Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-12-2014 Ran by Andrrzej Szachta at 2014-12-06 16:16:55 Run:1 Running from C:\Users\Andrrzej Szachta\Documents\Skany i Logi,Naprawa,Fixit.pl Loaded Profile: Andrrzej Szachta (Available profiles: Andrrzej Szachta) Boot Mode: Safe Mode (with Networking) ============================================== Content of fixlist: ***************** CloseProcesses: S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-11-19] (globalUpdate) [File not signed] S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-11-19] (globalUpdate) [File not signed] S2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32800 2014-11-02] () S2 wpsvc_1.10.0.2; C:\Program Files (x86)\WordProser_1.10.0.2\Service\wpsvc.exe [277584 2014-11-04] (Word Proser) S2 webinstrT; C:\WINDOWS\system32\Drivers\webinstrT.sys [63696 2014-11-19] (Corsica) R1 wpnfd_1_10_0_2; C:\Windows\System32\drivers\wpnfd_1_10_0_2.sys [58240 2014-11-04] (Word Proser) S3 huawei_enumerator; \SystemRoot\System32\drivers\ew_jubusenum.sys [X] S3 IntcAzAudAddService; \SystemRoot\system32\drivers\RTKVHD64.sys [X] Task: {05D5EC86-434F-4139-880E-A4488A411024} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5_user => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5.exe [2014-11-19] (CinPlusV19.11) <==== ATTENTION Task: {1197016B-46D6-4843-BF61-913A7D0D69B5} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-6 => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-6.exe [2014-11-19] (CinPlusV19.11) <==== ATTENTION Task: {1E310176-BCB1-4557-9985-B6BEA43B2E82} - System32\Tasks\QEDYQJMM => C:\Users\Andrrzej Szachta\AppData\Roaming\QEDYQJMM.exe <==== ATTENTION Task: {1F63FBEE-448C-4F83-A6D6-5AA570C756DC} - System32\Tasks\VKZRD => C:\Users\Andrrzej Szachta\AppData\Roaming\VKZRD.exe <==== ATTENTION Task: {3F697E01-AE2E-4B86-942C-D17EF56DE102} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-19] (globalUpdate) <==== ATTENTION Task: {3F6A0027-37BA-4EDE-A124-00C37BBEF9E3} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-11 => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-11.exe <==== ATTENTION Task: {47C5618E-9D8F-47CF-B8C2-BDE9FE32BEAE} - System32\Tasks\ed97fe52-20d5-4263-a231-ccd5ca6f83aa => C:\Program Files (x86)\CinPlus-2.4cV19.11\ed97fe52-20d5-4263-a231-ccd5ca6f83aa.exe [2014-11-19] (CinPlusV19.11) <==== ATTENTION Task: {4FB4ED19-264E-468A-9FB6-A7ADC6F4BCC8} - System32\Tasks\575b099a-cfe6-44dd-a987-55f1a33b68ef => C:\Program Files (x86)\Browsers Apps\575b099a-cfe6-44dd-a987-55f1a33b68ef.exe [2014-08-01] () <==== ATTENTION Task: {88773724-3DF9-40B1-BCA8-21DB520F1B1E} - System32\Tasks\VeriBrowse Update => C:\Program Files (x86)\ver7VeriBrowse\o4VeriBrowseZ61.exe [2014-11-19] () Task: {90908FBB-36B1-4235-8C92-146BA47C7124} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-1 => C:\Program Files (x86)\CinPlus-2.4cV19.11\CinPlus-2.4cV19.11-codedownloader.exe <==== ATTENTION Task: {B43D73FC-46BE-4263-BC1C-7FA6B364EA60} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5 => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5.exe [2014-11-19] (CinPlusV19.11) <==== ATTENTION Task: {BA74CF78-A665-453F-9D4D-5381CEF57EC6} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-2 => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-2.exe <==== ATTENTION Task: {D4409097-46BC-47AE-8638-E96B60307B54} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-3 => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-3.exe <==== ATTENTION Task: {DC770B38-3935-46DA-87E5-85F189E275E4} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-4 => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-4.exe <==== ATTENTION Task: {EE1A02F6-26FF-423C-A1BF-41781250340C} - System32\Tasks\66cf2788-31d0-47a5-a3ef-f2c9d1c969c9 => C:\Program Files (x86)\CinPlus-2.4cV19.11\66cf2788-31d0-47a5-a3ef-f2c9d1c969c9.exe [2014-11-19] () <==== ATTENTION Task: {FAB83138-8B46-437B-B754-D5E1A7E43B8E} - System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-7 => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\575b099a-cfe6-44dd-a987-55f1a33b68ef.job => C:\Program Files (x86)\Browsers Apps\575b099a-cfe6-44dd-a987-55f1a33b68ef.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\66cf2788-31d0-47a5-a3ef-f2c9d1c969c9.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\66cf2788-31d0-47a5-a3ef-f2c9d1c969c9.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-1.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\CinPlus-2.4cV19.11-codedownloader.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-11.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-11.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-2.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-2.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-3.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-3.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-4.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-4.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5_user.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-6.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-6.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-7.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-7.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\ed97fe52-20d5-4263-a231-ccd5ca6f83aa.job => C:\Program Files (x86)\CinPlus-2.4cV19.11\ed97fe52-20d5-4263-a231-ccd5ca6f83aa.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\QEDYQJMM.job => C:\Users\Andrrzej Szachta\AppData\Roaming\QEDYQJMM.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\VeriBrowse Update.job => C:\Program Files (x86)\ver7VeriBrowse\o4VeriBrowseZ61.exe Task: C:\WINDOWS\Tasks\VKZRD.job => C:\Users\Andrrzej Szachta\AppData\Roaming\VKZRD.exe <==== ATTENTION AppInit_DLLs: C:\Users\Andrrzej Szachta\AppData\Local\Smartbar\Application\Resources\crdlil64.dll => C:\Users\Andrrzej Szachta\AppData\Local\Smartbar\Application\Resources\crdlil64.dll [71680 2014-11-22] () HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [mbot_de_241] => C:\Program Files (x86)\mbot_de_241\mbot_de_241.exe [3977672 2014-11-05] () HKLM-x32\...\RunOnce: [upmbot_de_241.exe] => C:\Users\Andrrzej Szachta\AppData\Local\mbot_de_241\upmbot_de_241.exe [3306952 2014-11-05] () HKU\S-1-5-21-2101704784-470427644-3715861599-1001\...\Run: [InetStat] => C:\Users\Andrrzej Szachta\AppData\Roaming\InetStat\inetstat.exe [702478 2014-11-19] () HKU\S-1-5-21-2101704784-470427644-3715861599-1001\...\Run: [UpdateChecker] => C:\Users\Andrrzej Szachta\AppData\Local\UpdateChecker\UpdateCheckerApp.exe [7168 2014-02-16] () HKU\S-1-5-21-2101704784-470427644-3715861599-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\Andrrzej Szachta\AppData\Local\Smartbar\Application\Smartbar.exe [28192 2014-11-02] (Smartbar) HKU\S-1-5-21-2101704784-470427644-3715861599-1001\...\MountPoints2: {56917986-158b-11e4-bef7-a4db30ca0d03} - "G:\PMCsetup.exe" HKLM\...\Policies\Explorer: [NoControlPanel] 0 ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC6Q,,&q={searchTerms} HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjLQX0SpfRh3s_mQjp5QaT-C1CFSs9fre-02XEbCBL8AulLBK2e_Kag8maWKT89MQ,, HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC6Q,,&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1403293951&from=cor&uid=ST500LT012-9WS142_W0VGPJVXXXXXW0VGPJVX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1403293951&from=cor&uid=ST500LT012-9WS142_W0VGPJVXXXXXW0VGPJVX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1403293951&from=cor&uid=ST500LT012-9WS142_W0VGPJVXXXXXW0VGPJVX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1403293951&from=cor&uid=ST500LT012-9WS142_W0VGPJVXXXXXW0VGPJVX&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC6Q,,&q={searchTerms} SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC6Q,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2101704784-470427644-3715861599-1001 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC6Q,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2101704784-470427644-3715861599-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC6Q,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2101704784-470427644-3715861599-1001 -> {0CEC4E0A-503A-4AB6-B4B1-182894B25AE9} URL = SearchScopes: HKU\S-1-5-21-2101704784-470427644-3715861599-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={EBECDCFC-7986-4870-8652-6E7B51532E23}&mid=0db57432152147d29d437592762ee4f0-cb48b6ebb80d916311c2809980b8dc0f23c45ae0&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-17 20:55:29&v=4.0.0.19&pid=wtu&sg=&sap=dsp&q={searchTerms} BHO: Browsers Apps -> {11111111-1111-1111-1111-110611171187} -> C:\Program Files (x86)\Browsers Apps\Browsers Apps-bho64.dll (app) BHO: CinPlus-2.4cV19.11 -> {11111111-1111-1111-1111-110611381131} -> C:\Program Files (x86)\CinPlus-2.4cV19.11\CinPlus-2.4cV19.11-bho64.dll (CinPlusV19.11) BHO: Shopping Helper SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) BHO: WordProser -> {3EBB5099-9732-48AE-B032-58B702D86EEC} -> C:\Program Files\WordProser_1.10.0.2\IE\WordProserClientIE.dll (Word Proser)\ BHO: VeriBrowse -> {9FA3BE38-6695-25BE-DC95-8E4C027593D9} -> C:\Program Files (x86)\ver7VeriBrowse\183_x64.dll () BHO: TrustedShopper -> {BBE09607-D9BF-4B2E-88C2-C8D5DF7A7D37} -> C:\Program Files (x86)\SqueakyChocolate\TrustedShopper\adxloader64.dll () BHO-x32: Browsers Apps -> {11111111-1111-1111-1111-110611171187} -> C:\Program Files (x86)\Browsers Apps\Browsers Apps-bho.dll No File BHO-x32: CinPlus-2.4cV19.11 -> {11111111-1111-1111-1111-110611381131} -> C:\Program Files (x86)\CinPlus-2.4cV19.11\CinPlus-2.4cV19.11-bho.dll (CinPlusV19.11) BHO-x32: Shopping Helper SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\WINDOWS\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: WordProser -> {3EBB5099-9732-48AE-B032-58B702D86EEC} -> C:\Program Files (x86)\WordProser_1.10.0.2\IE\WordProserClientIE.dll (Word Proser) BHO-x32: VeriBrowse -> {9FA3BE38-6695-25BE-DC95-8E4C027593D9} -> C:\Program Files (x86)\ver7VeriBrowse\183.dll () BHO-x32: TrustedShopper -> {BBE09607-D9BF-4B2E-88C2-C8D5DF7A7D37} -> C:\Program Files (x86)\SqueakyChocolate\TrustedShopper\adxloader.dll () Toolbar: HKLM - Shopping Helper Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Shopping Helper Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\WINDOWS\SysWOW64\mscoree.dll (Microsoft Corporation) CHR HKLM-x32\...\Chrome\Extension: [fdjkhamgopgokjmllcmpkiijndjeidcl] - C:\Users\Andrrzej Szachta\AppData\Local\Temp\twsfiles\trustedshopper.crx [2014-02-25] C:\browserhelper.log C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\mozilla firefox C:\Program Files (x86)\Temp C:\ProgramData\374311380 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY C:\Users\Andrrzej Szachta\AppData\Local\globalUpdate C:\Users\Andrrzej Szachta\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Andrrzej Szachta\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\Andrrzej Szachta\AppData\Roaming\*.exe C:\Users\Andrrzej Szachta\AppData\Roaming\Mozilla C:\Users\Andrrzej Szachta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat C:\Users\Andrrzej Szachta\AppData\Roaming\sweet-page C:\Users\Andrrzej Szachta\AppData\Roaming\Systweak C:\Users\Andrrzej Szachta\Documents\Optimizer Pro C:\Users\Andrrzej Szachta\Downloads\ReimageRepair.exe C:\Users\Andrrzej Szachta\Downloads\setup.exe C:\Windows\patsearch.bin C:\Windows\system32\Drivers\webinstrT.sys C:\Windows\System32\drivers\wpnfd_1_10_0_2.sys Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v AutoConfigURL /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchUrl" /f CMD: sc config vToolbarUpdater18.1.10 start= disabled EmptyTemp: ***************** Processes closed successfully. globalUpdate => Service deleted successfully. globalUpdatem => Service deleted successfully. LPTSystemUpdater => Service deleted successfully. wpsvc_1.10.0.2 => Service deleted successfully. webinstrT => Service deleted successfully. wpnfd_1_10_0_2 => Unable to stop service wpnfd_1_10_0_2 => Service deleted successfully. huawei_enumerator => Service deleted successfully. IntcAzAudAddService => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{05D5EC86-434F-4139-880E-A4488A411024}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05D5EC86-434F-4139-880E-A4488A411024}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5_user => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5_user" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1197016B-46D6-4843-BF61-913A7D0D69B5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1197016B-46D6-4843-BF61-913A7D0D69B5}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-6 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-6" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1E310176-BCB1-4557-9985-B6BEA43B2E82}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E310176-BCB1-4557-9985-B6BEA43B2E82}" => Key deleted successfully. C:\Windows\System32\Tasks\QEDYQJMM => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QEDYQJMM" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1F63FBEE-448C-4F83-A6D6-5AA570C756DC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F63FBEE-448C-4F83-A6D6-5AA570C756DC}" => Key deleted successfully. C:\Windows\System32\Tasks\VKZRD => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\VKZRD" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3F697E01-AE2E-4B86-942C-D17EF56DE102}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F697E01-AE2E-4B86-942C-D17EF56DE102}" => Key deleted successfully. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3F6A0027-37BA-4EDE-A124-00C37BBEF9E3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F6A0027-37BA-4EDE-A124-00C37BBEF9E3}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-11 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-11" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{47C5618E-9D8F-47CF-B8C2-BDE9FE32BEAE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47C5618E-9D8F-47CF-B8C2-BDE9FE32BEAE}" => Key deleted successfully. C:\Windows\System32\Tasks\ed97fe52-20d5-4263-a231-ccd5ca6f83aa => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ed97fe52-20d5-4263-a231-ccd5ca6f83aa" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4FB4ED19-264E-468A-9FB6-A7ADC6F4BCC8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4FB4ED19-264E-468A-9FB6-A7ADC6F4BCC8}" => Key deleted successfully. C:\Windows\System32\Tasks\575b099a-cfe6-44dd-a987-55f1a33b68ef => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\575b099a-cfe6-44dd-a987-55f1a33b68ef" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{88773724-3DF9-40B1-BCA8-21DB520F1B1E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88773724-3DF9-40B1-BCA8-21DB520F1B1E}" => Key deleted successfully. C:\Windows\System32\Tasks\VeriBrowse Update => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\VeriBrowse Update" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{90908FBB-36B1-4235-8C92-146BA47C7124}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90908FBB-36B1-4235-8C92-146BA47C7124}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B43D73FC-46BE-4263-BC1C-7FA6B364EA60}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B43D73FC-46BE-4263-BC1C-7FA6B364EA60}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BA74CF78-A665-453F-9D4D-5381CEF57EC6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA74CF78-A665-453F-9D4D-5381CEF57EC6}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D4409097-46BC-47AE-8638-E96B60307B54}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4409097-46BC-47AE-8638-E96B60307B54}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-3 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DC770B38-3935-46DA-87E5-85F189E275E4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC770B38-3935-46DA-87E5-85F189E275E4}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-4 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-4" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EE1A02F6-26FF-423C-A1BF-41781250340C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EE1A02F6-26FF-423C-A1BF-41781250340C}" => Key deleted successfully. C:\Windows\System32\Tasks\66cf2788-31d0-47a5-a3ef-f2c9d1c969c9 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\66cf2788-31d0-47a5-a3ef-f2c9d1c969c9" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FAB83138-8B46-437B-B754-D5E1A7E43B8E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FAB83138-8B46-437B-B754-D5E1A7E43B8E}" => Key deleted successfully. C:\Windows\System32\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-7 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-7" => Key deleted successfully. C:\WINDOWS\Tasks\575b099a-cfe6-44dd-a987-55f1a33b68ef.job => Moved successfully. C:\WINDOWS\Tasks\66cf2788-31d0-47a5-a3ef-f2c9d1c969c9.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-1.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-11.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-2.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-3.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-4.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-5_user.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-6.job => Moved successfully. C:\WINDOWS\Tasks\a438dbb6-0d37-422e-8e57-4e522a5ddd7b-7.job => Moved successfully. C:\WINDOWS\Tasks\ed97fe52-20d5-4263-a231-ccd5ca6f83aa.job => Moved successfully. C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully. C:\WINDOWS\Tasks\QEDYQJMM.job => Moved successfully. C:\WINDOWS\Tasks\VeriBrowse Update.job => Moved successfully. C:\WINDOWS\Tasks\VKZRD.job => Moved successfully. "C:\Users\Andrrzej Szachta\AppData\Local\Smartbar\Application\Resources\crdlil64.dll" => Value Data removed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mbot_de_241 => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upmbot_de_241.exe => value deleted successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Windows\CurrentVersion\Run\\InetStat => value deleted successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Windows\CurrentVersion\Run\\UpdateChecker => value deleted successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Browser Infrastructure Helper => value deleted successfully. "HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56917986-158b-11e4-bef7-a4db30ca0d03}" => Key deleted successfully. "HKCR\CLSID\{56917986-158b-11e4-bef7-a4db30ca0d03}" => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. "HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key not found. "HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully. "HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found. "HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0CEC4E0A-503A-4AB6-B4B1-182894B25AE9}" => Key deleted successfully. "HKCR\CLSID\{0CEC4E0A-503A-4AB6-B4B1-182894B25AE9}" => Key not found. "HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171187}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110611171187}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611381131}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110611381131}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key deleted successfully. "HKCR\CLSID\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EBB5099-9732-48AE-B032-58B702D86EEC}" => Key deleted successfully. "HKCR\CLSID\{3EBB5099-9732-48AE-B032-58B702D86EEC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FA3BE38-6695-25BE-DC95-8E4C027593D9}" => Key deleted successfully. "HKCR\CLSID\{9FA3BE38-6695-25BE-DC95-8E4C027593D9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBE09607-D9BF-4B2E-88C2-C8D5DF7A7D37}" => Key deleted successfully. "HKCR\CLSID\{BBE09607-D9BF-4B2E-88C2-C8D5DF7A7D37}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171187}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611171187}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611381131}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611381131}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EBB5099-9732-48AE-B032-58B702D86EEC}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{3EBB5099-9732-48AE-B032-58B702D86EEC}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FA3BE38-6695-25BE-DC95-8E4C027593D9}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{9FA3BE38-6695-25BE-DC95-8E4C027593D9}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBE09607-D9BF-4B2E-88C2-C8D5DF7A7D37}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{BBE09607-D9BF-4B2E-88C2-C8D5DF7A7D37}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value deleted successfully. "HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fdjkhamgopgokjmllcmpkiijndjeidcl" => Key deleted successfully. C:\Users\Andrrzej Szachta\AppData\Local\Temp\twsfiles\trustedshopper.crx => Moved successfully. C:\browserhelper.log => Moved successfully. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Program Files (x86)\mozilla firefox => Moved successfully. C:\Program Files (x86)\Temp => Moved successfully. C:\ProgramData\374311380 => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Local\globalUpdate => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. "C:\Users\Andrrzej Szachta\AppData\Roaming\*.exe" => File/Directory not found. C:\Users\Andrrzej Szachta\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Roaming\sweet-page => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Roaming\Systweak => Moved successfully. C:\Users\Andrrzej Szachta\Documents\Optimizer Pro => Moved successfully. C:\Users\Andrrzej Szachta\Downloads\ReimageRepair.exe => Moved successfully. C:\Users\Andrrzej Szachta\Downloads\setup.exe => Moved successfully. C:\Windows\patsearch.bin => Moved successfully. C:\Windows\system32\Drivers\webinstrT.sys => Moved successfully. C:\Windows\System32\drivers\wpnfd_1_10_0_2.sys => Moved successfully. ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v AutoConfigURL /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config vToolbarUpdater18.1.10 start= disabled ========= [SC] ChangeServiceConfig SUCCESS ========= End of CMD: ========= EmptyTemp: => Removed 2.2 GB temporary data. The system needed a reboot. ==== End of Fixlog ====