Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-06-2014 Ran by Lenovo at 2014-06-23 11:34:51 Run:1 Running from C:\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,userinit.exe,C:\windows\system32\MSDCSC\msdcsc.exe HKU\S-1-5-21-3914683434-684966938-2725549555-1000\...\Run: [LG LinkAir] => [X] HKU\S-1-5-21-3914683434-684966938-2725549555-1000\...\Policies\system: [EnableLUA] 0 AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found AppInit_DLLs: C:\PROGRA~3\WebPlat\WEBPLA~1.DLL => C:\ProgramData\WebPlat\WebPlat_x64.dll [4275200 2013-12-28] () AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll" File Not Found Startup: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk SSODL-x32: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File Task: {1FC85F66-012C-4F58-B762-E6B18C2AB758} - System32\Tasks\Express FilesUpdate => C:\Program Files (x86)\ExpressFiles\EFUpdater.exe <==== ATTENTION Task: {259AC2CF-EC24-460B-BBC8-57355F69A24D} - System32\Tasks\{E19CAE8B-731A-4E18-8438-BC2F2A1A87F4} => C:\Program Files (x86)\Ares\Ares.exe Task: {41CFBD2B-8539-4A5A-8BED-13968F8B4FD4} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION Task: {68738944-BE9C-42C0-BB2F-E90978AA4410} - \DealPlyUpdate No Task File <==== ATTENTION Task: {6A29DB99-DD47-4FC8-A97E-7DB756D21F42} - System32\Tasks\{5813D8AE-E1FF-47F3-A707-765886861780} => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe <==== ATTENTION Task: {6D1C469E-2BB9-4905-97D9-6CF0A29B32F4} - \Dealply No Task File <==== ATTENTION Task: {78A8EC62-4BB8-49E2-B08D-6B9F460077EA} - System32\Tasks\{B5471B4D-EF56-41E9-AC9C-8C66FD76D2C5} => C:\Program Files (x86)\Rockstar Games\Grand Theft Auto Vice City HQ\gta-vc.exe Task: {BD1C4908-49E6-4D3D-9F29-FCD5208D315C} - System32\Tasks\{C6B23001-7DC6-479F-B0C8-2B1A91AFB5B8} => C:\Program Files (x86)\Ares\Ares.exe Task: {EC1C60E5-BB77-4AD7-BE5A-C79235054718} - System32\Tasks\pc-dis-upd => C:\Program Files (x86)\PC Cleaners\PCCleaners.exe <==== ATTENTION Task: C:\windows\Tasks\Dealply.job => C:\Users\Lenovo\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\windows\Tasks\pc-dis-upd.job => C:\Program Files (x86)\PC Cleaners\PCCleaners.exe Task: C:\windows\Tasks\{5813D8AE-E1FF-47F3-A707-765886861780}.job => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe S4 976137e5; "C:\windows\system32\rundll32.exe" "c:\progra~3\webplat\WebPlatSvc.dll",service U3 BcmSqlStartupSvc; S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] U2 IviRegMgr; U2 RichVideo; U3 SQLWriter; HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" ProxyServer: 8.8.8.8:80 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1388677655&from=wpm0102&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1388677655&from=wpm0102&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1388677655&from=wpm0102&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1388677655&from=wpm0102&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {72CB84B9-2592-4ED9-BA51-DFBA0B98CDAA} URL = http://www.mysearchresults.com/search?c=2402&t=15&q={searchTerms} SearchScopes: HKCU - {F8D1CDFB-2BBE-4A5F-9B5F-7E1ED3EF2BB6} URL = http://websearch.ask.com/redirect?client=ie&tb=CIE&o=2240&src=kw&q={searchTerms}&locale=&apn_ptnrs=^A2T&apn_dtid=^YYYYYY^YY^PL&apn_uid=48ED29AD-0359-4560-A61F-1F00B8E6E180&apn_sauid=54F67EE8-CE5C-4DCF-9FA4-49B05BF76F87 BHO: ssafeWeeb - {1FBA780A-5830-77F9-BC55-90A8E6A4A7E2} - C:\Program Files (x86)\ssafeWeeb\x8a8X.x64.dll () BHO: EnujoyCoUpoonu - {4AED814F-11C3-535A-4462-B8D8D277DA6A} - C:\ProgramData\EnujoyCoUpoonu\0.x64.dll No File BHO: CoupExtension - {7C662EA3-0373-0B0D-4EF9-D0497505BA25} - C:\ProgramData\CoupExtension\swKl0X5Yd6.x64.dll No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Babylon.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\delta-homes.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\portaldosites.xml CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Lenovo\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2014-03-10] CHR HKCU\...\Chrome\Extension: [dknkjnkhedbanphkkpbpcgoblmkbfhlf] - C:\Users\Lenovo\AppData\Local\CRE\dknkjnkhedbanphkkpbpcgoblmkbfhlf.crx [2014-03-10] CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Lenovo\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2014-03-10] CHR HKLM-x32\...\Chrome\Extension: [dknkjnkhedbanphkkpbpcgoblmkbfhlf] - C:\Users\Lenovo\AppData\Local\CRE\dknkjnkhedbanphkkpbpcgoblmkbfhlf.crx [2014-03-10] CHR HKLM-x32\...\Chrome\Extension: [hggpkhijoeadmdfmlbdepfbngmhaldci] - C:\Program Files (x86)\DealPly\DealPly.crx [2014-04-08] CHR HKLM-x32\...\Chrome\Extension: [nbmafkdmkkckhggblphicnnhlgljnoje] - C:\Program Files (x86)\TornTV.com\torn2_10.crx [2014-04-11] CHR HKLM-x32\...\Chrome\Extension: [ohlfohjgijhjlpidbbnmcdooegafnnnm] - C:\Program Files (x86)\SockshareDownloader\SockshareDownloader10.crx [2012-11-15] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://google.pl" ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.portaldosites.com/?utm_source=b&utm_medium=slbnew&from=slbnew&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192&ts=1369508672 ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1388677655&from=wpm0102&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192 ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.portaldosites.com/?utm_source=b&utm_medium=slbnew&from=slbnew&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192&ts=1369508672 ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192&ts=1373111218 ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.portaldosites.com/?utm_source=b&utm_medium=slbnew&from=slbnew&uid=WDCXWD5000BEVT-24A0RT0_WD-WX41A907719277192&ts=1369508672 ShortcutWithArgument: C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://google.pl" AlternateDataStreams: C:\ProgramData:NT2 AlternateDataStreams: C:\Users\All Users:NT2 AlternateDataStreams: C:\ProgramData\Application Data:NT2 AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT2 AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 AlternateDataStreams: C:\ProgramData\Temp:07F6D9E4 AlternateDataStreams: C:\ProgramData\Temp:56E2E879 AlternateDataStreams: C:\Users\Lenovo\Dane aplikacji:NT AlternateDataStreams: C:\Users\Lenovo\Dane aplikacji:NT2 AlternateDataStreams: C:\Users\Lenovo\AppData\Roaming:NT AlternateDataStreams: C:\Users\Lenovo\AppData\Roaming:NT2 C:\Program Files (x86)\Desk 365 C:\ProgramData\pclunst.exe C:\ProgramData\PC1Data C:\ProgramData\EnujoyCoUpoonu C:\ProgramData\eSafe C:\ProgramData\InstallMate C:\ProgramData\ssafeWeeb C:\ProgramData\simplitec C:\ProgramData\WebPlat C:\ProgramData\wxDownload C:\Users\Lenovo\Qtrax C:\Users\Lenovo\AppData\Local\B1E C:\Users\Lenovo\AppData\Local\Conduit C:\Users\Lenovo\AppData\Local\cre C:\Users\Lenovo\AppData\Local\SearchProtect C:\Users\Lenovo\AppData\Local\PutLockerDownloader C:\Users\Lenovo\AppData\Local\SwvUpdater C:\Users\Lenovo\AppData\Roaming\337 C:\Users\Lenovo\AppData\Roaming\B1Toolbar C:\Users\Lenovo\AppData\Roaming\Babylon C:\Users\Lenovo\AppData\Roaming\eIntaller C:\Users\Lenovo\AppData\Roaming\ExpressFiles C:\Users\Lenovo\AppData\Roaming\simplitec C:\Users\Lenovo\Start Menu\Programs\Browser Manager C:\Users\Lenovo\Documents\smart pc cleaner C:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ares" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\C:" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FixMyRegistry" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Cleaners" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\sllaunch" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\slwc" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup" /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{976137e5} /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC Cleaners" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PCData App" /f Reboot: ***************** HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. HKU\S-1-5-21-3914683434-684966938-2725549555-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LG LinkAir => Value not found. HKU\S-1-5-21-3914683434-684966938-2725549555-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\EnableLUA => value deleted successfully. "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll" => Value Data removed successfully. "C:\PROGRA~3\WebPlat\WEBPLA~1.DLL" => Value Data removed successfully. "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll" => Value Data removed successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk not found. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\0aMCPClient => Value not found. 'HKLM\Software\Wow6432Node\Classes\CLSID\{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1FC85F66-012C-4F58-B762-E6B18C2AB758}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1FC85F66-012C-4F58-B762-E6B18C2AB758}' => Key deleted successfully. C:\Windows\System32\Tasks\Express FilesUpdate => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Express FilesUpdate' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{259AC2CF-EC24-460B-BBC8-57355F69A24D}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{259AC2CF-EC24-460B-BBC8-57355F69A24D}' => Key deleted successfully. C:\Windows\System32\Tasks\{E19CAE8B-731A-4E18-8438-BC2F2A1A87F4} => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E19CAE8B-731A-4E18-8438-BC2F2A1A87F4}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41CFBD2B-8539-4A5A-8BED-13968F8B4FD4}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41CFBD2B-8539-4A5A-8BED-13968F8B4FD4}' => Key deleted successfully. C:\Windows\System32\Tasks\Desk 365 RunAsStdUser => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68738944-BE9C-42C0-BB2F-E90978AA4410}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68738944-BE9C-42C0-BB2F-E90978AA4410}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6A29DB99-DD47-4FC8-A97E-7DB756D21F42}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A29DB99-DD47-4FC8-A97E-7DB756D21F42}' => Key deleted successfully. C:\Windows\System32\Tasks\{5813D8AE-E1FF-47F3-A707-765886861780} => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5813D8AE-E1FF-47F3-A707-765886861780}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6D1C469E-2BB9-4905-97D9-6CF0A29B32F4}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D1C469E-2BB9-4905-97D9-6CF0A29B32F4}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78A8EC62-4BB8-49E2-B08D-6B9F460077EA}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78A8EC62-4BB8-49E2-B08D-6B9F460077EA}' => Key deleted successfully. C:\Windows\System32\Tasks\{B5471B4D-EF56-41E9-AC9C-8C66FD76D2C5} => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B5471B4D-EF56-41E9-AC9C-8C66FD76D2C5}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD1C4908-49E6-4D3D-9F29-FCD5208D315C}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD1C4908-49E6-4D3D-9F29-FCD5208D315C}' => Key deleted successfully. C:\Windows\System32\Tasks\{C6B23001-7DC6-479F-B0C8-2B1A91AFB5B8} => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C6B23001-7DC6-479F-B0C8-2B1A91AFB5B8}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EC1C60E5-BB77-4AD7-BE5A-C79235054718}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC1C60E5-BB77-4AD7-BE5A-C79235054718}' => Key deleted successfully. C:\Windows\System32\Tasks\pc-dis-upd => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pc-dis-upd' => Key deleted successfully. C:\windows\Tasks\Dealply.job => Moved successfully. C:\windows\Tasks\pc-dis-upd.job => Moved successfully. C:\windows\Tasks\{5813D8AE-E1FF-47F3-A707-765886861780}.job => Moved successfully. 976137e5 => Service deleted successfully. BcmSqlStartupSvc => Service deleted successfully. ewusbmbb => Service deleted successfully. ew_hwusbdev => Service deleted successfully. FairplayKD => Service deleted successfully. huawei_enumerator => Service deleted successfully. hwdatacard => Service deleted successfully. IviRegMgr => Service deleted successfully. RichVideo => Service deleted successfully. SQLWriter => Service deleted successfully. 'HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc' => Key deleted successfully. 'HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MCODS' => Key deleted successfully. 'HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc' => Key deleted successfully. 'HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MCODS' => Key deleted successfully. 'HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MpfService' => Key deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{72CB84B9-2592-4ED9-BA51-DFBA0B98CDAA}' => Key deleted successfully. 'HKCR\CLSID\{72CB84B9-2592-4ED9-BA51-DFBA0B98CDAA}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F8D1CDFB-2BBE-4A5F-9B5F-7E1ED3EF2BB6}' => Key deleted successfully. 'HKCR\CLSID\{F8D1CDFB-2BBE-4A5F-9B5F-7E1ED3EF2BB6}'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FBA780A-5830-77F9-BC55-90A8E6A4A7E2}' => Key deleted successfully. 'HKCR\CLSID\{1FBA780A-5830-77F9-BC55-90A8E6A4A7E2}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4AED814F-11C3-535A-4462-B8D8D277DA6A}' => Key deleted successfully. 'HKCR\CLSID\{4AED814F-11C3-535A-4462-B8D8D277DA6A}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C662EA3-0373-0B0D-4EF9-D0497505BA25}' => Key deleted successfully. 'HKCR\CLSID\{7C662EA3-0373-0B0D-4EF9-D0497505BA25}' => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully. 'HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}'=> Key not found. C:\Program Files (x86)\mozilla firefox\searchplugins\Babylon.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\delta-homes.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\portaldosites.xml => Moved successfully. 'HKCU\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp' => Key deleted successfully. C:\Users\Lenovo\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx => Moved successfully. 'HKCU\SOFTWARE\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf' => Key deleted successfully. C:\Users\Lenovo\AppData\Local\CRE\dknkjnkhedbanphkkpbpcgoblmkbfhlf.crx => Moved successfully. 'HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp' => Key deleted successfully. "C:\Users\Lenovo\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx" => File/Directory not found. 'HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf' => Key deleted successfully. "C:\Users\Lenovo\AppData\Local\CRE\dknkjnkhedbanphkkpbpcgoblmkbfhlf.crx" => File/Directory not found. 'HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hggpkhijoeadmdfmlbdepfbngmhaldci' => Key deleted successfully. "C:\Program Files (x86)\DealPly\DealPly.crx" => File/Directory not found. 'HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje' => Key deleted successfully. "C:\Program Files (x86)\TornTV.com\torn2_10.crx" => File/Directory not found. 'HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ohlfohjgijhjlpidbbnmcdooegafnnnm' => Key deleted successfully. C:\Program Files (x86)\SockshareDownloader\SockshareDownloader10.crx => Moved successfully. 'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully. 'HKCU\SOFTWARE\Policies\Google' => Key deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiający aplikacje Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk => Shortcut argument was removed successfully. C:\ProgramData => ":NT2" ADS removed successfully. "C:\Users\All Users" => ":NT2" ADS not found. "C:\ProgramData\Application Data" => ":NT2" ADS not found. "C:\ProgramData\Dane aplikacji" => ":NT2" ADS not found. C:\ProgramData\MTA San Andreas All => ":NT2" ADS removed successfully. C:\ProgramData\Temp => ":07F6D9E4" ADS removed successfully. C:\ProgramData\Temp => ":56E2E879" ADS removed successfully. "C:\Users\Lenovo\Dane aplikacji" => ":NT" ADS not found. "C:\Users\Lenovo\Dane aplikacji" => ":NT2" ADS not found. C:\Users\Lenovo\AppData\Roaming => ":NT" ADS removed successfully. C:\Users\Lenovo\AppData\Roaming => ":NT2" ADS removed successfully. C:\Program Files (x86)\Desk 365 => Moved successfully. C:\ProgramData\pclunst.exe => Moved successfully. C:\ProgramData\PC1Data => Moved successfully. C:\ProgramData\EnujoyCoUpoonu => Moved successfully. C:\ProgramData\eSafe => Moved successfully. C:\ProgramData\InstallMate => Moved successfully. C:\ProgramData\ssafeWeeb => Moved successfully. C:\ProgramData\simplitec => Moved successfully. C:\ProgramData\WebPlat => Moved successfully. C:\ProgramData\wxDownload => Moved successfully. C:\Users\Lenovo\Qtrax => Moved successfully. C:\Users\Lenovo\AppData\Local\B1E => Moved successfully. C:\Users\Lenovo\AppData\Local\Conduit => Moved successfully. C:\Users\Lenovo\AppData\Local\cre => Moved successfully. C:\Users\Lenovo\AppData\Local\SearchProtect => Moved successfully. C:\Users\Lenovo\AppData\Local\PutLockerDownloader => Moved successfully. C:\Users\Lenovo\AppData\Local\SwvUpdater => Moved successfully. C:\Users\Lenovo\AppData\Roaming\337 => Moved successfully. C:\Users\Lenovo\AppData\Roaming\B1Toolbar => Moved successfully. C:\Users\Lenovo\AppData\Roaming\Babylon => Moved successfully. C:\Users\Lenovo\AppData\Roaming\eIntaller => Moved successfully. C:\Users\Lenovo\AppData\Roaming\ExpressFiles => Moved successfully. C:\Users\Lenovo\AppData\Roaming\simplitec => Moved successfully. C:\Users\Lenovo\Start Menu\Programs\Browser Manager => Moved successfully. C:\Users\Lenovo\Documents\smart pc cleaner => Moved successfully. C:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ares" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\C:" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FixMyRegistry" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Cleaners" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\sllaunch" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\slwc" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{976137e5} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC Cleaners" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PCData App" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====