Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-12-2013 03 Ran by Marek at 2013-12-12 23:50:47 Run:1 Running from C:\Users\Marek\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** (BonanzaDeals) C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe () C:\Users\Marek\AppData\Local\tuto4pc_pl_1\supt4pc_pl_1.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe R2 BitGuard; C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3780064 2013-11-18] () S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-01] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-01] (BonanzaDeals) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) R2 supt4pc_pl_1; C:\Users\Marek\AppData\Local\tuto4pc_pl_1\supt4pc_pl_1.exe [3055976 2012-11-05] () S2 Update BatBrowse; "C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe" [x] S2 Util BatBrowse; "C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe" [x] HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKCU\...\Run: [AshSnap] - C:\Program Files (x86)\Ashampoo\Ashampoo Snap 6\ashsnap.exe HKCU\...\Run: [RGSC] - C:\Program Files (x86)\Rockstar Games Social Club\RGSCLauncher.exe /silent HKCU\...\Run: [BackgroundContainer] - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Marek\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun HKLM-x32\...\Run: [NeroFilterCheck] - C:\Windows\system32\NeroCheck.exe HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe Startup: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration .LNK HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=CA82666D57EEB7A4&affID=119357&tsp=5015 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://search.conduit.com?searchsource=10&ctid=ct3220468 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = URLSearchHook: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) URLSearchHook: HKCU - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) URLSearchHook: HKCU - (No Name) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No File SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=CA82666D57EEB7A4&affID=119357&tsp=5015 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {AC3F5DDF-BF4E-4967-B2EE-59251E88EDA2} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033 SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = SearchScopes: HKCU - ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± vË°!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁwľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)x­ä­ URL = BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20121103174247.dll No File BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20121103174247.dll No File BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll No File Toolbar: HKLM-x32 - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTo0.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File Toolbar: HKCU - No Name - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\qone8.xml FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Task: {0297BD3A-AFF9-473D-A7EA-C8208826FFA5} - System32\Tasks\{7B5C1D1E-0B1B-4D84-9669-383BA2DA9DDB} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {1189978C-C21A-4A62-B4F3-29700C354D1F} - System32\Tasks\{B945EA3D-2A91-4A6D-BCD7-24AD6ABD0D77} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {1743898C-5463-4C0E-ADFA-AF0AF803E956} - System32\Tasks\{4F2DE0DB-689A-4969-B8B1-AA5DC78DA581} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?source=lightinstaller&page=tsProgressBar Task: {2E68D97D-C96D-46D4-A211-C2652F9CDA1D} - System32\Tasks\{415D6440-47DA-4A12-B46C-06CEA1995B61} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {3C867F45-3462-4F44-8745-4429E02D2088} - System32\Tasks\{EFB8E1C5-CFBF-4D59-B5B4-30CC12B8A09A} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=6.3.0.107&LastError=12002 Task: {3D55D1A7-2C2A-4FC4-B823-BF2D7FE043FD} - System32\Tasks\{1119B3B2-C85F-4819-8798-6BF7805604DE} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {562D16A7-727A-48FE-B0A6-50C64935A935} - System32\Tasks\{98DDA102-BBAB-4E8A-A878-970321670ED2} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {6A169E4C-C18E-4660-A640-14A572298C63} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-01] (BonanzaDeals) Task: {7167B3FC-9083-4CD4-AF3C-116EAB292A3A} - System32\Tasks\{B1C8D972-5A88-493D-B867-EF7C00ACDABE} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsInstall Task: {A5C35279-AAC9-4F19-AE9E-233429EBF80C} - System32\Tasks\BonanzaDealsUpdate => C:\Program Task: {A8B675E4-C229-4F0B-85F8-7553A2CC6BBF} - System32\Tasks\{CAC3FD2E-D424-486D-A533-0A6045B29D4A} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {AF1F6A03-1D55-4A5F-BF0A-F1C80A4D3F87} - System32\Tasks\{4B5D9299-738A-4DE3-932E-BDCE88B3D6A2} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {B73910D3-2A23-4AE7-AB73-9755397EC9F5} - System32\Tasks\{BFFF2D71-F074-4932-A2CA-5D0116AEEEF0} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?source=lightinstaller&page=tsProgressBar Task: {BA0094B4-1237-4408-AF3D-43B4E2F4FC35} - System32\Tasks\{3752C818-BFE2-4734-8D8D-8D040FB0794A} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {C7F4305E-8999-473C-9AE2-2322B7947FE3} - System32\Tasks\{73783A4B-E09D-4EFF-92EB-27339BEA6D34} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: {CA13310E-3B41-40C3-B8E1-6D853515A773} - System32\Tasks\{DA0A83FB-193D-43E3-9C78-0C1A3FF8FC5D} => Firefox.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?source=lightinstaller&page=tsProgressBar Task: {DA2FEDFF-0EC5-4A26-9F77-B486A1DCF87D} - System32\Tasks\BackgroundContainer Startup Task => C:\Users\Marek\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll [2013-10-14] (Conduit Ltd.) Task: {EE28AB3F-FC8A-44BB-AA5E-9E9D761BD7E4} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-01] (BonanzaDeals) Task: {EEBFA431-004B-479E-AE3F-BA5F854FF3EF} - System32\Tasks\{CDD51755-59B3-4B02-A339-0CA57CCB5765} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?page=tsProgressBar Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe C:\Users\wangzhisong C:\Users\Marek\daemonprocess.txt C:\Users\Marek\AppData\Local\Mobogenie C:\Users\Marek\AppData\Local\cache C:\Users\Marek\AppData\Roaming\Babylon C:\Users\Marek\Documents\Mobogenie C:\Program Files (x86)\Mobogenie Reg: reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /t REG_SZ /d C:\Windows\system32\nvinitx.dll /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /t REG_SZ /d C:\Windows\SysWOW64\nvinit.dll /f ***************** [2492] C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe => Process closed successfully. C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe => No running process found C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe => No running process found [2988] C:\Users\Marek\AppData\Local\tuto4pc_pl_1\supt4pc_pl_1.exe => Process closed successfully. [4204] C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe => Process closed successfully. BitGuard => Service not found. bonanzadealslive => Service deleted successfully. bonanzadealslivem => Service deleted successfully. McComponentHostService => Service deleted successfully. supt4pc_pl_1 => Service deleted successfully. Update BatBrowse => Service deleted successfully. Util BatBrowse => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AshSnap => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\RGSC => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\BackgroundContainer => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration .LNK => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AC3F5DDF-BF4E-4967-B2EE-59251E88EDA2} => Key deleted successfully. HKCR\CLSID\{AC3F5DDF-BF4E-4967-B2EE-59251E88EDA2} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => Key deleted successfully. HKCR\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± vË°!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁwľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)x­ä­ => Key not found. HKCR\CLSID\ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± vË°!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁwľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)x­ä­ => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKCR\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => Key deleted successfully. HKCR\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully. HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Value deleted successfully. HKCR\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Value deleted successfully. HKCR\CLSID\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Key not found. HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully. HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key deleted successfully. HKCR\Wow6432Node\PROTOCOLS\Handler\skype-ie-addon-data => Key not found. HKCR\Wow6432Node\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key deleted successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin => Key deleted successfully. C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll => Moved successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3 => Key deleted successfully. C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll => Moved successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9 => Key deleted successfully. C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. C:\Program Files (x86)\mozilla firefox\searchplugins\qone8.xml => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60} => Value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0297BD3A-AFF9-473D-A7EA-C8208826FFA5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0297BD3A-AFF9-473D-A7EA-C8208826FFA5} => Key deleted successfully. C:\Windows\System32\Tasks\{7B5C1D1E-0B1B-4D84-9669-383BA2DA9DDB} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7B5C1D1E-0B1B-4D84-9669-383BA2DA9DDB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1189978C-C21A-4A62-B4F3-29700C354D1F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1189978C-C21A-4A62-B4F3-29700C354D1F} => Key deleted successfully. C:\Windows\System32\Tasks\{B945EA3D-2A91-4A6D-BCD7-24AD6ABD0D77} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B945EA3D-2A91-4A6D-BCD7-24AD6ABD0D77} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1743898C-5463-4C0E-ADFA-AF0AF803E956} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1743898C-5463-4C0E-ADFA-AF0AF803E956} => Key deleted successfully. C:\Windows\System32\Tasks\{4F2DE0DB-689A-4969-B8B1-AA5DC78DA581} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4F2DE0DB-689A-4969-B8B1-AA5DC78DA581} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2E68D97D-C96D-46D4-A211-C2652F9CDA1D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E68D97D-C96D-46D4-A211-C2652F9CDA1D} => Key deleted successfully. C:\Windows\System32\Tasks\{415D6440-47DA-4A12-B46C-06CEA1995B61} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{415D6440-47DA-4A12-B46C-06CEA1995B61} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C867F45-3462-4F44-8745-4429E02D2088} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C867F45-3462-4F44-8745-4429E02D2088} => Key deleted successfully. C:\Windows\System32\Tasks\{EFB8E1C5-CFBF-4D59-B5B4-30CC12B8A09A} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EFB8E1C5-CFBF-4D59-B5B4-30CC12B8A09A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D55D1A7-2C2A-4FC4-B823-BF2D7FE043FD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D55D1A7-2C2A-4FC4-B823-BF2D7FE043FD} => Key deleted successfully. C:\Windows\System32\Tasks\{1119B3B2-C85F-4819-8798-6BF7805604DE} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1119B3B2-C85F-4819-8798-6BF7805604DE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{562D16A7-727A-48FE-B0A6-50C64935A935} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{562D16A7-727A-48FE-B0A6-50C64935A935} => Key deleted successfully. C:\Windows\System32\Tasks\{98DDA102-BBAB-4E8A-A878-970321670ED2} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{98DDA102-BBAB-4E8A-A878-970321670ED2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6A169E4C-C18E-4660-A640-14A572298C63} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A169E4C-C18E-4660-A640-14A572298C63} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7167B3FC-9083-4CD4-AF3C-116EAB292A3A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7167B3FC-9083-4CD4-AF3C-116EAB292A3A} => Key deleted successfully. C:\Windows\System32\Tasks\{B1C8D972-5A88-493D-B867-EF7C00ACDABE} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B1C8D972-5A88-493D-B867-EF7C00ACDABE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A5C35279-AAC9-4F19-AE9E-233429EBF80C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A5C35279-AAC9-4F19-AE9E-233429EBF80C} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A8B675E4-C229-4F0B-85F8-7553A2CC6BBF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8B675E4-C229-4F0B-85F8-7553A2CC6BBF} => Key deleted successfully. C:\Windows\System32\Tasks\{CAC3FD2E-D424-486D-A533-0A6045B29D4A} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CAC3FD2E-D424-486D-A533-0A6045B29D4A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AF1F6A03-1D55-4A5F-BF0A-F1C80A4D3F87} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AF1F6A03-1D55-4A5F-BF0A-F1C80A4D3F87} => Key deleted successfully. C:\Windows\System32\Tasks\{4B5D9299-738A-4DE3-932E-BDCE88B3D6A2} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4B5D9299-738A-4DE3-932E-BDCE88B3D6A2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B73910D3-2A23-4AE7-AB73-9755397EC9F5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B73910D3-2A23-4AE7-AB73-9755397EC9F5} => Key deleted successfully. C:\Windows\System32\Tasks\{BFFF2D71-F074-4932-A2CA-5D0116AEEEF0} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BFFF2D71-F074-4932-A2CA-5D0116AEEEF0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BA0094B4-1237-4408-AF3D-43B4E2F4FC35} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA0094B4-1237-4408-AF3D-43B4E2F4FC35} => Key deleted successfully. C:\Windows\System32\Tasks\{3752C818-BFE2-4734-8D8D-8D040FB0794A} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3752C818-BFE2-4734-8D8D-8D040FB0794A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C7F4305E-8999-473C-9AE2-2322B7947FE3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7F4305E-8999-473C-9AE2-2322B7947FE3} => Key deleted successfully. C:\Windows\System32\Tasks\{73783A4B-E09D-4EFF-92EB-27339BEA6D34} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{73783A4B-E09D-4EFF-92EB-27339BEA6D34} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA13310E-3B41-40C3-B8E1-6D853515A773} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA13310E-3B41-40C3-B8E1-6D853515A773} => Key deleted successfully. C:\Windows\System32\Tasks\{DA0A83FB-193D-43E3-9C78-0C1A3FF8FC5D} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DA0A83FB-193D-43E3-9C78-0C1A3FF8FC5D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DA2FEDFF-0EC5-4A26-9F77-B486A1DCF87D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA2FEDFF-0EC5-4A26-9F77-B486A1DCF87D} => Key deleted successfully. C:\Windows\System32\Tasks\BackgroundContainer Startup Task => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EE28AB3F-FC8A-44BB-AA5E-9E9D761BD7E4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EE28AB3F-FC8A-44BB-AA5E-9E9D761BD7E4} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EEBFA431-004B-479E-AE3F-BA5F854FF3EF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEBFA431-004B-479E-AE3F-BA5F854FF3EF} => Key deleted successfully. C:\Windows\System32\Tasks\{CDD51755-59B3-4B02-A339-0CA57CCB5765} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CDD51755-59B3-4B02-A339-0CA57CCB5765} => Key deleted successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => Moved successfully. C:\Users\wangzhisong => Moved successfully. C:\Users\Marek\daemonprocess.txt => Moved successfully. C:\Users\Marek\AppData\Local\Mobogenie => Moved successfully. C:\Users\Marek\AppData\Local\cache => Moved successfully. C:\Users\Marek\AppData\Roaming\Babylon => Moved successfully. C:\Users\Marek\Documents\Mobogenie => Moved successfully. C:\Program Files (x86)\Mobogenie => Moved successfully. ========= reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /t REG_SZ /d C:\Windows\system32\nvinitx.dll /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /t REG_SZ /d C:\Windows\SysWOW64\nvinit.dll /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====