Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 14-12-2014 01 Ran by Magda at 2014-12-14 23:44:16 Run:1 Running from C:\Users\Magda\Desktop\Raporty Loaded Profile: Magda (Available profiles: Magda) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-251121527-2021168873-2295293381-1000\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? CustomCLSID: HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{010833F3-751A-402F-9FCC-C365B6A12E41}\localserver32 -> C:\Users\Magda\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\LNOA2PVZ\BESTPL~1.EXE No File CustomCLSID: HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{B6CE1A28-A831-43E4-A81F-E2B429D66231}\InprocServer32 -> C:\Users\Magda\AppData\Local\ASKTOO~1\DOWNLO~1\Nero.dll No File CustomCLSID: HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File Task: {0D81B941-5BCB-4412-9B51-A7EB872263C2} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-251121527-2021168873-2295293381-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe Task: {40695F6B-C7D2-4821-942D-2C2138508A36} - System32\Tasks\{965B7CB1-17A7-4F48-B9D9-1D69D9E793DD} => Iexplore.exe http://ui.skype.com/ui/0/5.3.0.111/en/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;userdeclined,google-chrome:notoffered;systemlevelpresent Task: {44E1CFD7-5443-4B12-819C-9C23D3980BEA} - System32\Tasks\{110CF5B1-6F5B-42FF-B866-2797758CB47E} => Iexplore.exe http://ui.skype.com/ui/0/6.16.0.105/pl/go/help.faq.installer?LastError=1638 Task: {46BEDFB8-2690-4677-9E96-A71AF5588D08} - System32\Tasks\{C028360A-DC07-44AC-A9CB-9FC66B828C1F} => Iexplore.exe http://ui.skype.com/ui/0/6.16.0.105/pl/go/help.faq.installer?LastError=1638 Task: {4FCBA4B1-2569-4CAF-8593-5EDFF3736229} - System32\Tasks\{CCC96478-C7F9-4A01-91B3-5D1C5DBE099D} => Iexplore.exe http://ui.skype.com/ui/0/5.5.0.113/en/abandoninstall?page=tsPlugin&installinfo=google-toolbar:notoffered;userdeclined,google-chrome:notoffered;systemlevelpresent Task: {661CDEEE-EE33-4C0F-9F40-EEC5F7D9E060} - System32\Tasks\{C534BC0B-078B-476C-B2D0-9BA77393A598} => Iexplore.exe http://ui.skype.com/ui/0/6.16.0.105/pl/go/help.faq.installer?LastError=1638 Task: {89BCAF6F-963E-4708-9AFA-9B9AC38523B0} - \WSE_Astromenda No Task File <==== ATTENTION Task: {C6A1977F-93EB-44CD-8202-6B6FEBFFAFAB} - \WSE_Lasaoren No Task File <==== ATTENTION Task: {DE6D5A83-55AB-401F-A612-B68182A7C9E8} - System32\Tasks\{7BB4C0E6-C61A-4319-A4AF-795947945B81} => Iexplore.exe http://ui.skype.com/ui/0/5.1.0.112/en/abandoninstall?page=tsMain&installinfo=google-toolbar:offered-installed,google-chrome:notoffered;toolbaroffered Task: {E2E7B910-9400-492F-B96D-AE7BC13CDE86} - System32\Tasks\{8A3011FD-BDCE-4134-9D03-482975D330A9} => Iexplore.exe http://ui.skype.com/ui/0/6.3.0.107/en/abandoninstall?page=tsProgressBar Task: {F5333235-BEAA-4596-80C9-D0E96606BE7B} - System32\Tasks\{6DA37219-06DA-4329-9505-604EAE013CD7} => Iexplore.exe http://ui.skype.com/ui/0/6.16.0.105/en/go/help.faq.installer?LastError=1638 Task: {F99D3FD8-06F3-4443-BDBD-1CED0B96029F} - System32\Tasks\Installation App Launcher => C:\Program Files\Lexmark 3600-4600 Series\ezprint.exe Task: {FEAE8A46-DAE8-4BBE-9B87-56197770B2D5} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-251121527-2021168873-2295293381-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe HKU\S-1-5-21-251121527-2021168873-2295293381-1000\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://uk.yahoo.com/?fr=hp-avast&type=agc511 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://uk.search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Microsoft\Internet Explorer\Main,Search Page = https://uk.search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms} HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://uk.yahoo.com/?fr=hp-avast&type=agc511 HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://uk.yahoo.com/?fr=hp-avast&type=agc511 StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://uk.search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_45_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtByD0FtCyB0BzztAyD0B0C0D0AtN0D0Tzu0StCtDyEtDtN1L2XzutAtFyCtFtDtFyEtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtCzz0C0C0C0B0BtGzz0EyCtCtGtDtC0D0BtGtD0Czy0AtGtB0D0CtB0CtAyEzyyByBzy0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtB0DyE0CyDtDtCtGtB0FtDtAtGyEyCzytCtG0A0C0AyBtGtB0ByE0BtBtAyC0F0ByBtA0E2Q&cr=1511266203&ir= SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ir_14_44_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtByD0FtCyB0BzztAyD0B0C0D0AtN0D0Tzu0StCtDtAyBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDtBtDzy0D0B0AtBtGyDtCtC0AtGtA0Dzy0BtGtC0A0BtAtGyEtCtCyB0B0EyBzz0FyEtA0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0AyDtD0D0EtC0A0FtGyC0DyDyBtGyEyCtCzztG0BtC0EyDtG0DyB0E0A0AyEyEyC0FyEtA0E2Q&cr=1384680931&ir= SearchScopes: HKLM -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://uk.search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKLM -> {A25AC313-DD19-4238-ACA2-401D6BEE4321} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 SearchScopes: HKU\S-1-5-21-251121527-2021168873-2295293381-1000 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://uk.search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKU\S-1-5-21-251121527-2021168873-2295293381-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-251121527-2021168873-2295293381-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://Lasaoren.com/results.php?f=4&q={searchTerms}&a=lrn_ir_14_45_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtByD0FtCyB0BzztAyD0B0C0D0AtN0D0Tzu0StCtDyEtDtN1L2XzutAtFyCtFtDtFyEtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtCzz0C0C0C0B0BtGzz0EyCtCtGtDtC0D0BtGtD0Czy0AtGtB0D0CtB0CtAyEzyyByBzy0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtB0DyE0CyDtDtCtGtB0FtDtAtGyEyCzytCtG0A0C0AyBtGtB0ByE0BtBtAyC0F0ByBtA0E2Q&cr=1511266203&ir= SearchScopes: HKU\S-1-5-21-251121527-2021168873-2295293381-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-21-251121527-2021168873-2295293381-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://uk.search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKU\S-1-5-21-251121527-2021168873-2295293381-1000 -> {A25AC313-DD19-4238-ACA2-401D6BEE4321} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - No Path FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Users\Magda\Downloads\FLVPlayer-Chrome.exe Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f CMD: netsh advfirewall reset EmptyTemp: ***************** Processes closed successfully. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}" => Key deleted successfully. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{010833F3-751A-402F-9FCC-C365B6A12E41}" => Key deleted successfully. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}" => Key deleted successfully. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}" => Key deleted successfully. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{B6CE1A28-A831-43E4-A81F-E2B429D66231}" => Key deleted successfully. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0D81B941-5BCB-4412-9B51-A7EB872263C2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D81B941-5BCB-4412-9B51-A7EB872263C2}" => Key deleted successfully. C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-251121527-2021168873-2295293381-1000 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealUpgradeLogonTaskS-1-5-21-251121527-2021168873-2295293381-1000" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40695F6B-C7D2-4821-942D-2C2138508A36}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40695F6B-C7D2-4821-942D-2C2138508A36}" => Key deleted successfully. C:\Windows\System32\Tasks\{965B7CB1-17A7-4F48-B9D9-1D69D9E793DD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{965B7CB1-17A7-4F48-B9D9-1D69D9E793DD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{44E1CFD7-5443-4B12-819C-9C23D3980BEA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44E1CFD7-5443-4B12-819C-9C23D3980BEA}" => Key deleted successfully. C:\Windows\System32\Tasks\{110CF5B1-6F5B-42FF-B866-2797758CB47E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{110CF5B1-6F5B-42FF-B866-2797758CB47E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{46BEDFB8-2690-4677-9E96-A71AF5588D08}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46BEDFB8-2690-4677-9E96-A71AF5588D08}" => Key deleted successfully. C:\Windows\System32\Tasks\{C028360A-DC07-44AC-A9CB-9FC66B828C1F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C028360A-DC07-44AC-A9CB-9FC66B828C1F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4FCBA4B1-2569-4CAF-8593-5EDFF3736229}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4FCBA4B1-2569-4CAF-8593-5EDFF3736229}" => Key deleted successfully. C:\Windows\System32\Tasks\{CCC96478-C7F9-4A01-91B3-5D1C5DBE099D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CCC96478-C7F9-4A01-91B3-5D1C5DBE099D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{661CDEEE-EE33-4C0F-9F40-EEC5F7D9E060}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{661CDEEE-EE33-4C0F-9F40-EEC5F7D9E060}" => Key deleted successfully. C:\Windows\System32\Tasks\{C534BC0B-078B-476C-B2D0-9BA77393A598} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C534BC0B-078B-476C-B2D0-9BA77393A598}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89BCAF6F-963E-4708-9AFA-9B9AC38523B0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89BCAF6F-963E-4708-9AFA-9B9AC38523B0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WSE_Astromenda" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6A1977F-93EB-44CD-8202-6B6FEBFFAFAB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6A1977F-93EB-44CD-8202-6B6FEBFFAFAB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WSE_Lasaoren" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE6D5A83-55AB-401F-A612-B68182A7C9E8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE6D5A83-55AB-401F-A612-B68182A7C9E8}" => Key deleted successfully. C:\Windows\System32\Tasks\{7BB4C0E6-C61A-4319-A4AF-795947945B81} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7BB4C0E6-C61A-4319-A4AF-795947945B81}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E2E7B910-9400-492F-B96D-AE7BC13CDE86}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2E7B910-9400-492F-B96D-AE7BC13CDE86}" => Key deleted successfully. C:\Windows\System32\Tasks\{8A3011FD-BDCE-4134-9D03-482975D330A9} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8A3011FD-BDCE-4134-9D03-482975D330A9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F5333235-BEAA-4596-80C9-D0E96606BE7B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5333235-BEAA-4596-80C9-D0E96606BE7B}" => Key deleted successfully. C:\Windows\System32\Tasks\{6DA37219-06DA-4329-9505-604EAE013CD7} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6DA37219-06DA-4329-9505-604EAE013CD7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F99D3FD8-06F3-4443-BDBD-1CED0B96029F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F99D3FD8-06F3-4443-BDBD-1CED0B96029F}" => Key deleted successfully. C:\Windows\System32\Tasks\Installation App Launcher => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installation App Launcher" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FEAE8A46-DAE8-4BBE-9B87-56197770B2D5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEAE8A46-DAE8-4BBE-9B87-56197770B2D5}" => Key deleted successfully. C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-251121527-2021168873-2295293381-1000 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealUpgradeScheduledTaskS-1-5-21-251121527-2021168873-2295293381-1000" => Key deleted successfully. HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDriveTypeAutoRun => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-251121527-2021168873-2295293381-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key deleted successfully. "HKCR\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}" => Key deleted successfully. "HKCR\CLSID\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A25AC313-DD19-4238-ACA2-401D6BEE4321}" => Key deleted successfully. "HKCR\CLSID\{A25AC313-DD19-4238-ACA2-401D6BEE4321}" => Key not found. HKU\S-1-5-21-251121527-2021168873-2295293381-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key deleted successfully. "HKCR\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => Key not found. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}" => Key deleted successfully. "HKCR\CLSID\{9CB96984-43C3-4D44-90EF-01466EFCF7BB}" => Key not found. "HKU\S-1-5-21-251121527-2021168873-2295293381-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A25AC313-DD19-4238-ACA2-401D6BEE4321}" => Key deleted successfully. "HKCR\CLSID\{A25AC313-DD19-4238-ACA2-401D6BEE4321}" => Key not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk" => Key deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\Users\Magda\Downloads\FLVPlayer-Chrome.exe => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= EmptyTemp: => Removed 1 GB temporary data. The system needed a reboot. ==== End of Fixlog ====