Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-04-2015 Ran by Dana at 2015-04-15 06:51:59 Run:1 Running from C:\Users\Dana\Desktop\usun Loaded Profiles: Dana & UpdatusUser (Available profiles: Dana & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-03-27] (globalUpdate) [File not signed] <==== ATTENTION R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-03-27] (SysTool PasSame LIMITED) [File not signed] HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-360924908-518354685-2704030000-1000\...\Run: [Skype] => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} HKU\S-1-5-21-360924908-518354685-2704030000-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT HKU\S-1-5-21-360924908-518354685-2704030000-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&q={searchTerms} SearchScopes: HKU\S-1-5-21-360924908-518354685-2704030000-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsurf.com/web/?utm_source=b&utm_medium=pcs&utm_campaign=install_ie&utm_content=ds&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&ts=1427447819&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-360924908-518354685-2704030000-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.istartsurf.com/web/?utm_source=b&utm_medium=pcs&utm_campaign=install_ie&utm_content=ds&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&ts=1427447819&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-360924908-518354685-2704030000-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsurf.com/web/?utm_source=b&utm_medium=pcs&utm_campaign=install_ie&utm_content=ds&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&ts=1427447819&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-360924908-518354685-2704030000-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?utm_source=b&utm_medium=pcs&utm_campaign=install_ie&utm_content=ds&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&ts=1427447819&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-360924908-518354685-2704030000-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.istartsurf.com/web/?utm_source=b&utm_medium=pcs&utm_campaign=install_ie&utm_content=ds&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT&ts=1427447819&type=default&q={searchTerms} BHO: Norton Identity Protection -> {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} -> C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.0.43\coIEPlg.dll No File BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\XTab\SupTab.dll [2015-03-16] (Thinknice Co. Limited) Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.0.43\coIEPlg.dll No File Toolbar: HKU\S-1-5-21-360924908-518354685-2704030000-1000 -> Norton Identity Safe Toolbar - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files (x86)\Norton Identity Safe\Engine64\2014.7.0.43\coIEPlg.dll No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1427447776&from=pcs&uid=TOSHIBAXMK3252GSX_48TZT0NRTXX48TZT0NRT FF HKLM-x32\...\Firefox\Extensions: [searchengine@gmail.com] - C:\Users\Dana\AppData\Roaming\Mozilla\Firefox\Profiles\iw5dhuwu.default-1395077970526\extensions\searchengine@gmail.com FF HKLM-x32\...\Firefox\Extensions: [istart_ffnt@gmail.com] - C:\Users\Dana\AppData\Roaming\Mozilla\Firefox\Profiles\iw5dhuwu.default-1395077970526\extensions\istart_ffnt@gmail.com Task: {0ACD2C2B-CFCE-4955-9019-2D551B273218} - System32\Tasks\{7F49692B-F382-42D1-93D1-7F3A6E6A1A00} => Firefox.exe http://ui.skype.com/ui/0/6.2.0.106/pl/abandoninstall?page=tsProgressBar Task: {36E79571-790F-4DCD-BEBC-03F4678DE48F} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION Task: {614C2E0A-6F58-4C35-B5D1-78791B6860BA} - System32\Tasks\Norton Identity Safe\Norton Error Analyzer => C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\SymErr.exe Task: {65361B65-E06C-4870-8635-DEBCFF80A580} - System32\Tasks\{F1F8CA6B-BDF6-4ADE-B8A4-D802D0D69C85} => pcalua.exe -a C:\Users\Dana\Downloads\sp37811.exe -d C:\Users\Dana\Downloads Task: {68189F4D-EC64-414A-BCB3-3B80669244CE} - System32\Tasks\{76ED6E2C-85BF-4787-8534-D6B392F60B40} => Firefox.exe http://ui.skype.com/ui/0/6.2.0.106/pl/abandoninstall?page=tsProgressBar Task: {6FC76FD5-2CE0-4F82-984F-DD6219570C47} - System32\Tasks\{0D259B92-6D36-478C-8B28-74EAE4CCC2CD} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=4.1.0.179.217&LastError=404 Task: {708C7CBB-AFF5-4EB3-9EC6-C7B44F942CBC} - System32\Tasks\{3B3C6651-0B42-4188-B19C-AE087567C566} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=4.1.0.179.217&LastError=404 Task: {85DDC2BC-57B9-4044-A0D5-EB85FC3B5796} - System32\Tasks\{C11EDAEA-23C6-4D05-8BE4-7F67454BDDA4} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=4.1.0.179.217&LastError=404 Task: {870608BB-780D-4C7D-9D30-38ED3FCB3611} - System32\Tasks\{0861B560-92FA-4F7C-AA26-B1B181EE684E} => C:\Program Files (x86)\Skype\\Phone\Skype.exe Task: {A9426EC2-FB80-4BDF-A38B-F76BFC43E66E} - System32\Tasks\{F79D4A52-A6E6-45B3-A6DC-97D679F5CAD2} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=4.1.0.179.217&LastError=404 Task: {BA260342-101F-4CD2-A403-34330EA78E70} - System32\Tasks\{C8179842-A8BD-47E0-BF65-23455A025343} => Firefox.exe http://ui.skype.com/ui/0/6.2.0.106/pl/abandoninstall?page=tsProgressBar Task: {BD5504FC-0A8E-4AB7-AD2A-D6802181481F} - System32\Tasks\{0151A142-AF65-4D01-BF32-01AC1541C7FD} => Firefox.exe http://ui.skype.com/ui/0/6.2.0.106/pl/abandoninstall?page=tsProgressBar Task: {D0B3D2A8-5E45-42F2-9A85-726143DC5099} - System32\Tasks\Norton Identity Safe\Norton Error Processor => C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\SymErr.exe Task: {E8BC01A9-A259-434F-AD2B-B5ECA8F40272} - System32\Tasks\{ADA115D4-3DB2-4194-AB3B-997FAD2CE3DD} => Firefox.exe http://ui.skype.com/ui/0/5.3.0.120/pl/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault Task: {F52B8B44-F692-4FFD-BB31-343470303CFE} - System32\Tasks\{352675B2-0931-423C-851F-F5D4B176660F} => Firefox.exe http://ui.skype.com/ui/0/5.3.0.120/pl/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;alreadyoffered Task: {F94BFA3C-C5BD-4D6A-8570-7CAE15C00615} - System32\Tasks\{EC346AFA-455C-44BD-B66F-AED5516B4C5A} => Firefox.exe http://ui.skype.com/ui/0/6.2.0.106/pl/abandoninstall?page=tsProgressBar C:\Program Files (x86)\Mozilla Firefox\extensions C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\Internet Speed Checker C:\Program Files (x86)\XTab C:\ProgramData\IHProtectUpDate C:\ProgramData\WindowsMangerProtect C:\Users\Dana\AppData\Local\globalUpdate C:\Users\Dana\AppData\Roaming\istartsurf C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton C:\Users\Dana\PULPIT\Rózności\Norton Internet Security.lnk C:\Users\Public\Downloads\Norton C:\Windows\System32\Tasks\Norton Identity Safe CMD: for /d %f in (C:\Users\Dana\AppData\Local\{*}) do rd /s /q "%f" DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Identity Safe EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. globalUpdate => Service deleted successfully. WindowsMangerProtect => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-360924908-518354685-2704030000-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-360924908-518354685-2704030000-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-360924908-518354685-2704030000-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKU\S-1-5-21-360924908-518354685-2704030000-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-360924908-518354685-2704030000-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-360924908-518354685-2704030000-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => Key deleted successfully. HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => Key not found. "HKU\S-1-5-21-360924908-518354685-2704030000-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-360924908-518354685-2704030000-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => Key deleted successfully. HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB4C7833-A6EC-433f-B9FE-6B14B1A2F836}" => Key deleted successfully. "HKCR\CLSID\{AB4C7833-A6EC-433f-B9FE-6B14B1A2F836}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{A13C2648-91D4-4bf3-BC6D-0079707C4389} => value deleted successfully. "HKCR\CLSID\{A13C2648-91D4-4bf3-BC6D-0079707C4389}" => Key deleted successfully. HKU\S-1-5-21-360924908-518354685-2704030000-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A13C2648-91D4-4BF3-BC6D-0079707C4389} => value deleted successfully. HKCR\CLSID\{A13C2648-91D4-4BF3-BC6D-0079707C4389} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}" => Key Deleted successfully. "HKCR\PROTOCOLS\Handler\WSWSVCUchrome" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\searchengine@gmail.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\istart_ffnt@gmail.com => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0ACD2C2B-CFCE-4955-9019-2D551B273218}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0ACD2C2B-CFCE-4955-9019-2D551B273218}" => Key deleted successfully. C:\Windows\System32\Tasks\{7F49692B-F382-42D1-93D1-7F3A6E6A1A00} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7F49692B-F382-42D1-93D1-7F3A6E6A1A00}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36E79571-790F-4DCD-BEBC-03F4678DE48F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36E79571-790F-4DCD-BEBC-03F4678DE48F}" => Key deleted successfully. C:\Windows\System32\Tasks\LaunchSignup => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{614C2E0A-6F58-4C35-B5D1-78791B6860BA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{614C2E0A-6F58-4C35-B5D1-78791B6860BA}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton Identity Safe\Norton Error Analyzer => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Identity Safe\Norton Error Analyzer" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65361B65-E06C-4870-8635-DEBCFF80A580}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65361B65-E06C-4870-8635-DEBCFF80A580}" => Key deleted successfully. C:\Windows\System32\Tasks\{F1F8CA6B-BDF6-4ADE-B8A4-D802D0D69C85} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F1F8CA6B-BDF6-4ADE-B8A4-D802D0D69C85}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68189F4D-EC64-414A-BCB3-3B80669244CE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68189F4D-EC64-414A-BCB3-3B80669244CE}" => Key deleted successfully. C:\Windows\System32\Tasks\{76ED6E2C-85BF-4787-8534-D6B392F60B40} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{76ED6E2C-85BF-4787-8534-D6B392F60B40}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6FC76FD5-2CE0-4F82-984F-DD6219570C47}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FC76FD5-2CE0-4F82-984F-DD6219570C47}" => Key deleted successfully. C:\Windows\System32\Tasks\{0D259B92-6D36-478C-8B28-74EAE4CCC2CD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0D259B92-6D36-478C-8B28-74EAE4CCC2CD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{708C7CBB-AFF5-4EB3-9EC6-C7B44F942CBC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{708C7CBB-AFF5-4EB3-9EC6-C7B44F942CBC}" => Key deleted successfully. C:\Windows\System32\Tasks\{3B3C6651-0B42-4188-B19C-AE087567C566} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3B3C6651-0B42-4188-B19C-AE087567C566}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{85DDC2BC-57B9-4044-A0D5-EB85FC3B5796}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85DDC2BC-57B9-4044-A0D5-EB85FC3B5796}" => Key deleted successfully. C:\Windows\System32\Tasks\{C11EDAEA-23C6-4D05-8BE4-7F67454BDDA4} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C11EDAEA-23C6-4D05-8BE4-7F67454BDDA4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{870608BB-780D-4C7D-9D30-38ED3FCB3611}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{870608BB-780D-4C7D-9D30-38ED3FCB3611}" => Key deleted successfully. C:\Windows\System32\Tasks\{0861B560-92FA-4F7C-AA26-B1B181EE684E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0861B560-92FA-4F7C-AA26-B1B181EE684E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9426EC2-FB80-4BDF-A38B-F76BFC43E66E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9426EC2-FB80-4BDF-A38B-F76BFC43E66E}" => Key deleted successfully. C:\Windows\System32\Tasks\{F79D4A52-A6E6-45B3-A6DC-97D679F5CAD2} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F79D4A52-A6E6-45B3-A6DC-97D679F5CAD2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BA260342-101F-4CD2-A403-34330EA78E70}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA260342-101F-4CD2-A403-34330EA78E70}" => Key deleted successfully. C:\Windows\System32\Tasks\{C8179842-A8BD-47E0-BF65-23455A025343} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C8179842-A8BD-47E0-BF65-23455A025343}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD5504FC-0A8E-4AB7-AD2A-D6802181481F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD5504FC-0A8E-4AB7-AD2A-D6802181481F}" => Key deleted successfully. C:\Windows\System32\Tasks\{0151A142-AF65-4D01-BF32-01AC1541C7FD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0151A142-AF65-4D01-BF32-01AC1541C7FD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D0B3D2A8-5E45-42F2-9A85-726143DC5099}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0B3D2A8-5E45-42F2-9A85-726143DC5099}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton Identity Safe\Norton Error Processor => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Identity Safe\Norton Error Processor" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E8BC01A9-A259-434F-AD2B-B5ECA8F40272}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E8BC01A9-A259-434F-AD2B-B5ECA8F40272}" => Key deleted successfully. C:\Windows\System32\Tasks\{ADA115D4-3DB2-4194-AB3B-997FAD2CE3DD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{ADA115D4-3DB2-4194-AB3B-997FAD2CE3DD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F52B8B44-F692-4FFD-BB31-343470303CFE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F52B8B44-F692-4FFD-BB31-343470303CFE}" => Key deleted successfully. C:\Windows\System32\Tasks\{352675B2-0931-423C-851F-F5D4B176660F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{352675B2-0931-423C-851F-F5D4B176660F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F94BFA3C-C5BD-4D6A-8570-7CAE15C00615}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F94BFA3C-C5BD-4D6A-8570-7CAE15C00615}" => Key deleted successfully. C:\Windows\System32\Tasks\{EC346AFA-455C-44BD-B66F-AED5516B4C5A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EC346AFA-455C-44BD-B66F-AED5516B4C5A}" => Key deleted successfully. C:\Program Files (x86)\Mozilla Firefox\extensions => Moved successfully. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Program Files (x86)\Internet Speed Checker => Moved successfully. C:\Program Files (x86)\XTab => Moved successfully. C:\ProgramData\IHProtectUpDate => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\Users\Dana\AppData\Local\globalUpdate => Moved successfully. C:\Users\Dana\AppData\Roaming\istartsurf => Moved successfully. C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton => Moved successfully. C:\Users\Dana\PULPIT\Rózności\Norton Internet Security.lnk => Moved successfully. C:\Users\Public\Downloads\Norton => Moved successfully. C:\Windows\System32\Tasks\Norton Identity Safe => Moved successfully. ========= for /d %f in (C:\Users\Dana\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Key Deleted Successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Identity Safe => Key Deleted successfully.