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5A1E3B8E-1DD6-4885-A917-1AF56E4BDD58}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A1E3B8E-1DD6-4885-A917-1AF56E4BDD58}" => Key deleted successfully. C:\Windows\System32\Tasks\{E0BAC9A1-853D-4B28-B3A8-4814E0F48583} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E0BAC9A1-853D-4B28-B3A8-4814E0F48583}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78C543BB-5491-46F2-B572-B618DDB772C4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78C543BB-5491-46F2-B572-B618DDB772C4}" => Key deleted successfully. C:\Windows\System32\Tasks\Symantec\Norton Error Analyzer 18.6.0.29 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Symantec\Norton Error Analyzer 18.6.0.29" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8FD4B633-27C6-4D34-904B-870C7AC40493}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FD4B633-27C6-4D34-904B-870C7AC40493}" => Key deleted successfully. C:\Windows\System32\Tasks\{8E82E1DF-2265-4724-9017-FBDF336CF588} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8E82E1DF-2265-4724-9017-FBDF336CF588}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AFA14807-B62A-44BB-98BB-5394FC2D9302}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AFA14807-B62A-44BB-98BB-5394FC2D9302}" => Key deleted successfully. C:\Windows\System32\Tasks\{64097DB9-622C-4BED-A5F5-946A01432E4B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{64097DB9-622C-4BED-A5F5-946A01432E4B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CC3B5B95-0F13-4475-AC8E-CB14D3680AA5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC3B5B95-0F13-4475-AC8E-CB14D3680AA5}" => Key deleted successfully. C:\Windows\System32\Tasks\EasyPartitionManager => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EasyPartitionManager" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC94F45D-CB75-4B11-B3B7-CE2E3CA684B0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC94F45D-CB75-4B11-B3B7-CE2E3CA684B0}" => Key deleted successfully. C:\Windows\System32\Tasks\{3844D976-0EC0-498F-9D35-5DA155B9BDEF} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3844D976-0EC0-498F-9D35-5DA155B9BDEF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D3A1BC40-F056-4BA3-B1CE-AFE331FF2774}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3A1BC40-F056-4BA3-B1CE-AFE331FF2774}" => Key deleted successfully. C:\Windows\System32\Tasks\Symantec\Norton Error Processor 18.6.0.29 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Symantec\Norton Error Processor 18.6.0.29" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D632650A-7DB2-49F0-AFD0-6E6E31BA5068}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D632650A-7DB2-49F0-AFD0-6E6E31BA5068}" => Key deleted successfully. C:\Windows\System32\Tasks\{280B954B-E01B-4065-B48E-30F2D5F04042} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{280B954B-E01B-4065-B48E-30F2D5F04042}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DADCEB1A-04AA-4007-BC0E-A6B622E9928D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DADCEB1A-04AA-4007-BC0E-A6B622E9928D}" => Key deleted successfully. C:\Windows\System32\Tasks\{1A45A83B-276F-46FB-8DF6-E3587F1EA7DD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1A45A83B-276F-46FB-8DF6-E3587F1EA7DD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E73E0127-3400-4A10-8C53-34120909C727}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E73E0127-3400-4A10-8C53-34120909C727}" => Key deleted successfully. C:\Windows\System32\Tasks\{D46EF293-11F6-406A-A7F4-140C0A7D2BBF} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D46EF293-11F6-406A-A7F4-140C0A7D2BBF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E7F3B44A-8828-4797-804E-3A60B5B45784}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E7F3B44A-8828-4797-804E-3A60B5B45784}" => Key deleted successfully. C:\Windows\System32\Tasks\{1D3E57E1-D932-47F5-B65F-65A564596CB6} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1D3E57E1-D932-47F5-B65F-65A564596CB6}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda" => Key deleted successfully. C:\Users\DOM\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gpicboiclhmnllnjdcfcffifpoaebgkm" => Key deleted successfully. "C:\Program Files (x86)\Freecorder extension\Freecorder.crx" => File/Directory not found. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\MozillaPlugins\ubisoft.com/uplaypc" => Key deleted successfully. C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll not found. "C:\Program Files\Freecorder extension x64" => File/Directory not found. "C:\Program Files (x86)\Freecorder extension" => File/Directory not found. C:\Program Files (x86)\Hold Page => Moved successfully. C:\Users\DOM\AppData\Local\CRE => Moved successfully. C:\Users\DOM\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\DOM\AppData\Local\WMTools Downloaded Files => Moved successfully. C:\Users\DOM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton => Moved successfully. C:\Users\DOM\AppData\Roaming\Thinstall => Moved successfully. C:\Users\DOM\Downloads\*(*)-dp*.exe => Moved successfully. C:\Users\DOM\Downloads\Niepotwierdzony*.crdownload => Moved successfully. C:\Users\DOM\Downloads\wlsetup*.exe => Moved successfully. C:\Users\UpdatusUser\Desktop\*.lnk => Moved successfully. C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys => Moved successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Run /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= for /d %f in (C:\Users\DOM\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: BA6C-BBA9 Katalog: C:\Program Files 2014-12-02 10:31 . 2014-12-02 10:31 .. 2011-11-19 12:57 CCleaner 2012-02-29 10:20 Common Files 2009-07-14 05:54 174 desktop.ini 2012-04-16 23:38 DVD Maker 2011-11-18 16:47 Elantech 2014-11-28 22:45 GIMP 2 2011-11-18 16:47 Intel 2014-11-12 21:33 Internet Explorer 2011-09-06 23:43 Microsoft Games 2011-12-01 18:08 Microsoft Office 2014-07-29 10:42 Microsoft Silverlight 2009-07-14 06:32 MSBuild 2014-11-30 21:03 NVIDIA Corporation 2011-09-07 04:43 Realtek 2009-07-14 06:32 Reference Assemblies 2011-09-07 05:00 Samsung 2009-07-14 06:09 Uninstall Information 2013-07-11 09:20 Windows Defender 2014-07-10 13:51 Windows Journal 2014-11-30 22:02 Windows Live 2012-04-16 23:46 Windows Mail 2013-12-13 17:23 Windows Media Player 2009-07-14 06:32 Windows NT 2012-04-16 23:46 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2012-04-16 23:46 Windows Sidebar 2012-01-10 21:43 WinPcap 1 plik(¢w) 174 bajt¢w 28 katalog(¢w) 168ÿ010ÿ903ÿ552 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: BA6C-BBA9 Katalog: C:\Program Files (x86) 2014-12-02 10:33 . 2014-12-02 10:33 .. 2014-10-12 14:59 Adobe 2014-11-30 20:59 AGEIA Technologies 2013-01-09 20:02 Applian Technologies 2012-09-27 18:49 Brother 2013-03-23 21:20 Browny02 2014-12-01 00:58 Common Files 2013-03-23 21:20 ControlCenter4 2011-09-07 05:56 CyberLink 2009-07-14 05:54 174 desktop.ini 2014-11-29 15:05 Google 2012-01-05 13:33 Image-Line 2014-12-02 09:56 InstallShield Installation Information 2011-11-18 16:47 Intel 2014-11-12 21:33 Internet Explorer 2014-10-15 14:43 Java 2011-09-07 05:57 Microsoft 2014-01-28 19:21 Microsoft Analysis Services 2014-02-27 20:00 Microsoft Office 2014-11-30 20:59 Microsoft OneDrive 2014-07-29 10:42 Microsoft Silverlight 2014-11-30 22:08 Microsoft SQL Server Compact Edition 2014-02-27 20:31 Microsoft Sync Framework 2012-11-15 20:06 Microsoft Synchronization Services 2014-04-03 21:57 Microsoft Visual Studio 8 2014-06-26 10:48 Microsoft WSE 2012-11-15 20:05 Microsoft.NET 2014-11-30 21:42 Movie Maker 2.6 2014-04-03 19:42 MSBuild 2012-11-14 19:40 MSECache 2012-09-27 18:28 MSXML 4.0 2013-03-23 21:15 Nuance 2014-11-30 20:51 NVIDIA Corporation 2011-11-21 11:33 OpenOffice.org 3 2012-01-05 13:33 Outsim 2011-12-03 18:20 Pando Networks 2011-09-07 04:44 Realtek 2009-07-14 06:32 Reference Assemblies 2011-09-07 05:00 Samsung 2014-03-06 17:19 Skype 2014-03-04 16:35 Sony 2013-07-05 15:42 Sony Ericsson 2014-03-04 16:34 Sony Media Go Install 2011-09-07 04:43 Temp 2013-04-27 14:02 TomTom International B.V 2014-03-28 12:20 Ubisoft 2009-07-14 05:57 Uninstall Information 2011-09-07 04:55 WildGames 2013-07-11 09:20 Windows Defender 2014-11-30 22:11 Windows Live 2012-04-16 23:46 Windows Mail 2013-12-13 17:23 Windows Media Player 2009-07-14 06:32 Windows NT 2012-04-16 23:46 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2012-04-16 23:46 Windows Sidebar 2013-03-03 19:14 Xuggle 1 plik(¢w) 174 bajt¢w 57 katalog(¢w) 168ÿ010ÿ379ÿ264 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: BA6C-BBA9 Katalog: C:\ProgramData 2014-12-02 10:31 . 2014-12-02 10:31 .. 2014-10-12 14:59 Adobe 2009-07-14 06:08 Application Data [C:\ProgramData] 2013-12-07 12:19 AVAST Software 2012-09-27 18:41 Brother 2013-03-23 21:20 ControlCenter4 2012-03-07 19:58 CyberLink 2012-04-14 15:50 DAEMON Tools Lite 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2014-06-26 10:52 Electronic Arts 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2012-09-27 18:31 FLEXnet 2011-11-21 16:10 Gadu-Gadu 10 2013-03-07 15:56 InstallMate 2013-11-17 11:08 McAfee 2012-04-17 19:13 Media Center Programs 2014-11-30 22:03 Microsoft 2014-11-14 17:14 Microsoft Help 2014-11-29 19:30 Microsoft OneDrive 2014-08-08 13:40 MobileBrServ 2014-11-13 23:53 My Family Tree 2011-11-23 16:07 NFS Underground Demo 2012-01-21 10:04 Norton 2011-09-07 04:56 NortonInstaller 2014-12-01 23:43 266 ntuser.pol 2013-03-23 21:16 Nuance 2014-11-30 20:53 NVIDIA 2014-11-30 18:14 NVIDIA Corporation 2012-03-31 19:24 OpenFM 2014-10-15 15:01 Oracle 2013-11-02 20:15 Orbit 2014-07-04 22:19 Package Cache 2014-07-23 16:16 PMB Files 2014-07-16 19:05 Riot Games 2011-09-07 07:15 SAMSUNG 2013-03-23 21:15 ScanSoft 2014-03-06 17:19 Skype 2013-03-07 15:55 SoftSafe 2013-05-09 15:10 Sony 2014-03-04 16:34 Sony Corporation 2013-07-05 15:42 Sony Ericsson 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2013-11-22 23:06 Steam 2011-11-21 11:32 Sun 2011-09-07 05:55 Temp 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2013-02-05 21:25 TERA 2011-11-19 13:03 Trymedia 2012-06-24 08:54 VirtualizedApplications 2013-12-20 16:48 WildTangent 2014-11-30 21:00 WinClon 2013-03-23 21:16 Zeon 2011-09-07 05:55 109 {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2011-09-07 05:47 113 {34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log 2011-09-07 05:53 105 {40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2011-09-07 05:52 106 {80E158EA-7181-40FE-A701-301CE6BE64AB}.log 2011-09-07 05:54 110 {CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 6 plik(¢w) 809 bajt¢w 53 katalog(¢w) 168ÿ010ÿ375ÿ168 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\DOM\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: BA6C-BBA9 Katalog: C:\Users\DOM\AppData\Local 2014-12-02 10:33 . 2014-12-02 10:33 .. 2013-11-17 11:10 Adobe 2014-11-13 23:53 Chronoplex_Software 2014-12-02 10:27 CrashDumps 2014-03-24 17:48 CyberLink 2011-11-18 16:41 Dane aplikacji [C:\Users\DOM\AppData\Local] 2014-11-30 21:52 10ÿ240 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-11-29 23:37 Diagnostics 2014-03-04 16:33 Downloaded Installations 2012-04-14 15:59 Electronic Arts 2014-10-31 15:27 ElevatedDiagnostics 2014-06-02 18:33 EmieSiteList 2014-06-02 18:33 EmieUserList 2014-11-28 22:45 fontconfig 2013-01-14 23:55 Freecorder 7 Audio 2013-01-09 20:09 Freecorder 7 Converter 2013-01-09 20:09 Freecorder 7 Video 2014-11-12 21:38 121ÿ392 GDIPFONTCACHEV1.DAT 2014-11-28 22:45 gegl-0.2 2014-11-29 15:06 Google 2014-11-29 16:29 gtk-2.0 2011-11-18 16:41 Historia [C:\Users\DOM\AppData\Local\Microsoft\Windows\History] 2014-12-02 10:19 2ÿ567ÿ182 IconCache.db 2014-12-02 10:25 Jaksta_Technologies_Pty_L 2014-11-30 21:42 Microsoft 2012-01-29 22:43 Microsoft Games 2012-02-01 14:12 Microsoft Help 2012-11-15 19:24 MicrosoftStore 2012-09-08 19:29 MigWiz 2014-11-21 17:27 My Family Tree 2014-11-30 00:53 NVIDIA 2014-11-30 00:33 NVIDIA Corporation 2013-03-09 18:39 PCSX2 2014-07-23 16:16 PMB Files 2011-11-18 16:49 Power2Go 2013-11-22 22:54 Programs 2012-01-07 10:02 PunkBuster 2014-11-29 16:29 42ÿ850 recently-used.xbel 2011-11-18 19:24 Samsung 2014-07-04 22:42 Sniper3 2011-12-01 18:09 SoftGrid Client 2014-03-04 16:36 Sony 2014-12-02 10:33 Temp 2011-11-18 16:41 Temporary Internet Files [C:\Users\DOM\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2012-09-09 10:02 TomTom 2013-12-28 17:18 Ubisoft 2014-03-28 12:20 Ubisoft Game Launcher 2013-01-11 20:44 VirtualStore 2014-11-29 14:13 webkit 2014-11-30 22:18 Windows Live 4 plik(¢w) 2ÿ741ÿ664 bajt¢w 47 katalog(¢w) 168ÿ010ÿ895ÿ360 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\DOM\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: BA6C-BBA9 Katalog: C:\Users\DOM\AppData\LocalLow 2014-11-29 16:37 . 2014-11-29 16:37 .. 2011-11-22 09:29 Adblock Pro 2011-11-23 21:13 Adobe 2013-03-20 17:29 Brother 2013-03-03 18:13 Conduit 2014-11-29 16:40 EmieBrowserModeList 2014-09-26 13:53 EmieSiteList 2014-09-26 13:53 EmieUserList 2014-11-29 19:25 Microsoft 2011-11-21 11:31 Sun 0 plik(¢w) 0 bajt¢w 11 katalog(¢w) 168ÿ010ÿ895ÿ360 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\DOM\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: BA6C-BBA9 Katalog: C:\Users\DOM\AppData\Roaming 2014-12-02 10:33 . 2014-12-02 10:33 .. 2011-11-23 21:13 Adobe 2013-12-07 12:44 AVAST Software 2013-03-20 17:29 Brother 2014-07-15 21:47 ControlCenter4 2012-06-30 12:48 CyberLink 2011-11-27 11:44 169 D2Info0 2014-07-04 23:30 DAEMON Tools Lite 2011-11-27 11:55 Dofus 2 2011-11-23 21:23 Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 2011-11-26 22:36 Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 2011-11-21 23:29 Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 2011-11-27 11:57 8 DofusAppId0_1 2011-11-27 11:57 8 DofusAppId0_2 2011-11-26 22:53 8 DofusAppId0_3 2012-09-27 19:00 FLEXnet 2013-01-14 23:55 Freecorder 7 Audio 2013-01-09 20:09 Freecorder 7 Converter 2013-11-26 00:51 Freecorder 7 Video 2013-10-12 15:48 Gadu-Gadu 10 2012-01-05 13:04 GetRightToGo 2011-11-18 16:48 Identities 2012-09-27 18:34 InstallShield 2011-12-03 20:30 LolClient 2012-05-24 16:00 LolClient2 2011-11-18 16:50 Macromedia 2011-09-06 23:43 Media Center Programs 2014-09-13 23:48 Media Player Classic 2014-07-02 10:56 Microsoft 2013-11-11 15:29 Might & Magic Heroes VI 2012-08-11 13:14 Mozilla 2013-03-23 21:04 Nuance 2011-11-22 17:46 OpenFM 2011-11-21 11:34 OpenOffice.org 2014-11-28 22:39 PhotoScape 2012-02-02 13:35 Pioneer 2011-11-25 14:10 Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1 2011-11-19 12:54 Rovio 2012-11-07 20:34 Skype 2014-01-27 20:25 SoftGrid Client 2014-03-04 16:37 Sony 2013-07-31 22:16 testy.2013.DVD 2012-02-29 17:38 Tibia 2012-08-11 13:14 TomTom 2011-12-01 18:09 TP 2014-06-08 23:12 TS3Client 2014-12-02 10:22 uTorrent 2011-11-18 17:46 WildTangent 2011-12-04 11:00 WinRAR 2013-03-23 21:04 Zeon 4 plik(¢w) 193 bajt¢w 47 katalog(¢w) 168ÿ010ÿ891ÿ264 bajt¢w wolnych ========= End of CMD: ========= ==== End of Fixlog ====