Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-01-2014 Ran by Myszka at 2014-01-23 19:17:06 Run:1 Running from C:\Users\Myszka\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe () C:\Program Files\Web Assistant\ExtensionUpdaterService.exe () C:\Users\Myszka\AppData\Roaming\pwo6\svchost.exe () C:\Users\Myszka\AppData\Local\Temp\_MEI24882\bin\winlogon.exe () C:\Program Files\RightSurf\updateRightSurf.exe R2 Update RightSurf; C:\Program Files\RightSurf\updateRightSurf.exe [97056 2014-01-10] () R2 Web Assistant; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-01-29] () R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-02] (Cherished Technololgy LIMITED) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKCU\...\Run: [] - [x] HKCU\...\Run: [pwo6] - C:\Users\Myszka\AppData\Roaming\pwo6\svchost.exe [7321417 2013-10-09] () HKCU\...\Run: [NextLive] - C:\Users\Myszka\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe) Task: {4402CEE0-B23E-49DC-B57F-343F473870A9} - System32\Tasks\a2zLyrics-1-firefoxinstaller => C:\Program Files\a2zLyrics-1\a2zLyrics-1-firefoxinstaller.exe <==== ATTENTION Task: {7A777AA2-8CBB-4848-B81C-2CCF02406E8B} - System32\Tasks\EPUpdater => C:\Users\Myszka\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-08-04] () <==== ATTENTION Task: {90BF8550-365B-4792-9348-EE6E37E65AB6} - \AdobeFlashPlayerUpdate No Task File Task: {AA8158DA-D600-46C1-B046-015432F0E3F4} - System32\Tasks\e-pity2012_styczen => C:\Program Files\e-file\e-pity2012\signxml.exe Task: {B30E3A21-0A82-46BF-B976-02D5ED8043F2} - \AdobeFlashPlayerUpdate 2 No Task File Task: {ED9044CC-8193-47E6-85E5-DBEA391C8AF4} - System32\Tasks\temp_a2zLyrics-1-enabler => C:\Users\Myszka\AppData\Local\Temp\nsrF733.tmp\a2zLyrics-1-enabler.exe <==== ATTENTION Task: {F391A995-EEBC-4E67-AE30-3EC0B9424D32} - System32\Tasks\e-pity2012_kwiecien => C:\Program Files\e-file\e-pity2012\signxml.exe Task: {F64824B4-ADC6-4B2A-99F3-9BB073D85BBB} - System32\Tasks\a2zLyrics-1-codedownloader => C:\Program Files\a2zLyrics-1\a2zLyrics-1-codedownloader.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=3192&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=hp&from=cor&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&ts=1384108367 HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=3192 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=3192&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=3192&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=hp&from=cor&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&ts=1384108367 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1388687266&from=wpm0102&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=hp&from=cor&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&ts=1384108367 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=hp&from=cor&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&ts=1384108367 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1388687266&from=wpm0102&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=3192 HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=3192&st=bs&q= URLSearchHook: HKCU - (No Name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&ts=1384108367 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388687266&from=wpm0102&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&q={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.certified-toolbar.com?si=41460&st=bs&tid=3192&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388687266&from=wpm0102&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&q={searchTerms} SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=0A09001B77DD8F5B&affID=119357&tsp=5021 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?aff=1&src=sp&cf=9fbf9679-256b-11e1-b99c-0016d3ea2c06&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=0A09001B77DD8F5B&affID=119357&tsp=5021 SearchScopes: HKCU - {29C52667-3732-4BDB-BC79-6B76F74B94BD} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=YYYYYYYYPL&apn_uid=E3183166-1365-4633-BEB6-66B2DF75D33B&apn_sauid=E10C82B8-E20E-48DC-952A-56D44A06857F SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388687266&from=wpm0102&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX&q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://www.claro-search.com/?q={searchTerms}&affID=117423&tt=5112_7&babsrc=SP_ss&mntrId=0a0919f1000000000000001b77dd8f5b SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb203?a=6R8vmOCu38&search={searchTerms}&i=26 BHO: No Name - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - No File BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll () BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll (Montera Technologeis LTD) BHO: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.) BHO: RightSurf - {88be1aa9-6740-461c-9e3e-f35eb8fa741c} - C:\Program Files\RightSurf\RightSurfbho.dll (RightSurf) Toolbar: HKLM - VShareToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.) Toolbar: HKLM - Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll (Montera Technologeis LTD) Toolbar: HKLM - No Name - {9E131A93-EED7-4BEB-B015-A0ADB30B5646} - No File Toolbar: HKCU - No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} - No File FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll (vShare.tv ) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\delta-homes.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\dosearches.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Web Search.xml FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox FF HKLM\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] - C:\Program Files\Web Assistant\Firefox FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe http://www.delta-homes.com/?type=sc&ts=1388687266&from=wpm0102&uid=HitachiXHTS541612J9SA00_SB2504H6JGDMDUJGDMDUX S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [x] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] C:\ProgramData\eSafe C:\Users\Myszka\.android C:\Users\Myszka\daemonprocess.txt C:\Users\Myszka\AppData\Local\cache C:\Users\Myszka\AppData\Local\genienext C:\Users\Myszka\AppData\Local\Google\Chrome C:\Users\Myszka\AppData\Local\Mobogenie C:\Users\Myszka\AppData\Local\Temp\_MEI24882 C:\Users\Myszka\AppData\Roaming\BabSolution C:\Users\Myszka\AppData\Roaming\Babylon C:\Users\Myszka\AppData\Roaming\dosearches C:\Users\Myszka\AppData\Roaming\File Scout C:\Users\Myszka\AppData\Roaming\newnext.me C:\Users\Myszka\AppData\Roaming\OpenCandy C:\Users\Myszka\AppData\Roaming\pwo6 C:\Users\Myszka\AppData\Roaming\systweak C:\Users\Myszka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie C:\Users\Myszka\Documents\Mobogenie C:\Users\Myszka\Downloads\Farbar Recovery Scan Tool.exe C:\Users\Myszka\Downloads\FRST.* C:\Windows\system32\log Reg: reg delete HKLM\SOFTWARE\Google\Chrome /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ***************** [1584] C:\ProgramData\WPM\wprotectmanager.exe => Process closed successfully. [2556] C:\Program Files\Web Assistant\ExtensionUpdaterService.exe => Process closed successfully. [3032] C:\Users\Myszka\AppData\Roaming\pwo6\svchost.exe => Process closed successfully. [5676] C:\Users\Myszka\AppData\Local\Temp\_MEI24882\bin\winlogon.exe => Process closed successfully. [2640] C:\Program Files\RightSurf\updateRightSurf.exe => Process closed successfully. Update RightSurf => Service deleted successfully. Web Assistant => Service deleted successfully. Wpm => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\pwo6 => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4402CEE0-B23E-49DC-B57F-343F473870A9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4402CEE0-B23E-49DC-B57F-343F473870A9} => Key deleted successfully. C:\Windows\System32\Tasks\a2zLyrics-1-firefoxinstaller => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a2zLyrics-1-firefoxinstaller => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A777AA2-8CBB-4848-B81C-2CCF02406E8B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A777AA2-8CBB-4848-B81C-2CCF02406E8B} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{90BF8550-365B-4792-9348-EE6E37E65AB6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90BF8550-365B-4792-9348-EE6E37E65AB6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AA8158DA-D600-46C1-B046-015432F0E3F4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA8158DA-D600-46C1-B046-015432F0E3F4} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2012_styczen => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2012_styczen => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B30E3A21-0A82-46BF-B976-02D5ED8043F2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B30E3A21-0A82-46BF-B976-02D5ED8043F2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED9044CC-8193-47E6-85E5-DBEA391C8AF4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED9044CC-8193-47E6-85E5-DBEA391C8AF4} => Key deleted successfully. C:\Windows\System32\Tasks\temp_a2zLyrics-1-enabler => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\temp_a2zLyrics-1-enabler => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F391A995-EEBC-4E67-AE30-3EC0B9424D32} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F391A995-EEBC-4E67-AE30-3EC0B9424D32} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2012_kwiecien => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2012_kwiecien => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F64824B4-ADC6-4B2A-99F3-9BB073D85BBB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F64824B4-ADC6-4B2A-99F3-9BB073D85BBB} => Key deleted successfully. C:\Windows\System32\Tasks\a2zLyrics-1-codedownloader => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a2zLyrics-1-codedownloader => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Default_Page_URL => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Default_Page_URL => Value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{29C52667-3732-4BDB-BC79-6B76F74B94BD} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{29C52667-3732-4BDB-BC79-6B76F74B94BD} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000F18F2-09EB-4A59-82B2-5AE4184C39C3} => Key deleted successfully. HKCR\CLSID\{000F18F2-09EB-4A59-82B2-5AE4184C39C3} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} => Key deleted successfully. HKCR\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} => Key deleted successfully. HKCR\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} => Key deleted successfully. HKCR\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88be1aa9-6740-461c-9e3e-f35eb8fa741c} => Key deleted successfully. HKCR\CLSID\{88be1aa9-6740-461c-9e3e-f35eb8fa741c} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => Value deleted successfully. HKCR\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{F9639E4A-801B-4843-AEE3-03D9DA199E77} => Value deleted successfully. HKCR\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{9E131A93-EED7-4BEB-B015-A0ADB30B5646} => Value deleted successfully. HKCR\CLSID\{9E131A93-EED7-4BEB-B015-A0ADB30B5646} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{687578B9-7132-4A7A-80E4-30EE31099E03} => Value deleted successfully. HKCR\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03} => Key not found. C:\Program Files\mozilla firefox\searchplugins\babylon.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\delta-homes.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\dosearches.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\Web Search.xml => Moved successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} => Value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052} => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. ewusbmbb => Service deleted successfully. ew_hwusbdev => Service deleted successfully. ew_usbenumfilter => Service deleted successfully. huawei_enumerator => Service deleted successfully. hwdatacard => Service deleted successfully. C:\ProgramData\eSafe => Moved successfully. C:\Users\Myszka\.android => Moved successfully. C:\Users\Myszka\daemonprocess.txt => Moved successfully. C:\Users\Myszka\AppData\Local\cache => Moved successfully. C:\Users\Myszka\AppData\Local\genienext => Moved successfully. "C:\Users\Myszka\AppData\Local\Google\Chrome" directory move: C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Preferences.acp => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Web Data => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Web Data.acp => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\appCntrl.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\bg.html => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\bg.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\CrmAdpt.dll => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\ct.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\CTB.dll => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\dpk.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\hprtkMsg.htm => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\hprtkMsg.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\json2.min.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\logo.png => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0_0\manifest.json => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\appCntrl.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\bg.html => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\bg.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\CrmAdpt.dll => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\ct.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\CTB.dll => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\dpk.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\hprtkMsg.htm => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\hprtkMsg.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\json2.min.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\logo.png => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn\1.0\manifest.json => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.573_0\background.html => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.573_0\main.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.573_0\manifest.json => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.573_0\npbrowserext.dll => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.573_0\resources\localscript.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.573_0\libraries\ContentScript.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.573_0\libraries\DataExchangeScript.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\BabMaint.x => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\bg.html => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\bg.js => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\BUSolution.dll => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\manifest.json => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\mixidj128.png => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\mixidj48.png => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\NPObject.dll => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\redirect.html => Moved successfully. C:\Users\Myszka\AppData\Local\Google\Chrome\User Data\Default\Extensions\boipimhfjpakfgckhbljjengakjhkcbp\1.1\redirect.js => Moved successfully. Could not move "C:\Users\Myszka\AppData\Local\Google\Chrome" directory. => Scheduled to move on reboot. C:\Users\Myszka\AppData\Local\Mobogenie => Moved successfully. C:\Users\Myszka\AppData\Local\Temp\_MEI24882 => Moved successfully. C:\Users\Myszka\AppData\Roaming\BabSolution => Moved successfully. C:\Users\Myszka\AppData\Roaming\Babylon => Moved successfully. C:\Users\Myszka\AppData\Roaming\dosearches => Moved successfully. C:\Users\Myszka\AppData\Roaming\File Scout => Moved successfully. C:\Users\Myszka\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Myszka\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Myszka\AppData\Roaming\pwo6 => Moved successfully. C:\Users\Myszka\AppData\Roaming\systweak => Moved successfully. C:\Users\Myszka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie => Moved successfully. C:\Users\Myszka\Documents\Mobogenie => Moved successfully. C:\Users\Myszka\Downloads\Farbar Recovery Scan Tool.exe => Moved successfully. C:\Users\Myszka\Downloads\FRST.* => Moved successfully. C:\Windows\system32\log => Moved successfully. ========= reg delete HKLM\SOFTWARE\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-01-23 19:52:25)<= C:\Users\Myszka\AppData\Local\Google\Chrome => Is moved successfully. ==== End of Fixlog ====