Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-11-2014 01 Ran by Gosia at 2014-11-23 00:47:08 Run:1 Running from C:\Users\Gosia\Downloads Loaded Profile: Gosia (Available profiles: Gosia) Boot Mode: Safe Mode (minimal) ============================================== Content of fixlist: ***************** CloseProcesses: R1 {c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t; C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t.sys [55232 2014-04-24] (StdLib) S3 cpuz134; \??\C:\Users\Gosia\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X] S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X] S2 savesenselive; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-03-10] (SaveSense) S3 savesenselivem; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-03-10] (SaveSense) Task: {06508FAB-11F0-4DF4-85DB-E728B66CB494} - System32\Tasks\EPUpdater => C:\Users\Gosia\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-12-12] () <==== ATTENTION Task: {0E78B473-D3F5-4CA6-8725-704288C75661} - System32\Tasks\HDvid Codec V1-updater => C:\Program Files\HDvid Codec V1\HDvid Codec V1-updater.exe <==== ATTENTION Task: {216FE8A7-3E1E-4AAE-B0CC-4F137CD828E9} - System32\Tasks\SaveSense => C:\Users\Gosia\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {2A6C57CF-B959-486B-8B5B-781CD9186372} - System32\Tasks\DSite => C:\Users\Gosia\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {43B969A2-0009-4936-859D-55A429D700AE} - System32\Tasks\0214dUpdateInfo => C:\ProgramData\Avg_Update_0214d\0214d_AVG-Secure-Search-Update.exe [2014-03-24] () Task: {4BB2F95F-0809-41B0-BBF6-E45FB6C921E9} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [2014-03-10] (SaveSense) <==== ATTENTION Task: {5611C3D0-6A0D-40C5-BB4B-E7162BBCCE7C} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\Gosia\AppData\Local\FilesFrog Update Checker\update_checker.exe <==== ATTENTION Task: {5EA5BB33-5448-45F8-A81D-20F4572478DD} - System32\Tasks\Digital Sites => C:\Users\Gosia\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {70BD6F7B-BE47-4B3C-8CBF-804604A15F7C} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{66E8FD3B-95CE-4617-AF01-12BA940258CB}.exe Task: {78DF095A-5158-4FFE-A51C-F5BA69F41CF7} - System32\Tasks\WinThruster => C:\Program Files\WinThruster\WinThruster.exe Task: {87AEFBA3-EBAB-4C0E-9FF6-AC3930395F2C} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [2014-03-10] (SaveSense) <==== ATTENTION Task: {A9688860-6B3C-463E-BCCD-FC8FF3274317} - System32\Tasks\HDvid Codec V1-codedownloader => C:\Program Files\HDvid Codec V1\HDvid Codec V1-codedownloader.exe <==== ATTENTION Task: {D7252E30-B4DB-4216-B108-14BBA264DA04} - System32\Tasks\HDvid Codec V1-enabler => C:\Program Files\HDvid Codec V1\HDvid Codec V1-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\0214dUpdateInfo.job => C:\ProgramData\Avg_Update_0214d\0214d_AVG-Secure-Search-Update.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{66E8FD3B-95CE-4617-AF01-12BA940258CB}.exe Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\Gosia\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\DSite.job => C:\Users\Gosia\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\HDvid Codec V1-codedownloader.job => C:\Program Files\HDvid Codec V1\HDvid Codec V1-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\HDvid Codec V1-enabler.job => C:\Program Files\HDvid Codec V1\HDvid Codec V1-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\HDvid Codec V1-updater.job => C:\Program Files\HDvid Codec V1\HDvid Codec V1-updater.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSense.job => C:\Users\Gosia\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe HKU\S-1-5-21-559585761-812252448-234664116-1000\...\Run: [LiveSupport] => "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log HKU\S-1-5-21-559585761-812252448-234664116-1000\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x95000000 HKU\S-1-5-21-559585761-812252448-234664116-1000\...\MountPoints2: {d3865cea-d104-11e2-91fd-fbb37fab426d} - E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\dll32.exe HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=D6E10015AF704DD2&affID=119357&tsp=5009 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=D6E10015AF704DD2&affID=127886&tsp=5180 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://www.search.ask.com/web?tpid=ORJ-V7-SAT&o=APN11461&pf=V7&p2=^BE7^OSJ000^YY^PL&gct=sb&itbv=12.10.6.53&apn_uid=6AAFB0B1-AC35-474F-9FB3-0551CF6D6FF4&apn_ptnrs=BE7&apn_dtid=^OSJ000^YY^PL&apn_dbr=Opera.exe_0_12.17.1863.0&doi=2014-05-22&trgb=IE&q={searchTerms}&psv= SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://www.yd.delta-search.com/?q={searchTerms}&affID=119535&tt=030213_yd&babsrc=SP_ss&mntrId=d6e1c958000000000000000000000000 BHO: Babylon toolbar helper -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.11.10\bh\BabylonToolbar.dll (Babylon BHO) BHO: SaveSense -> {71e129ff-6c2a-4984-818c-7e2c998b8d99} -> C:\Users\Gosia\AppData\Local\SaveSense\SaveSenseIE.dll (SaveSense) Toolbar: HKLM - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.11.10\BabylonToolbarTlbr.dll (Babylon Ltd.) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKCU - No Name - {434D452D-5637-006A-76A7-7A786E7484D7} - No File Toolbar: HKCU - No Name - {4F524A2D-5637-2D53-4154-7A786E7484D7} - No File CHR Extension: (Buenosearch Toolbar) - C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk [2014-10-25] CHR HKLM\...\Chrome\Extension: [acfoobbgoakpihljnfedbcfaipcdlfhk] - C:\Users\Gosia\AppData\Roaming\BabSolution\CR\bueno.crx [2014-03-08] CHR HKLM\...\Chrome\Extension: [dnllcmllkjofnojidnaknldfehfhehoo] - C:\Program Files\HDvidCodec.com\HDvidCodec10.crx [2013-06-30] CHR HKLM\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - C:\Program Files\BonanzaDeals\BonanzaDeals.crx [2013-06-30] CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2013-06-30] C:\Program Files\BabylonToolbar C:\Program Files\BonanzaDeals C:\Program Files\Common Files\Java(1) C:\Program Files\HDvid Codec V1 C:\Program Files\HDvidCodec.com C:\Program Files\Java(3) C:\Program Files\Mozilla Firefox C:\Program Files\RegClean Pro C:\Program Files\Protected Search C:\Program Files\SaveSenseLive C:\Program Files\SupTab C:\ProgramData\IePluginService C:\ProgramData\SaveSenseLive C:\ProgramData\TEMP C:\ProgramData\WPM C:\Users\Gosia\.android C:\Users\Gosia\Adobe-Reader(12627).exe C:\Users\Gosia\FileScoutInstall.zip C:\Users\Gosia\SaveAsPDFandXPS.exe C:\Users\Gosia\AppData\Local\Babylon C:\Users\Gosia\AppData\Local\cache C:\Users\Gosia\AppData\Local\genienext C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences C:\Users\Gosia\AppData\Local\Mobogenie C:\Users\Gosia\AppData\Local\Mozilla C:\Users\Gosia\AppData\Local\Opera Software C:\Users\Gosia\AppData\Local\SaveSense C:\Users\Gosia\AppData\Local\SaveSenseLive C:\Users\Gosia\AppData\Roaming\BabSolution C:\Users\Gosia\AppData\Roaming\Babylon C:\Users\Gosia\AppData\Roaming\DigitalSites C:\Users\Gosia\AppData\Roaming\DSite C:\Users\Gosia\AppData\Roaming\Mozilla C:\Users\Gosia\AppData\Roaming\newnext.me C:\Users\Gosia\AppData\Roaming\Opera C:\Users\Gosia\AppData\Roaming\Opera Software C:\Users\Gosia\AppData\Roaming\PDF Writer Packages C:\Users\Gosia\AppData\Roaming\PerformerSoft C:\Users\Gosia\AppData\Roaming\SaveSense C:\Users\Gosia\AppData\Roaming\Solvusoft C:\Users\Gosia\AppData\Roaming\SupTab C:\Users\Gosia\AppData\Roaming\sweet-page C:\Users\Gosia\AppData\Roaming\Systweak C:\Users\Gosia\AppData\Roaming\Updater C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense C:\Users\Gosia\Desktop\Programy\HDVidCodec.lnk C:\Users\Gosia\Desktop\Programy\McAfee Security Scan Plus.lnk C:\Users\Gosia\Desktop\Programy\Pliki instalacyjne Norton.lnk C:\Users\Gosia\Desktop\Programy\RegClean Pro.lnk C:\Windows\Reimage.ini C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\System32\sqlite3.dll C:\Windows\System32\unrar.dll C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t.sys Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PDF Writer Packages" /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDvid Codec V1" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstaller" /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f CMD: dir /a "C:\Program Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users CMD: dir /a C:\Users\Gosia\AppData\Local CMD: dir /a C:\Users\Gosia\AppData\LocalLow CMD: dir /a C:\Users\Gosia\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. {c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t => Service deleted successfully. cpuz134 => Service deleted successfully. IntcAzAudAddService => Service deleted successfully. savesenselive => Service deleted successfully. savesenselivem => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06508FAB-11F0-4DF4-85DB-E728B66CB494}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06508FAB-11F0-4DF4-85DB-E728B66CB494}" => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E78B473-D3F5-4CA6-8725-704288C75661}" => Key not found. C:\Windows\System32\Tasks\HDvid Codec V1-updater not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDvid Codec V1-updater" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{216FE8A7-3E1E-4AAE-B0CC-4F137CD828E9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{216FE8A7-3E1E-4AAE-B0CC-4F137CD828E9}" => Key deleted successfully. C:\Windows\System32\Tasks\SaveSense => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A6C57CF-B959-486B-8B5B-781CD9186372}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A6C57CF-B959-486B-8B5B-781CD9186372}" => Key deleted successfully. C:\Windows\System32\Tasks\DSite => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{43B969A2-0009-4936-859D-55A429D700AE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43B969A2-0009-4936-859D-55A429D700AE}" => Key deleted successfully. C:\Windows\System32\Tasks\0214dUpdateInfo => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0214dUpdateInfo" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4BB2F95F-0809-41B0-BBF6-E45FB6C921E9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BB2F95F-0809-41B0-BBF6-E45FB6C921E9}" => Key deleted successfully. C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5611C3D0-6A0D-40C5-BB4B-E7162BBCCE7C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5611C3D0-6A0D-40C5-BB4B-E7162BBCCE7C}" => Key deleted successfully. C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5EA5BB33-5448-45F8-A81D-20F4572478DD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EA5BB33-5448-45F8-A81D-20F4572478DD}" => Key deleted successfully. C:\Windows\System32\Tasks\Digital Sites => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Digital Sites" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{70BD6F7B-BE47-4B3C-8CBF-804604A15F7C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70BD6F7B-BE47-4B3C-8CBF-804604A15F7C}" => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{78DF095A-5158-4FFE-A51C-F5BA69F41CF7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78DF095A-5158-4FFE-A51C-F5BA69F41CF7}" => Key deleted successfully. C:\Windows\System32\Tasks\WinThruster => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinThruster" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87AEFBA3-EBAB-4C0E-9FF6-AC3930395F2C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87AEFBA3-EBAB-4C0E-9FF6-AC3930395F2C}" => Key deleted successfully. C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9688860-6B3C-463E-BCCD-FC8FF3274317}" => Key not found. C:\Windows\System32\Tasks\HDvid Codec V1-codedownloader not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDvid Codec V1-codedownloader" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7252E30-B4DB-4216-B108-14BBA264DA04}" => Key not found. C:\Windows\System32\Tasks\HDvid Codec V1-enabler not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDvid Codec V1-enabler" => Key not found. C:\Windows\Tasks\0214dUpdateInfo.job => Moved successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Windows\Tasks\Digital Sites.job => Moved successfully. C:\Windows\Tasks\DSite.job => Moved successfully. C:\Windows\Tasks\HDvid Codec V1-codedownloader.job not found. C:\Windows\Tasks\HDvid Codec V1-enabler.job not found. C:\Windows\Tasks\HDvid Codec V1-updater.job not found. C:\Windows\Tasks\SaveSense.job => Moved successfully. C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => value deleted successfully. HKU\S-1-5-21-559585761-812252448-234664116-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LiveSupport => value deleted successfully. HKU\S-1-5-21-559585761-812252448-234664116-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDriveTypeAutoRun => value deleted successfully. "HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d3865cea-d104-11e2-91fd-fbb37fab426d}" => Key deleted successfully. "HKCR\CLSID\{d3865cea-d104-11e2-91fd-fbb37fab426d}" => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Default_Page_URL => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Default_Page_URL => Value not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Bar => Value not found. \\{D8278076-BC68-4484-9233-6E7F1628B56C} => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q={searchTerms} => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} => Value not found. \\SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Value not found. \\SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=D6E10015AF704DD2&affID=127886&tsp=5180 => Value not found. \\SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://www.search.ask.com/web?tpid=ORJ-V7-SAT&o=APN11461&pf=V7&p2=^BE7^OSJ000^YY^PL&gct=sb&itbv=12.10.6.53&apn_uid=6AAFB0B1-AC35-474F-9FB3-0551CF6D6FF4&apn_ptnrs=BE7&apn_dtid=^OSJ000^YY^PL&apn_dbr=Opera.exe_0_12.17.1863.0&doi=2014-05-22&trgb=IE&q={searchTerms}&psv= => Value not found. \\SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} => Value not found. \\SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = => Value not found. \\SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://www.yd.delta-search.com/?q={searchTerms}&affID=119535&tt=030213_yd&babsrc=SP_ss&mntrId=d6e1c958000000000000000000000000 => Value not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}" => Key deleted successfully. "HKCR\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}" => Key deleted successfully. "HKCR\CLSID\{71e129ff-6c2a-4984-818c-7e2c998b8d99}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} => value deleted successfully. "HKCR\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}" => Key deleted successfully. \\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value not found. "HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => Key deleted successfully. \\{434D452D-5637-006A-76A7-7A786E7484D7} => Value not found. "HKCR\CLSID\{434D452D-5637-006A-76A7-7A786E7484D7}" => Key not found. \\{4F524A2D-5637-2D53-4154-7A786E7484D7} => Value not found. "HKCR\CLSID\{4F524A2D-5637-2D53-4154-7A786E7484D7}" => Key not found. C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk => Moved successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk" => Key deleted successfully. C:\Users\Gosia\AppData\Roaming\BabSolution\CR\bueno.crx => Moved successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\dnllcmllkjofnojidnaknldfehfhehoo" => Key deleted successfully. "C:\Program Files\HDvidCodec.com\HDvidCodec10.crx" => File/Directory not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\ieadcoanfjloocmfafkebdnfefmohngj" => Key deleted successfully. "C:\Program Files\BonanzaDeals\BonanzaDeals.crx" => File/Directory not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma" => Key deleted successfully. "C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx" => File/Directory not found. C:\Program Files\BabylonToolbar => Moved successfully. C:\Program Files\BonanzaDeals => Moved successfully. C:\Program Files\Common Files\Java(1) => Moved successfully. "C:\Program Files\HDvid Codec V1" => File/Directory not found. C:\Program Files\HDvidCodec.com => Moved successfully. C:\Program Files\Java(3) => Moved successfully. C:\Program Files\Mozilla Firefox => Moved successfully. C:\Program Files\RegClean Pro => Moved successfully. C:\Program Files\Protected Search => Moved successfully. C:\Program Files\SaveSenseLive => Moved successfully. C:\Program Files\SupTab => Moved successfully. C:\ProgramData\IePluginService => Moved successfully. C:\ProgramData\SaveSenseLive => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\Gosia\.android => Moved successfully. C:\Users\Gosia\Adobe-Reader(12627).exe => Moved successfully. C:\Users\Gosia\FileScoutInstall.zip => Moved successfully. C:\Users\Gosia\SaveAsPDFandXPS.exe => Moved successfully. C:\Users\Gosia\AppData\Local\Babylon => Moved successfully. C:\Users\Gosia\AppData\Local\cache => Moved successfully. C:\Users\Gosia\AppData\Local\genienext => Moved successfully. C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences => Moved successfully. C:\Users\Gosia\AppData\Local\Mobogenie => Moved successfully. C:\Users\Gosia\AppData\Local\Mozilla => Moved successfully. C:\Users\Gosia\AppData\Local\Opera Software => Moved successfully. C:\Users\Gosia\AppData\Local\SaveSense => Moved successfully. C:\Users\Gosia\AppData\Local\SaveSenseLive => Moved successfully. C:\Users\Gosia\AppData\Roaming\BabSolution => Moved successfully. C:\Users\Gosia\AppData\Roaming\Babylon => Moved successfully. C:\Users\Gosia\AppData\Roaming\DigitalSites => Moved successfully. C:\Users\Gosia\AppData\Roaming\DSite => Moved successfully. C:\Users\Gosia\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Gosia\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Gosia\AppData\Roaming\Opera => Moved successfully. C:\Users\Gosia\AppData\Roaming\Opera Software => Moved successfully. C:\Users\Gosia\AppData\Roaming\PDF Writer Packages => Moved successfully. C:\Users\Gosia\AppData\Roaming\PerformerSoft => Moved successfully. C:\Users\Gosia\AppData\Roaming\SaveSense => Moved successfully. C:\Users\Gosia\AppData\Roaming\Solvusoft => Moved successfully. C:\Users\Gosia\AppData\Roaming\SupTab => Moved successfully. C:\Users\Gosia\AppData\Roaming\sweet-page => Moved successfully. C:\Users\Gosia\AppData\Roaming\Systweak => Moved successfully. C:\Users\Gosia\AppData\Roaming\Updater => Moved successfully. C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard => Moved successfully. C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com => Moved successfully. C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie => Moved successfully. C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton => Moved successfully. C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense => Moved successfully. C:\Users\Gosia\Desktop\Programy\HDVidCodec.lnk => Moved successfully. C:\Users\Gosia\Desktop\Programy\McAfee Security Scan Plus.lnk => Moved successfully. C:\Users\Gosia\Desktop\Programy\Pliki instalacyjne Norton.lnk => Moved successfully. C:\Users\Gosia\Desktop\Programy\RegClean Pro.lnk => Moved successfully. C:\Windows\Reimage.ini => Moved successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\Windows\System32\sqlite3.dll => Moved successfully. C:\Windows\System32\unrar.dll => Moved successfully. C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t.sys => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\PDF Writer Packages" /f ========= Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload /f ========= Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDvid Codec V1" /f ========= Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstaller" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\mozilla.org /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C to SYSTEM Numer seryjny woluminu: D6E1-C958 Katalog: C:\Program Files 2014-11-23 00:48