Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-01-2015 Ran by Dominik at 2015-01-07 15:28:21 Run:1 Running from C:\Users\Dominik\Desktop Loaded Profile: Dominik (Available profiles: Dominik) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: (Microsoft Corporation) C:\Windows\explorer.exe CreateRestorePoint: HKLM\...\Run: [gmsd_pl_16] => [X] HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\...\Run: [] => [X] HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Dominik\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.) HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\...\Policies\Explorer: [HideSCAHealth] 1 IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\safetynut\x64\safetycrt.dll S2 bonanzadealslive; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-09-25] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-09-25] (BonanzaDeals) R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) S4 rqpbhevlkc32; C:\Program Files\004\rqpbhevlkc32.exe [543232 2014-06-10] () [File not signed] S2 savesenselive; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-02-13] (SaveSense) S3 savesenselivem; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-02-13] (SaveSense) S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S1 MpKsl13a62a37; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{35BA8387-C265-47B5-8930-D45B408C9DBB}\MpKsl13a62a37.sys [X] S1 netfilter; system32\drivers\netfilter.sys [X] S3 vtany; \??\C:\Windows\vtany.sys [X] S3 WinRing0_1_2_0; \??\C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [X] S3 XDva401; \??\C:\Windows\system32\XDva401.sys [X] S3 XDva402; \??\C:\Windows\system32\XDva402.sys [X] S3 XDva409; \??\C:\Windows\system32\XDva409.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] Task: {01C4E655-24EF-4262-842E-908A4095A613} - System32\Tasks\DealPly => C:\Windows\System32\config\systemprofile\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe [2013-04-23] () <==== ATTENTION Task: {2EAD9E21-1875-4786-9D2F-54F692B759F7} - System32\Tasks\EPUpdater => C:\Users\Dominik\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-08-04] () <==== ATTENTION Task: {4053F668-3EC6-4036-9637-2E79A6C95617} - System32\Tasks\GoodGameEmpire W1 => Chrome.exe --app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1= --app-window-size=1280,1024 Task: {5A3ED164-A29F-4698-B7F6-D534FB816E7A} - System32\Tasks\task358833 => C:\Windows\Temp\_ex-08.exe <==== ATTENTION Task: {62E4808D-C63B-4C0A-B621-B42DBE028A58} - \systems No Task File <==== ATTENTION Task: {6E042961-23D9-4FD5-BC83-41FD93DC2150} - System32\Tasks\GoodGameEmpire W2 => Chrome.exe --app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1= --app-window-size=1280,1024 Task: {77930916-DC41-4D13-91D7-3C2D5FCD42E7} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [2014-02-13] (SaveSense) <==== ATTENTION Task: {8576AD86-5029-43F2-8C67-B1F41116F93B} - System32\Tasks\GoodGameEmpire NextW1 => Chrome.exe --app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1= --app-window-size=1280,1024 Task: {AA1B585A-F14A-42BF-91F1-DEC9DF5CDB85} - \fbagent No Task File <==== ATTENTION Task: {AA3D7EEB-7C06-4283-AAB9-36511726160C} - System32\Tasks\{00E2789E-2120-4C0A-B516-7D5841DE9AAF} => pcalua.exe -a "C:\Program Files\CAPCOM\Devil May Cry 3 Edycja Specjalna\uninstall.exe" -d "C:\Program Files\CAPCOM\Devil May Cry 3 Edycja Specjalna" Task: {B5E62214-A5F9-4E42-964B-3890A7CDEC92} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files\IObit\Game Booster 3\AutoUpdate.exe Task: {B94EFB4F-3084-45D3-89AA-A84C90420EDE} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-09-25] (BonanzaDeals) <==== ATTENTION Task: {B9ADAE2A-425D-42DB-84FA-F0CB7A00DB38} - System32\Tasks\GoodGameEmpire NextW2 => Chrome.exe --app=http://a2g-secure.com/?E=bwsPamg0MAiwFF%2bnM1a0Fg%3d%3d&s1= --app-window-size=1280,1024 Task: {C174EEE4-8B17-43CC-A512-81BC7E0FF118} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [2014-02-13] (SaveSense) <==== ATTENTION Task: {DE2E9F63-9081-45AC-B045-5C725B4BC358} - System32\Tasks\{778FC7CC-15CA-4C08-B6C4-DCEAE647707C} => pcalua.exe -a "C:\Deluxe Ski Jump 3\Setup.exe" -d "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deluxe Ski Jump 3" Task: {E0DE6DAF-CEEB-42D4-A022-BC1D31AF5728} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-09-25] (BonanzaDeals) <==== ATTENTION Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe <==== ATTENTION Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 ShortcutWithArgument: C:\Users\Dominik\Desktop\Ie.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 ShortcutWithArgument: C:\Users\Dominik\Desktop\ww.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 ShortcutWithArgument: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 ShortcutWithArgument: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 ShortcutWithArgument: C:\Users\Dominik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 URLSearchHook: HKLM - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} URLSearchHook: HKLM - SiteFinder - {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files\SiteFinder\SiteFinder.dll (Site Finder) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248&q={searchTerms} SearchScopes: HKLM -> {575B1647-F599-45FB-92FA-158AA62F3396} URL = http://startsear.ch/?aff=2&src=sp&cf=d19cadc4-236d-11e1-b919-001a4d5231a0&q={searchTerms} SearchScopes: HKLM -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={CD349B77-016D-4F1D-B17B-C1EA361EE6EA} SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248&q={searchTerms} SearchScopes: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248&q={searchTerms} SearchScopes: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> {575B1647-F599-45FB-92FA-158AA62F3396} URL = http://startsear.ch/?aff=2&src=sp&cf=d19cadc4-236d-11e1-b919-001a4d5231a0&q={searchTerms} SearchScopes: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={CD349B77-016D-4F1D-B17B-C1EA361EE6EA} BHO: HDvid Codec V1 -> {11111111-1111-1111-1111-110311431162} -> C:\Program Files\HDvid Codec V1\HDvid Codec V1-bho.dll (installdaddy) BHO: SweetPacks Browser Helper -> {EEE6C35C-6118-11DC-9C72-001320C79847} -> C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) BHO: Yontoo -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -> C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC) Toolbar: HKLM - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File Toolbar: HKLM - SiteFinder - {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files\SiteFinder\SiteFinder.dll (Site Finder) Toolbar: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> No Name - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File Toolbar: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKU\S-1-5-21-2109998537-1096708334-3085003647-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M2AFC0F76-707D-477D-94B3-9083CFF0F7CC&SearchSource=55&CUI=&UM=8&UP=SP6DC3A597-E075-4BA6-8DA0-2789E522E7E2&SSPV=" CHR StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe http://www.delta-homes.com/?type=sc&ts=1419851507&from=wpm12262&uid=SAMSUNGXHD161HJ_S0V3J9CP931248 FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 -> C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 -> C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF Plugin: @tools.updaterss.com/SaveSenseLive Update;version=3 -> C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF Plugin: @tools.updaterss.com/SaveSenseLive Update;version=9 -> C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Classes\.exe: exefile => <===== ATTENTION! AlternateDataStreams: C:\Users\Dominik\Dane aplikacji:NT AlternateDataStreams: C:\Users\Dominik\AppData\Roaming:NT C:\END C:\Program Files\004 C:\Program Files\BonanzaDealsLive C:\Program Files\globalUpdate C:\Program Files\gmsd_pl_16 C:\Program Files\Gophoto.it C:\Program Files\HDvid Codec V1 C:\Program Files\HDvidCodec.com C:\Program Files\predm C:\Program Files\SaveSenseLive C:\Program Files\SiteFinder C:\Program Files\SweetIM C:\Program Files\WinZipper C:\Program Files\Yontoo C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder C:\ProgramData\IePluginServices C:\ProgramData\WindowsMangerProtect C:\Users\Dominik\AppData\Local\{*} C:\Users\Dominik\AppData\Local\RealSummerSale.crx C:\Users\Dominik\AppData\Local\CrashRpt C:\Users\Dominik\AppData\Local\GGEmpire C:\Users\Dominik\AppData\Local\globalUpdate C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\External Extensions C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\Dominik\AppData\Roaming\BabMaint.exe C:\Users\Dominik\AppData\Roaming\0D1F1S1C1P0P1C1F1N1C1T1H2UtF1E1I C:\Users\Dominik\AppData\Roaming\0I0M0D1F2W1G1I1F1T1Q1P1C C:\Users\Dominik\AppData\Roaming\Ask.com C:\Users\Dominik\AppData\Roaming\BabSolution C:\Users\Dominik\AppData\Roaming\Babylon C:\Users\Dominik\AppData\Roaming\DealPly C:\Users\Dominik\AppData\Roaming\dlg C:\Users\Dominik\AppData\Roaming\DSite C:\Users\Dominik\AppData\Roaming\DVDVideoSoft C:\Users\Dominik\AppData\Roaming\DVDVideoSoftIEHelpers C:\Users\Dominik\AppData\Roaming\GGEmpire441 C:\Users\Dominik\AppData\Roaming\HoolappForAndroid C:\Users\Dominik\AppData\Roaming\Media Finder C:\Users\Dominik\AppData\Roaming\Mipony C:\Users\Dominik\AppData\Roaming\OpenCandy C:\Users\Dominik\AppData\Roaming\Opera C:\Users\Dominik\AppData\Roaming\PerformerSoft C:\Users\Dominik\AppData\Roaming\rmi C:\Users\Dominik\AppData\Roaming\SaveSense C:\Users\Dominik\AppData\Roaming\SimilarSites C:\Users\Dominik\AppData\Roaming\Solvusoft C:\Users\Dominik\AppData\Roaming\systweak C:\Users\Dominik\AppData\Roaming\TMNT C:\Users\Dominik\AppData\Roaming\WinZipper C:\Users\Dominik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GoodGameEmpire.lnk C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense C:\Users\Dominik\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} C:\Users\Dominik\Desktop\Niepotwierdzony*.crdownload C:\Users\Public\Documents\ShopperPro C:\Users\Dominik\Downloads\*Downloader*.exe c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup C:\Windows\System32\roboot.exe C:\Windows\system32\Drivers\SPPD.sys Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Google\Chrome\Extensions /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f Reg; reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D}" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f CMD: netsh advfirewall reset CMD: dir /a "C:\Program Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Dominik\AppData\Local CMD: dir /a C:\Users\Dominik\AppData\LocalLow CMD: dir /a C:\Users\Dominik\AppData\Roaming ***************** Processes closed successfully. [1808] C:\Windows\explorer.exe => Process closed successfully. Restore point was successfully created. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_16 => value deleted successfully. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => value deleted successfully. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => Key deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => value deleted successfully. bonanzadealslive => Service deleted successfully. bonanzadealslivem => Service deleted successfully. IePluginServices => Service deleted successfully. rqpbhevlkc32 => Service deleted successfully. savesenselive => Service deleted successfully. savesenselivem => Service deleted successfully. EagleXNt => Service deleted successfully. ewusbnet => Service deleted successfully. ew_usbenumfilter => Service deleted successfully. huawei_enumerator => Service deleted successfully. hwdatacard => Service deleted successfully. MpKsl13a62a37 => Service deleted successfully. netfilter => Service deleted successfully. vtany => Service deleted successfully. WinRing0_1_2_0 => Service deleted successfully. XDva401 => Service deleted successfully. XDva402 => Service deleted successfully. XDva409 => Service deleted successfully. xhunter1 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{01C4E655-24EF-4262-842E-908A4095A613}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01C4E655-24EF-4262-842E-908A4095A613}" => Key deleted successfully. C:\Windows\System32\Tasks\DealPly => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2EAD9E21-1875-4786-9D2F-54F692B759F7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2EAD9E21-1875-4786-9D2F-54F692B759F7}" => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4053F668-3EC6-4036-9637-2E79A6C95617}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4053F668-3EC6-4036-9637-2E79A6C95617}" => Key deleted successfully. C:\Windows\System32\Tasks\GoodGameEmpire W1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoodGameEmpire W1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5A3ED164-A29F-4698-B7F6-D534FB816E7A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A3ED164-A29F-4698-B7F6-D534FB816E7A}" => Key deleted successfully. C:\Windows\System32\Tasks\task358833 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\task358833" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{62E4808D-C63B-4C0A-B621-B42DBE028A58}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{62E4808D-C63B-4C0A-B621-B42DBE028A58}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\systems" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6E042961-23D9-4FD5-BC83-41FD93DC2150}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E042961-23D9-4FD5-BC83-41FD93DC2150}" => Key deleted successfully. C:\Windows\System32\Tasks\GoodGameEmpire W2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoodGameEmpire W2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{77930916-DC41-4D13-91D7-3C2D5FCD42E7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77930916-DC41-4D13-91D7-3C2D5FCD42E7}" => Key deleted successfully. C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8576AD86-5029-43F2-8C67-B1F41116F93B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8576AD86-5029-43F2-8C67-B1F41116F93B}" => Key deleted successfully. C:\Windows\System32\Tasks\GoodGameEmpire NextW1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoodGameEmpire NextW1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AA1B585A-F14A-42BF-91F1-DEC9DF5CDB85}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA1B585A-F14A-42BF-91F1-DEC9DF5CDB85}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\fbagent" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AA3D7EEB-7C06-4283-AAB9-36511726160C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA3D7EEB-7C06-4283-AAB9-36511726160C}" => Key deleted successfully. C:\Windows\System32\Tasks\{00E2789E-2120-4C0A-B516-7D5841DE9AAF} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{00E2789E-2120-4C0A-B516-7D5841DE9AAF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B5E62214-A5F9-4E42-964B-3890A7CDEC92}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5E62214-A5F9-4E42-964B-3890A7CDEC92}" => Key deleted successfully. C:\Windows\System32\Tasks\Game_Booster_AutoUpdate => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Game_Booster_AutoUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B94EFB4F-3084-45D3-89AA-A84C90420EDE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B94EFB4F-3084-45D3-89AA-A84C90420EDE}" => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B9ADAE2A-425D-42DB-84FA-F0CB7A00DB38}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B9ADAE2A-425D-42DB-84FA-F0CB7A00DB38}" => Key deleted successfully. C:\Windows\System32\Tasks\GoodGameEmpire NextW2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoodGameEmpire NextW2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C174EEE4-8B17-43CC-A512-81BC7E0FF118}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C174EEE4-8B17-43CC-A512-81BC7E0FF118}" => Key deleted successfully. C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE2E9F63-9081-45AC-B045-5C725B4BC358}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE2E9F63-9081-45AC-B045-5C725B4BC358}" => Key deleted successfully. C:\Windows\System32\Tasks\{778FC7CC-15CA-4C08-B6C4-DCEAE647707C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{778FC7CC-15CA-4C08-B6C4-DCEAE647707C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E0DE6DAF-CEEB-42D4-A022-BC1D31AF5728}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0DE6DAF-CEEB-42D4-A022-BC1D31AF5728}" => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore" => Key deleted successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Dominik\Desktop\Ie.lnk => Shortcut argument was removed successfully. C:\Users\Dominik\Desktop\ww.lnk => Shortcut argument was removed successfully. C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Dominik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully. HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\{CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} => Value not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{575B1647-F599-45FB-92FA-158AA62F3396}" => Key deleted successfully. HKCR\CLSID\{575B1647-F599-45FB-92FA-158AA62F3396} => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key deleted successfully. HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{575B1647-F599-45FB-92FA-158AA62F3396}" => Key deleted successfully. HKCR\CLSID\{575B1647-F599-45FB-92FA-158AA62F3396} => Key not found. "HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key deleted successfully. HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311431162}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110311431162}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} => Key not found. HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} => Key not found. HKCR\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} => Value not found. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} => value deleted successfully. HKCR\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} => Value not found. HKCR\CLSID\{CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} => Key not found. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => value deleted successfully. HKCR\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => Key not found. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value deleted successfully. "HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => Key deleted successfully. Chrome StartupUrls deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. "HKLM\Software\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3" => Key deleted successfully. C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll => Moved successfully. "HKLM\Software\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9" => Key deleted successfully. C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. "HKLM\Software\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=3" => Key deleted successfully. C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll => Moved successfully. "HKLM\Software\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=9" => Key deleted successfully. C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml => Moved successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. "HKU\S-1-5-21-2109998537-1096708334-3085003647-1000\Software\Classes\.exe" => Key deleted successfully. "C:\Users\Dominik\Dane aplikacji" => ":NT" ADS not found. C:\Users\Dominik\AppData\Roaming => ":NT" ADS removed successfully. C:\END => Moved successfully. C:\Program Files\004 => Moved successfully. C:\Program Files\BonanzaDealsLive => Moved successfully. C:\Program Files\globalUpdate => Moved successfully. C:\Program Files\gmsd_pl_16 => Moved successfully. C:\Program Files\Gophoto.it => Moved successfully. C:\Program Files\HDvid Codec V1 => Moved successfully. C:\Program Files\HDvidCodec.com => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\SaveSenseLive => Moved successfully. "C:\Program Files\SiteFinder" => File/Directory not found. "C:\Program Files\SweetIM" => File/Directory not found. C:\Program Files\WinZipper => Moved successfully. "C:\Program Files\Yontoo" => File/Directory not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\Users\Dominik\AppData\Local\{*} => Moved successfully. C:\Users\Dominik\AppData\Local\RealSummerSale.crx => Moved successfully. C:\Users\Dominik\AppData\Local\CrashRpt => Moved successfully. C:\Users\Dominik\AppData\Local\GGEmpire => Moved successfully. C:\Users\Dominik\AppData\Local\globalUpdate => Moved successfully. C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx => Moved successfully. C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh => Moved successfully. "C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\External Extensions" => File/Directory not found. C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\Dominik\AppData\Roaming\BabMaint.exe => Moved successfully. "C:\Users\Dominik\AppData\Roaming\0D1F1S1C1P0P1C1F1N1C1T1H2UtF1E1I" => File/Directory not found. "C:\Users\Dominik\AppData\Roaming\0I0M0D1F2W1G1I1F1T1Q1P1C" => File/Directory not found. C:\Users\Dominik\AppData\Roaming\Ask.com => Moved successfully. C:\Users\Dominik\AppData\Roaming\BabSolution => Moved successfully. C:\Users\Dominik\AppData\Roaming\Babylon => Moved successfully. C:\Users\Dominik\AppData\Roaming\DealPly => Moved successfully. C:\Users\Dominik\AppData\Roaming\dlg => Moved successfully. C:\Users\Dominik\AppData\Roaming\DSite => Moved successfully. C:\Users\Dominik\AppData\Roaming\DVDVideoSoft => Moved successfully. C:\Users\Dominik\AppData\Roaming\DVDVideoSoftIEHelpers => Moved successfully. C:\Users\Dominik\AppData\Roaming\GGEmpire441 => Moved successfully. C:\Users\Dominik\AppData\Roaming\HoolappForAndroid => Moved successfully. C:\Users\Dominik\AppData\Roaming\Media Finder => Moved successfully. C:\Users\Dominik\AppData\Roaming\Mipony => Moved successfully. C:\Users\Dominik\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Dominik\AppData\Roaming\Opera => Moved successfully. C:\Users\Dominik\AppData\Roaming\PerformerSoft => Moved successfully. C:\Users\Dominik\AppData\Roaming\rmi => Moved successfully. C:\Users\Dominik\AppData\Roaming\SaveSense => Moved successfully. C:\Users\Dominik\AppData\Roaming\SimilarSites => Moved successfully. C:\Users\Dominik\AppData\Roaming\Solvusoft => Moved successfully. C:\Users\Dominik\AppData\Roaming\systweak => Moved successfully. C:\Users\Dominik\AppData\Roaming\TMNT => Moved successfully. C:\Users\Dominik\AppData\Roaming\WinZipper => Moved successfully. C:\Users\Dominik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GoodGameEmpire.lnk => Moved successfully. C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire => Moved successfully. C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com => Moved successfully. C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense => Moved successfully. C:\Users\Dominik\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} => Moved successfully. "C:\Users\Dominik\Desktop\Niepotwierdzony*.crdownload" => File/Directory not found. C:\Users\Public\Documents\ShopperPro => Moved successfully. C:\Users\Dominik\Downloads\*Downloader*.exe => Moved successfully. c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup => Moved successfully. C:\Windows\System32\roboot.exe => Moved successfully. C:\Windows\system32\Drivers\SPPD.sys => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Google\Chrome\Extensions /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= Reg; reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D}" /f => Error: No automatic fix found for this entry. ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 0A27-0611 Katalog: C:\Program Files 2015-01-07 15:29