Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-12-2014 Ran by DOM at 2014-12-02 10:33:01 Run:1 Running from C:\Users\DOM\Desktop\scnay Loaded Profiles: UpdatusUser & DOM (Available profiles: UpdatusUser & DOM) Boot Mode: Normal ============================================== Content of fixlist: ***************** R1 {df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64; C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys [48776 2014-11-29] (StdLib) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) S3 catchme; \??\C:\1234aa.exe168021\catchme.sys [X] HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 -> {CAAF45EA-FED9-4150-A588-64A3DD21CE05} URL = http://startsear.ch/?aff=1&src=sp&cf=078e0ab0-9927-11e1-bb33-dca971544231&q={searchTerms} SearchScopes: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001 -> {CAAF45EA-FED9-4150-A588-64A3DD21CE05} URL = http://startsear.ch/?aff=1&src=sp&cf=078e0ab0-9927-11e1-bb33-dca971544231&q={searchTerms} Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\DOM\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File Task: {108BEE63-2766-4082-94F9-A61E192C52BD} - System32\Tasks\{B7E75CE9-1262-4690-AA0A-5B03EA04AA5B} => D:\PowerPoint\Microsoft Office PowerPoint 2007 PL.exe Task: {27D837BC-2143-491D-AAB6-043871D9C48A} - System32\Tasks\{A749C1FF-4F43-4E34-8BB2-9E0759156C2F} => D:\PowerPoint\Microsoft Office PowerPoint 2007 PL.exe Task: {56C2E152-8EE1-4DF0-B489-E3118A984267} - System32\Tasks\{B1419125-866F-4406-8442-C3CA4BF07D48} => D:\NARUTOSGNTS\GAME.exe Task: {5A1E3B8E-1DD6-4885-A917-1AF56E4BDD58} - System32\Tasks\{E0BAC9A1-853D-4B28-B3A8-4814E0F48583} => C:\PROGRAMY\SubEdit-Player\subedit.exe Task: {78C543BB-5491-46F2-B572-B618DDB772C4} - System32\Tasks\Symantec\Norton Error Analyzer 18.6.0.29 => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\SymErr.exe Task: {8FD4B633-27C6-4D34-904B-870C7AC40493} - System32\Tasks\{8E82E1DF-2265-4724-9017-FBDF336CF588} => D:\SpellForce - Cień Feniksa\spellforce.exe Task: {AFA14807-B62A-44BB-98BB-5394FC2D9302} - System32\Tasks\{64097DB9-622C-4BED-A5F5-946A01432E4B} => D:\NARUTOSGNTS\Dolphin.exe Task: {CC3B5B95-0F13-4475-AC8E-CB14D3680AA5} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-12225A02\EPM.exe Task: {CC94F45D-CB75-4B11-B3B7-CE2E3CA684B0} - System32\Tasks\{3844D976-0EC0-498F-9D35-5DA155B9BDEF} => D:\NARUTOSGNTS\GAME.exe Task: {D3A1BC40-F056-4BA3-B1CE-AFE331FF2774} - System32\Tasks\Symantec\Norton Error Processor 18.6.0.29 => C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\SymErr.exe Task: {D632650A-7DB2-49F0-AFD0-6E6E31BA5068} - System32\Tasks\{280B954B-E01B-4065-B48E-30F2D5F04042} => D:\NARUTOSGNTS\Dolphin.exe Task: {DADCEB1A-04AA-4007-BC0E-A6B622E9928D} - System32\Tasks\{1A45A83B-276F-46FB-8DF6-E3587F1EA7DD} => D:\Sniper Elite III\Sniper Elite 3\bin\SniperElite3.exe Task: {E73E0127-3400-4A10-8C53-34120909C727} - System32\Tasks\{D46EF293-11F6-406A-A7F4-140C0A7D2BBF} => D:\SpellForce - Cień Feniksa\spellforce.exe Task: {E7F3B44A-8828-4797-804E-3A60B5B45784} - System32\Tasks\{1D3E57E1-D932-47F5-B65F-65A564596CB6} => D:\SpellForce - Cień Feniksa\spellforce.exe CHR HKLM-x32\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\DOM\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2013-02-03] CHR HKLM-x32\...\Chrome\Extension: [gpicboiclhmnllnjdcfcffifpoaebgkm] - C:\Program Files (x86)\Freecorder extension\Freecorder.crx [2012-10-13] FF Plugin HKU\S-1-5-21-1480235242-2075340924-4091109271-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File C:\Program Files\Freecorder extension x64 C:\Program Files (x86)\Freecorder extension C:\Program Files (x86)\Hold Page C:\Users\DOM\AppData\Local\CRE C:\Users\DOM\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\DOM\AppData\Local\WMTools Downloaded Files C:\Users\DOM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton C:\Users\DOM\AppData\Roaming\Thinstall C:\Users\DOM\Downloads\*(*)-dp*.exe C:\Users\DOM\Downloads\Niepotwierdzony*.crdownload C:\Users\DOM\Downloads\wlsetup*.exe C:\Users\UpdatusUser\Desktop\*.lnk C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Run /f Reg: reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome" /f CMD: for /d %f in (C:\Users\DOM\AppData\Local\{*}) do rd /s /q "%f" CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\DOM\AppData\Local CMD: dir /a C:\Users\DOM\AppData\LocalLow CMD: dir /a C:\Users\DOM\AppData\Roaming ***************** {df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64 => Service stopped successfully. {df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64 => Service deleted successfully. AppMgmt => Service deleted successfully. catchme => Service deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key not found. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key deleted successfully. "HKCR\CLSID\{CAAF45EA-FED9-4150-A588-64A3DD21CE05}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. "HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => Key deleted successfully. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{108BEE63-2766-4082-94F9-A61E192C52BD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{108BEE63-2766-4082-94F9-A61E192C52BD}" => Key deleted successfully. C:\Windows\System32\Tasks\{B7E75CE9-1262-4690-AA0A-5B03EA04AA5B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B7E75CE9-1262-4690-AA0A-5B03EA04AA5B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27D837BC-2143-491D-AAB6-043871D9C48A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27D837BC-2143-491D-AAB6-043871D9C48A}" => Key deleted successfully. C:\Windows\System32\Tasks\{A749C1FF-4F43-4E34-8BB2-9E0759156C2F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A749C1FF-4F43-4E34-8BB2-9E0759156C2F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{56C2E152-8EE1-4DF0-B489-E3118A984267}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56C2E152-8EE1-4DF0-B489-E3118A984267}" => Key deleted successfully. C:\Windows\System32\Tasks\{B1419125-866F-4406-8442-C3CA4BF07D48} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B1419125-866F-4406-8442-C3CA4BF07D48}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5A1E3B8E-1DD6-4885-A917-1AF56E4BDD58}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A1E3B8E-1DD6-4885-A917-1AF56E4BDD58}" => Key deleted successfully. C:\Windows\System32\Tasks\{E0BAC9A1-853D-4B28-B3A8-4814E0F48583} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E0BAC9A1-853D-4B28-B3A8-4814E0F48583}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78C543BB-5491-46F2-B572-B618DDB772C4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78C543BB-5491-46F2-B572-B618DDB772C4}" => Key deleted successfully. C:\Windows\System32\Tasks\Symantec\Norton Error Analyzer 18.6.0.29 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Symantec\Norton Error Analyzer 18.6.0.29" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8FD4B633-27C6-4D34-904B-870C7AC40493}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FD4B633-27C6-4D34-904B-870C7AC40493}" => Key deleted successfully. C:\Windows\System32\Tasks\{8E82E1DF-2265-4724-9017-FBDF336CF588} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8E82E1DF-2265-4724-9017-FBDF336CF588}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AFA14807-B62A-44BB-98BB-5394FC2D9302}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AFA14807-B62A-44BB-98BB-5394FC2D9302}" => Key deleted successfully. C:\Windows\System32\Tasks\{64097DB9-622C-4BED-A5F5-946A01432E4B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{64097DB9-622C-4BED-A5F5-946A01432E4B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CC3B5B95-0F13-4475-AC8E-CB14D3680AA5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC3B5B95-0F13-4475-AC8E-CB14D3680AA5}" => Key deleted successfully. C:\Windows\System32\Tasks\EasyPartitionManager => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EasyPartitionManager" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC94F45D-CB75-4B11-B3B7-CE2E3CA684B0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC94F45D-CB75-4B11-B3B7-CE2E3CA684B0}" => Key deleted successfully. C:\Windows\System32\Tasks\{3844D976-0EC0-498F-9D35-5DA155B9BDEF} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3844D976-0EC0-498F-9D35-5DA155B9BDEF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D3A1BC40-F056-4BA3-B1CE-AFE331FF2774}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3A1BC40-F056-4BA3-B1CE-AFE331FF2774}" => Key deleted successfully. C:\Windows\System32\Tasks\Symantec\Norton Error Processor 18.6.0.29 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Symantec\Norton Error Processor 18.6.0.29" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D632650A-7DB2-49F0-AFD0-6E6E31BA5068}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D632650A-7DB2-49F0-AFD0-6E6E31BA5068}" => Key deleted successfully. C:\Windows\System32\Tasks\{280B954B-E01B-4065-B48E-30F2D5F04042} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{280B954B-E01B-4065-B48E-30F2D5F04042}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DADCEB1A-04AA-4007-BC0E-A6B622E9928D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DADCEB1A-04AA-4007-BC0E-A6B622E9928D}" => Key deleted successfully. C:\Windows\System32\Tasks\{1A45A83B-276F-46FB-8DF6-E3587F1EA7DD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1A45A83B-276F-46FB-8DF6-E3587F1EA7DD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E73E0127-3400-4A10-8C53-34120909C727}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E73E0127-3400-4A10-8C53-34120909C727}" => Key deleted successfully. C:\Windows\System32\Tasks\{D46EF293-11F6-406A-A7F4-140C0A7D2BBF} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D46EF293-11F6-406A-A7F4-140C0A7D2BBF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E7F3B44A-8828-4797-804E-3A60B5B45784}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E7F3B44A-8828-4797-804E-3A60B5B45784}" => Key deleted successfully. C:\Windows\System32\Tasks\{1D3E57E1-D932-47F5-B65F-65A564596CB6} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1D3E57E1-D932-47F5-B65F-65A564596CB6}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda" => Key deleted successfully. C:\Users\DOM\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gpicboiclhmnllnjdcfcffifpoaebgkm" => Key deleted successfully. "C:\Program Files (x86)\Freecorder extension\Freecorder.crx" => File/Directory not found. "HKU\S-1-5-21-1480235242-2075340924-4091109271-1001\Software\MozillaPlugins\ubisoft.com/uplaypc" => Key deleted successfully. C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll not found. "C:\Program Files\Freecorder extension x64" => File/Directory not found. "C:\Program Files (x86)\Freecorder extension" => File/Directory not found. C:\Program Files (x86)\Hold Page => Moved successfully. C:\Users\DOM\AppData\Local\CRE => Moved successfully. C:\Users\DOM\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\DOM\AppData\Local\WMTools Downloaded Files => Moved successfully. C:\Users\DOM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton => Moved successfully. C:\Users\DOM\AppData\Roaming\Thinstall => Moved successfully. C:\Users\DOM\Downloads\*(*)-dp*.exe => Moved successfully. C:\Users\DOM\Downloads\Niepotwierdzony*.crdownload => Moved successfully. C:\Users\DOM\Downloads\wlsetup*.exe => Moved successfully. C:\Users\UpdatusUser\Desktop\*.lnk => Moved successfully. C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys => Moved successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Run /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-1480235242-2075340924-4091109271-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= for /d %f in (C:\Users\DOM\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: BA6C-BBA9 Katalog: C:\Program Files 2014-12-02 10:31