Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01 Ran by ALEKSANDRA at 2015-02-20 07:01:28 Run:1 Running from C:\Users\ALEKSANDRA\Downloads Loaded Profiles: ALEKSANDRA (Available profiles: ALEKSANDRA) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61112 2014-03-14] (StdLib) R1 {58aaf827-6246-4d80-8213-f02005f6345c}w64; C:\Windows\System32\drivers\{58aaf827-6246-4d80-8213-f02005f6345c}w64.sys [48776 2014-11-30] (StdLib) R1 {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64; C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys [61112 2014-04-24] (StdLib) S1 F06DEFF2-5B9C-490D-910F-35D3A9119622; \??\C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\configmgrc2.cfg [X] IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe HKLM\...\Policies\Explorer: [NoControlPanel] 0 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-1941029217-1621239754-420919328-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TEUA&bmod=TEUA SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=a13277-330&apn_uid=2285144208314075&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=a13277-330&apn_uid=2285144208314075&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKU\S-1-5-21-1941029217-1621239754-420919328-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-1941029217-1621239754-420919328-1000 -> {817B9F6D-9CAF-499E-9906-6581FA90C6BB} URL = http://search.babylon.com/?q={searchTerms}&affID=110000&babsrc=SP_ss&mntrId=3c8da18d00000000000074de2bebcc12 SearchScopes: HKU\S-1-5-21-1941029217-1621239754-420919328-1000 -> {9017BACF-6012-4FBF-B98E-06FF65153EAC} URL = http://rts.dsrlte.com/?affID=na&q={searchTerms}&r=349 SearchScopes: HKU\S-1-5-21-1941029217-1621239754-420919328-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=101&systemid=488&v=a13277-330&apn_uid=2285144208314075&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKU\S-1-5-21-1941029217-1621239754-420919328-1000 -> {A4D199F8-A5D3-4859-87FE-963C70F4E5FA} URL = http://searchya.com/?chnl=tst-215&s=1&cr=1343013061&cd=2XzutAtN2Y1L1Qzu0D0CtD0E0AtCtA0AtB0A0AyC0AtCzz0DtN0D0TzutBtDtCtBtDyEtDzz&q={searchTerms} Toolbar: HKU\S-1-5-21-1941029217-1621239754-420919328-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR HomePage: Default -> hxxp://rts.dsrlte.com?affID=na CHR RestoreOnStartup: Default -> "hxxp://rts.dsrlte.com?affID=pr_46eb5e1d-f7f2-4562-8d60-f4ff377de045" CHR Extension: (SiteAdvisor) - C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-02-02] CHR Extension: (CinPl2.3c) - C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\iobcbdgacfkninlcbphihhdlkobkehia [2014-09-03] CHR Extension: (Allin1Convert) - C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfkanglmmnniiolknlhaajllgmlgcdkj [2014-01-30] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - No Path FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml FF Plugin-x32: @java.com/DTPlugin,version=10.4.1 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor Task: {0591D8C2-1230-483F-8E07-25282BA9AD9E} - System32\Tasks\{053A3232-8627-4376-9855-ED352F3EEFA2} => Firefox.exe http://ui.skype.com/ui/0/5.10.0.116/pl/abandoninstall?page=tsProgressBar Task: {38A75E1E-1A9D-404A-81BD-8E644A7966CE} - System32\Tasks\{0D06F980-7FB8-4AA8-A50C-FCA657668871} => pcalua.exe -a "C:\Program Files (x86)\PLAY ONLINE\uninst.exe" Task: {67E41725-63D5-4770-A5D8-146A6616813D} - System32\Tasks\DealPly => C:\Users\ALEKSA~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\Dealply.job => C:\Users\ALEKSA~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION C:\Program Files (x86)\mozilla firefox\plugins C:\Program Files (x86)\globalUpdate C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup C:\Windows\pss\OpenOffice.org 3.3.lnk.Startup C:\Windows\System32\drivers\{58aaf827-6246-4d80-8213-f02005f6345c}w64.sys C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys C:\Windows\System32\drivers\wStLibG64.sys Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^ALEKSANDRA^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Aeria Ignite" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnTBMon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Gadu-Gadu 10" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mcui_exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetIM" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator" /f CMD: sc config "Internet Manager. RunOuc" start= disabled CMD: sc config "PLAY ONLINE. RunOuc" start= disabled CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a "C:\Program Files (x86)\Common Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\ALEKSANDRA\AppData\Local CMD: dir /a C:\Users\ALEKSANDRA\AppData\LocalLow CMD: dir /a C:\Users\ALEKSANDRA\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. wStLibG64 => Service stopped successfully. wStLibG64 => Service deleted successfully. {58aaf827-6246-4d80-8213-f02005f6345c}w64 => Service stopped successfully. {58aaf827-6246-4d80-8213-f02005f6345c}w64 => Service deleted successfully. {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64 => Service stopped successfully. {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64 => Service deleted successfully. F06DEFF2-5B9C-490D-910F-35D3A9119622 => Service deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe" => Key deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKU\S-1-5-21-1941029217-1621239754-420919328-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => Key not found. "HKU\S-1-5-21-1941029217-1621239754-420919328-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. "HKU\S-1-5-21-1941029217-1621239754-420919328-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{817B9F6D-9CAF-499E-9906-6581FA90C6BB}" => Key deleted successfully. HKCR\CLSID\{817B9F6D-9CAF-499E-9906-6581FA90C6BB} => Key not found. "HKU\S-1-5-21-1941029217-1621239754-420919328-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9017BACF-6012-4FBF-B98E-06FF65153EAC}" => Key deleted successfully. HKCR\CLSID\{9017BACF-6012-4FBF-B98E-06FF65153EAC} => Key not found. "HKU\S-1-5-21-1941029217-1621239754-420919328-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => Key not found. "HKU\S-1-5-21-1941029217-1621239754-420919328-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A4D199F8-A5D3-4859-87FE-963C70F4E5FA}" => Key deleted successfully. HKCR\CLSID\{A4D199F8-A5D3-4859-87FE-963C70F4E5FA} => Key not found. HKU\S-1-5-21-1941029217-1621239754-420919328-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. Chrome HomePage deleted successfully. Chrome RestoreOnStartup deleted successfully. C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho => Moved successfully. C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\iobcbdgacfkninlcbphihhdlkobkehia => Moved successfully. C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfkanglmmnniiolknlhaajllgmlgcdkj => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho" => Key deleted successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml => Moved successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.4.1" => Key deleted successfully. C:\Windows\SysWOW64\npDeployJava1.dll => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92} => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0591D8C2-1230-483F-8E07-25282BA9AD9E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0591D8C2-1230-483F-8E07-25282BA9AD9E}" => Key deleted successfully. C:\Windows\System32\Tasks\{053A3232-8627-4376-9855-ED352F3EEFA2} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{053A3232-8627-4376-9855-ED352F3EEFA2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{38A75E1E-1A9D-404A-81BD-8E644A7966CE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38A75E1E-1A9D-404A-81BD-8E644A7966CE}" => Key deleted successfully. C:\Windows\System32\Tasks\{0D06F980-7FB8-4AA8-A50C-FCA657668871} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0D06F980-7FB8-4AA8-A50C-FCA657668871}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{67E41725-63D5-4770-A5D8-146A6616813D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{67E41725-63D5-4770-A5D8-146A6616813D}" => Key deleted successfully. C:\Windows\System32\Tasks\DealPly => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly" => Key deleted successfully. C:\Windows\Tasks\Dealply.job => Moved successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Users\ALEKSANDRA\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup => Moved successfully. C:\Windows\pss\OpenOffice.org 3.3.lnk.Startup => Moved successfully. C:\Windows\System32\drivers\{58aaf827-6246-4d80-8213-f02005f6345c}w64.sys => Moved successfully. C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys => Moved successfully. C:\Windows\System32\drivers\wStLibG64.sys => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^ALEKSANDRA^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Aeria Ignite" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnTBMon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Gadu-Gadu 10" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mcui_exe" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetIM" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "Internet Manager. RunOuc" start= disabled ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config "PLAY ONLINE. RunOuc" start= disabled ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\Program Files 2015-02-20 06:14 . 2015-02-20 06:14 .. 2014-09-20 16:17 Common Files 2009-07-14 05:54 174 desktop.ini 2010-11-21 14:04 DVD Maker 2012-07-09 19:31 Google 2015-02-19 06:45 Internet Explorer 2010-11-21 14:03 Microsoft Games 2012-07-19 17:02 Microsoft Office 2015-02-18 19:13 Microsoft Security Client 2014-11-17 16:33 Microsoft Silverlight 2009-07-14 06:32 MSBuild 2011-08-04 09:00 PlayReady 2011-12-09 05:38 Realtek 2009-07-14 06:32 Reference Assemblies 2011-12-09 05:48 Synaptics 2011-12-09 05:56 TOSHIBA 2009-07-14 06:09 Uninstall Information 2015-02-19 09:44 Windows Defender 2015-02-19 09:45 Windows Journal 2011-08-04 09:21 Windows Live 2010-11-21 13:53 Windows Mail 2015-02-19 09:45 Windows Media Player 2012-02-02 14:20 Windows NT 2010-11-21 13:53 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2010-11-21 13:53 Windows Sidebar 1 plik(¢w) 174 bajt¢w 26 katalog(¢w) 76ÿ521ÿ467ÿ904 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\Program Files (x86) 2015-02-20 07:02 . 2015-02-20 07:02 .. 2013-03-15 17:28 7-Zip 2012-08-05 21:10 CDex 2013-02-01 15:45 ChomikBox 2015-02-20 06:57 Common Files 2014-09-17 17:51 Comodo 2014-08-30 05:00 DAEMON Tools Lite 2013-06-01 11:25 DealPly 2009-07-14 05:54 174 desktop.ini 2013-03-16 14:40 Electronic Arts 2012-07-09 19:31 Google 2012-04-21 13:56 GPLGS 2014-08-31 19:42 InstallShield Installation Information 2011-12-09 05:35 Intel 2015-02-19 06:45 Internet Explorer 2012-05-03 10:37 ipla 2012-04-06 16:09 K-Lite Codec Pack 2014-04-11 20:54 Microsoft 2012-07-19 17:05 Microsoft Office 2015-02-18 19:13 Microsoft Security Client 2014-11-17 16:32 Microsoft Silverlight 2011-08-04 09:22 Microsoft SQL Server Compact Edition 2012-07-19 17:05 Microsoft Visual Studio 2012-07-19 17:02 Microsoft Visual Studio 8 2015-02-19 07:14 Microsoft Works 2011-08-04 09:08 Microsoft.NET 2015-02-20 07:02 Mozilla Firefox 2014-11-18 11:29 Mozilla Firefox.bak 2014-11-18 15:10 Mozilla Maintenance Service 2012-07-19 17:05 MSBuild 2012-03-12 14:49 MSECache 2012-03-06 12:43 MSXML 4.0 2012-04-06 16:15 NapiProjekt 2011-08-04 09:16 Nero 2015-02-20 06:42 OpenOffice.org 3 2012-04-21 13:55 PDFCreator 2012-11-16 21:55 PLAY ONLINE 2011-12-09 05:48 Realtek 2011-12-09 05:49 Realtek WLAN Driver 2009-07-14 06:32 Reference Assemblies 2015-02-08 14:40 Skype 2013-07-19 15:09 softendo.com 2011-12-09 05:38 Temp 2011-12-09 05:56 TOSHIBA 2011-08-04 09:26 Toshiba TEMPRO 2009-07-14 05:57 Uninstall Information 2014-09-01 10:07 Wied«min 2 2013-07-08 07:29 Winamp 2013-07-08 07:29 Winamp Detect 2015-02-19 09:44 Windows Defender 2011-08-04 09:24 Windows Live 2010-11-21 13:53 Windows Mail 2015-02-19 09:45 Windows Media Player 2009-07-14 06:32 Windows NT 2010-11-21 13:53 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2010-11-21 13:53 Windows Sidebar 2012-02-11 15:47 WinRAR 1 plik(¢w) 174 bajt¢w 58 katalog(¢w) 76ÿ521ÿ463ÿ808 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files\Common Files" ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\Program Files\Common Files 2014-09-20 16:17 . 2014-09-20 16:17 .. 2012-07-19 17:03 Microsoft Shared 2009-07-14 04:20 Services 2009-07-14 04:20 SpeechEngines 2012-03-06 21:14 System 0 plik(¢w) 0 bajt¢w 6 katalog(¢w) 76ÿ521ÿ463ÿ808 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files" ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\Program Files (x86)\Common Files 2015-02-20 06:57 . 2015-02-20 06:57 .. 2015-02-20 03:19 DESIGNER 2011-12-09 05:37 InstallShield 2015-02-19 07:14 microsoft shared 2011-08-04 09:15 Nero 2011-12-09 05:32 postureAgent 2009-07-14 04:20 Services 2015-02-08 14:40 Skype 2009-07-14 04:20 SpeechEngines 2015-02-20 03:09 System 2011-08-04 09:20 Windows Live 2011-08-04 09:26 Wise Installation Wizard 0 plik(¢w) 0 bajt¢w 13 katalog(¢w) 76ÿ521ÿ463ÿ808 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\ProgramData 2015-02-20 06:57 . 2015-02-20 06:57 .. 2015-02-20 06:32 Adobe 2012-09-06 11:10 Aeria Games 2013-07-08 09:01 APN 2009-07-14 06:08 Application Data [C:\ProgramData] 2014-08-31 10:04 AVG 2012-04-21 13:55 Babylon 2014-01-30 20:56 BlueStacks 2014-01-30 20:57 BlueStacksSetup 2014-08-30 10:55 Common Files 2014-08-30 05:03 DAEMON Tools Lite 2012-02-02 14:20 Dane aplikacji [C:\ProgramData] 2012-11-16 21:55 DatacardService 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2012-02-02 14:20 Dokumenty [C:\Users\Public\Documents] 2014-09-20 15:29 Electronic Arts 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2012-02-25 14:22 Gadu-Gadu 10 2012-07-09 19:26 Google 2012-02-02 14:31 Internet Manager 2013-06-15 21:03 ipla 2013-03-26 08:27 log 2012-02-02 14:20 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2015-02-18 19:13 Microsoft 2015-02-20 03:31 Microsoft Help 2012-05-05 14:19 Mozilla 2011-08-04 09:16 Nero 2015-02-19 06:49 266 ntuser.pol 2015-02-20 06:59 OnlineUpdate 2012-03-20 23:40 OpenFM 2012-07-09 19:25 Origin 2012-02-25 13:59 Partner 2012-11-16 21:55 PLAY ONLINE 2012-02-02 14:20 Pulpit [C:\Users\Public\Desktop] 2014-06-02 09:17 RDRM 2015-02-08 14:40 Skype 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2011-08-04 09:00 Sun 2012-02-02 14:20 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2012-02-02 14:24 Toshiba 2012-02-02 14:21 ToshibaEurope 2012-02-02 14:20 Ulubione [C:\Users\Public\Favorites] 2012-03-05 17:54 VirtualizedApplications 2011-12-09 05:40 vista32 2011-12-09 05:40 vista64 2011-12-09 05:44 win7_32 2011-12-09 05:44 win7_64 2011-12-09 05:40 xp 2014-08-30 10:55 {01BD4FC9-2F86-4706-A62E-774BB7E9D308} 1 plik(¢w) 266 bajt¢w 51 katalog(¢w) 76ÿ521ÿ459ÿ712 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\ALEKSANDRA\AppData\Local ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\Users\ALEKSANDRA\AppData\Local 2015-02-20 06:31 . 2015-02-20 06:31 .. 2015-02-20 06:32 Adobe 2012-09-06 08:41 Aeria Games 2014-08-30 10:55 AVG 2014-01-30 21:07 BlueStacks 2014-01-30 21:07 BlueStacksSetup 2014-02-28 03:31 cache 2013-06-15 21:08 ChomikBox 2013-07-08 09:03 Comodo 2014-01-30 20:58 CrashRpt 2014-04-22 19:16 CUSTPDF Writer 2012-02-02 14:20 Dane aplikacji [C:\Users\ALEKSANDRA\AppData\Local] 2014-03-29 14:06 4ÿ608 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-31 10:06 Diagnostics 2014-08-30 05:11 ElevatedDiagnostics 2012-02-28 21:59 Facebook 2015-02-19 07:54 115ÿ432 GDIPFONTCACHEV1.DAT 2014-09-17 18:05 Genesis_08300402 2014-02-28 02:56 genienext 2014-08-30 05:04 globalUpdate 2012-07-09 19:26 Google 2012-02-02 14:20 Historia [C:\Users\ALEKSANDRA\AppData\Local\Microsoft\Windows\History] 2015-02-20 06:58 2ÿ184ÿ006 IconCache.db 2013-06-01 11:19 Macromedia 2014-08-17 16:55 Microsoft 2012-03-01 01:43 Microsoft Games 2013-01-14 17:29 Microsoft Help 2014-02-28 03:32 Mobogenie 2013-11-09 10:28 Mozilla 2012-09-27 19:45 Nero 2012-07-29 14:26 Nero_AG 2014-11-09 12:40 Pay-By-Ads 2014-08-17 16:55 Skype 2012-03-05 00:50 SoftGrid Client 2015-02-20 07:02 Temp 2012-02-02 14:20 Temporary Internet Files [C:\Users\ALEKSANDRA\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2014-08-30 05:48 The Witcher 2 2012-02-02 14:31 Toshiba 2012-02-02 15:51 TOSHIBA_Corporation 2012-05-02 21:48 VirtualStore 3 plik(¢w) 2ÿ304ÿ046 bajt¢w 38 katalog(¢w) 76ÿ521ÿ459ÿ712 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\ALEKSANDRA\AppData\LocalLow ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\Users\ALEKSANDRA\AppData\LocalLow 2014-09-17 17:51 . 2014-09-17 17:51 .. 2013-11-06 17:52 Adobe 2014-09-06 19:49 DataMngr 2013-06-01 11:19 Microsoft 2012-05-28 12:46 Oracle 2012-02-29 12:49 Sun 0 plik(¢w) 0 bajt¢w 7 katalog(¢w) 76ÿ521ÿ455ÿ616 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\ALEKSANDRA\AppData\Roaming ========= Wolumin w stacji C to WINDOWS Numer seryjny woluminu: 3C8D-A18D Katalog: C:\Users\ALEKSANDRA\AppData\Roaming 2015-02-20 06:15 . 2015-02-20 06:15 .. 2012-02-20 20:10 Adobe 2012-09-06 08:36 Aeria Games & Entertainment 2014-08-30 10:55 AVG 2012-04-21 13:55 Babylon 2012-08-08 18:43 BESTplayer 2014-04-09 13:18 BitTorrent 2014-07-05 12:44 Browser Tab Search by Ask 2014-08-16 18:46 BRT 2014-08-30 05:02 DAEMON Tools Lite 2013-02-10 13:05 DealPly 2012-06-16 10:35 Gadu-Gadu 10 2012-02-25 10:19 Google 2012-02-02 14:22 Identities 2014-06-04 13:16 ipla 2012-02-02 14:37 Macromedia 2010-11-21 14:03 Media Center Programs 2012-04-06 16:09 Media Player Classic 2014-05-25 12:33 Microsoft 2012-02-02 14:53 Mozilla 2012-04-06 16:16 NapiProjekt 2012-04-10 14:00 Nero 2014-09-20 23:48 newnext.me 2012-02-02 14:30 ol 2014-08-30 04:54 OpenCandy 2012-03-20 03:45 OpenFM 2012-05-12 07:32 OpenOffice.org 2012-07-08 12:08 Origin 2014-08-30 04:54 RHEng 2014-08-30 04:54 rmi 2015-02-08 16:31 Skype 2012-07-19 16:52 SoftGrid Client 2012-02-02 16:35 Toshiba 2012-02-02 14:42 TOSHIBA Online Product Information 2012-03-05 00:50 TP 2014-09-21 00:20 uTorrent 2014-09-17 17:37 155 WB.CFG 2012-04-19 21:51 Winamp 2012-02-11 15:48 WinRAR 1 plik(¢w) 155 bajt¢w 39 katalog(¢w) 76ÿ521ÿ455ÿ616 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 6.3 GB temporary data. The system needed a reboot. ==== End of Fixlog 07:10:46 ====