Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-12-2014 Ran by macio at 2014-12-02 17:24:25 Run:3 Running from C:\Documents and Settings\ania\7M Loaded Profile: macio (Available profiles: macio & ania & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** Reg: reg add HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318} /v UpperFilters /t REG_MULTI_SZ /d PartMgr /f Reg: reg add HKLM\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F} /v UpperFilters /t REG_MULTI_SZ /d VolSnap /f Reg: reg delete HKLM\SYSTEM\CurrentControlSet\Services\gupdate /f Reg: reg delete HKLM\SYSTEM\CurrentControlSet\Services\gupdatem /f Reg: reg delete HKLM\SYSTEM\CurrentControlSet\Services\snapman /f Reg: reg delete HKLM\SYSTEM\CurrentControlSet\Services\timounter /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ffdshow_is1 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDFCreator Toolbar" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObit Malware Fighter_is1" /f Reg: reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ignite /f Reg: reg delete "HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Search" /f Reg: reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Google\Chrome /f Reg: reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Mozilla\SeaMonkey /f S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2283296 2014-10-28] (IObit) S2 StarWindServiceAE; E:\wav\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed] S4 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed] S2 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [X] S2 JavaQuickStarterService; "C:\Program Files\Java\jre1.6.0_26\bin\jqs.exe" -service -config "C:\Program Files\Java\jre1.6.0_26\lib\deploy\jqs\jqs.conf" R0 tdrpman; C:\WINDOWS\System32\DRIVERS\tdrpman.sys [368480 2012-02-02] (Acronis) R2 tifsfilter; C:\WINDOWS\System32\DRIVERS\tifsfilt.sys [44384 2012-02-02] (Acronis) S3 FileMonitor; \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [X] S3 RegFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys [X] S3 UrlFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys [X] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service" HKLM\...\Run: [IObit Malware Fighter] => "C:\Program Files\IObit\IObit Malware Fighter\IMF.exe" /autostart Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-343818398-823518204-725345543-1003Core.job => C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-343818398-823518204-725345543-1003UA.job => C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\ReclaimerUpdateFiles_macio.job => C:\Documents and Settings\macio\Dane aplikacji\Real\Update\UpgradeHelper\RealPlayer\11.02\agent\rnupgagent.exe Task: C:\WINDOWS\Tasks\ReclaimerUpdateXML_macio.job => C:\Documents and Settings\macio\Dane aplikacji\Real\Update\UpgradeHelper\RealPlayer\11.02\agent\rnupgagent.exe Task: C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_macio.job => C:\Documents and Settings\macio\Dane aplikacji\Real\Update\UpgradeHelper\RealPlayer\11.02\agent\rnupgagent.exe HKU\S-1-5-21-343818398-823518204-725345543-1003\...\Run: [Google Update] => C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [116648 2013-07-02] (Google Inc.) HKU\S-1-5-21-343818398-823518204-725345543-1003\...\Run: [Advanced SystemCare 7] => "C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe" /auto HKU\S-1-5-21-343818398-823518204-725345543-1003\...\Run: [Yahoo! Search] => C:\Documents and Settings\macio\Dane aplikacji\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe [533352 2014-11-10] (Pay By Ads LTD) HKU\S-1-5-21-343818398-823518204-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com?affID=na HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1415003126&from=smt&uid=ST3500418AS_6VM2QEKCXXXX6VM2QEKC&q={searchTerms} HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1415003126&from=smt&uid=ST3500418AS_6VM2QEKCXXXX6VM2QEKC&q={searchTerms} HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1415003126&from=smt&uid=ST3500418AS_6VM2QEKCXXXX6VM2QEKC URLSearchHook: HKU\S-1-5-21-343818398-823518204-725345543-1003 - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File URLSearchHook: HKU\S-1-5-21-343818398-823518204-725345543-1003 - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File URLSearchHook: HKU\S-1-5-21-343818398-823518204-725345543-1003 - (No Name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - No File SearchScopes: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> DefaultScope {7BB22B29-1157-46CC-B5B7-A8E1DF62118C} URL = http://www.search.ask.com/web?tpid=ORJ-ST-SPE&o=APN11461&pf=V7&p2=^BE7^OSJ000^YY^PL&gct=sb&itbv=12.18.0.81&apn_uid=B99E999C-BAB2-48FF-98B9-AC7D90990771&apn_ptnrs=BE7&apn_dtid=^OSJ000^YY^PL&apn_dbr=Opera.exe_0_12.17.1863.0&doi=2014-10-28&trgb=IE&q={searchTerms}&psv=&pt=tb SearchScopes: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear SearchScopes: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> {7BB22B29-1157-46CC-B5B7-A8E1DF62118C} URL = http://www.search.ask.com/web?tpid=ORJ-ST-SPE&o=APN11461&pf=V7&p2=^BE7^OSJ000^YY^PL&gct=sb&itbv=12.18.0.81&apn_uid=B99E999C-BAB2-48FF-98B9-AC7D90990771&apn_ptnrs=BE7&apn_dtid=^OSJ000^YY^PL&apn_dbr=Opera.exe_0_12.17.1863.0&doi=2014-10-28&trgb=IE&q={searchTerms}&psv=&pt=tb SearchScopes: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> {F4939972-756F-40CA-A72A-2482EB2993CC} URL = http://search.aol.pl/aol/search?s_it=tb50winamp&q={searchTerms} BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File BHO: Ads Removal -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> C:\Program Files\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll No File BHO: JQSIEStartDetectorImpl Class -> {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -> C:\Program Files\Java\jre1.6.0_26\lib\deploy\jqs\ie\jqs_plugin.dll No File Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File Toolbar: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> No Name - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - No File Toolbar: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> No Name - {A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} - No File Toolbar: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> No Name - {4F524A2D-5350-4500-76A7-7A786E7484D7} - No File Toolbar: HKU\S-1-5-21-343818398-823518204-725345543-1003 -> No Name - {4F524A2D-5354-2D53-5045-7A786E7484D7} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.8.0/jinstall-1_8_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab FF HKLM\...\Firefox\Extensions: [jqs@sun.com] - C:\Program Files\Java\jre1.6.0_26\lib\deploy\jqs\ff FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll No File FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKU\S-1-5-21-343818398-823518204-725345543-1003: opencandy.com/Ignite -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Ignite\npOCDM.1.1.4.0.dll (OpenCandy, Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{6fc9af94-39ee-5a57-935c-17c37e34e33b}\InprocServer32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Ignite\npOCDM.1.1.4.0.dll (OpenCandy, Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.25.11\psuser.dll (Google Inc.) C:\Documents and Settings\ania\Dane aplikacji\Real C:\Documents and Settings\ania\Dane aplikacji\IObit C:\Documents and Settings\macio\*.exe C:\Documents and Settings\macio\Dane aplikacji\IObit C:\Documents and Settings\macio\Dane aplikacji\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} C:\Documents and Settings\macio\Dane aplikacji\mystartsearch C:\Documents and Settings\macio\Dane aplikacji\Pay-By-Ads C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Chrome C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Ignite C:\Program Files\Common Files\Real C:\Program Files\Common Files\Ulead Systems C:\Program Files\Google\Update C:\Program Files\IObit C:\Program Files\Real C:\WINDOWS\Tasks\ImCleanDisabled C:\WINDOWS\system32\REN*.tmp C:\WINDOWS\system32\config\*.iobit C:\WINDOWS\system32\config\*.iodefrag.* C:\WINDOWS\system32\drivers\snapman.sys C:\WINDOWS\System32\DRIVERS\tdrpman.sys C:\WINDOWS\System32\DRIVERS\tifsfilt.sys C:\WINDOWS\system32\drivers\timntr.sys E:\wav\Alcohol 120 RestoreQuarantine: C:\FRST\Quarantine\C\Documents and Settings\All Users\Dane aplikacji\GG CMD: dir /a "C:\Documents and Settings\All Users\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\ania\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\ania\Ustawienia lokalne\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\macio\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\LocalService\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\NetworkService\Dane aplikacji" CMD: dir /a "C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji" Reboot: ***************** ========= reg add HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318} /v UpperFilters /t REG_MULTI_SZ /d PartMgr /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg add HKLM\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F} /v UpperFilters /t REG_MULTI_SZ /d VolSnap /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SYSTEM\CurrentControlSet\Services\gupdate /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SYSTEM\CurrentControlSet\Services\gupdatem /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SYSTEM\CurrentControlSet\Services\snapman /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SYSTEM\CurrentControlSet\Services\timounter /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ffdshow_is1 /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDFCreator Toolbar" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IObit Malware Fighter_is1" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ignite /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Google\Chrome /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Mozilla\SeaMonkey /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= LiveUpdateSvc => Service deleted successfully. StarWindServiceAE => Service deleted successfully. UleadBurningHelper => Service deleted successfully. IMFservice => Service deleted successfully. JavaQuickStarterService => Service deleted successfully. tdrpman => Unable to stop service tdrpman => Service deleted successfully. tifsfilter => Service stopped successfully. tifsfilter => Service deleted successfully. FileMonitor => Service deleted successfully. RegFilter => Service deleted successfully. UrlFilter => Service deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice" => Key deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\IObit Malware Fighter => value deleted successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-343818398-823518204-725345543-1003Core.job => Moved successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-343818398-823518204-725345543-1003UA.job => Moved successfully. C:\WINDOWS\Tasks\ReclaimerUpdateFiles_macio.job => Moved successfully. C:\WINDOWS\Tasks\ReclaimerUpdateXML_macio.job => Moved successfully. C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_macio.job => Moved successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 7 => value deleted successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo! Search => value deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => value deleted successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} => value deleted successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} => value deleted successfully. HKU\S-1-5-21-343818398-823518204-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. "HKU\S-1-5-21-343818398-823518204-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7BB22B29-1157-46CC-B5B7-A8E1DF62118C}" => Key deleted successfully. "HKCR\CLSID\{7BB22B29-1157-46CC-B5B7-A8E1DF62118C}" => Key not found. "HKU\S-1-5-21-343818398-823518204-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F4939972-756F-40CA-A72A-2482EB2993CC}" => Key deleted successfully. "HKCR\CLSID\{F4939972-756F-40CA-A72A-2482EB2993CC}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => Key deleted successfully. "HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}" => Key deleted successfully. "HKCR\CLSID\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}" => Key deleted successfully. "HKCR\CLSID\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{10921475-03CE-4E04-90CE-E2E7EF20C814} => value deleted successfully. "HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => Key not found. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} => value deleted successfully. "HKCR\CLSID\{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}" => Key not found. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} => value deleted successfully. "HKCR\CLSID\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9}" => Key not found. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4F524A2D-5350-4500-76A7-7A786E7484D7} => value deleted successfully. "HKCR\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}" => Key not found. HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4F524A2D-5354-2D53-5045-7A786E7484D7} => value deleted successfully. "HKCR\CLSID\{4F524A2D-5354-2D53-5045-7A786E7484D7}" => Key not found. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => Key deleted successfully. "HKCR\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA}" => Key deleted successfully. "HKCR\CLSID\{CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => Key deleted successfully. "HKCR\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => Key deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\jqs@sun.com => value deleted successfully. "HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0" => Key deleted successfully. "HKLM\Software\MozillaPlugins\@java.com/JavaPlugin" => Key deleted successfully. "HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully. C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll => Moved successfully. "HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully. C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll not found. "HKU\S-1-5-21-343818398-823518204-725345543-1003\Software\MozillaPlugins\opencandy.com/Ignite" => Key deleted successfully. C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Ignite\npOCDM.1.1.4.0.dll => Moved successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{6fc9af94-39ee-5a57-935c-17c37e34e33b}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}" => Key deleted successfully. "HKU\S-1-5-21-343818398-823518204-725345543-1003_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}" => Key deleted successfully. C:\Documents and Settings\ania\Dane aplikacji\Real => Moved successfully. C:\Documents and Settings\ania\Dane aplikacji\IObit => Moved successfully. C:\Documents and Settings\macio\*.exe => Moved successfully. C:\Documents and Settings\macio\Dane aplikacji\IObit => Moved successfully. C:\Documents and Settings\macio\Dane aplikacji\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} => Moved successfully. C:\Documents and Settings\macio\Dane aplikacji\mystartsearch => Moved successfully. C:\Documents and Settings\macio\Dane aplikacji\Pay-By-Ads => Moved successfully. C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Google\Chrome => Moved successfully. C:\Documents and Settings\macio\Ustawienia lokalne\Dane aplikacji\Ignite => Moved successfully. C:\Program Files\Common Files\Real => Moved successfully. C:\Program Files\Common Files\Ulead Systems => Moved successfully. C:\Program Files\Google\Update => Moved successfully. C:\Program Files\IObit => Moved successfully. C:\Program Files\Real => Moved successfully. C:\WINDOWS\Tasks\ImCleanDisabled => Moved successfully. C:\WINDOWS\system32\REN*.tmp => Moved successfully. C:\WINDOWS\system32\config\*.iobit => Moved successfully. C:\WINDOWS\system32\config\*.iodefrag.* => Moved successfully. C:\WINDOWS\system32\drivers\snapman.sys => Moved successfully. C:\WINDOWS\System32\DRIVERS\tdrpman.sys => Moved successfully. C:\WINDOWS\System32\DRIVERS\tifsfilt.sys => Moved successfully. C:\WINDOWS\system32\drivers\timntr.sys => Moved successfully. E:\wav\Alcohol 120 => Moved successfully. RestoreQuarantine: C:\FRST\Quarantine\C\Documents and Settings\All Users\Dane aplikacji\GG=> Restoring from Quarantine completed. ========= dir /a "C:\Documents and Settings\All Users\Dane aplikacji" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 887B-F11E Katalog: C:\Documents and Settings\All Users\Dane aplikacji 2014-12-02 17:29