Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-02-2015 Ran by Lenovo at 2015-02-05 13:31:24 Run:1 Running from C:\Users\Lenovo\Desktop Loaded Profiles: Lenovo (Available profiles: Lenovo) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 {1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64; C:\Windows\System32\drivers\{1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64.sys [48792 2015-01-26] (StdLib) R1 {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64; C:\Windows\System32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys [61120 2014-04-24] (StdLib) R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system) R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [464384 2015-01-26] (SysTool PasSame LIMITED) [File not signed] U3 BcmSqlStartupSvc; No ImagePath U2 IAStorDataMgrSvc; No ImagePath U2 IviRegMgr; No ImagePath U2 RichVideo; No ImagePath U3 SQLWriter; No ImagePath HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1422290996&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1422290996&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422290996&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422290996&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hppp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=dspp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hppp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} SearchScopes: HKU\S-1-5-21-2998680915-4221821129-92501040-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} SearchScopes: HKU\S-1-5-21-2998680915-4221821129-92501040-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&ts=1422291063&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2998680915-4221821129-92501040-1000 -> {18AA1513-B377-48F1-88D4-50DD0399B873} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&ts=1422291063&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2998680915-4221821129-92501040-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&ts=1422291063&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2998680915-4221821129-92501040-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=dspp&ts=1422291045&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&q={searchTerms} SearchScopes: HKU\S-1-5-21-2998680915-4221821129-92501040-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST9500325AS_S2W7CC5JXXXXS2W7CC5J&ts=1422291063&type=default&q={searchTerms} BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\XTab\SupTab.dll (Thinknice Co. Limited) Toolbar: HKU\S-1-5-21-2998680915-4221821129-92501040-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Task: {0281C558-1927-4F45-BCAF-D899D5AE1561} - System32\Tasks\{1E8D7D7A-7A17-4BF4-8B10-531BA0E2EA3F} => pcalua.exe -a C:\Users\Lenovo\Desktop\winamp\CLIMAX\CLIMAX11.exe -d C:\Users\Lenovo\Desktop\winamp\CLIMAX Task: {150B0A05-FCDD-4DC5-91B0-A11C4AB554AE} - \Digital Sites No Task File <==== ATTENTION Task: {47530DD9-4393-434C-A4DE-B62A42EC4A88} - System32\Tasks\{BD41EE31-7CF5-4A82-9585-FD2D8DDEC283} => pcalua.exe -a "C:\Users\Lenovo\Desktop\Metal Gear Solid 2 - Substance PC + Crack.Fix\DirectX81\dxsetup.exe" -d "C:\Users\Lenovo\Desktop\Metal Gear Solid 2 - Substance PC + Crack.Fix\DirectX81" Task: {59C7DA98-F539-4B33-AD1A-44F6192D2F0C} - \Dealply No Task File <==== ATTENTION Task: {5CB3B361-A15D-461E-B51E-CF9DF8279FA8} - \BitGuard No Task File <==== ATTENTION Task: {65CF9611-1861-443F-91F7-8FC220C280A7} - System32\Tasks\{91A6DF79-6377-41DE-A89B-2B82C02DD0DB} => pcalua.exe -a C:\Users\Lenovo\Desktop\winamp\Geiss\geiss_423.exe -d C:\Users\Lenovo\Desktop\winamp\Geiss Task: {927FADB0-170F-4247-B6AE-B617872943BF} - \DigitalSite No Task File <==== ATTENTION Task: {A9586169-E49B-48BC-B1A0-3759FAAD0D4D} - \EPUpdater No Task File <==== ATTENTION Task: {B4CB07FE-3982-49D5-802B-698B6E572F2F} - System32\Tasks\{DCD2DAFD-EA69-47FB-9537-6C7DAF4D6B2D} => pcalua.exe -a "C:\Users\Lenovo\Desktop\winamp\Winamp 3DGL\wa3dgl150b.exe" -d "C:\Users\Lenovo\Desktop\winamp\Winamp 3DGL" Task: {BD784FCF-106B-4F32-9723-00256C1D5F3F} - System32\Tasks\{698395FE-8F0C-44AE-B291-C4ED64006490} => pcalua.exe -a "C:\Program Files (x86)\AbiWord\UninstallAbiWord2.exe" Task: {E44CCEEA-B715-4338-9DE4-8BDBCBE847EC} - System32\Tasks\{BDEF2D4B-06C6-4639-8758-C024651FC44D} => pcalua.exe -a C:\Users\Lenovo\Desktop\winamp\Tonic\Tonic_v_02_-_Made_In_Bulgaria.exe -d C:\Users\Lenovo\Desktop\winamp\Tonic Task: {ED5E912F-25DA-4B7D-ADF5-57965AC78F36} - System32\Tasks\{3F8DE417-CEA8-4C16-ABB2-1B98D70A5DBB} => pcalua.exe -a C:\Users\Lenovo\Desktop\winamp\Space\Space_v09b.exe -d C:\Users\Lenovo\Desktop\winamp\Space Task: {F4A33AA5-47B0-4BA1-9297-410D989B56F9} - System32\Tasks\{BDF9C1BA-5F85-49AC-8C4F-EF9BDF327647} => pcalua.exe -a C:\Users\Lenovo\Desktop\winamp\Jet\Jet.exe -d C:\Users\Lenovo\Desktop\winamp\Jet C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\Solution Real C:\Program Files (x86)\XTab C:\ProgramData\IHProtectUpDate C:\ProgramData\WindowsMangerProtect C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor C:\Users\Lenovo\AppData\Local\Gameo C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\Lenovo\AppData\Roaming\GoldenGate C:\Users\Lenovo\AppData\Roaming\omiga-plus C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url C:\Users\Lenovo\Downloads\sh-remover.exe C:\Users\Lenovo\Downloads\Winamp wizualizacje 5.56.exe C:\Windows\System32\drivers\{1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64.sys C:\Windows\System32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f EmptyTemp: ***************** Processes closed successfully. Error: (0) Failed to create a restore point. {1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64 => Unable to stop service {1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64 => Service deleted successfully. {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64 => Unable to stop service {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64 => Service deleted successfully. IHProtect Service => Service deleted successfully. WindowsMangerProtect => Service deleted successfully. BcmSqlStartupSvc => Service deleted successfully. IAStorDataMgrSvc => Service deleted successfully. IviRegMgr => Service deleted successfully. RichVideo => Service deleted successfully. SQLWriter => Service deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-2998680915-4221821129-92501040-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-2998680915-4221821129-92501040-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-2998680915-4221821129-92501040-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{18AA1513-B377-48F1-88D4-50DD0399B873}" => Key deleted successfully. HKCR\CLSID\{18AA1513-B377-48F1-88D4-50DD0399B873} => Key not found. "HKU\S-1-5-21-2998680915-4221821129-92501040-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => Key deleted successfully. HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => Key not found. "HKU\S-1-5-21-2998680915-4221821129-92501040-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-2998680915-4221821129-92501040-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => Key deleted successfully. HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. HKU\S-1-5-21-2998680915-4221821129-92501040-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0281C558-1927-4F45-BCAF-D899D5AE1561}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0281C558-1927-4F45-BCAF-D899D5AE1561}" => Key deleted successfully. C:\Windows\System32\Tasks\{1E8D7D7A-7A17-4BF4-8B10-531BA0E2EA3F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1E8D7D7A-7A17-4BF4-8B10-531BA0E2EA3F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{150B0A05-FCDD-4DC5-91B0-A11C4AB554AE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{150B0A05-FCDD-4DC5-91B0-A11C4AB554AE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Digital Sites" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47530DD9-4393-434C-A4DE-B62A42EC4A88}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47530DD9-4393-434C-A4DE-B62A42EC4A88}" => Key deleted successfully. C:\Windows\System32\Tasks\{BD41EE31-7CF5-4A82-9585-FD2D8DDEC283} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BD41EE31-7CF5-4A82-9585-FD2D8DDEC283}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{59C7DA98-F539-4B33-AD1A-44F6192D2F0C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59C7DA98-F539-4B33-AD1A-44F6192D2F0C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5CB3B361-A15D-461E-B51E-CF9DF8279FA8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5CB3B361-A15D-461E-B51E-CF9DF8279FA8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65CF9611-1861-443F-91F7-8FC220C280A7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65CF9611-1861-443F-91F7-8FC220C280A7}" => Key deleted successfully. C:\Windows\System32\Tasks\{91A6DF79-6377-41DE-A89B-2B82C02DD0DB} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{91A6DF79-6377-41DE-A89B-2B82C02DD0DB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{927FADB0-170F-4247-B6AE-B617872943BF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927FADB0-170F-4247-B6AE-B617872943BF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9586169-E49B-48BC-B1A0-3759FAAD0D4D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9586169-E49B-48BC-B1A0-3759FAAD0D4D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B4CB07FE-3982-49D5-802B-698B6E572F2F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4CB07FE-3982-49D5-802B-698B6E572F2F}" => Key deleted successfully. C:\Windows\System32\Tasks\{DCD2DAFD-EA69-47FB-9537-6C7DAF4D6B2D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DCD2DAFD-EA69-47FB-9537-6C7DAF4D6B2D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD784FCF-106B-4F32-9723-00256C1D5F3F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD784FCF-106B-4F32-9723-00256C1D5F3F}" => Key deleted successfully. C:\Windows\System32\Tasks\{698395FE-8F0C-44AE-B291-C4ED64006490} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{698395FE-8F0C-44AE-B291-C4ED64006490}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E44CCEEA-B715-4338-9DE4-8BDBCBE847EC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E44CCEEA-B715-4338-9DE4-8BDBCBE847EC}" => Key deleted successfully. C:\Windows\System32\Tasks\{BDEF2D4B-06C6-4639-8758-C024651FC44D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BDEF2D4B-06C6-4639-8758-C024651FC44D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED5E912F-25DA-4B7D-ADF5-57965AC78F36}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED5E912F-25DA-4B7D-ADF5-57965AC78F36}" => Key deleted successfully. C:\Windows\System32\Tasks\{3F8DE417-CEA8-4C16-ABB2-1B98D70A5DBB} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3F8DE417-CEA8-4C16-ABB2-1B98D70A5DBB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F4A33AA5-47B0-4BA1-9297-410D989B56F9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4A33AA5-47B0-4BA1-9297-410D989B56F9}" => Key deleted successfully. C:\Windows\System32\Tasks\{BDF9C1BA-5F85-49AC-8C4F-EF9BDF327647} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BDF9C1BA-5F85-49AC-8C4F-EF9BDF327647}" => Key deleted successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\Program Files (x86)\Solution Real => Moved successfully. C:\Program Files (x86)\XTab => Moved successfully. C:\ProgramData\IHProtectUpDate => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor => Moved successfully. C:\Users\Lenovo\AppData\Local\Gameo => Moved successfully. C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\Lenovo\AppData\Roaming\GoldenGate => Moved successfully. C:\Users\Lenovo\AppData\Roaming\omiga-plus => Moved successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url => Moved successfully. C:\Users\Lenovo\Downloads\sh-remover.exe => Moved successfully. C:\Users\Lenovo\Downloads\Winamp wizualizacje 5.56.exe => Moved successfully. C:\Windows\System32\drivers\{1d7d694e-604c-4da2-9100-b2601d3a1c57}Gw64.sys => Moved successfully. C:\Windows\System32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 90.7 MB temporary data. The system needed a reboot. ==== End of Fixlog 13:31:43 ====