Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-02-2015 02 Ran by zawias at 2015-02-11 20:33:42 Run:1 Running from C:\Users\zawias\Desktop\frst Loaded Profiles: zawias (Available profiles: zawias) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R2 IHProtect Service; C:\Program Files (x86)\STab\ProtectService.exe [158864 2014-11-10] (TODO: ) S2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe -service [X] S2 Update Reverse Page; "C:\Program Files (x86)\Reverse Page\updateReversePage.exe" [X] Task: {0692A0E5-41A9-48BE-B48A-5FC0C1817E9D} - System32\Tasks\{F6E3395F-9ADD-4B8C-99B0-A451F74C383A} => pcalua.exe -a E:\FSetup.exe -d E:\ Task: {229AD8F5-8B6E-4A74-91A6-DA9E9EA32CEF} - System32\Tasks\{4FF4B804-14F2-4A66-A05C-35D7A4A1058C} => pcalua.exe -a C:\ProgramData\ChampionDeals\ChampionDeals.exe -c /progname=ChampionDeals /progver=3.4.2 /progpub=ChampionDeals /proguninstallurl=asdahjka.com /deleteappfolder=0 /VERYSILENT Task: {4F17FF95-BDD6-4474-ADE1-A8A8DFBE84BB} - System32\Tasks\{D3DC525C-F459-4827-AA74-0F29FF6235D6} => pcalua.exe -a C:\Users\zawias\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt Task: {54FF6882-C441-41C7-8788-49AEFE20A433} - System32\Tasks\Run_Bobby_Browser => C:\Users\zawias\AppData\Local\BoBrowser\Application\bobrowser.exe <==== ATTENTION Task: {6269C19D-B12B-4E1F-ADA2-61964535918C} - System32\Tasks\XSVOYY => C:\Users\zawias\AppData\Roaming\XSVOYY.exe <==== ATTENTION Task: {65211436-EF59-409F-9732-C0D61897E362} - System32\Tasks\{C0D82179-B214-49C8-94BA-FDE75E656EFA} => pcalua.exe -a C:\ProgramData\deaLpeak\WS6kDeonXdalcR.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" "" Task: {E6B728E7-00FB-42FB-9906-9CB9214B96D8} - System32\Tasks\CGRMXE => C:\Users\zawias\AppData\Roaming\CGRMXE.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\CGRMXE.job => C:\Users\zawias\AppData\Roaming\CGRMXE.exe <==== ATTENTION Task: C:\Windows\Tasks\XSVOYY.job => C:\Users\zawias\AppData\Roaming\XSVOYY.exe <==== ATTENTION HKLM\...\Run: [] => [X] Startup: C:\Users\zawias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-157093298-1084357142-467351005-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omigaweb/?type=dspp&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omigaweb/?type=dspp&q={searchTerms} SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=3650&r=2014/12/26&hid=6934257787264173893&lg=EN&cc=PL&unqvl=72 SearchScopes: HKU\S-1-5-21-157093298-1084357142-467351005-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-157093298-1084357142-467351005-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omigaweb/?type=dspp&q={searchTerms} SearchScopes: HKU\S-1-5-21-157093298-1084357142-467351005-1000 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=3650&r=2014/12/26&hid=6934257787264173893&lg=EN&cc=PL&unqvl=72 BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File DPF: HKLM-x32 {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1419279347&from=ild&uid=WDCXWD7500BPVT-00HXZT3_WD-WX51A711254412544 C:\END C:\Program Files (x86)\ApptioU C:\Program Files (x86)\clasicnote C:\Program Files (x86)\cooupuonpEaik C:\Program Files (x86)\deal2deeaaliT C:\Program Files (x86)\dealester C:\Program Files (x86)\deaLpeak C:\Program Files (x86)\DizzyDing C:\Program Files (x86)\ESET C:\Program Files (x86)\ezLinkPreview C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\Google C:\Program Files (x86)\GU Player C:\Program Files (x86)\Lights off! C:\Program Files (x86)\Online SpongeBob Games C:\Program Files (x86)\saVer beoox C:\Program Files (x86)\SaveerPro C:\Program Files (x86)\savveitkueep C:\Program Files (x86)\SooftCouuP C:\Program Files (x86)\STab C:\Program Files (x86)\Temp C:\Program Files (x86)\ver8SpeedChecker C:\Program Files (x86)\Wheretoget C:\Program Files (x86)\WowwCouapon C:\Program Files (x86)\YooutubeAdBlocke C:\ProgramData\{4230c405-4d60-6b1a-4230-0c4054d61015} C:\ProgramData\1078601655 C:\ProgramData\1374afa80000451b C:\ProgramData\18cde976000005a9 C:\ProgramData\61493b34e22a9fed C:\ProgramData\7010199393297670125 C:\ProgramData\c74a5aab00003619 C:\ProgramData\ChampionDeals C:\ProgramData\CouponFactory C:\ProgramData\DAEMON Tools Pro C:\ProgramData\deaLpeak C:\ProgramData\Google C:\ProgramData\IePluginServices C:\ProgramData\PC Tools C:\ProgramData\SooftCouuP C:\ProgramData\TEMP C:\ProgramData\uTDFjDJLaO C:\ProgramData\ZombieInvasion C:\shoplog C:\Users\zawias\AppData\Local\nsl1E66.tmp C:\Users\zawias\AppData\Local\nsx5D27.tmp C:\Users\zawias\AppData\Local\18765 C:\Users\zawias\AppData\Local\Google C:\Users\zawias\AppData\Local\mtt_de_4 C:\Users\zawias\AppData\Local\ZombieInvasion C:\Users\zawias\AppData\Roaming\appdataFr3.bin C:\Users\zawias\AppData\Roaming\CGRMXE C:\Users\zawias\AppData\Roaming\XSVOYY C:\Users\zawias\AppData\Roaming\AnyProtectEx C:\Users\zawias\AppData\Roaming\systweak C:\Users\zawias\AppData\Roaming\Taplika C:\Users\zawias\AppData\Roaming\TestApp C:\Users\zawias\AppData\Roaming\WSE_Taplika C:\Users\zawias\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9469243fe2b7cb05\BoBrowser.lnk C:\Users\zawias\Desktop\sd9setup.exe.lnk C:\Users\zawias\Downloads\sd9setup.exe C:\Users\zawias\Documents\Optimizer Pro Reg: reg delete HKCU\Software\Google /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Google /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a "C:\Program Files (x86)\Common Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\zawias\AppData\Local CMD: dir /a C:\Users\zawias\AppData\LocalLow CMD: dir /a C:\Users\zawias\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. IHProtect Service => Service stopped successfully. IHProtect Service => Service deleted successfully. IePluginServices => Service deleted successfully. Update Reverse Page => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0692A0E5-41A9-48BE-B48A-5FC0C1817E9D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0692A0E5-41A9-48BE-B48A-5FC0C1817E9D}" => Key deleted successfully. C:\Windows\System32\Tasks\{F6E3395F-9ADD-4B8C-99B0-A451F74C383A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F6E3395F-9ADD-4B8C-99B0-A451F74C383A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{229AD8F5-8B6E-4A74-91A6-DA9E9EA32CEF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{229AD8F5-8B6E-4A74-91A6-DA9E9EA32CEF}" => Key deleted successfully. C:\Windows\System32\Tasks\{4FF4B804-14F2-4A66-A05C-35D7A4A1058C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4FF4B804-14F2-4A66-A05C-35D7A4A1058C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4F17FF95-BDD6-4474-ADE1-A8A8DFBE84BB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F17FF95-BDD6-4474-ADE1-A8A8DFBE84BB}" => Key deleted successfully. C:\Windows\System32\Tasks\{D3DC525C-F459-4827-AA74-0F29FF6235D6} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D3DC525C-F459-4827-AA74-0F29FF6235D6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{54FF6882-C441-41C7-8788-49AEFE20A433}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{54FF6882-C441-41C7-8788-49AEFE20A433}" => Key deleted successfully. C:\Windows\System32\Tasks\Run_Bobby_Browser => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_Bobby_Browser" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6269C19D-B12B-4E1F-ADA2-61964535918C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6269C19D-B12B-4E1F-ADA2-61964535918C}" => Key deleted successfully. C:\Windows\System32\Tasks\XSVOYY => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\XSVOYY" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65211436-EF59-409F-9732-C0D61897E362}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65211436-EF59-409F-9732-C0D61897E362}" => Key deleted successfully. C:\Windows\System32\Tasks\{C0D82179-B214-49C8-94BA-FDE75E656EFA} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C0D82179-B214-49C8-94BA-FDE75E656EFA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E6B728E7-00FB-42FB-9906-9CB9214B96D8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B728E7-00FB-42FB-9906-9CB9214B96D8}" => Key deleted successfully. C:\Windows\System32\Tasks\CGRMXE => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CGRMXE" => Key deleted successfully. C:\Windows\Tasks\APSnotifierPP3.job => Moved successfully. C:\Windows\Tasks\CGRMXE.job => Moved successfully. C:\Windows\Tasks\XSVOYY.job => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. C:\Users\zawias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKU\S-1-5-21-157093298-1084357142-467351005-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. HKU\S-1-5-21-157093298-1084357142-467351005-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-157093298-1084357142-467351005-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-157093298-1084357142-467351005-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key deleted successfully. HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55}" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. C:\END => Moved successfully. C:\Program Files (x86)\ApptioU => Moved successfully. C:\Program Files (x86)\clasicnote => Moved successfully. C:\Program Files (x86)\cooupuonpEaik => Moved successfully. C:\Program Files (x86)\deal2deeaaliT => Moved successfully. C:\Program Files (x86)\dealester => Moved successfully. C:\Program Files (x86)\deaLpeak => Moved successfully. C:\Program Files (x86)\DizzyDing => Moved successfully. C:\Program Files (x86)\ESET => Moved successfully. C:\Program Files (x86)\ezLinkPreview => Moved successfully. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Program Files (x86)\Google => Moved successfully. C:\Program Files (x86)\GU Player => Moved successfully. C:\Program Files (x86)\Lights off! => Moved successfully. C:\Program Files (x86)\Online SpongeBob Games => Moved successfully. "C:\Program Files (x86)\saVer beoox" => File/Directory not found. C:\Program Files (x86)\SaveerPro => Moved successfully. C:\Program Files (x86)\savveitkueep => Moved successfully. C:\Program Files (x86)\SooftCouuP => Moved successfully. C:\Program Files (x86)\STab => Moved successfully. C:\Program Files (x86)\Temp => Moved successfully. "C:\Program Files (x86)\ver8SpeedChecker" => File/Directory not found. C:\Program Files (x86)\Wheretoget => Moved successfully. C:\Program Files (x86)\WowwCouapon => Moved successfully. C:\Program Files (x86)\YooutubeAdBlocke => Moved successfully. C:\ProgramData\{4230c405-4d60-6b1a-4230-0c4054d61015} => Moved successfully. C:\ProgramData\1078601655 => Moved successfully. C:\ProgramData\1374afa80000451b => Moved successfully. C:\ProgramData\18cde976000005a9 => Moved successfully. C:\ProgramData\61493b34e22a9fed => Moved successfully. C:\ProgramData\7010199393297670125 => Moved successfully. C:\ProgramData\c74a5aab00003619 => Moved successfully. C:\ProgramData\ChampionDeals => Moved successfully. C:\ProgramData\CouponFactory => Moved successfully. C:\ProgramData\DAEMON Tools Pro => Moved successfully. C:\ProgramData\deaLpeak => Moved successfully. "C:\ProgramData\Google" => File/Directory not found. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\PC Tools => Moved successfully. C:\ProgramData\SooftCouuP => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\uTDFjDJLaO => Moved successfully. C:\ProgramData\ZombieInvasion => Moved successfully. C:\shoplog => Moved successfully. C:\Users\zawias\AppData\Local\nsl1E66.tmp => Moved successfully. C:\Users\zawias\AppData\Local\nsx5D27.tmp => Moved successfully. C:\Users\zawias\AppData\Local\18765 => Moved successfully. C:\Users\zawias\AppData\Local\Google => Moved successfully. C:\Users\zawias\AppData\Local\mtt_de_4 => Moved successfully. C:\Users\zawias\AppData\Local\ZombieInvasion => Moved successfully. C:\Users\zawias\AppData\Roaming\appdataFr3.bin => Moved successfully. C:\Users\zawias\AppData\Roaming\CGRMXE => Moved successfully. C:\Users\zawias\AppData\Roaming\XSVOYY => Moved successfully. C:\Users\zawias\AppData\Roaming\AnyProtectEx => Moved successfully. C:\Users\zawias\AppData\Roaming\systweak => Moved successfully. C:\Users\zawias\AppData\Roaming\Taplika => Moved successfully. C:\Users\zawias\AppData\Roaming\TestApp => Moved successfully. C:\Users\zawias\AppData\Roaming\WSE_Taplika => Moved successfully. C:\Users\zawias\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9469243fe2b7cb05\BoBrowser.lnk => Moved successfully. C:\Users\zawias\Desktop\sd9setup.exe.lnk => Moved successfully. C:\Users\zawias\Downloads\sd9setup.exe => Moved successfully. C:\Users\zawias\Documents\Optimizer Pro => Moved successfully. ========= reg delete HKCU\Software\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\Program Files 2015-02-10 10:51 . 2015-02-10 10:51 .. 2015-02-10 10:49 Common Files 2009-07-14 05:54 174 desktop.ini 2011-04-12 14:32 DVD Maker 2011-04-12 14:21 Internet Explorer 2015-02-10 10:51 Lavasoft 2015-01-15 22:17 Microsoft Silverlight 2009-07-14 06:32 MSBuild 2015-01-13 21:01 Realtek 2009-07-14 06:32 Reference Assemblies 2014-12-07 13:04 SkanerOnline 2009-07-14 06:09 Uninstall Information 2011-04-12 14:21 Windows Defender 2011-04-12 14:32 Windows Journal 2011-04-12 14:21 Windows Mail 2011-04-12 14:21 Windows Media Player 2014-10-11 07:54 Windows NT 2011-04-12 14:21 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2011-04-12 14:21 Windows Sidebar 1 plik(¢w) 174 bajt¢w 20 katalog(¢w) 70ÿ857ÿ666ÿ560 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\Program Files (x86) 2015-02-11 20:33 . 2015-02-11 20:33 .. 2014-12-23 10:27 be4d59e8-5f8d-4f3f-b07a-cf3ed29c4bf0 2015-01-13 21:00 Common Files 2009-07-14 05:54 174 desktop.ini 2015-01-13 21:00 InstallShield Installation Information 2011-04-12 14:21 Internet Explorer 2015-02-11 20:22 IP Address 2014-10-12 18:29 K-Lite Codec Pack 2015-01-15 22:17 Microsoft Silverlight 2009-07-14 06:32 MSBuild 2014-12-23 22:07 NapiProjekt 2014-12-23 23:10 Opera 2014-12-23 23:10 Optimizer Pro 3.16 2014-10-13 21:45 PDFCreator 2014-11-20 10:01 predm 2015-01-13 21:00 Realtek 2009-07-14 06:32 Reference Assemblies 2015-02-06 09:44 saVer beoox 2014-11-19 17:54 Skype 2009-07-14 05:57 Uninstall Information 2014-12-26 15:31 uuNisalesi 2011-04-12 14:21 Windows Defender 2011-04-12 14:21 Windows Mail 2011-04-12 14:21 Windows Media Player 2009-07-14 06:32 Windows NT 2011-04-12 14:21 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2011-04-12 14:21 Windows Sidebar 2014-12-26 15:43 WinRAR 1 plik(¢w) 174 bajt¢w 29 katalog(¢w) 70ÿ857ÿ666ÿ560 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files\Common Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\Program Files\Common Files 2015-02-10 10:49 . 2015-02-10 10:49 .. 2015-02-10 10:49 Lavasoft 2014-12-08 20:17 Microsoft Shared 2009-07-14 04:20 Services 2009-07-14 04:20 SpeechEngines 2011-04-12 14:21 System 0 plik(¢w) 0 bajt¢w 7 katalog(¢w) 70ÿ857ÿ666ÿ560 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\Program Files (x86)\Common Files 2015-01-13 21:00 . 2015-01-13 21:00 .. 2014-12-30 23:20 Apple 2015-01-13 21:00 InstallShield 2014-12-30 23:08 microsoft shared 2009-07-14 04:20 Services 2014-11-19 17:54 Skype 2009-07-14 04:20 SpeechEngines 2011-04-12 14:21 System 2014-12-08 19:01 Wise Installation Wizard 0 plik(¢w) 0 bajt¢w 10 katalog(¢w) 70ÿ857ÿ666ÿ560 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\ProgramData 2015-02-11 20:33 . 2015-02-11 20:33 .. 2015-02-10 11:51 Adobe 2014-12-21 14:26 APN 2014-12-30 23:20 Apple 2014-12-17 17:30 Apple Computer 2009-07-14 06:08 Application Data [C:\ProgramData] 2015-02-10 11:18 BitDefender 2015-02-06 15:54 DAEMON Tools Lite 2014-10-11 07:54 Dane aplikacji [C:\ProgramData] 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2014-10-11 07:54 Dokumenty [C:\Users\Public\Documents] 2014-12-23 10:36 E1864A66-75E3-486a-BD95-D1B7D99A84A7 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2014-12-22 21:16 IHProtectUpDate 2014-12-26 15:31 joddnbnfkpjjoodjfjbgkcaijogkdcda 2015-02-10 10:46 Lavasoft 2014-11-20 10:15 Malwarebytes 2014-10-11 07:54 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-11-20 09:40 Microsoft 2014-10-11 07:54 Pulpit [C:\Users\Public\Desktop] 2014-11-19 17:55 Skype 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-10-11 07:54 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2014-10-11 07:54 Ulubione [C:\Users\Public\Favorites] 0 plik(¢w) 0 bajt¢w 27 katalog(¢w) 70ÿ857ÿ662ÿ464 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\zawias\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\Users\zawias\AppData\Local 2015-02-11 20:33 . 2015-02-11 20:33 .. 2015-02-10 12:02 Adobe 2014-12-17 17:26 Apple 2014-12-17 17:37 Apple Computer 2014-10-25 19:22 Apps 2014-10-11 07:54 Dane aplikacji [C:\Users\zawias\AppData\Local] 2014-10-25 19:23 Deployment 2015-01-31 10:36 Diagnostics 2014-10-11 09:40 57ÿ560 GDIPFONTCACHEV1.DAT 2014-12-22 19:11 globalUpdate 2014-10-11 07:54 Historia [C:\Users\zawias\AppData\Local\Microsoft\Windows\History] 2015-02-10 17:25 1ÿ056ÿ345 IconCache.db 2014-12-11 23:55 Microsoft 2014-12-23 23:09 Opera Software 2014-10-12 18:29 Programs 2014-11-19 17:56 Skype 2015-02-11 20:33 Temp 2014-10-11 07:54 Temporary Internet Files [C:\Users\zawias\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2015-02-11 10:29 Viber 2015-02-04 14:19 VirtualStore 2 plik(¢w) 1ÿ113ÿ905 bajt¢w 19 katalog(¢w) 70ÿ857ÿ662ÿ464 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\zawias\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\Users\zawias\AppData\LocalLow 2014-11-20 10:03 . 2014-11-20 10:03 .. 2015-02-04 15:25 Company 2014-11-20 09:40 Microsoft 0 plik(¢w) 0 bajt¢w 4 katalog(¢w) 70ÿ857ÿ662ÿ464 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\zawias\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 1425-D7A9 Katalog: C:\Users\zawias\AppData\Roaming 2015-02-11 20:33 . 2015-02-11 20:33 .. 2014-11-19 22:42 Adobe 2014-12-18 16:29 Apple Computer 2014-12-30 23:22 DAEMON Tools Lite 2015-01-04 00:11 EurekaLog 2014-10-11 07:54 Identities 2014-12-23 22:07 IHlpr 2015-02-10 12:44 Lavasoft 2015-02-10 11:00 LavasoftStatistics 2014-11-19 22:42 Macromedia 2011-04-12 14:32 Media Center Programs 2014-10-12 18:30 Media Player Classic 2014-12-08 20:38 Microsoft 2014-12-23 22:08 NapiProjekt 2014-12-23 22:07 OpenCandy 2014-12-23 23:09 Opera Software 2014-12-21 14:26 RHEng 2015-02-06 15:54 Skype 2014-12-30 21:58 uTorrent 2015-02-11 10:29 ViberPC 2015-01-13 21:00 WinBatch 2014-12-26 15:44 WinRAR 2014-11-20 09:42 {37E99E86-D615-4B08-937F-F8F935C455F3}_ANZHUANG 0 plik(¢w) 0 bajt¢w 24 katalog(¢w) 70ÿ857ÿ658ÿ368 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 814 MB temporary data. The system needed a reboot. ==== End of Fixlog 20:34:31 ====