Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-02-2015 Ran by Rostov at 2015-02-04 20:21:07 Run:2 Running from C:\Users\Rostov\Desktop Loaded Profiles: Rostov (Available profiles: Rostov) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: S3 SPPD; \??\C:\windows\system32\drivers\SPPD.sys [X] HKU\S-1-5-21-764258043-3443933537-1065429426-1000\...\Run: [Facebook Update] => "C:\Users\Rostov\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = SearchScopes: HKU\S-1-5-21-764258043-3443933537-1065429426-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3325388&octid=EB_ORIGINAL_CTID&ISID=M7FDA8802-98D3-41A4-B33B-9DBF990F201A&SearchSource=58&CUI=&UM=6&UP=SP428CE062-120E-47F3-8525-370DA23AB577&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-764258043-3443933537-1065429426-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3325388&octid=EB_ORIGINAL_CTID&ISID=M7FDA8802-98D3-41A4-B33B-9DBF990F201A&SearchSource=58&CUI=&UM=6&UP=SP428CE062-120E-47F3-8525-370DA23AB577&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-764258043-3443933537-1065429426-1000 -> {AFA8A8ED-F0BE-4D84-B080-916ECBFD8C20} URL = http://www.idg.pl?q={searchTerms} FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3325388&octid=EB_ORIGINAL_CTID&ISID=M7FDA8802-98D3-41A4-B33B-9DBF990F201A&SearchSource=69&CUI=&SSPV=&Lay=1&UM=6&UP=SP428CE062-120E-47F3-8525-370DA23AB577 FF DefaultSearchUrl: FF SearchEngineOrder.1: FF Plugin HKU\S-1-5-21-764258043-3443933537-1065429426-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Rostov\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin HKU\S-1-5-21-764258043-3443933537-1065429426-1000: eagleget.com/EagleGet -> C:\Program Files (x86)\EagleGet\npEagleget.dll No File FF Plugin HKU\S-1-5-21-764258043-3443933537-1065429426-1000: egtcps.com/captures -> C:\Program Files (x86)\EagleGet\captures.dll No File FF user.js: detected! => C:\Users\Rostov\AppData\Roaming\Mozilla\Firefox\Profiles\5mfjbeoz.default\user.js C:\Program Files (x86)\mozilla firefox\plugins CHR HKU\S-1-5-21-764258043-3443933537-1065429426-1000\...\Chrome\Extension: [jfhffdajidfgpobcfdgilfcgbngginod] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [Not Found] CHR HKU\S-1-5-21-764258043-3443933537-1065429426-1000\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [Not Found] CHR HKLM-x32\...\Chrome\Extension: [jfhffdajidfgpobcfdgilfcgbngginod] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [Not Found] CustomCLSID: HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Rostov\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Rostov\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Rostov\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Rostov\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Rostov\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File Task: {237097CD-4CC6-46E6-8541-588C09B24F20} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-25] (Google Inc.) Task: {386AF916-24B8-4C92-9DA4-3FFC4CCFBAF7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-25] (Google Inc.) Task: {3FEB9356-EBF5-4043-B266-1C8E661803FE} - System32\Tasks\{3A4C5CFB-CFBF-49C7-938F-990297722075} => pcalua.exe -a "C:\Program Files (x86)\gs\uninstgs.exe" -d "C:\Program Files (x86)\gs" Task: {5247D7CD-58E5-445B-B3EF-8D726E496AEB} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000Core => C:\Users\Rostov\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {650DBC86-AC83-4E4B-8031-F0D078AFB7D9} - System32\Tasks\{8FD5E414-5C74-4450-B771-7776E38FBA5F} => pcalua.exe -a C:\Users\Rostov\Desktop\MP3ext34b23.exe -d C:\Users\Rostov\Desktop Task: {66A5D9F6-FA12-4510-B70F-9499ADF141DD} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000UA => C:\Users\Rostov\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {7C58DA59-4E29-4718-9198-011E86EE5AC8} - System32\Tasks\{11C156CD-716F-4DD4-9D40-4E352A821EBC} => pcalua.exe -a C:\Users\Rostov\Desktop\irfanview_lang_polski.exe -d C:\Users\Rostov\Desktop Task: {8E84496B-78B5-4107-9FB8-8B80A2A6BF34} - System32\Tasks\{D93F76A1-EA12-43BF-B7A1-748B140A56C4} => pcalua.exe -a C:\Users\Rostov\Desktop\irfanview_plugins_432_setup.exe -d C:\Users\Rostov\Desktop Task: {CC96370F-4976-4BDC-9572-54C0FC2B8948} - System32\Tasks\{9D9CD558-5656-4028-99EC-307255F6080A} => pcalua.exe -a E:\SecureTraveler.exe -d E:\ Task: {D884FD42-E726-43CD-8BC8-6E0CF1752509} - System32\Tasks\{2BB4D936-E831-4399-BD6F-4532083A957E} => pcalua.exe -a "C:\Users\Rostov\D\Portable Photoshop CS4 PL portable\PhotoshopPortable.exe" -d "C:\Users\Rostov\D\Portable Photoshop CS4 PL portable" Task: {F3D6ABF7-3733-4311-BF70-960922F5083E} - System32\Tasks\{D35DAD41-225B-4C63-9923-06E888234131} => pcalua.exe -a C:\Users\Rostov\Desktop\DjVuBrowserPlugin.exe -d C:\Users\Rostov\Desktop Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000Core.job => C:\Users\Rostov\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000UA.job => C:\Users\Rostov\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dBpowerAMP Music Converter\Uninstall dMC.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Fix components.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free Video to DVD Converter.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EagleGet C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopTray C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Teleport Pro C:\Users\Rostov\AppData\Roaming\Microsoft\Windows\SendTo\Dropbox.lnk C:\Users\Rostov\AppData\Roaming\Microsoft\Windows\SendTo\XnView.lnk C:\Users\Rostov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView C:\Users\Rostov\D\Moje dokumenty\Nowy folder\Gadu-Gadu.lnk C:\Users\Rostov\D\Moje dokumenty\Nowy folder\Iarsn TaskInfo 6.x.lnk C:\Users\Rostov\D\Moje dokumenty\Nowy folder\Microsoft Word.lnk C:\Users\Rostov\D\Moje dokumenty\Nowy folder\PowerGG.lnk C:\Users\Rostov\D\multimonitortool\off.lnk C:\Users\Rostov\D\multimonitortool\on.lnk C:\Users\Rostov\D\SEAGATE\Ceedo\User\Start Menu\Programs\Seagate\Install FreeAgent Tools.lnk C:\Users\Rostov\Links\Dropbox.lnk C:\Users\Rostov\Links\SkyDrive.lnk Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers" /s Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters" /s EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. SPPD => Service deleted successfully. HKU\S-1-5-21-764258043-3443933537-1065429426-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully. HKU\S-1-5-21-764258043-3443933537-1065429426-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully. HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key not found. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFA8A8ED-F0BE-4D84-B080-916ECBFD8C20}" => Key deleted successfully. HKCR\CLSID\{AFA8A8ED-F0BE-4D84-B080-916ECBFD8C20} => Key not found. Firefox newtab deleted successfully. Firefox DefaultSearchUrl deleted successfully. Firefox SearchEngineOrder.1 deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin" => Key deleted successfully. C:\Users\Rostov\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll not found. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000\Software\MozillaPlugins\eagleget.com/EagleGet" => Key deleted successfully. C:\Program Files (x86)\EagleGet\npEagleget.dll not found. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000\Software\MozillaPlugins\egtcps.com/captures" => Key deleted successfully. C:\Program Files (x86)\EagleGet\captures.dll not found. C:\Users\Rostov\AppData\Roaming\Mozilla\Firefox\Profiles\5mfjbeoz.default\user.js => Moved successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000\SOFTWARE\Google\Chrome\Extensions\jfhffdajidfgpobcfdgilfcgbngginod" => Key deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000\SOFTWARE\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jfhffdajidfgpobcfdgilfcgbngginod" => Key deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => Key deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => Key deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => Key deleted successfully. "HKU\S-1-5-21-764258043-3443933537-1065429426-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{237097CD-4CC6-46E6-8541-588C09B24F20}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{237097CD-4CC6-46E6-8541-588C09B24F20}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{386AF916-24B8-4C92-9DA4-3FFC4CCFBAF7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{386AF916-24B8-4C92-9DA4-3FFC4CCFBAF7}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3FEB9356-EBF5-4043-B266-1C8E661803FE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FEB9356-EBF5-4043-B266-1C8E661803FE}" => Key deleted successfully. C:\Windows\System32\Tasks\{3A4C5CFB-CFBF-49C7-938F-990297722075} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3A4C5CFB-CFBF-49C7-938F-990297722075}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5247D7CD-58E5-445B-B3EF-8D726E496AEB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5247D7CD-58E5-445B-B3EF-8D726E496AEB}" => Key deleted successfully. C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000Core => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000Core" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{650DBC86-AC83-4E4B-8031-F0D078AFB7D9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{650DBC86-AC83-4E4B-8031-F0D078AFB7D9}" => Key deleted successfully. C:\Windows\System32\Tasks\{8FD5E414-5C74-4450-B771-7776E38FBA5F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8FD5E414-5C74-4450-B771-7776E38FBA5F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{66A5D9F6-FA12-4510-B70F-9499ADF141DD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66A5D9F6-FA12-4510-B70F-9499ADF141DD}" => Key deleted successfully. C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000UA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000UA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7C58DA59-4E29-4718-9198-011E86EE5AC8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C58DA59-4E29-4718-9198-011E86EE5AC8}" => Key deleted successfully. C:\Windows\System32\Tasks\{11C156CD-716F-4DD4-9D40-4E352A821EBC} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{11C156CD-716F-4DD4-9D40-4E352A821EBC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8E84496B-78B5-4107-9FB8-8B80A2A6BF34}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E84496B-78B5-4107-9FB8-8B80A2A6BF34}" => Key deleted successfully. C:\Windows\System32\Tasks\{D93F76A1-EA12-43BF-B7A1-748B140A56C4} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D93F76A1-EA12-43BF-B7A1-748B140A56C4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC96370F-4976-4BDC-9572-54C0FC2B8948}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC96370F-4976-4BDC-9572-54C0FC2B8948}" => Key deleted successfully. C:\Windows\System32\Tasks\{9D9CD558-5656-4028-99EC-307255F6080A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9D9CD558-5656-4028-99EC-307255F6080A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D884FD42-E726-43CD-8BC8-6E0CF1752509}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D884FD42-E726-43CD-8BC8-6E0CF1752509}" => Key deleted successfully. C:\Windows\System32\Tasks\{2BB4D936-E831-4399-BD6F-4532083A957E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2BB4D936-E831-4399-BD6F-4532083A957E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3D6ABF7-3733-4311-BF70-960922F5083E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3D6ABF7-3733-4311-BF70-960922F5083E}" => Key deleted successfully. C:\Windows\System32\Tasks\{D35DAD41-225B-4C63-9923-06E888234131} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D35DAD41-225B-4C63-9923-06E888234131}" => Key deleted successfully. C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000Core.job => Moved successfully. C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-764258043-3443933537-1065429426-1000UA.job => Moved successfully. C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dBpowerAMP Music Converter\Uninstall dMC.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Fix components.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free Video to DVD Converter.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EagleGet => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopTray => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Teleport Pro => Moved successfully. C:\Users\Rostov\AppData\Roaming\Microsoft\Windows\SendTo\Dropbox.lnk => Moved successfully. C:\Users\Rostov\AppData\Roaming\Microsoft\Windows\SendTo\XnView.lnk => Moved successfully. C:\Users\Rostov\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView => Moved successfully. C:\Users\Rostov\D\Moje dokumenty\Nowy folder\Gadu-Gadu.lnk => Moved successfully. C:\Users\Rostov\D\Moje dokumenty\Nowy folder\Iarsn TaskInfo 6.x.lnk => Moved successfully. C:\Users\Rostov\D\Moje dokumenty\Nowy folder\Microsoft Word.lnk => Moved successfully. C:\Users\Rostov\D\Moje dokumenty\Nowy folder\PowerGG.lnk => Moved successfully. C:\Users\Rostov\D\multimonitortool\off.lnk => Moved successfully. C:\Users\Rostov\D\multimonitortool\on.lnk => Moved successfully. C:\Users\Rostov\D\SEAGATE\Ceedo\User\Start Menu\Programs\Seagate\Install FreeAgent Tools.lnk => Moved successfully. C:\Users\Rostov\Links\Dropbox.lnk => Moved successfully. C:\Users\Rostov\Links\SkyDrive.lnk => Moved successfully. ========= reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{25CBB996-92ED-457e-B28C-4774084BD562} (domy˜lny) REG_SZ GenericProvider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{3dd6bec0-8193-4ffe-ae25-e08e39ea4063} (domy˜lny) REG_SZ NPProvider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{503739d0-4c5e-4cfd-b3ba-d881334f0df2} (domy˜lny) REG_SZ VaultCredProvider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{6f45dc1e-5384-457a-bc13-2cd81b0d28ed} (domy˜lny) REG_SZ PasswordProvider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{6f45dc1e-5384-457a-bc13-2cd81b0d28ed}\LogonPasswordReset (domy˜lny) REG_SZ {8841d728-1a76-4682-bb6f-a9ea53b4b3ba} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{8bf9a910-a8ff-457f-999f-a5ca10b4a885} (domy˜lny) REG_SZ Smartcard Credential Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{94596c7e-3744-41ce-893e-bbf09122f76a} (domy˜lny) REG_SZ Smartcard Pin Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{AC3AC249-E820-4343-A65B-377AC634DC09} (domy˜lny) REG_SZ WinBio Credential Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{e74e57b0-6c6d-44d5-9cda-fb2df5ed7435} (domy˜lny) REG_SZ CertCredProvider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{F8A0B131-5F68-486c-8040-7E8FC3C85BB6} (domy˜lny) REG_SZ WLIDCredentialProvider ========= End of Reg: ========= ========= reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters\{DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE} (domy˜lny) REG_SZ GenericFilter ========= End of Reg: ========= EmptyTemp: => Removed 513.3 MB temporary data. The system needed a reboot. ==== End of Fixlog 20:22:13 ====