Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-01-2015 Ran by Niiesmiertelny at 2015-01-10 19:46:52 Run:2 Running from D:\Programy\Kasowanie blednych lokow wirusówOTL FRST Loaded Profile: Niiesmiertelny (Available profiles: Niiesmiertelny) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: (Microsoft Corporation) C:\Windows\explorer.exe CreateRestorePoint: R2 SPBIUpd; C:\Program Files\Common Files\ShopperPro\spbiu.exe [2346880 2015-01-06] (ShopperPro) S2 AddonsHelper; C:\Users\Niiesmiertelny\AppData\Local\Temp\OCS\Downloads\9f8cc62c3640bf6eb115b4c78bb22a3f\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [X] R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [41856 2015-01-06] () R2 SPDRIVER_1463.0.0.0; C:\Program Files (x86)\ShopperPro\JSDriver\1463.0.0.0\jsdrv.sys [52584 2015-01-06] () S1 iSafeKrnlMon; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [X] HKLM-x32\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1463.0.0.0\jsdrv.exe [3224576 2015-01-06] () HKU\S-1-5-21-2955672183-3658250396-1376213474-1001\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1463.0.0.0\jsdrv.exe [3224576 2015-01-06] () Task: {01226C22-118D-4991-82B8-88293021E608} - System32\Tasks\{54E296FB-613E-4618-B122-53F0764825C7} => pcalua.exe -a I:\Directx\dxsetup.exe -d I:\ Task: {1C15D103-49C6-4B1A-8A2A-AAE46BE2CB8A} - System32\Tasks\{05ACB4DD-3A09-4323-BA75-C25309A03039} => pcalua.exe -a H:\setup-top_netinfo.exe -d H:\ Task: {22783CC4-3E00-4B6D-91D9-B7A452209111} - System32\Tasks\{11C605A1-1E66-4337-AC84-02DD051600C0} => pcalua.exe -a "C:\Program Files (x86)\Mobile Partner\Driver\DriverSetup.exe" -d "C:\Program Files (x86)\Mobile Partner\Driver" Task: {2A0039D4-9DC9-4D6A-B170-2BD366B61A5A} - System32\Tasks\Installer_sense => C:\Users\Niiesmiertelny\AppData\Local\Installer\Installsense_7912\ins_postInst.exe [2015-01-08] () <==== ATTENTION Task: {3815A207-5866-4C99-A3A8-8201D6239239} - System32\Tasks\{7062D436-B5D5-49D6-BFE9-24831605484E} => pcalua.exe -a C:\Users\Niiesmiertelny\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor Task: {442C58A0-A590-48AA-9BEF-D372A446C40A} - System32\Tasks\{0E437703-A890-4DF1-9FB5-FD6D9FB82329} => Firefox.exe http://ui.skype.com/ui/0/7.0.59.100/pl/abandoninstall?page=tsMain Task: {54BCFE45-2E7C-41CA-A603-A140C6B9FB1A} - System32\Tasks\{8995D2B1-DC7B-4543-BEF8-8AFD0586814D} => Firefox.exe http://ui.skype.com/ui/0/6.18.0.106/pl/abandoninstall?source=lightinstaller&page=tsInstall Task: {5B147C41-A47A-4D66-8832-9612BD6F45C1} - System32\Tasks\Trojan Killer => C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe Task: {6E10A0A2-8E06-4E03-8198-5DEEB1D6BF1A} - System32\Tasks\{376FB0AB-6D50-49C1-ADCF-FB1452970C2F} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe" Task: {753BFED2-9242-4213-B150-288A92E06516} - System32\Tasks\ShopperProJSUpd => C:\Program Files (x86)\ShopperPro\updater.exe [2015-01-06] (Goobzo) <==== ATTENTION Task: {925718C6-0B5C-415D-8667-A44BCB01DE66} - System32\Tasks\{0027B74B-AEA6-4A3E-821C-A284620D0F12} => pcalua.exe -a C:\Users\Niiesmiertelny\Downloads\VGA_nVidia_WIN7_32_815118619\setup.exe -d C:\Users\Niiesmiertelny\Downloads\VGA_nVidia_WIN7_32_815118619 Task: {932D7CE4-C936-4937-B8C0-5D22DDFAF9B2} - System32\Tasks\{366E04DE-6923-46B0-A1BF-365621BE6D02} => pcalua.exe -a G:\InstellBluetooth.exe -d G:\ Task: {9C4CA337-254B-4FA0-84AD-5A2A707CAC5D} - System32\Tasks\SPBIW_UpdateTask_Time_313732363537393832392d3437415a556c2a3223346c41 => Wscript.exe //B "C:\ProgramData\ShopperPro\spbihe.js" spbiu.exe /invoke /f:check_services /l:0 <==== ATTENTION Task: {C51A485C-2A49-4FB3-BB2C-697CDF4C7796} - System32\Tasks\Installer_iwebar => C:\Users\Niiesmiertelny\AppData\Local\Installer\Installiwebar_12661\ins_postInst.exe [2015-01-08] () <==== ATTENTION Task: {CCC2C849-CE8F-4463-B3F8-E4957ABF7285} - System32\Tasks\ShopperPro => C:\Program Files (x86)\ShopperPro\ShopperPro.exe [2015-01-06] (Goobzo LTD) <==== ATTENTION Task: {D090263A-23D6-4FA2-803C-561EC19A3C1C} - System32\Tasks\{BB30B820-0605-4C2A-BC2B-31692E3AA327} => pcalua.exe -a "H:\need for speed most wanted\NFSMW\eauninstall.exe" -d "H:\need for speed most wanted\NFSMW" Task: {EB983D28-8B18-492B-9278-E871994F6FAC} - System32\Tasks\SPDriver => C:\Program Files (x86)\ShopperPro\JSDriver\1463.0.0.0\jsdrv.exe [2015-01-06] () <==== ATTENTION Task: {F16D1B45-0916-4E9D-B3C8-AB1AC3D895C4} - System32\Tasks\{AAC21D45-3A43-4F18-908D-7FCA635EDA6B} => pcalua.exe -a C:\Users\Niiesmiertelny\Downloads\BluetoothDriverInstaller.exe -d C:\Users\Niiesmiertelny\Downloads HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1417797528&from=cor&uid=3219913727_67194_FC9C0241&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1417797528&from=cor&uid=3219913727_67194_FC9C0241&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1417797528&from=cor&uid=3219913727_67194_FC9C0241&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1417797528&from=cor&uid=3219913727_67194_FC9C0241&q={searchTerms} SearchScopes: HKLM-x32 -> {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = http://www.firetab.org/?type=ds3se&p={searchTerms} SearchScopes: HKU\S-1-5-21-2955672183-3658250396-1376213474-1001 -> DefaultScope {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = http://www.firetab.org/?type=ds3se&p={searchTerms} SearchScopes: HKU\S-1-5-21-2955672183-3658250396-1376213474-1001 -> {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = http://www.firetab.org/?type=ds3se&p={searchTerms} BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro64.dll (Goobzo Ltd.) BHO-x32: No Name -> {9B6B03F1-16CF-4491-BBBB-E872802DD717} -> No File BHO-x32: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File FF HKLM-x32\...\Firefox\Extensions: [dnshelp@dnshelp.com] - C:\Users\Niiesmiertelny\AppData\Roaming\Helper C:\Program Files (x86)\MiPony C:\ProgramData\DNSErrorHelper C:\ProgramData\TEMP C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppsHat C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Cleaner 3 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Password C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Techland C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winmail Opener C:\Users\Niiesmiertelny\AppData\Local\Installer C:\Users\Niiesmiertelny\AppData\Roaming\*.exe C:\Users\Niiesmiertelny\AppData\Roaming\DigitalSite C:\Users\Niiesmiertelny\AppData\Roaming\Gameo C:\Users\Niiesmiertelny\AppData\Roaming\GoforFiles C:\Users\Niiesmiertelny\AppData\Roaming\GoldenGate C:\Users\Niiesmiertelny\AppData\Roaming\Helper C:\Users\Niiesmiertelny\AppData\Roaming\Mipony C:\Users\Niiesmiertelny\AppData\Roaming\NCdownloader C:\Users\Niiesmiertelny\AppData\Roaming\NetMeter C:\Users\Niiesmiertelny\AppData\Roaming\OpenCandy C:\Users\Niiesmiertelny\AppData\Roaming\Opera Software C:\Users\Niiesmiertelny\AppData\Roaming\SmartBluetoothMarketing C:\Users\Niiesmiertelny\AppData\Roaming\WebTest C:\Users\Niiesmiertelny\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\PeÅ‚ne czyszczenie Å›mieci.lnk C:\Users\Niiesmiertelny\Downloads\yet_another_cleaner_sk_15627.exe C:\Users\Niiesmiertelny\Downloads\Real_Alternative_202_Lite.exe C:\Users\Public\Documents\ShopperPro C:\Windows\system32\log Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\Users\Niiesmiertelny\AppData\Local CMD: dir /a C:\Users\Niiesmiertelny\AppData\LocalLow ***************** Processes closed successfully. [1464] C:\Windows\explorer.exe => Process closed successfully. Restore point was successfully created. SPBIUpd => Service deleted successfully. AddonsHelper => Service deleted successfully. SPBIUpdd => Service stopped successfully. SPBIUpdd => Service deleted successfully. SPDRIVER_1463.0.0.0 => Service stopped successfully. SPDRIVER_1463.0.0.0 => Service deleted successfully. iSafeKrnlMon => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SPDriver => value deleted successfully. HKU\S-1-5-21-2955672183-3658250396-1376213474-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{01226C22-118D-4991-82B8-88293021E608}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01226C22-118D-4991-82B8-88293021E608}" => Key deleted successfully. C:\Windows\System32\Tasks\{54E296FB-613E-4618-B122-53F0764825C7} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{54E296FB-613E-4618-B122-53F0764825C7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1C15D103-49C6-4B1A-8A2A-AAE46BE2CB8A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1C15D103-49C6-4B1A-8A2A-AAE46BE2CB8A}" => Key deleted successfully. C:\Windows\System32\Tasks\{05ACB4DD-3A09-4323-BA75-C25309A03039} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{05ACB4DD-3A09-4323-BA75-C25309A03039}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{22783CC4-3E00-4B6D-91D9-B7A452209111}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{22783CC4-3E00-4B6D-91D9-B7A452209111}" => Key deleted successfully. C:\Windows\System32\Tasks\{11C605A1-1E66-4337-AC84-02DD051600C0} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{11C605A1-1E66-4337-AC84-02DD051600C0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A0039D4-9DC9-4D6A-B170-2BD366B61A5A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A0039D4-9DC9-4D6A-B170-2BD366B61A5A}" => Key deleted successfully. C:\Windows\System32\Tasks\Installer_sense => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_sense" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3815A207-5866-4C99-A3A8-8201D6239239}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3815A207-5866-4C99-A3A8-8201D6239239}" => Key deleted successfully. C:\Windows\System32\Tasks\{7062D436-B5D5-49D6-BFE9-24831605484E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7062D436-B5D5-49D6-BFE9-24831605484E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{442C58A0-A590-48AA-9BEF-D372A446C40A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{442C58A0-A590-48AA-9BEF-D372A446C40A}" => Key deleted successfully. C:\Windows\System32\Tasks\{0E437703-A890-4DF1-9FB5-FD6D9FB82329} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0E437703-A890-4DF1-9FB5-FD6D9FB82329}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{54BCFE45-2E7C-41CA-A603-A140C6B9FB1A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{54BCFE45-2E7C-41CA-A603-A140C6B9FB1A}" => Key deleted successfully. C:\Windows\System32\Tasks\{8995D2B1-DC7B-4543-BEF8-8AFD0586814D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8995D2B1-DC7B-4543-BEF8-8AFD0586814D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B147C41-A47A-4D66-8832-9612BD6F45C1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B147C41-A47A-4D66-8832-9612BD6F45C1}" => Key deleted successfully. C:\Windows\System32\Tasks\Trojan Killer => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Trojan Killer" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6E10A0A2-8E06-4E03-8198-5DEEB1D6BF1A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E10A0A2-8E06-4E03-8198-5DEEB1D6BF1A}" => Key deleted successfully. C:\Windows\System32\Tasks\{376FB0AB-6D50-49C1-ADCF-FB1452970C2F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{376FB0AB-6D50-49C1-ADCF-FB1452970C2F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{753BFED2-9242-4213-B150-288A92E06516}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{753BFED2-9242-4213-B150-288A92E06516}" => Key deleted successfully. C:\Windows\System32\Tasks\ShopperProJSUpd => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{925718C6-0B5C-415D-8667-A44BCB01DE66}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{925718C6-0B5C-415D-8667-A44BCB01DE66}" => Key deleted successfully. C:\Windows\System32\Tasks\{0027B74B-AEA6-4A3E-821C-A284620D0F12} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0027B74B-AEA6-4A3E-821C-A284620D0F12}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{932D7CE4-C936-4937-B8C0-5D22DDFAF9B2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{932D7CE4-C936-4937-B8C0-5D22DDFAF9B2}" => Key deleted successfully. C:\Windows\System32\Tasks\{366E04DE-6923-46B0-A1BF-365621BE6D02} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{366E04DE-6923-46B0-A1BF-365621BE6D02}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9C4CA337-254B-4FA0-84AD-5A2A707CAC5D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C4CA337-254B-4FA0-84AD-5A2A707CAC5D}" => Key deleted successfully. C:\Windows\System32\Tasks\SPBIW_UpdateTask_Time_313732363537393832392d3437415a556c2a3223346c41 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_313732363537393832392d3437415a556c2a3223346c41" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C51A485C-2A49-4FB3-BB2C-697CDF4C7796}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C51A485C-2A49-4FB3-BB2C-697CDF4C7796}" => Key deleted successfully. C:\Windows\System32\Tasks\Installer_iwebar => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_iwebar" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CCC2C849-CE8F-4463-B3F8-E4957ABF7285}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCC2C849-CE8F-4463-B3F8-E4957ABF7285}" => Key deleted successfully. C:\Windows\System32\Tasks\ShopperPro => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D090263A-23D6-4FA2-803C-561EC19A3C1C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D090263A-23D6-4FA2-803C-561EC19A3C1C}" => Key deleted successfully. C:\Windows\System32\Tasks\{BB30B820-0605-4C2A-BC2B-31692E3AA327} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BB30B820-0605-4C2A-BC2B-31692E3AA327}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EB983D28-8B18-492B-9278-E871994F6FAC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB983D28-8B18-492B-9278-E871994F6FAC}" => Key deleted successfully. C:\Windows\System32\Tasks\SPDriver => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F16D1B45-0916-4E9D-B3C8-AB1AC3D895C4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F16D1B45-0916-4E9D-B3C8-AB1AC3D895C4}" => Key deleted successfully. C:\Windows\System32\Tasks\{AAC21D45-3A43-4F18-908D-7FCA635EDA6B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AAC21D45-3A43-4F18-908D-7FCA635EDA6B}" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{721061fb-eb79-4568-a03c-3ce26d68dae9}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{721061fb-eb79-4568-a03c-3ce26d68dae9} => Key not found. HKU\S-1-5-21-2955672183-3658250396-1376213474-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-2955672183-3658250396-1376213474-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{721061fb-eb79-4568-a03c-3ce26d68dae9}" => Key deleted successfully. HKCR\CLSID\{721061fb-eb79-4568-a03c-3ce26d68dae9} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}" => Key deleted successfully. "HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9B6B03F1-16CF-4491-BBBB-E872802DD717} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\dnshelp@dnshelp.com => value deleted successfully. C:\Program Files (x86)\MiPony => Moved successfully. C:\ProgramData\DNSErrorHelper => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppsHat => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Cleaner 3 => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Password => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Techland => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winmail Opener => Moved successfully. C:\Users\Niiesmiertelny\AppData\Local\Installer => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\*.exe => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\DigitalSite => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\Gameo => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\GoforFiles => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\GoldenGate => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\Helper => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\Mipony => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\NCdownloader => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\NetMeter => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\Opera Software => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\SmartBluetoothMarketing => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\WebTest => Moved successfully. C:\Users\Niiesmiertelny\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\PeÅ‚ne czyszczenie Å›mieci.lnk => Moved successfully. C:\Users\Niiesmiertelny\Downloads\yet_another_cleaner_sk_15627.exe => Moved successfully. C:\Users\Niiesmiertelny\Downloads\Real_Alternative_202_Lite.exe => Moved successfully. C:\Users\Public\Documents\ShopperPro => Moved successfully. C:\Windows\system32\log => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: FC9C-0241 Katalog: C:\Program Files 2014-12-08 12:40 . 2014-12-08 12:40 .. 2012-12-16 17:53 AVAST Software 2014-02-18 13:52 CCleaner 2015-01-08 20:03 Common Files 2013-05-20 20:52 Core Temp 2013-01-17 21:09 CPUID 2009-07-14 05:54 174 desktop.ini 2012-11-11 13:44 DIFX 2013-03-20 10:25 DVD Maker 2014-04-05 17:10 Enigma Software Group 2013-10-12 19:47 HP 2014-12-10 10:34 Internet Explorer 2014-02-28 18:14 Java 2009-07-14 19:09 Microsoft Games 2013-05-02 20:50 Microsoft Office 2009-07-14 06:32 MSBuild 2014-02-19 14:41 NVIDIA Corporation 2009-07-14 06:32 Reference Assemblies 2015-01-10 19:36 SUPERAntiSpyware 2009-07-14 06:09 Uninstall Information 2013-07-12 17:48 Windows Defender 2014-07-31 15:21 Windows Journal 2013-03-20 10:25 Windows Mail 2013-12-12 15:10 Windows Media Player 2012-09-25 18:44 Windows NT 2013-03-20 10:25 Windows Photo Viewer 2013-03-20 10:25 Windows Portable Devices 2013-03-20 10:25 Windows Sidebar 2012-12-13 15:25 WinRAR 1 plik(¢w) 174 bajt¢w 29 katalog(¢w) 12ÿ108ÿ464ÿ128 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: FC9C-0241 Katalog: C:\Program Files (x86) 2015-01-10 19:47 . 2015-01-10 19:47 .. 2014-03-19 18:46 AbiWord 2012-11-05 19:22 Adobe 2014-01-09 20:54 AGEIA Technologies 2014-03-31 20:15 Ahead 2014-03-31 20:41 Alcohol Soft 2012-11-14 17:31 ALLMediaServer 2012-11-14 17:30 ALLPlayer 2013-01-17 08:54 BitTorrent 2014-03-02 13:55 Bridge Building Game 2013-02-25 18:54 BrowseToSave 2014-03-04 17:49 Cheat Engine 6.3 2014-09-22 17:28 Common Files 2013-01-12 09:24 DAEMON Tools Lite 2009-07-14 05:54 174 desktop.ini 2012-09-25 20:20 Formatowanie Dysk¢w 2013-03-06 21:15 Frappsy 2012-11-13 18:35 GoforFiles 2014-03-03 18:13 Halycon Media 2013-10-12 19:49 HP 2013-10-12 19:50 HP Photo Creations 2014-07-20 13:37 InstallShield Installation Information 2012-12-23 14:50 INTERIAPL 2014-12-10 10:34 Internet Explorer 2014-06-09 18:34 Java 2012-12-10 20:44 Logitech 2014-02-28 18:37 Microsoft 2013-05-02 20:53 Microsoft Office 2013-02-26 09:53 Microsoft Silverlight 2013-05-02 20:53 Microsoft Visual Studio 2013-05-02 20:50 Microsoft Visual Studio 8 2013-05-02 20:53 Microsoft Works 2013-05-02 20:52 Microsoft.NET 2014-02-18 19:06 Mobile Partner 2014-12-09 18:23 Mozilla Firefox 2014-12-09 22:05 Mozilla Maintenance Service 2012-12-17 15:43 Mplayer 2013-05-02 20:53 MSBuild 2014-04-02 12:16 MSXML 4.0 2012-11-30 15:05 NetMeter 2014-02-19 14:41 NVIDIA Corporation 2014-12-05 17:50 Opera 2013-02-26 09:52 pazera-software 2013-02-26 09:24 QuickTime 2009-07-14 06:32 Reference Assemblies 2015-01-08 20:03 ShopperPro 2014-09-22 17:28 Skype 2014-03-28 10:42 Surftastic 2013-09-23 20:26 SweetIM 2012-11-11 13:14 SweetPacks 2013-02-26 09:24 TechSmith 2014-11-01 13:43 top_netinfo 2009-07-14 05:57 Uninstall Information 2012-11-18 14:51 VideoLAN 2012-09-25 20:22 Winamp 2013-07-12 17:48 Windows Defender 2013-03-20 10:26 Windows Mail 2013-12-12 15:10 Windows Media Player 2013-03-07 21:03 Windows Movie Maker 2009-07-14 06:32 Windows NT 2013-03-20 10:26 Windows Photo Viewer 2013-03-20 10:26 Windows Portable Devices 2013-03-20 10:26 Windows Sidebar 1 plik(¢w) 174 bajt¢w 63 katalog(¢w) 12ÿ108ÿ464ÿ128 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Niiesmiertelny\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: FC9C-0241 Katalog: C:\Users\Niiesmiertelny\AppData\Local 2015-01-10 19:47 . 2015-01-10 19:47 .. 2014-01-09 20:54 Adobe 2012-11-14 17:31 ALLMediaServer 2015-01-01 19:17 ALLPlayer 2012-11-22 16:59 Apps 2012-12-13 18:38 Ares 2014-03-05 17:19 BridgeProject 2014-12-05 18:45 CrashRpt 2012-09-25 18:45 Dane aplikacji [C:\Users\Niiesmiertelny\AppData\Local] 2013-03-07 21:10 6ÿ144 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-11-22 16:59 Deployment 2014-10-23 14:01 Diagnostics 2013-05-20 20:56 Downloaded Installations 2013-08-02 19:02 ElevatedDiagnostics 2014-12-01 16:22 EmieBrowserModeList 2014-04-26 12:43 EmieSiteList 2014-04-26 12:43 EmieUserList 2014-03-03 19:52 Facebook 2013-05-24 09:01 Frappsy 2014-12-05 18:42 Gameo 2013-05-03 09:45 109ÿ296 GDIPFONTCACHEV1.DAT 2014-12-07 13:47 GG 2012-09-25 18:45 Historia [C:\Users\Niiesmiertelny\AppData\Local\Microsoft\Windows\History] 2013-10-12 20:02 HP 2015-01-09 23:04 4ÿ194ÿ226 IconCache.db 2012-12-10 20:44 LogiShrd 2012-12-09 18:09 LogitechR Webcam Software 2012-09-29 18:03 Macromedia 2014-02-07 20:07 Microsoft 2013-01-06 17:07 Microsoft Games 2014-09-25 04:33 Microsoft Help 2013-09-16 02:22 Mozilla 2014-02-19 14:43 NVIDIA 2014-02-19 14:42 NVIDIA Corporation 2014-11-02 11:33 OpenFM 2014-03-19 18:49 Opera Software 2012-11-14 17:29 Programs 2012-12-31 17:14 7ÿ611 Resmon.ResmonCfg 2013-04-29 19:58 Screamer Radio 2014-08-10 09:46 Skype 2013-02-26 09:26 TechSmith 2015-01-10 19:47 Temp 2012-09-25 18:45 Temporary Internet Files [C:\Users\Niiesmiertelny\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2013-11-29 17:26 Unity 2013-10-12 20:02 VirtualStore 2013-03-07 21:04 WMTools Downloaded Files 2013-05-24 09:01 YouTubeDownloader 4 plik(¢w) 4ÿ317ÿ277 bajt¢w 44 katalog(¢w) 12ÿ108ÿ464ÿ128 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Niiesmiertelny\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: FC9C-0241 Katalog: C:\Users\Niiesmiertelny\AppData\LocalLow 2015-01-05 18:22 . 2015-01-05 18:22 .. 2012-11-05 19:25 Adobe 2013-02-26 09:54 Microsoft 2013-09-23 19:10 8ÿ220 SkwConfig.bin 2012-09-27 18:36 Sun 2013-04-29 20:11 Temp 2014-12-06 09:31 Unity 1 plik(¢w) 8ÿ220 bajt¢w 7 katalog(¢w) 12ÿ108ÿ464ÿ128 bajt¢w wolnych ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog 19:47:29 ====