Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-02-2015 Ran by Admin at 2015-02-07 00:12:36 Run:1 Running from C:\Users\Admin\Downloads Loaded Profiles: Admin (Available profiles: Admin) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 {4889ddce-7a83-45e6-afc9-1e4f1149fff4}Gw64; C:\Windows\System32\drivers\{4889ddce-7a83-45e6-afc9-1e4f1149fff4}Gw64.sys [48832 2015-02-03] (StdLib) R2 webinstrNewH; C:\Windows\system32\Drivers\webinstrNewH.sys [106456 2014-12-27] (Corsica) R2 82bea50f; c:\PROGRAM Files (x86)\CutterEdit\CutterEdit.dll [2353664 2015-01-18] () [File not signed] R2 b4704e3b; c:\Program Files (x86)\SystemAssister\SystemAssister.dll [1927680 2015-01-18] () [File not signed] R2 IHProtect Service; C:\Program Files (x86)\STab\ProtectService.exe [158864 2014-11-10] (TODO: ) R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7410024 2015-01-14] (Reimage®) R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [464384 2015-02-03] (SysTool PasSame LIMITED) [File not signed] S2 4dd8d474; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\RelayDouble\RelayDouble.dll",serv S3 cpuz136; \??\C:\Users\Admin\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S3 SMUpdd; \??\C:\Program Files\Common Files\Goobzo\GBUpdate\smw.sys [X] S2 Update Cyti Web; "C:\Program Files (x86)\Cyti Web\updateCytiWeb.exe" [X] S2 Util Cyti Web; "C:\Program Files (x86)\Cyti Web\bin\utilCytiWeb.exe" [X] Task: {09268FFA-65EC-4DFA-A183-33DF086675E9} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {4295E571-F86E-4BA5-AAFA-E0EDC7487210} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {56066274-369E-4977-AFA9-4F2DE98B2998} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION Task: {580E06B7-AC26-4553-A8A9-9E1D1EB800D6} - System32\Tasks\{8950104A-BAA4-4D7D-8ECA-A9CF20156427} => pcalua.exe -a "C:\Program Files (x86)\Cyti Web\CytiWebuninstall.exe" Task: {5D2309D7-290B-42AF-954E-E5A5F80533D1} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe [2014-11-30] () <==== ATTENTION Task: {6FC20A39-6CD8-425B-9BF1-18DB8E193F55} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {80C54186-01D1-49CC-866D-7F4A7D038AD9} - System32\Tasks\LuckyTab => C:\Program Files (x86)\LuckyTab\LuckyTab.exe <==== ATTENTION Task: {A36AA8A6-D688-492E-B0AA-2103E92356E4} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2015-01-14] (Reimage®) <==== ATTENTION Task: {D27F3C77-2841-415D-BB7C-3DF10A750B55} - System32\Tasks\SMupdate1 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update1 <==== ATTENTION Task: {D488BCAA-FCEB-4E1B-AA3A-DE4EE4E2303F} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Admin\AppData\Local\SmartWeb\SmartWebHelper.exe [2015-01-28] (SoftBrain Technologies Ltd.) Task: {E3172335-1454-4B78-AA66-232D3BBB13D7} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION HKLM-x32\...\Run: [gmsd_pl_5] => [X] HKLM-x32\...\Run: [gmsd_pl_42] => [X] HKLM-x32\...\Run: [rec_pl_1] => [X] HKLM-x32\...\Run: [rec_pl_2] => [X] HKLM-x32\...\Run: [SmartWeb] => C:\Users\Admin\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-01-28] (SoftBrain Technologies Ltd.) HKLM\...\Policies\Explorer: [NoControlPanel] 0 Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File BootExecute: autocheck autochk * aswBoot.exe /M:e3c391c91 /wow /dir:"C:\Program Files\AVAST Software\Avast" GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hppp&ts=1418079068&from=exp&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX /verysilent /hideuninstall HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1422968011&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hppp&ts=1418079068&from=exp&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX /verysilent /hideuninstall HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422968011&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&q={searchTerms} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422968011&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422968011&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&q={searchTerms} SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422968011&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422968011&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&q={searchTerms} SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-2305985715-200173359-747348330-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-2305985715-200173359-747348330-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=face&utm_campaign=install_ie&utm_content=ds&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&ts=1422968126&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2305985715-200173359-747348330-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=face&utm_campaign=install_ie&utm_content=ds&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&ts=1422968126&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2305985715-200173359-747348330-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-2305985715-200173359-747348330-1001 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=face&utm_campaign=install_ie&utm_content=ds&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&ts=1422968126&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2305985715-200173359-747348330-1001 -> {ADE86A6D-9873-40C4-985B-EFC8D13D3878} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=face&utm_campaign=install_ie&utm_content=ds&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&ts=1422968126&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2305985715-200173359-747348330-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=face&utm_campaign=install_ie&utm_content=ds&from=face&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX&ts=1422968126&type=default&q={searchTerms} BHO: HQ-Video-Pro-2.1V27.12 -> {11111111-1111-1111-1111-110611571181} -> C:\Program Files (x86)\HQ-Video-Pro-2.1V27.12\HQ-Video-Pro-2.1V27.12-bho64.dll No File BHO: Media+PlayerVidEd2.1 -> {11111111-1111-1111-1111-110611791113} -> C:\Program Files (x86)\Media+PlayerVidEd2.1\Media+PlayerVidEd2.1-bho64.dll (Enter) BHO: deaoielyyprize -> {140848b7-ba94-4612-871b-1419493e870c} -> C:\ProgramData\deaoielyyprize\5nn11NmzMfokOG.x64.dll () BHO: apaPsave -> {48d798ae-8cb8-4403-8e2e-a2cfd02abbab} -> C:\ProgramData\apaPsave\bhaNKpXrgVKPy1.x64.dll () BHO: nitroDeal -> {59de4826-a00e-475f-8311-b5580916e3c1} -> C:\ProgramData\nitroDeal\KTLTd32RimTYV7.x64.dll () BHO: nnItrodeeal -> {87f6fba8-c6eb-4f03-9e18-12a29daee7a7} -> C:\ProgramData\nnItrodeeal\yaL8qPURPSmwEB.x64.dll () BHO-x32: HQ-Video-Pro-2.1V27.12 -> {11111111-1111-1111-1111-110611571181} -> C:\Program Files (x86)\HQ-Video-Pro-2.1V27.12\HQ-Video-Pro-2.1V27.12-bho.dll No File BHO-x32: Media+PlayerVidEd2.1 -> {11111111-1111-1111-1111-110611791113} -> C:\Program Files (x86)\Media+PlayerVidEd2.1\Media+PlayerVidEd2.1-bho.dll (Enter) BHO-x32: deaoielyyprize -> {140848b7-ba94-4612-871b-1419493e870c} -> C:\ProgramData\deaoielyyprize\5nn11NmzMfokOG.dll () BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\XTab\SupTab.dll (Thinknice Co. Limited) BHO-x32: apaPsave -> {48d798ae-8cb8-4403-8e2e-a2cfd02abbab} -> C:\ProgramData\apaPsave\bhaNKpXrgVKPy1.dll () BHO-x32: nitroDeal -> {59de4826-a00e-475f-8311-b5580916e3c1} -> C:\ProgramData\nitroDeal\KTLTd32RimTYV7.dll () BHO-x32: nnItrodeeal -> {87f6fba8-c6eb-4f03-9e18-12a29daee7a7} -> C:\ProgramData\nnItrodeeal\yaL8qPURPSmwEB.dll () StartMenuInternet: IEXPLORE.EXE - iexplore.exe FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\pn8gqu1z.default\extensions\fftoolbar2014@etech.com FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\pn8gqu1z.default\extensions\faststartff@gmail.com FF HKU\S-1-5-21-2305985715-200173359-747348330-1001\...\Firefox\Extensions: [{4B55B3C6-B7D6-F951-65AD-4BBEB0EF1F8E}] - C:\Program Files (x86)\ver2SpeedCheck\184.xpi CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hppp&ts=1418079068&from=exp&uid=HGSTXHTS541010A9E680_JB1000132X9RZP2X9RZPX\t/verysilent /hideuninstall" CHR DefaultSearchKeyword: Default -> webssearches HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" C:\Program Files\Common Files\mcafee C:\Program Files\Common Files\System\SysMenu.dll C:\Program Files\Reimage C:\Program Files (x86)\6add4cc5-a266-486a-81cd-809c0a8fba83 C:\Program Files (x86)\CutterEdit C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\HQ-Video-Pro-2.1V27.12 C:\Program Files (x86)\LuckyTab C:\Program Files (x86)\Media+PlayerVidEd2.1 C:\Program Files (x86)\predm C:\Program Files (x86)\RelayDouble C:\Program Files (x86)\STab C:\Program Files (x86)\SystemAssister C:\Program Files (x86)\XTab C:\ProgramData\352b27b7506f20d3 C:\ProgramData\apaPsave C:\ProgramData\CoupExtension C:\ProgramData\d09d987b00003f95 C:\ProgramData\deaoielyyprize C:\ProgramData\GreatSave4U C:\ProgramData\ifophngfmomhnbechadpikpkbopikibe C:\ProgramData\MFAData C:\ProgramData\nitroDeal C:\ProgramData\nnItrodeeal C:\ProgramData\pbfmjflhfenidpddejoaeggopfdbepjd C:\ProgramData\Trusted Publisher C:\ProgramData\WindowsMangerProtect C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair C:\Users\Admin\AppData\Local\nsyCEF3.tmp C:\Users\Admin\AppData\Local\Avg2014 C:\Users\Admin\AppData\Local\CrashRpt C:\Users\Admin\AppData\Local\globalUpdate C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local storage\*localstorage* C:\Users\Admin\AppData\Local\SmartWeb C:\Users\Admin\AppData\Roaming\appdataFr2.bin C:\Users\Admin\AppData\Roaming\BMFHCHWA C:\Users\Admin\AppData\Roaming\LBOVY C:\Users\Admin\AppData\Roaming\OLLRJBOY C:\Users\Admin\AppData\Roaming\TCEAppLauncherLog.txt C:\Users\Admin\AppData\Roaming\UNDIQAF C:\Users\Admin\AppData\Roaming\337Games C:\Users\Admin\AppData\Roaming\AnyProtectEx C:\Users\Admin\AppData\Roaming\omiga-plus C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\*localstorage* C:\Users\Admin\AppData\Roaming\SYSTWEAK C:\Users\Admin\Desktop\Continue Live INSTALLATION.lnk C:\Users\Public\Documents\ShopperPro C:\Windows\patsearch.bin C:\Windows\Reimage.ini C:\Windows\system32\OptimizerMonitorOff.ini C:\Windows\system32\roboot64.exe C:\Windows\System32\drivers\{4889ddce-7a83-45e6-afc9-1e4f1149fff4}Gw64.sys C:\Windows\system32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf C:\Windows\system32\drivers\webinstrNewH.sys C:\Windows\SysWOW64\OptimizerMonitor.ini C:\Windows\SysWOW64\OptimizerMonitorOff.ini Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. {4889ddce-7a83-45e6-afc9-1e4f1149fff4}Gw64 => Unable to stop service {4889ddce-7a83-45e6-afc9-1e4f1149fff4}Gw64 => Service deleted successfully. webinstrNewH => Unable to stop service webinstrNewH => Service deleted successfully. 82bea50f => Service deleted successfully. b4704e3b => Service deleted successfully. IHProtect Service => Service deleted successfully. ReimageRealTimeProtector => Service not found. WindowsMangerProtect => Service deleted successfully. 4dd8d474 => Service deleted successfully. cpuz136 => Service deleted successfully. MBAMSwissArmy => Service deleted successfully. SMUpdd => Service deleted successfully. Update Cyti Web => Service deleted successfully. Util Cyti Web => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{09268FFA-65EC-4DFA-A183-33DF086675E9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09268FFA-65EC-4DFA-A183-33DF086675E9}" => Key deleted successfully. C:\Windows\System32\Tasks\APSnotifierPP3 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4295E571-F86E-4BA5-AAFA-E0EDC7487210}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4295E571-F86E-4BA5-AAFA-E0EDC7487210}" => Key deleted successfully. C:\Windows\System32\Tasks\APSnotifierPP2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{56066274-369E-4977-AFA9-4F2DE98B2998}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56066274-369E-4977-AFA9-4F2DE98B2998}" => Key deleted successfully. C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{580E06B7-AC26-4553-A8A9-9E1D1EB800D6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{580E06B7-AC26-4553-A8A9-9E1D1EB800D6}" => Key deleted successfully. C:\Windows\System32\Tasks\{8950104A-BAA4-4D7D-8ECA-A9CF20156427} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8950104A-BAA4-4D7D-8ECA-A9CF20156427}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D2309D7-290B-42AF-954E-E5A5F80533D1} => Key not found. C:\Windows\System32\Tasks\Reimage Reminder not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Reimage Reminder => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6FC20A39-6CD8-425B-9BF1-18DB8E193F55}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FC20A39-6CD8-425B-9BF1-18DB8E193F55}" => Key deleted successfully. C:\Windows\System32\Tasks\APSnotifierPP1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{80C54186-01D1-49CC-866D-7F4A7D038AD9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80C54186-01D1-49CC-866D-7F4A7D038AD9}" => Key deleted successfully. C:\Windows\System32\Tasks\LuckyTab => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LuckyTab" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A36AA8A6-D688-492E-B0AA-2103E92356E4} => Key not found. C:\Windows\System32\Tasks\ReimageUpdater not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ReimageUpdater => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D27F3C77-2841-415D-BB7C-3DF10A750B55}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D27F3C77-2841-415D-BB7C-3DF10A750B55}" => Key deleted successfully. C:\Windows\System32\Tasks\SMupdate1 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMupdate1" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D488BCAA-FCEB-4E1B-AA3A-DE4EE4E2303F} => Key not found. C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E3172335-1454-4B78-AA66-232D3BBB13D7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3172335-1454-4B78-AA66-232D3BBB13D7}" => Key deleted successfully. C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\SMupdate2" => Key deleted successfully. C:\Windows\Tasks\APSnotifierPP1.job => Moved successfully. C:\Windows\Tasks\APSnotifierPP2.job => Moved successfully. C:\Windows\Tasks\APSnotifierPP3.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_5 => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_42 => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\rec_pl_1 => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\rec_pl_2 => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SmartWeb => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}" => Key deleted successfully. HKCR\CLSID\{80c554b9-c7f8-4a21-9471-06d606da78a2} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{80c554b9-c7f8-4a21-9471-06d606da78a2} => Key not found. HKU\S-1-5-21-2305985715-200173359-747348330-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-2305985715-200173359-747348330-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-2305985715-200173359-747348330-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => Key deleted successfully. HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => Key not found. "HKU\S-1-5-21-2305985715-200173359-747348330-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-2305985715-200173359-747348330-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}" => Key deleted successfully. HKCR\CLSID\{80c554b9-c7f8-4a21-9471-06d606da78a2} => Key not found. "HKU\S-1-5-21-2305985715-200173359-747348330-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ADE86A6D-9873-40C4-985B-EFC8D13D3878}" => Key deleted successfully. HKCR\CLSID\{ADE86A6D-9873-40C4-985B-EFC8D13D3878} => Key not found. "HKU\S-1-5-21-2305985715-200173359-747348330-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => Key deleted successfully. HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110611571181}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611791113}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110611791113}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{140848b7-ba94-4612-871b-1419493e870c}" => Key deleted successfully. "HKCR\CLSID\{140848b7-ba94-4612-871b-1419493e870c}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48d798ae-8cb8-4403-8e2e-a2cfd02abbab}" => Key deleted successfully. "HKCR\CLSID\{48d798ae-8cb8-4403-8e2e-a2cfd02abbab}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59de4826-a00e-475f-8311-b5580916e3c1}" => Key deleted successfully. "HKCR\CLSID\{59de4826-a00e-475f-8311-b5580916e3c1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87f6fba8-c6eb-4f03-9e18-12a29daee7a7}" => Key deleted successfully. "HKCR\CLSID\{87f6fba8-c6eb-4f03-9e18-12a29daee7a7}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611571181}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611791113}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611791113}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{140848b7-ba94-4612-871b-1419493e870c}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{140848b7-ba94-4612-871b-1419493e870c}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48d798ae-8cb8-4403-8e2e-a2cfd02abbab}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{48d798ae-8cb8-4403-8e2e-a2cfd02abbab}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59de4826-a00e-475f-8311-b5580916e3c1}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{59de4826-a00e-475f-8311-b5580916e3c1}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87f6fba8-c6eb-4f03-9e18-12a29daee7a7}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{87f6fba8-c6eb-4f03-9e18-12a29daee7a7}" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\fftoolbar2014@etech.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\faststartff@gmail.com => value deleted successfully. HKU\S-1-5-21-2305985715-200173359-747348330-1001\Software\Mozilla\Firefox\Extensions\\{4B55B3C6-B7D6-F951-65AD-4BBEB0EF1F8E} => value deleted successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSearchKeyword deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc" => Key deleted successfully. C:\Program Files\Common Files\mcafee => Moved successfully. C:\Program Files\Common Files\System\SysMenu.dll => Moved successfully. "C:\Program Files\Reimage" => File/Directory not found. C:\Program Files (x86)\6add4cc5-a266-486a-81cd-809c0a8fba83 => Moved successfully. C:\Program Files (x86)\CutterEdit => Moved successfully. C:\Program Files (x86)\globalUpdate => Moved successfully. "C:\Program Files (x86)\HQ-Video-Pro-2.1V27.12" => File/Directory not found. C:\Program Files (x86)\LuckyTab => Moved successfully. C:\Program Files (x86)\Media+PlayerVidEd2.1 => Moved successfully. C:\Program Files (x86)\predm => Moved successfully. C:\Program Files (x86)\RelayDouble => Moved successfully. C:\Program Files (x86)\STab => Moved successfully. C:\Program Files (x86)\SystemAssister => Moved successfully. C:\Program Files (x86)\XTab => Moved successfully. C:\ProgramData\352b27b7506f20d3 => Moved successfully. C:\ProgramData\apaPsave => Moved successfully. C:\ProgramData\CoupExtension => Moved successfully. C:\ProgramData\d09d987b00003f95 => Moved successfully. C:\ProgramData\deaoielyyprize => Moved successfully. C:\ProgramData\GreatSave4U => Moved successfully. C:\ProgramData\ifophngfmomhnbechadpikpkbopikibe => Moved successfully. C:\ProgramData\MFAData => Moved successfully. C:\ProgramData\nitroDeal => Moved successfully. C:\ProgramData\nnItrodeeal => Moved successfully. C:\ProgramData\pbfmjflhfenidpddejoaeggopfdbepjd => Moved successfully. C:\ProgramData\Trusted Publisher => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair" => File/Directory not found. C:\Users\Admin\AppData\Local\nsyCEF3.tmp => Moved successfully. C:\Users\Admin\AppData\Local\Avg2014 => Moved successfully. C:\Users\Admin\AppData\Local\CrashRpt => Moved successfully. C:\Users\Admin\AppData\Local\globalUpdate => Moved successfully. C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local storage\*localstorage* => Moved successfully. "C:\Users\Admin\AppData\Local\SmartWeb" => File/Directory not found. C:\Users\Admin\AppData\Roaming\appdataFr2.bin => Moved successfully. C:\Users\Admin\AppData\Roaming\BMFHCHWA => Moved successfully. C:\Users\Admin\AppData\Roaming\LBOVY => Moved successfully. C:\Users\Admin\AppData\Roaming\OLLRJBOY => Moved successfully. C:\Users\Admin\AppData\Roaming\TCEAppLauncherLog.txt => Moved successfully. C:\Users\Admin\AppData\Roaming\UNDIQAF => Moved successfully. C:\Users\Admin\AppData\Roaming\337Games => Moved successfully. C:\Users\Admin\AppData\Roaming\AnyProtectEx => Moved successfully. C:\Users\Admin\AppData\Roaming\omiga-plus => Moved successfully. C:\Users\Admin\AppData\Roaming\Opera Software\Opera Stable\Local Storage\*localstorage* => Moved successfully. C:\Users\Admin\AppData\Roaming\SYSTWEAK => Moved successfully. C:\Users\Admin\Desktop\Continue Live INSTALLATION.lnk => Moved successfully. C:\Users\Public\Documents\ShopperPro => Moved successfully. C:\Windows\patsearch.bin => Moved successfully. C:\Windows\Reimage.ini => Moved successfully. C:\Windows\system32\OptimizerMonitorOff.ini => Moved successfully. C:\Windows\system32\roboot64.exe => Moved successfully. C:\Windows\System32\drivers\{4889ddce-7a83-45e6-afc9-1e4f1149fff4}Gw64.sys => Moved successfully. C:\Windows\system32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf => Moved successfully. C:\Windows\system32\drivers\webinstrNewH.sys => Moved successfully. C:\Windows\SysWOW64\OptimizerMonitor.ini => Moved successfully. C:\Windows\SysWOW64\OptimizerMonitorOff.ini => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 509 MB temporary data. The system needed a reboot. ==== End of Fixlog 00:14:38 ====