Fix result of Farbar Recovery Scan Tool (x86) Version:11-08-2015 02 Ran by Ja (2015-08-12 14:01:21) Run:1 Running from C:\Users\Ja\Documents\Antywirusy Loaded Profiles: Ja (Available Profiles: Ja) Boot Mode: Normal ============================================== fixlist content: ***************** HKU\S-1-5-21-70149214-1339082029-3386996294-1000\...\Run: [NextLive] => C:\Windows\system32\rundll32.exe "C:\Users\Ja\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l C:\Users\Ja\AppData\Roaming\newnext.me Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Task: {1DA5EFBF-EA8B-4524-B765-C852458A30B9} - System32\Tasks\{F1EE77D7-94D4-48C7-ADFB-637152AF86A9} => pcalua.exe -a "C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.11.10\GUninstaller.exe" -c -uprtc -aname='Babylon Toolbar' -bname=bbl -key "BabylonToolbar" Task: {223A8EEE-7CF8-46D4-BC6B-4C1BD6CCC6E5} - System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-6 => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-6.exe <==== ATTENTION Task: {3E737DC4-5013-4AD5-A8AD-6A5932D1B556} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Ja\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION Task: {537C8414-E145-419C-9672-FFBB1CB681D4} - System32\Tasks\LuckyTab => C:\Program Files\LuckyTab\LuckyTab.exe <==== ATTENTION Task: {7689C934-A3FB-4125-A5B7-15E7EB27A8DB} - System32\Tasks\{17D1DD41-F79A-47D2-A370-63D3C0350524} => pcalua.exe -a E:\Installer.exe -d E:\ Task: {78E3ED00-4C80-4735-A869-513EE8B4ACEB} - System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5_user => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-5.exe <==== ATTENTION Task: {7B039CF8-E151-43B3-A71E-6A97ACF9F648} - System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-7 => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-7.exe <==== ATTENTION Task: {7B92C51E-3B4A-4ACA-BDF6-9A08B401B8C5} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: {83CA9A64-0FF0-4003-94FC-FC5AE3159419} - System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-10_user => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-10.exe <==== ATTENTION Task: {8996799E-919E-4898-9391-F74D87649C5A} - System32\Tasks\{328DDE31-E18D-4CD1-B892-063355CC970D} => pcalua.exe -a "C:\Program Files\Babylon\Babylon-Pro\Utils\uninstbb.exe" Task: {8A864F9A-5299-41A5-811D-4ADF4433EBD8} - System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5 => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-5.exe <==== ATTENTION Task: {B94702EE-3DB2-4CB7-8088-78BB76144D3E} - System32\Tasks\Periodic Synchronize Task => c:\programdata\{1bc1ea52-93bf-5c1a-1bc1-1ea5293ba94a}\hqghumeaylnlf.exe <==== ATTENTION Task: {BA1B609C-ED6A-4B4D-BA3F-9ACC17A43DDB} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: {C15C604E-0715-4F12-849D-75BF378FF399} - System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-4 => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-4.exe <==== ATTENTION Task: C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-6.job => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-6.exe <==== ATTENTION Task: C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-7.job => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-7.exe <==== ATTENTION Task: C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-10_user.job => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-10.exe <==== ATTENTION Task: C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-4.job => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-4.exe <==== ATTENTION Task: C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5.job => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-5.exe <==== ATTENTION Task: C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5_user.job => C:\Program Files\SavePass 1.1\8a4da2f0-6def-4f34-ab69-a1c786022b55-5.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\globalupdate.exe <==== ATTENTION Task: C:\Windows\Tasks\Periodic Synchronize Task.job => c:\programdata\{1bc1ea52-93bf-5c1a-1bc1-1ea5293ba94a}\hqghumeaylnlf.exe <==== ATTENTION c:\programdata\{1bc1ea52-93bf-5c1a-1bc1-1ea5293ba94a} C:\Program Files\globalUpdate C:\Program Files\SavePass 1.1 C:\Program Files\Babylon C:\Users\Ja\AppData\Local\SmartWeb HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" HKLM\...\Run: [gmsd_pl_114] => [X] IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe HKLM\...\AppCertDlls: [x64] -> c:\program files\browser tab search by ask\safetynut\x64\safetycrt.dll HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Browser Tab Search by Ask\SafetyNut\safetycrt.dll ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File c:\program files\browser tab search by ask GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-70149214-1339082029-3386996294-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsur...ZXCXXXX6RY0HZXC HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsur...ZXCXXXX6RY0HZXC SearchScopes: HKLM -> DefaultScope value is missing SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.as...q={searchTerms} Toolbar: HKU\S-1-5-21-70149214-1339082029-3386996294-1000 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsur...ZXCXXXX6RY0HZXC FF NewTab: https://pl.search.ya...gn_150727__yaff FF HKLM\...\Firefox\Extensions: [searchengine@gmail.com] - C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\r5ks1og2.default\extensions\searchengine@gmail.com FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\r5ks1og2.default\extensions\faststartff@gmail.com FF HKLM\...\Firefox\Extensions: [searchffv2@gmail.com] - C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\r5ks1og2.default\extensions\searchffv2@gmail.com FF HKLM\...\Firefox\Extensions: [sweetsearch@gmail.com] - C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\r5ks1og2.default\extensions\sweetsearch@gmail.com S2 SafetyNutManager; C:\Program Files\Browser Tab Search by Ask\SafetyNut\SafetyNutManager.exe [X] 3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x32.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S1 F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Browser Tab Search by Ask\SafetyNut\configmgrc1.cfg [X] S1 innfd_1_10_0_13; system32\drivers\innfd_1_10_0_13.sys [X] S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 usbbus; system32\DRIVERS\lgusbbus.sys [X] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\x264vfw\Uninstall x264vfw.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Milionerzy\Milionerzy.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Milionerzy\Usuń program Milionerzy.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Monopoly Here & Now Edition\Play Monopoly Here & Now Edition.lnk C:\Users\Ja\Music\mariuszek\Mike Candys feat. Evelyn & Patrick Miller - 2012 (If The World Would End) (radio edit).lnk C:\Users\Ja\Music\mariuszek\Old Hits Mix Dj BuLL.mp3.lnk C:\Users\Ja\Music\mariuszek\mariuszek\0809200248336bieg%20wejhera64[1] — skrót.lnk C:\Users\Ja\Music\mariuszek\mariuszek\Arka Gdynia 2 — skrót.lnk C:\Users\Ja\Music\mariuszek\mariuszek\Arsenal 01 — skrót.lnk C:\Users\Ja\Music\mariuszek\mariuszek\Balkonik — skrót.lnk C:\Users\Ja\Music\mariuszek\mariuszek\Dla Mariuszka — skrót.lnk C:\Users\Ja\Music\mariuszek\mariuszek\Goku — skrót.lnk C:\Users\Ja\Music\mariuszek\mariuszek\Kusicielka — skrót.lnk C:\Users\Ja\Music\mariuszek\mariuszek\Obraz 0003 — skrót.lnk EmptyTemp: ***************** HKU\S-1-5-21-70149214-1339082029-3386996294-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => value removed successfully. "C:\Users\Ja\AppData\Roaming\newnext.me" => File/Folder not found. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie. ========= End of Reg: ========= "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DA5EFBF-EA8B-4524-B765-C852458A30B9}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DA5EFBF-EA8B-4524-B765-C852458A30B9}" => key removed successfully. C:\Windows\System32\Tasks\{F1EE77D7-94D4-48C7-ADFB-637152AF86A9} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F1EE77D7-94D4-48C7-ADFB-637152AF86A9}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{223A8EEE-7CF8-46D4-BC6B-4C1BD6CCC6E5}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{223A8EEE-7CF8-46D4-BC6B-4C1BD6CCC6E5}" => key removed successfully. C:\Windows\System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-6 => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-6" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E737DC4-5013-4AD5-A8AD-6A5932D1B556}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E737DC4-5013-4AD5-A8AD-6A5932D1B556}" => key removed successfully. C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{537C8414-E145-419C-9672-FFBB1CB681D4}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{537C8414-E145-419C-9672-FFBB1CB681D4}" => key removed successfully. C:\Windows\System32\Tasks\LuckyTab => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LuckyTab" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7689C934-A3FB-4125-A5B7-15E7EB27A8DB}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7689C934-A3FB-4125-A5B7-15E7EB27A8DB}" => key removed successfully. C:\Windows\System32\Tasks\{17D1DD41-F79A-47D2-A370-63D3C0350524} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{17D1DD41-F79A-47D2-A370-63D3C0350524}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{78E3ED00-4C80-4735-A869-513EE8B4ACEB}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78E3ED00-4C80-4735-A869-513EE8B4ACEB}" => key removed successfully. C:\Windows\System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5_user => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8a4da2f0-6def-4f34-ab69-a1c786022b55-5_user" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7B039CF8-E151-43B3-A71E-6A97ACF9F648}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B039CF8-E151-43B3-A71E-6A97ACF9F648}" => key removed successfully. C:\Windows\System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-7 => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-7" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B92C51E-3B4A-4ACA-BDF6-9A08B401B8C5}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B92C51E-3B4A-4ACA-BDF6-9A08B401B8C5}" => key removed successfully. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{83CA9A64-0FF0-4003-94FC-FC5AE3159419}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83CA9A64-0FF0-4003-94FC-FC5AE3159419}" => key removed successfully. C:\Windows\System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-10_user => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8a4da2f0-6def-4f34-ab69-a1c786022b55-10_user" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8996799E-919E-4898-9391-F74D87649C5A}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8996799E-919E-4898-9391-F74D87649C5A}" => key removed successfully. C:\Windows\System32\Tasks\{328DDE31-E18D-4CD1-B892-063355CC970D} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{328DDE31-E18D-4CD1-B892-063355CC970D}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8A864F9A-5299-41A5-811D-4ADF4433EBD8}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A864F9A-5299-41A5-811D-4ADF4433EBD8}" => key removed successfully. C:\Windows\System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5 => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8a4da2f0-6def-4f34-ab69-a1c786022b55-5" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B94702EE-3DB2-4CB7-8088-78BB76144D3E}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B94702EE-3DB2-4CB7-8088-78BB76144D3E}" => key removed successfully. C:\Windows\System32\Tasks\Periodic Synchronize Task => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Periodic Synchronize Task" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BA1B609C-ED6A-4B4D-BA3F-9ACC17A43DDB}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA1B609C-ED6A-4B4D-BA3F-9ACC17A43DDB}" => key removed successfully. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C15C604E-0715-4F12-849D-75BF378FF399}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C15C604E-0715-4F12-849D-75BF378FF399}" => key removed successfully. C:\Windows\System32\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-4 => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8a4da2f0-6def-4f34-ab69-a1c786022b55-4" => key removed successfully. C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-6.job => moved successfully. C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-1-7.job => moved successfully. C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-10_user.job => moved successfully. C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-4.job => moved successfully. C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5.job => moved successfully. C:\Windows\Tasks\8a4da2f0-6def-4f34-ab69-a1c786022b55-5_user.job => moved successfully. C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => moved successfully. C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => moved successfully. C:\Windows\Tasks\Periodic Synchronize Task.job => moved successfully. "c:\programdata\{1bc1ea52-93bf-5c1a-1bc1-1ea5293ba94a}" => File/Folder not found. "C:\Program Files\globalUpdate" => File/Folder not found. "C:\Program Files\SavePass 1.1" => File/Folder not found. "C:\Program Files\Babylon" => File/Folder not found. "C:\Users\Ja\AppData\Local\SmartWeb" => File/Folder not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart" => key removed successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys" => key removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_114 => value removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe" => key removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe" => key removed successfully. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => value removed successfully. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x86 => value removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending" => key removed successfully. HKCR\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced" => key removed successfully. HKCR\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing" => key removed successfully. HKCR\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. "c:\program files\browser tab search by ask" => File/Folder not found. C:\Windows\system32\GroupPolicy\Machine => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Policies\Google" => key removed successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully. "HKU\S-1-5-21-70149214-1339082029-3386996294-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}" => key removed successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} => key not found. HKU\S-1-5-21-70149214-1339082029-3386996294-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C55BBCD6-41AD-48AD-9953-3609C48EACC7} => value removed successfully. HKCR\CLSID\{C55BBCD6-41AD-48AD-9953-3609C48EACC7} => key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully Firefox "newtab" removed successfully. HKLM\Software\Mozilla\Firefox\Extensions\\searchengine@gmail.com => value removed successfully. HKLM\Software\Mozilla\Firefox\Extensions\\faststartff@gmail.com => value removed successfully. HKLM\Software\Mozilla\Firefox\Extensions\\searchffv2@gmail.com => value removed successfully. HKLM\Software\Mozilla\Firefox\Extensions\\sweetsearch@gmail.com => value removed successfully. SafetyNutManager => service removed successfully. 3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x32.sys [X] => Error: No automatic fix found for this entry. EagleXNt => service removed successfully. F06DEFF2-5B9C-490D-910F-35D3A91196222 => service removed successfully. innfd_1_10_0_13 => service removed successfully. innfd_1_10_0_14 => service removed successfully. IpInIp => service removed successfully. NwlnkFlt => service removed successfully. NwlnkFwd => service removed successfully. usbbus => service removed successfully. UsbDiag => service removed successfully. USBModem => service removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\x264vfw\Uninstall x264vfw.lnk => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Milionerzy\Milionerzy.lnk => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Milionerzy\Usuń program Milionerzy.lnk => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Monopoly Here & Now Edition\Play Monopoly Here & Now Edition.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\Mike Candys feat. Evelyn & Patrick Miller - 2012 (If The World Would End) (radio edit).lnk => moved successfully. C:\Users\Ja\Music\mariuszek\Old Hits Mix Dj BuLL.mp3.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\0809200248336bieg%20wejhera64[1] — skrót.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\Arka Gdynia 2 — skrót.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\Arsenal 01 — skrót.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\Balkonik — skrót.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\Dla Mariuszka — skrót.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\Goku — skrót.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\Kusicielka — skrót.lnk => moved successfully. C:\Users\Ja\Music\mariuszek\mariuszek\Obraz 0003 — skrót.lnk => moved successfully. EmptyTemp: => 348.2 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 14:02:14 ====