Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 16-11-2014 01 Ran by Sławek at 2014-11-16 18:50:13 Run:1 Running from C:\Users\Sławek\Desktop Loaded Profile: Sławek (Available profiles: Sławek) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 {ed7eb956-75ed-460d-8f69-29a93b07afd1}t; C:\Windows\System32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}t.sys [55232 2014-08-09] (StdLib) R1 tStLibG; C:\Windows\System32\drivers\tStLibG.sys [55224 2014-03-25] (StdLib) R2 MaintainerSvc3.62.8360938; C:\ProgramData\421e43cc-ed79-4e60-91b6-5efd8c307dd0\maintainer.exe [123680 2014-11-15] () R2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [425104 2014-02-26] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U4 WMCoreService; No ImagePath S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] Task: {12902C28-561A-41A0-81EC-D4D830CB4D37} - \SaveSenseLiveUpdateTaskMachineCore No Task File <==== ATTENTION Task: {2230D236-8880-48E2-ADCF-45C09CBCBD78} - \7a781de1-3377-41d3-b84f-61fedd171008-4 No Task File <==== ATTENTION Task: {507F6EF4-70A2-4341-BEFA-3AA33A1D25BD} - System32\Tasks\Windows Updater => C:\Users\Sławek\AppData\Roaming\Oxy\Updater.exe [2014-06-16] () <==== ATTENTION Task: {551B0ABB-D1B7-4DBD-89A9-9C9AC1E03D30} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {55B26115-8E45-4A77-BCCB-53F5D7CBDB92} - \7a781de1-3377-41d3-b84f-61fedd171008-3 No Task File <==== ATTENTION Task: {78E6367F-A758-4C60-A986-06776D565F76} - \7a781de1-3377-41d3-b84f-61fedd171008-1 No Task File <==== ATTENTION Task: {89AF4914-0ADB-4BEC-9406-AA0B4AE49A32} - System32\Tasks\Opera D5 => C:\Program Files\Opera\launcher.exe Task: {8B05BEDB-DE9E-4DA9-89EA-98C0C00AAED1} - \7a781de1-3377-41d3-b84f-61fedd171008-11 No Task File <==== ATTENTION Task: {8D3E9B97-AB30-4725-99DA-628A5F26F56C} - \7a781de1-3377-41d3-b84f-61fedd171008-5 No Task File <==== ATTENTION Task: {96BD9A69-742A-46FC-AFDE-7A37956EFDEB} - \SaveSense No Task File <==== ATTENTION Task: {A956FA93-343D-47C5-9467-DCBD75395700} - System32\Tasks\LuckyTab => C:\Program Files\LuckyTab\LuckyTab.exe [2014-11-02] (http://lucky-tab.com/) <==== ATTENTION Task: {B52744BF-6CC4-48ED-9326-93E653F0CAB2} - System32\Tasks\PileFile reminder => C:\Users\SAWEK~1\AppData\Local\Temp\install.exeDownload_66A5\install.exe_Downloader.exe <==== ATTENTION Task: {BC0DB3D8-87B4-4AB5-B9AF-50EA0A7A97DF} - System32\Tasks\Oxy => C:\Users\Sławek\AppData\Roaming\Oxy\Updater.exe [2014-06-16] () <==== ATTENTION Task: {C0206D6A-C726-480A-A80B-9E45299D4A64} - \7a781de1-3377-41d3-b84f-61fedd171008-6 No Task File <==== ATTENTION Task: {C3C78A75-D0D0-4579-8A39-FE8F6D521E0A} - \7a781de1-3377-41d3-b84f-61fedd171008-7 No Task File <==== ATTENTION Task: {D1BD05D2-6DA5-41DC-8D23-358A73734C97} - \SaveSenseLiveUpdateTaskMachineUA No Task File <==== ATTENTION Task: {DB8A769B-DBC6-4830-B78A-EC771F7C5070} - \9c58613a-4d4c-4bc2-b8c7-d8e2c5bfff38 No Task File <==== ATTENTION Task: {E44A11E3-2F0D-4D12-8231-5D6A804C277A} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {FEB67D06-DBBA-48FD-B2E7-B609A3AB7767} - System32\Tasks\PileFile logon => C:\Users\SAWEK~1\AppData\Local\Temp\install.exeDownload_66A5\install.exe_Downloader.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSense.job => C:\Users\SAWEK~1\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION CustomCLSID: HKU\S-1-5-21-2720886539-1331735733-2511516463-1000_Classes\CLSID\{9000834c-c6c7-43ac-b8ee-dc9668f39a81}\localserver32 -> C:\Users\SAWEK~1\AppData\Local\Temp\{91814ec0-b5f0-11d2-80b9-00104b1f6cea}\IDriver.NonElevated.exe N (the data entry has 6 more characters). ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Sławek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Sławek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G ShortcutWithArgument: C:\Users\Sławek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.istartsurf.com/?type=sc&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKLM\...\Chrome\Extension: [ogfjmhfnldnajmfaofeiaepghjenbgjo] - C:\Users\Sławek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ep.crx [2014-02-26] HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G&ts=1393440641&type=default&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp220141109 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp220141109 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1407624859&from=ild&uid=ST9250320AS_5SW33W3GXXXX5SW33W3G&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Program Files\BonanzaDeals C:\Program Files\globalUpdate C:\Program Files\Mobogenie C:\Program Files\predm C:\Program Files\LuckyTab C:\Program Files\SaveSenseLive C:\Program Files\SupTab C:\Program Files\TheTorntv V10 C:\Program Files\WebSpades C:\Program Files\WinZipper C:\ProgramData\421e43cc-ed79-4e60-91b6-5efd8c307dd0 C:\ProgramData\boost_interprocess C:\ProgramData\IePluginServices C:\ProgramData\TEMP C:\ProgramData\WindowsMangerProtect C:\ProgramData\WPM C:\Users\Sławek\AppData\Local\genienext C:\Users\Sławek\AppData\Local\globalUpdate C:\Users\Sławek\AppData\Local\Pay-By-Ads C:\Users\Sławek\AppData\Local\SaveSense C:\Users\Sławek\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} C:\Users\Sławek\AppData\Roaming\newnext.me C:\Users\Sławek\AppData\Roaming\Oxy C:\Users\Sławek\AppData\Roaming\SimpleFiles C:\Users\Sławek\AppData\Roaming\SupTab C:\Users\Sławek\AppData\Roaming\systweak C:\Users\Sławek\AppData\Roaming\WebExtend C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense C:\Users\Sławek\Desktop\Continue installation*.lnk C:\Users\Sławek\Downloads\*downloader.exe C:\Users\Sławek\Downloads\SoftonicDownloader*.exe C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\System32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}t.sys C:\Windows\System32\drivers\tStLibG.sys RemoveDirectory: C:\Users\Sławek\Desktop\Stare dane programu Firefox Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Torntv Downloader" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent" /f CMD: dir /a "C:\Program Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Sławek\AppData\Local CMD: dir /a C:\Users\Sławek\AppData\LocalLow CMD: dir /a C:\Users\Sławek\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. {ed7eb956-75ed-460d-8f69-29a93b07afd1}t => Unable to stop service {ed7eb956-75ed-460d-8f69-29a93b07afd1}t => Service deleted successfully. tStLibG => Unable to stop service tStLibG => Service deleted successfully. MaintainerSvc3.62.8360938 => Service deleted successfully. winzipersvc => Service not found. massfilter => Service deleted successfully. NwlnkFlt => Service deleted successfully. NwlnkFwd => Service deleted successfully. WMCoreService => Service deleted successfully. ZTEusbmdm6k => Service deleted successfully. ZTEusbnet => Service deleted successfully. ZTEusbnmea => Service deleted successfully. ZTEusbser6k => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{12902C28-561A-41A0-81EC-D4D830CB4D37}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12902C28-561A-41A0-81EC-D4D830CB4D37}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2230D236-8880-48E2-ADCF-45C09CBCBD78}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2230D236-8880-48E2-ADCF-45C09CBCBD78}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-4" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{507F6EF4-70A2-4341-BEFA-3AA33A1D25BD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{507F6EF4-70A2-4341-BEFA-3AA33A1D25BD}" => Key deleted successfully. C:\Windows\System32\Tasks\Windows Updater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Updater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{551B0ABB-D1B7-4DBD-89A9-9C9AC1E03D30}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{551B0ABB-D1B7-4DBD-89A9-9C9AC1E03D30}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{55B26115-8E45-4A77-BCCB-53F5D7CBDB92}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55B26115-8E45-4A77-BCCB-53F5D7CBDB92}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{78E6367F-A758-4C60-A986-06776D565F76}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78E6367F-A758-4C60-A986-06776D565F76}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89AF4914-0ADB-4BEC-9406-AA0B4AE49A32}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89AF4914-0ADB-4BEC-9406-AA0B4AE49A32}" => Key deleted successfully. C:\Windows\System32\Tasks\Opera D5 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D5" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8B05BEDB-DE9E-4DA9-89EA-98C0C00AAED1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B05BEDB-DE9E-4DA9-89EA-98C0C00AAED1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-11" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8D3E9B97-AB30-4725-99DA-628A5F26F56C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D3E9B97-AB30-4725-99DA-628A5F26F56C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-5" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{96BD9A69-742A-46FC-AFDE-7A37956EFDEB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{96BD9A69-742A-46FC-AFDE-7A37956EFDEB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A956FA93-343D-47C5-9467-DCBD75395700}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A956FA93-343D-47C5-9467-DCBD75395700}" => Key deleted successfully. C:\Windows\System32\Tasks\LuckyTab => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LuckyTab" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B52744BF-6CC4-48ED-9326-93E653F0CAB2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B52744BF-6CC4-48ED-9326-93E653F0CAB2}" => Key deleted successfully. C:\Windows\System32\Tasks\PileFile reminder => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PileFile reminder" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC0DB3D8-87B4-4AB5-B9AF-50EA0A7A97DF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC0DB3D8-87B4-4AB5-B9AF-50EA0A7A97DF}" => Key deleted successfully. C:\Windows\System32\Tasks\Oxy => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Oxy" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C0206D6A-C726-480A-A80B-9E45299D4A64}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0206D6A-C726-480A-A80B-9E45299D4A64}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-6" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C3C78A75-D0D0-4579-8A39-FE8F6D521E0A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3C78A75-D0D0-4579-8A39-FE8F6D521E0A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7a781de1-3377-41d3-b84f-61fedd171008-7" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D1BD05D2-6DA5-41DC-8D23-358A73734C97}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1BD05D2-6DA5-41DC-8D23-358A73734C97}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DB8A769B-DBC6-4830-B78A-EC771F7C5070}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB8A769B-DBC6-4830-B78A-EC771F7C5070}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9c58613a-4d4c-4bc2-b8c7-d8e2c5bfff38" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E44A11E3-2F0D-4D12-8231-5D6A804C277A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E44A11E3-2F0D-4D12-8231-5D6A804C277A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FEB67D06-DBBA-48FD-B2E7-B609A3AB7767}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEB67D06-DBBA-48FD-B2E7-B609A3AB7767}" => Key deleted successfully. C:\Windows\System32\Tasks\PileFile logon => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PileFile logon" => Key deleted successfully. C:\Windows\Tasks\SaveSense.job => Moved successfully. "HKU\S-1-5-21-2720886539-1331735733-2511516463-1000_Classes\CLSID\{9000834c-c6c7-43ac-b8ee-dc9668f39a81}" => Key deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Google Chrome.lnk => File not found. C:\Users\Public\Desktop\Mozilla Firefox.lnk => File not found. C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Sławek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Sławek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Sławek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\ogfjmhfnldnajmfaofeiaepghjenbgjo" => Key deleted successfully. C:\Users\Sławek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ep.crx => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. C:\Program Files\BonanzaDeals => Moved successfully. C:\Program Files\globalUpdate => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\LuckyTab => Moved successfully. "C:\Program Files\SaveSenseLive" => File/Directory not found. C:\Program Files\SupTab => Moved successfully. C:\Program Files\TheTorntv V10 => Moved successfully. C:\Program Files\WebSpades => Moved successfully. C:\Program Files\WinZipper => Moved successfully. C:\ProgramData\421e43cc-ed79-4e60-91b6-5efd8c307dd0 => Moved successfully. C:\ProgramData\boost_interprocess => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\Sławek\AppData\Local\genienext => Moved successfully. C:\Users\Sławek\AppData\Local\globalUpdate => Moved successfully. C:\Users\Sławek\AppData\Local\Pay-By-Ads => Moved successfully. C:\Users\Sławek\AppData\Local\SaveSense => Moved successfully. C:\Users\Sławek\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} => Moved successfully. C:\Users\Sławek\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Sławek\AppData\Roaming\Oxy => Moved successfully. C:\Users\Sławek\AppData\Roaming\SimpleFiles => Moved successfully. C:\Users\Sławek\AppData\Roaming\SupTab => Moved successfully. C:\Users\Sławek\AppData\Roaming\systweak => Moved successfully. C:\Users\Sławek\AppData\Roaming\WebExtend => Moved successfully. C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab => Moved successfully. "C:\Users\Sławek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense" => File/Directory not found. "C:\Users\Sławek\Desktop\Continue installation*.lnk" => File/Directory not found. C:\Users\Sławek\Downloads\*downloader.exe => Moved successfully. C:\Users\Sławek\Downloads\SoftonicDownloader*.exe => Moved successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\Windows\System32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}t.sys => Moved successfully. C:\Windows\System32\drivers\tStLibG.sys => Moved successfully. "C:\Users\Sławek\Desktop\Stare dane programu Firefox" => File/Directory not found. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Torntv Downloader" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: D06C-30B4 Katalog: C:\Program Files 2014-11-16 18:50