Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 16-11-2014 01 Ran by SÅ‚awek at 2014-11-16 18:50:13 Run:1 Running from C:\Users\SÅ‚awek\Desktop Loaded Profile: SÅ‚awek (Available profiles: SÅ‚awek) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 {ed7eb956-75ed-460d-8f69-29a93b07afd1}t; C:\Windows\System32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}t.sys [55232 2014-08-09] (StdLib) R1 tStLibG; C:\Windows\System32\drivers\tStLibG.sys [55224 2014-03-25] (StdLib) R2 MaintainerSvc3.62.8360938; C:\ProgramData\421e43cc-ed79-4e60-91b6-5efd8c307dd0\maintainer.exe [123680 2014-11-15] () R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [425104 2014-02-26] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U4 WMCoreService; No ImagePath S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] Task: {12902C28-561A-41A0-81EC-D4D830CB4D37} - \SaveSenseLiveUpdateTaskMachineCore No Task File <==== ATTENTION Task: {2230D236-8880-48E2-ADCF-45C09CBCBD78} - \7a781de1-3377-41d3-b84f-61fedd171008-4 No Task File <==== ATTENTION Task: {507F6EF4-70A2-4341-BEFA-3AA33A1D25BD} - System32\Tasks\Windows Updater => C:\Users\SÅ‚awek\AppData\Roaming\Oxy\Updater.exe [2014-06-16] () <==== ATTENTION Task: {551B0ABB-D1B7-4DBD-89A9-9C9AC1E03D30} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {55B26115-8E45-4A77-BCCB-53F5D7CBDB92} - \7a781de1-3377-41d3-b84f-61fedd171008-3 No Task File <==== ATTENTION Task: {78E6367F-A758-4C60-A986-06776D565F76} - \7a781de1-3377-41d3-b84f-61fedd171008-1 No Task File <==== ATTENTION Task: {89AF4914-0ADB-4BEC-9406-AA0B4AE49A32} - System32\Tasks\Opera D5 => C:\Program Files\Opera\launcher.exe Task: {8B05BEDB-DE9E-4DA9-89EA-98C0C00AAED1} - \7a781de1-3377-41d3-b84f-61fedd171008-11 No Task File <==== ATTENTION Task: {8D3E9B97-AB30-4725-99DA-628A5F26F56C} - \7a781de1-3377-41d3-b84f-61fedd171008-5 No Task File <==== ATTENTION Task: {96BD9A69-742A-46FC-AFDE-7A37956EFDEB} - \SaveSense No Task File <==== ATTENTION Task: {A956FA93-343D-47C5-9467-DCBD75395700} - System32\Tasks\LuckyTab => C:\Program Files\LuckyTab\LuckyTab.exe [2014-11-02] (http://lucky-tab.com/) <==== ATTENTION Task: {B52744BF-6CC4-48ED-9326-93E653F0CAB2} - System32\Tasks\PileFile reminder => C:\Users\SAWEK~1\AppData\Local\Temp\install.exeDownload_66A5\install.exe_Downloader.exe <==== ATTENTION Task: {BC0DB3D8-87B4-4AB5-B9AF-50EA0A7A97DF} - System32\Tasks\Oxy => C:\Users\SÅ‚awek\AppData\Roaming\Oxy\Updater.exe [2014-06-16] () <==== ATTENTION Task: {C0206D6A-C726-480A-A80B-9E45299D4A64} - \7a781de1-3377-41d3-b84f-61fedd171008-6 No Task File <==== ATTENTION Task: {C3C78A75-D0D0-4579-8A39-FE8F6D521E0A} - \7a781de1-3377-41d3-b84f-61fedd171008-7 No Task File <==== ATTENTION Task: {D1BD05D2-6DA5-41DC-8D23-358A73734C97} - \SaveSenseLiveUpdateTaskMachineUA No Task File <==== ATTENTION Task: {DB8A769B-DBC6-4830-B78A-EC771F7C5070} - \9c58613a-4d4c-4bc2-b8c7-d8e2c5bfff38 No Task File <==== ATTENTION Task: {E44A11E3-2F0D-4D12-8231-5D6A804C277A} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {FEB67D06-DBBA-48FD-B2E7-B609A3AB7767} - System32\Tasks\PileFile logon => C:\Users\SAWEK~1\AppData\Local\Temp\install.exeDownload_66A5\install.exe_Downloader.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSense.job => C:\Users\SAWEK~1\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION CustomCLSID: HKU\S-1-5-21-2720886539-1331735733-2511516463-1000_Classes\CLSID\{9000834c-c6c7-43ac-b8ee-dc9668f39a81}\localserver32 -> C:\Users\SAWEK~1\AppData\Local\Temp\{91814ec0-b5f0-11d2-80b9-00104b1f6cea}\IDriver.NonElevated.exe N (the data entry has 6 more characters). ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKLM\...\Chrome\Extension: [ogfjmhfnldnajmfaofeiaepghjenbgjo] - C:\Users\SÅ‚awek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ep.crx [2014-02-26] HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G&ts=1393440641&type=default&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp220141109 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp220141109 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Program Files\BonanzaDeals C:\Program Files\globalUpdate C:\Program Files\Mobogenie C:\Program Files\predm C:\Program Files\LuckyTab C:\Program Files\SaveSenseLive C:\Program Files\SupTab C:\Program Files\TheTorntv V10 C:\Program Files\WebSpades C:\Program Files\WinZipper C:\ProgramData\421e43cc-ed79-4e60-91b6-5efd8c307dd0 C:\ProgramData\boost_interprocess C:\ProgramData\IePluginServices C:\ProgramData\TEMP C:\ProgramData\WindowsMangerProtect C:\ProgramData\WPM C:\Users\SÅ‚awek\AppData\Local\genienext C:\Users\SÅ‚awek\AppData\Local\globalUpdate C:\Users\SÅ‚awek\AppData\Local\Pay-By-Ads C:\Users\SÅ‚awek\AppData\Local\SaveSense C:\Users\SÅ‚awek\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} C:\Users\SÅ‚awek\AppData\Roaming\newnext.me C:\Users\SÅ‚awek\AppData\Roaming\Oxy C:\Users\SÅ‚awek\AppData\Roaming\SimpleFiles C:\Users\SÅ‚awek\AppData\Roaming\SupTab C:\Users\SÅ‚awek\AppData\Roaming\systweak C:\Users\SÅ‚awek\AppData\Roaming\WebExtend C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense C:\Users\SÅ‚awek\Desktop\Continue installation*.lnk C:\Users\SÅ‚awek\Downloads\*downloader.exe C:\Users\SÅ‚awek\Downloads\SoftonicDownloader*.exe C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\System32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}t.sys C:\Windows\System32\drivers\tStLibG.sys RemoveDirectory: C:\Users\SÅ‚awek\Desktop\Stare dane programu Firefox Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Torntv Downloader" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent" /f CMD: dir /a "C:\Program Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\SÅ‚awek\AppData\Local CMD: dir /a C:\Users\SÅ‚awek\AppData\LocalLow CMD: dir /a C:\Users\SÅ‚awek\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. {ed7eb956-75ed-460d-8f69-29a93b07afd1}t => Unable to stop service {ed7eb956-75ed-460d-8f69-29a93b07afd1}t => Service deleted successfully. tStLibG => Unable to stop service tStLibG => Service deleted successfully. MaintainerSvc3.62.8360938 => Service deleted successfully. winzipersvc => Service not found. massfilter => Service deleted successfully. NwlnkFlt => Service deleted successfully. NwlnkFwd => Service deleted successfully. WMCoreService => Service deleted successfully. ZTEusbmdm6k => Service deleted successfully. ZTEusbnet => Service deleted successfully. ZTEusbnmea => Service deleted successfully. ZTEusbser6k => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{12902C28-561A-41A0-81EC-D4D830CB4D37}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12902C28-561A-41A0-81EC-D4D830CB4D37}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2230D236-8880-48E2-ADCF-45C09CBCBD78}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2230D236-8880-48E2-ADCF-45C09CBCBD78}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-4" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{507F6EF4-70A2-4341-BEFA-3AA33A1D25BD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{507F6EF4-70A2-4341-BEFA-3AA33A1D25BD}" => Key deleted successfully. C:\Windows\System32\Tasks\Windows Updater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Updater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{551B0ABB-D1B7-4DBD-89A9-9C9AC1E03D30}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{551B0ABB-D1B7-4DBD-89A9-9C9AC1E03D30}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{55B26115-8E45-4A77-BCCB-53F5D7CBDB92}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55B26115-8E45-4A77-BCCB-53F5D7CBDB92}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{78E6367F-A758-4C60-A986-06776D565F76}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78E6367F-A758-4C60-A986-06776D565F76}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89AF4914-0ADB-4BEC-9406-AA0B4AE49A32}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89AF4914-0ADB-4BEC-9406-AA0B4AE49A32}" => Key deleted successfully. C:\Windows\System32\Tasks\Opera D5 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D5" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8B05BEDB-DE9E-4DA9-89EA-98C0C00AAED1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B05BEDB-DE9E-4DA9-89EA-98C0C00AAED1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-11" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8D3E9B97-AB30-4725-99DA-628A5F26F56C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D3E9B97-AB30-4725-99DA-628A5F26F56C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-5" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{96BD9A69-742A-46FC-AFDE-7A37956EFDEB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{96BD9A69-742A-46FC-AFDE-7A37956EFDEB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A956FA93-343D-47C5-9467-DCBD75395700}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A956FA93-343D-47C5-9467-DCBD75395700}" => Key deleted successfully. C:\Windows\System32\Tasks\LuckyTab => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LuckyTab" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B52744BF-6CC4-48ED-9326-93E653F0CAB2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B52744BF-6CC4-48ED-9326-93E653F0CAB2}" => Key deleted successfully. C:\Windows\System32\Tasks\PileFile reminder => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PileFile reminder" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC0DB3D8-87B4-4AB5-B9AF-50EA0A7A97DF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC0DB3D8-87B4-4AB5-B9AF-50EA0A7A97DF}" => Key deleted successfully. C:\Windows\System32\Tasks\Oxy => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Oxy" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C0206D6A-C726-480A-A80B-9E45299D4A64}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0206D6A-C726-480A-A80B-9E45299D4A64}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-6" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C3C78A75-D0D0-4579-8A39-FE8F6D521E0A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3C78A75-D0D0-4579-8A39-FE8F6D521E0A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-7" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D1BD05D2-6DA5-41DC-8D23-358A73734C97}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1BD05D2-6DA5-41DC-8D23-358A73734C97}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DB8A769B-DBC6-4830-B78A-EC771F7C5070}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB8A769B-DBC6-4830-B78A-EC771F7C5070}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9c58613a-4d4c-4bc2-b8c7-d8e2c5bfff38" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E44A11E3-2F0D-4D12-8231-5D6A804C277A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E44A11E3-2F0D-4D12-8231-5D6A804C277A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FEB67D06-DBBA-48FD-B2E7-B609A3AB7767}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEB67D06-DBBA-48FD-B2E7-B609A3AB7767}" => Key deleted successfully. C:\Windows\System32\Tasks\PileFile logon => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PileFile logon" => Key deleted successfully. C:\Windows\Tasks\SaveSense.job => Moved successfully. "HKU\S-1-5-21-2720886539-1331735733-2511516463-1000_Classes\CLSID\{9000834c-c6c7-43ac-b8ee-dc9668f39a81}" => Key deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Google Chrome.lnk => File not found. C:\Users\Public\Desktop\Mozilla Firefox.lnk => File not found. C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\ogfjmhfnldnajmfaofeiaepghjenbgjo" => Key deleted successfully. C:\Users\SÅ‚awek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ep.crx => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. C:\Program Files\BonanzaDeals => Moved successfully. C:\Program Files\globalUpdate => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\LuckyTab => Moved successfully. "C:\Program Files\SaveSenseLive" => File/Directory not found. C:\Program Files\SupTab => Moved successfully. C:\Program Files\TheTorntv V10 => Moved successfully. C:\Program Files\WebSpades => Moved successfully. C:\Program Files\WinZipper => Moved successfully. C:\ProgramData\421e43cc-ed79-4e60-91b6-5efd8c307dd0 => Moved successfully. C:\ProgramData\boost_interprocess => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\SÅ‚awek\AppData\Local\genienext => Moved successfully. C:\Users\SÅ‚awek\AppData\Local\globalUpdate => Moved successfully. C:\Users\SÅ‚awek\AppData\Local\Pay-By-Ads => Moved successfully. C:\Users\SÅ‚awek\AppData\Local\SaveSense => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\newnext.me => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\Oxy => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\SimpleFiles => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\SupTab => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\systweak => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\WebExtend => Moved successfully. C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab => Moved successfully. "C:\Users\SÅ‚awek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense" => File/Directory not found. "C:\Users\SÅ‚awek\Desktop\Continue installation*.lnk" => File/Directory not found. C:\Users\SÅ‚awek\Downloads\*downloader.exe => Moved successfully. C:\Users\SÅ‚awek\Downloads\SoftonicDownloader*.exe => Moved successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\Windows\System32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}t.sys => Moved successfully. C:\Windows\System32\drivers\tStLibG.sys => Moved successfully. "C:\Users\SÅ‚awek\Desktop\Stare dane programu Firefox" => File/Directory not found. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Torntv Downloader" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: D06C-30B4 Katalog: C:\Program Files 2014-11-16 18:50 . 2014-11-16 18:50 .. 2013-09-17 11:28 7-Zip 2014-11-15 19:00 Adobe 2014-03-02 17:42 AGEIA Technologies 2014-08-27 21:31 ALLPlayer 2013-11-10 20:05 Aspyr 2014-11-16 10:53 Atheros 2013-08-27 10:33 AVAST Software 2014-01-30 16:24 BitLocker 2013-11-16 23:25 CCleaner 2014-11-15 20:18 Cisco 2014-11-10 19:09 City Interactive 2014-09-27 17:03 Common Files 2014-01-30 16:22 CONEXANT 2013-11-10 20:01 DAEMON Tools Lite 2013-09-16 12:53 174 desktop.ini 2014-06-17 10:44 directx 2014-04-10 19:36 FindRight 2014-10-26 13:57 GameSpy Arcade 2013-12-12 20:55 Google 2013-12-22 16:00 Guitar Hero - World Tour 2013-06-13 20:33 GUM204C.tmp 2013-06-13 20:33 4ÿ096ÿ000 GUT204D.tmp 2013-06-14 16:09 Hewlett-Packard 2013-06-14 16:21 HP 2014-11-16 10:52 InstallShield Installation Information 2013-09-16 15:43 Intel 2014-09-13 13:06 Internet Explorer 2014-04-12 20:24 IObit 2014-09-27 17:02 Java 2014-11-15 20:59 ltmoh 2014-11-16 11:04 Malwarebytes Anti-Malware 2014-11-16 10:28 Marvell 2014-01-30 16:25 Microsoft Games 2013-06-12 08:50 Microsoft Office 2013-10-16 07:29 Microsoft Silverlight 2013-06-12 08:50 Microsoft Visual Studio 2013-06-12 08:48 Microsoft Visual Studio 8 2013-06-12 08:51 Microsoft Works 2013-09-17 14:15 Microsoft.NET 2013-09-17 12:56 Movie Maker 2014-11-10 18:33 Mozilla Firefox 2014-11-11 12:25 Mozilla Maintenance Service 2013-06-12 08:51 MSBuild 2013-08-19 14:25 MSXML 4.0 2014-11-10 19:17 OpenAL 2014-08-27 21:38 Opera 2013-12-06 17:21 OrangeBS 2014-10-26 20:58 PDF Architect 2 2014-10-26 21:52 PDFCreator 2014-08-27 21:33 Plus Internet 2014-11-15 19:34 Realtek 2006-11-02 13:35 Reference Assemblies 2014-11-14 18:26 Rockstar Games 2014-06-24 15:26 Skype 2014-08-27 21:35 SpeedFan 2014-01-30 16:25 Synaptics 2014-09-27 17:04 SystemRequirementsLab 2013-09-16 11:35 TOSHIBA 2014-06-18 19:19 Ubi Soft 2006-11-02 14:00 Uninstall Information 2014-08-10 16:38 VideoLAN 2013-09-16 13:52 Windows Calendar 2013-09-16 13:52 Windows Collaboration 2013-09-16 13:52 Windows Defender 2014-07-10 02:19 Windows Journal 2013-09-17 12:56 Windows Mail 2013-09-17 12:56 Windows Media Player 2013-06-10 08:26 Windows NT 2013-09-16 13:52 Windows Photo Gallery 2013-09-17 12:56 Windows Portable Devices 2013-09-16 13:52 Windows Sidebar 2014-11-15 20:00 WinRAR 2014-11-16 10:28 Wise 2 plik(¢w) 4ÿ096ÿ174 bajt¢w 73 katalog(¢w) 19ÿ266ÿ998ÿ272 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: D06C-30B4 Katalog: C:\ProgramData 2014-11-16 18:50 . 2014-11-16 18:50 .. 2014-02-02 14:09 Adobe 2014-08-27 21:31 ALLPlayer 2006-11-02 14:00 Application Data [C:\ProgramData] 2014-11-16 10:52 Atheros 2013-12-12 20:33 AVAST Software 2014-02-03 19:19 AVG 2014-08-11 18:36 Buena Vista Games 2014-02-02 13:40 Common Files 2013-11-10 20:03 DAEMON Tools Lite 2013-06-10 08:26 Dane aplikacji [C:\ProgramData] 2006-11-02 14:00 Desktop [C:\Users\Public\Desktop] 2006-11-02 14:00 Documents [C:\Users\Public\Documents] 2013-06-10 08:26 Dokumenty [C:\Users\Public\Documents] 2006-11-02 14:00 Favorites [C:\Users\Public\Favorites] 2014-02-28 20:15 Guitar Pro 6 2013-06-14 16:03 Hewlett-Packard 2013-06-14 16:26 HP 2013-06-14 16:12 HP Product Assistant 2013-06-14 16:21 HPSSUPPLY 2014-01-27 19:13 1ÿ829 hpzinstall.log 2014-08-09 23:55 IePluginService 2014-06-15 16:55 InstallMate 2014-04-12 20:24 IObit 2014-11-16 11:04 Malwarebytes 2013-06-10 08:26 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-02-26 18:57 Microsoft 2013-06-12 08:53 Microsoft Help 2014-08-07 21:50 MobileBrServ 2013-06-13 19:23 Mozilla 2014-11-16 10:30 8 ntuser.pol 2014-09-27 17:03 Oracle 2014-10-26 20:56 PDF Architect 2 2014-10-26 14:15 PopCap Games 2013-06-10 08:26 Pulpit [C:\Users\Public\Desktop] 2014-06-24 15:26 Skype 2006-11-02 14:00 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-09-27 17:03 Sun 2013-06-10 08:26 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2006-11-02 14:00 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2013-06-10 08:26 Ulubione [C:\Users\Public\Favorites] 2013-06-14 16:26 WEBREG 2014-02-02 13:40 {01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2 plik(¢w) 1ÿ837 bajt¢w 42 katalog(¢w) 19ÿ266ÿ998ÿ272 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\SÅ‚awek\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: D06C-30B4 Katalog: C:\Users\Sˆawek\AppData\Local 2014-11-16 18:50 . 2014-11-16 18:50 .. 2014-10-17 22:45 Adobe 2014-01-29 20:19 ApplicationHistory 2013-11-15 21:20 Aspyr 2014-01-06 16:17 cache 2013-06-10 09:35 680 d3d9caps.dat 2013-06-10 08:28 Dane aplikacji [C:\Users\Sˆawek\AppData\Local] 2014-11-15 16:32 39ÿ936 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-29 20:19 94 fusioncache.dat 2014-11-03 18:44 100ÿ432 GDIPFONTCACHEV1.DAT 2013-11-15 21:15 Google 2013-06-10 08:28 Historia [C:\Users\Sˆawek\AppData\Local\Microsoft\Windows\History] 2014-01-20 20:09 HP 2014-11-16 10:26 2ÿ000ÿ419 IconCache.db 2013-06-14 22:41 iPQ 2014-01-29 20:18 Lollipop 2013-06-13 20:28 Macromedia 2014-08-10 16:23 Microsoft 2014-02-01 18:39 Microsoft Games 2013-11-03 15:45 Microsoft Help 2014-01-29 20:22 Mobogenie 2013-06-13 19:23 Mozilla 2014-06-24 15:20 Opera Software 2014-01-28 16:23 SaveSenseLive 2014-06-24 15:27 Skype 2014-11-16 18:52 Temp 2013-06-10 08:28 Temporary Internet Files [C:\Users\Sˆawek\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2014-10-12 14:12 The Witcher 2013-10-07 17:58 Unity 2014-04-14 20:54 VirtualStore 5 plik(¢w) 2ÿ141ÿ561 bajt¢w 26 katalog(¢w) 19ÿ266ÿ994ÿ176 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\SÅ‚awek\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: D06C-30B4 Katalog: C:\Users\Sˆawek\AppData\LocalLow 2014-09-27 16:54 . 2014-09-27 16:54 .. 2014-02-02 14:11 Adobe 2013-12-03 19:28 Microsoft 2014-04-12 11:20 Red Dot Games 2014-09-27 16:54 Sun 2013-10-07 17:58 Unity 0 plik(¢w) 0 bajt¢w 7 katalog(¢w) 19ÿ266ÿ994ÿ176 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\SÅ‚awek\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: D06C-30B4 Katalog: C:\Users\Sˆawek\AppData\Roaming 2014-11-16 18:50 . 2014-11-16 18:50 .. 2014-06-16 21:07 Adobe 2013-12-12 20:51 AVAST Software 2014-02-02 13:44 AVG 2014-10-26 18:07 CadSoft 2014-11-10 00:00 DAEMON Tools Lite 2014-08-10 16:59 dvdcss 2014-08-27 21:32 Guitar Pro 6 2014-01-27 19:22 HP 2013-06-14 16:21 HPAppData 2013-06-10 08:28 Identities 2013-06-10 08:40 InstallShield 2013-06-13 20:28 Macromedia 2006-11-02 13:35 Media Center Programs 2014-08-10 16:23 Microsoft 2013-06-13 19:23 Mozilla 2014-06-24 15:20 Opera Software 2014-10-26 20:59 PDF Architect 2 2014-10-26 20:55 pdfforge 2014-01-30 16:05 QuickScan 2014-02-02 13:38 rmi 2013-11-10 20:12 SecuROM 2014-07-17 23:54 Skype 2014-06-19 15:55 24 temp.ini 2013-06-10 08:34 TMP 2013-10-07 18:01 Unity 2014-11-16 10:28 uTorrent 2014-11-09 22:52 vlc 2013-12-22 21:37 Wargaming.net 2014-01-28 16:24 62 WB.CFG 2014-11-15 20:01 WinBatch 2014-02-28 20:00 WinZipper 2014-11-16 10:28 Wise Disk Cleaner 2 plik(¢w) 86 bajt¢w 32 katalog(¢w) 19ÿ266ÿ990ÿ080 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 583 MB temporary data. The system needed a reboot. ==== End of Fixlog ====