Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01 Ran by Karolina at 2015-01-25 14:20:21 Run:1 Running from C:\Users\Karolina\Downloads Loaded Profiles: Karolina (Available profiles: Karolina) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=B6054C0F6E10A720&affID=119357&tt=080913_ctrl&tsp=5000 HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5736z&r=27361110f235l0424z155v47524269 HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/search?q={searchTerms} HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=18&q={searchTerms}&barid={12113390-2E4B-4415-89D1-74DB9DE622BF} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69} URL = http://search.bearshare.com/web?src=ieb&systemid=2&q={searchTerms} SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=18&q={searchTerms}&barid={12113390-2E4B-4415-89D1-74DB9DE622BF} SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={FB4215A1-B731-4501-A2D6-AD1838594A26}&mid=8bd0cd6fdd0d47d0af0f59e75b65a113-bc3ae82cd2758b5f87515caab2e724511db09901&lang=pl&ds=gm011&coid=avgtbdisgm&cmpid=&pr=sa&d=2014-02-16 19:20:35&v=18.1.9.799&pid=safeguard&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://www.bing.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?aff=2&src=sp&cf=050f35f6-dd55-11e1-88a8-88ae1d8148e0&q={searchTerms} SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.golsearch.com/?q={searchTerms}&babsrc=SP_ss_Btisdt6&mntrId=B6054C0F6E10A720&affID=119357&tt=080913_ctrl&tsp=5000 SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {6FC41EDD-4B02-4442-AA2B-B635C036EFAA} URL = http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={FB4215A1-B731-4501-A2D6-AD1838594A26}&mid=8bd0cd6fdd0d47d0af0f59e75b65a113-bc3ae82cd2758b5f87515caab2e724511db09901&lang=pl&ds=gm011&coid=avgtbdisgm&cmpid=&pr=sa&d=2014-02-16 19:20:35&v=18.1.9.799&pid=safeguard&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69} URL = http://search.bearshare.com/web?src=ieb&systemid=2&q={searchTerms} SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {AE0883A7-7BCD-4BCE-A0D4-F06B92B62D40} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^PL&apn_uid=EA2EB7E7-163D-474D-89C6-80D2D89736C0&apn_sauid=9CBB111D-F6A6-49BA-8435-F866CD561E14 SearchScopes: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&st=17&q={searchTerms}&barid={12113390-2E4B-4415-89D1-74DB9DE622BF} BHO-x32: MediaBar -> {0974BA1E-64EC-11DE-B2A5-E43756D89593} -> C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll No File BHO-x32: RewardsArcade -> {597A9974-8CB0-4f41-B61F-ED065738A397} -> C:\Program Files (x86)\RewardsArcade\RewardsArcade.dll (215 Apps) BHO-x32: IE5BarLauncherBHO Class -> {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} -> C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll No File BHO-x32: SweetPacks Browser Helper -> {EEE6C35C-6118-11DC-9C72-001320C79847} -> C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM-x32 - MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\PROGRA~2\BEARSH~1\MediaBar\ToolBar\BearshareMediabarDx.dll No File Toolbar: HKLM-x32 - StartSearchToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll No File Toolbar: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> No Name - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File Toolbar: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKU\S-1-5-21-905848300-39378253-2338670776-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml FF HKLM-x32\...\Firefox\Extensions: [crossriderapp498@crossrider.com] - C:\Users\Karolina\AppData\Local\RewardsArcade\498\Firefox FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799 CHR HKLM\...\Chrome\Extension: [khongjfjjmklggionajlpjcpmnppdace] - C:\Users\Karolina\AppData\Local\BargainJoy.crx [2013-09-12] CHR HKU\S-1-5-21-905848300-39378253-2338670776-1000\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [Not Found] CHR HKU\S-1-5-21-905848300-39378253-2338670776-1000\...\Chrome\Extension: [khongjfjjmklggionajlpjcpmnppdace] - C:\Users\Karolina\AppData\Local\BargainJoy.crx [2013-09-12] CHR HKLM-x32\...\Chrome\Extension: [dcmagccbogebndpoodhhhafmofelpffh] - C:\Users\Karolina\AppData\Local\RewardsArcade\498\Chrome\rewardsarcade.crx [2011-11-04] CHR HKLM-x32\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [Not Found] CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2012-06-14] CHR HKLM-x32\...\Chrome\Extension: [khongjfjjmklggionajlpjcpmnppdace] - C:\Users\Karolina\AppData\Local\BargainJoy.crx [2013-09-12] CHR HKLM-x32\...\Chrome\Extension: [pbiamblgmkgbcgbcgejjgebalncpmhnp] - C:\Program Files (x86)\StartSearch plugin\vshareplg.crx [2011-10-27] Task: {0CCA079F-1668-41BB-B8C9-30E9B395400F} - System32\Tasks\{46797E31-69B5-4EEE-8AB7-E7A250FCA824} => C:\Users\Karolina\Downloads\Photoshop_CS2_tryout\Photoshop CS2\Setup.exe Task: {3F04A133-AB9C-4D28-BF12-A244AE1C3626} - System32\Tasks\{B18BF057-A4BC-4512-97A2-CB3306BAE6AB} => C:\Users\Karolina\Downloads\Photoshop_CS2_tryout\Photoshop CS2\Setup.exe Task: {44123C41-5CE7-4687-91D2-6A0942312E47} - System32\Tasks\DealPly => C:\Users\Karolina\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {8FE1B1C3-5297-424C-9BDD-29E0A74A7DA1} - System32\Tasks\{2BB855C5-D278-4C41-A04D-5A794105E36A} => pcalua.exe -a "C:\Users\Karolina\Desktop\z kompa\upc_webstar_2000_series_usb_drvrs_v.3.2.3222\UNDPX2K.EXE" -d "C:\Users\Karolina\Desktop\z kompa\upc_webstar_2000_series_usb_drvrs_v.3.2.3222" Task: {C59DBBD7-9AA4-4271-B186-B3804E0CE99F} - System32\Tasks\DSite => C:\Users\Karolina\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {F84ABE94-6118-480C-8C2C-A6E84BE4EEF7} - \DealPlyUpdate No Task File <==== ATTENTION Task: C:\Windows\Tasks\DSite.job => C:\Users\Karolina\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION S3 UNDPR3K; \??\C:\Windows\system32\drivers\UNDPR3K.SYS [X] S3 UNDPX2A; \??\C:\Windows\system32\drivers\UNDPX2A.SYS [X] S3 UNDPX2K; \??\C:\Windows\system32\drivers\UNDPX2K.SYS [X] C:\Program Files (x86)\Mozilla Firefox\extensions C:\Program Files (x86)\Mozilla Firefox\plugins C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml C:\Program Files (x86)\RewardsArcade C:\Program Files (x86)\StartSearch plugin C:\ProgramData\whlb32g.dll C:\ProgramData\Temp C:\Users\Karolina\AppData\Local\{*} C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\Karolina\AppData\Local\RewardsArcade C:\Users\Karolina\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z C:\Users\Karolina\AppData\Roaming\AVG C:\Users\Karolina\AppData\Roaming\Babylon C:\Users\Karolina\AppData\Roaming\DealPly C:\Users\Karolina\AppData\Roaming\DigitalSites C:\Users\Karolina\AppData\Roaming\DSite C:\Users\Karolina\AppData\Roaming\Gadu-Gadu 10 C:\Users\Karolina\AppData\Roaming\OpenCandy C:\Users\Karolina\AppData\Roaming\OpenFM C:\Users\Karolina\AppData\Roaming\PerformerSoft C:\Users\Karolina\AppData\Roaming\Tlen.pl Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly /f CMD: netsh advfirewall reset CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a "C:\Program Files (x86)\Common Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Karolina\AppData\Local CMD: dir /a C:\Users\Karolina\AppData\LocalLow CMD: dir /a C:\Users\Karolina\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully. HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6FC41EDD-4B02-4442-AA2B-B635C036EFAA}" => Key deleted successfully. HKCR\CLSID\{6FC41EDD-4B02-4442-AA2B-B635C036EFAA} => Key not found. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}" => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69} => Key not found. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AE0883A7-7BCD-4BCE-A0D4-F06B92B62D40}" => Key deleted successfully. HKCR\CLSID\{AE0883A7-7BCD-4BCE-A0D4-F06B92B62D40} => Key not found. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key deleted successfully. HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{0974BA1E-64EC-11DE-B2A5-E43756D89593}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{597A9974-8CB0-4f41-B61F-ED065738A397} => Key not found. HKCR\Wow6432Node\CLSID\{597A9974-8CB0-4f41-B61F-ED065738A397} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} => Key not found. HKCR\Wow6432Node\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{0974BA1E-64EC-11DE-B2A5-E43756D89593} => value deleted successfully. HKCR\Wow6432Node\CLSID\{0974BA1E-64EC-11DE-B2A5-E43756D89593} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}" => Key deleted successfully. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => value deleted successfully. HKCR\CLSID\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} => Key not found. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key not found. HKU\S-1-5-21-905848300-39378253-2338670776-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\crossriderapp498@crossrider.com => Value not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\avg@toolbar => Value not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\khongjfjjmklggionajlpjcpmnppdace" => Key deleted successfully. C:\Users\Karolina\AppData\Local\BargainJoy.crx => Moved successfully. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje" => Key deleted successfully. "HKU\S-1-5-21-905848300-39378253-2338670776-1000\SOFTWARE\Google\Chrome\Extensions\khongjfjjmklggionajlpjcpmnppdace" => Key deleted successfully. "C:\Users\Karolina\AppData\Local\BargainJoy.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dcmagccbogebndpoodhhhafmofelpffh => Key not found. "C:\Users\Karolina\AppData\Local\RewardsArcade\498\Chrome\rewardsarcade.crx" => File/Directory not found. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn" => Key deleted successfully. C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\khongjfjjmklggionajlpjcpmnppdace" => Key deleted successfully. "C:\Users\Karolina\AppData\Local\BargainJoy.crx" => File/Directory not found. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp" => Key deleted successfully. "C:\Program Files (x86)\StartSearch plugin\vshareplg.crx" => File/Directory not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0CCA079F-1668-41BB-B8C9-30E9B395400F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0CCA079F-1668-41BB-B8C9-30E9B395400F}" => Key deleted successfully. C:\Windows\System32\Tasks\{46797E31-69B5-4EEE-8AB7-E7A250FCA824} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{46797E31-69B5-4EEE-8AB7-E7A250FCA824}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3F04A133-AB9C-4D28-BF12-A244AE1C3626}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F04A133-AB9C-4D28-BF12-A244AE1C3626}" => Key deleted successfully. C:\Windows\System32\Tasks\{B18BF057-A4BC-4512-97A2-CB3306BAE6AB} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B18BF057-A4BC-4512-97A2-CB3306BAE6AB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{44123C41-5CE7-4687-91D2-6A0942312E47}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44123C41-5CE7-4687-91D2-6A0942312E47}" => Key deleted successfully. C:\Windows\System32\Tasks\DealPly => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8FE1B1C3-5297-424C-9BDD-29E0A74A7DA1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FE1B1C3-5297-424C-9BDD-29E0A74A7DA1}" => Key deleted successfully. C:\Windows\System32\Tasks\{2BB855C5-D278-4C41-A04D-5A794105E36A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2BB855C5-D278-4C41-A04D-5A794105E36A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C59DBBD7-9AA4-4271-B186-B3804E0CE99F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C59DBBD7-9AA4-4271-B186-B3804E0CE99F}" => Key deleted successfully. C:\Windows\System32\Tasks\DSite => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F84ABE94-6118-480C-8C2C-A6E84BE4EEF7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F84ABE94-6118-480C-8C2C-A6E84BE4EEF7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate" => Key deleted successfully. C:\Windows\Tasks\DSite.job => Moved successfully. UNDPR3K => Service deleted successfully. UNDPX2A => Service deleted successfully. UNDPX2K => Service deleted successfully. C:\Program Files (x86)\Mozilla Firefox\extensions => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\plugins => Moved successfully. C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml => Moved successfully. "C:\Program Files (x86)\RewardsArcade" => File/Directory not found. C:\Program Files (x86)\StartSearch plugin => Moved successfully. C:\ProgramData\whlb32g.dll => Moved successfully. C:\ProgramData\Temp => Moved successfully. "C:\Users\Karolina\AppData\Local\{*}" directory move: Could not move "C:\Users\Karolina\AppData\Local\{*}" directory. => Scheduled to move on reboot. C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Karolina\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. "C:\Users\Karolina\AppData\Local\RewardsArcade" => File/Directory not found. C:\Users\Karolina\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z => Moved successfully. C:\Users\Karolina\AppData\Roaming\AVG => Moved successfully. C:\Users\Karolina\AppData\Roaming\Babylon => Moved successfully. C:\Users\Karolina\AppData\Roaming\DealPly => Moved successfully. C:\Users\Karolina\AppData\Roaming\DigitalSites => Moved successfully. C:\Users\Karolina\AppData\Roaming\DSite => Moved successfully. C:\Users\Karolina\AppData\Roaming\Gadu-Gadu 10 => Moved successfully. C:\Users\Karolina\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Karolina\AppData\Roaming\OpenFM => Moved successfully. C:\Users\Karolina\AppData\Roaming\PerformerSoft => Moved successfully. C:\Users\Karolina\AppData\Roaming\Tlen.pl => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= reg delete HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly /f ========= Operacja ukoäczona pomylnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C to Acer Numer seryjny woluminu: B605-9584 Katalog: C:\Program Files 2014-08-06 19:39