Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-02-2015 Ran by Wojtuq at 2015-02-15 19:14:16 Run:3 Running from C:\Users\Wojtuq\Desktop Loaded Profiles: Wojtuq (Available profiles: Wojtuq) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 kqemu; C:\Windows\SysWOW64\DRIVERS\kqemu.sys [144622 2015-02-12] () [File not signed] S3 MWAC; \??\C:\Windows\system32\drivers\ [0 ] () <==== ATTENTION (zero size file/folder) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [X] S3 usj; \??\D:\GAMES\AeriaGames\EdenEternal\avital\ussjcs64.sys [X] Task: {106FA3BD-95F7-4731-9294-B54A677ED16E} - System32\Tasks\Norton Management\Norton Error Analyzer => C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\SymErr.exe Task: {3033ABA6-AC2E-4CAD-BFAD-1F1043B80D6C} - System32\Tasks\{E119F1B4-AEE2-464F-8771-C6570DC8D568} => pcalua.exe -a "C:\Program Files (x86)\MSI\Live Update\LU5\DL_FILE\Atheros_Network_Drivers_2.1.0.21\setup.exe" -d C:\Windows\system32 -c /s /f1.\setup.iss /f2c:\AtherosLAN.log Task: {3A8129C7-8FDA-4EA6-99E4-B7A635E9F279} - System32\Tasks\{0246BC4A-7A55-4363-AD5D-67EF758CEA83} => pcalua.exe -a J:\Setup.EXE -d J:\ Task: {3B8FC219-DD61-49B8-8FE3-BF2148DB9894} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001Core => C:\Users\Wojtuq\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-12-08] (Facebook Inc.) Task: {45902C7C-F777-41B0-8EEB-EBF112542153} - System32\Tasks\{664AA5A3-0CF3-4CCB-88CB-3EB39BD46504} => pcalua.exe -a C:\Users\Wojtuq\Downloads\Shockwave_Installer_Slim.exe -d C:\Users\Wojtuq\Downloads Task: {509886A8-38CA-4EB1-AFA6-F12D8F7D25EC} - System32\Tasks\{98556B1C-C28B-4521-A443-DD906C0F6E38} => pcalua.exe -a "C:\Users\Wojtuq\Desktop\zdjęcia patryk\Shockwave_Installer_Slim.exe" -d "C:\Users\Wojtuq\Desktop\zdjęcia patryk" Task: {65563870-5609-4610-BF29-46A856B37A38} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001UA => C:\Users\Wojtuq\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-12-08] (Facebook Inc.) Task: {E1101349-DC3B-4769-8206-DA8EF73D394F} - System32\Tasks\Norton Management\Norton Error Processor => C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\SymErr.exe Task: {FF5BD6AE-E0A6-4FAA-9148-1B3B47B28A16} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1603038381-1674390504-77248367-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001Core.job => C:\Users\Wojtuq\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001UA.job => C:\Users\Wojtuq\AppData\Local\Facebook\Update\FacebookUpdate.exe HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-1603038381-1674390504-77248367-1001\...\Policies\system: [DisableLockWorkstation] 0 ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => No File ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => No File ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => No File ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => No File ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => No File ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => No File ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => No File ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1603038381-1674390504-77248367-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1603038381-1674390504-77248367-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1603038381-1674390504-77248367-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\PrivitizeVPN C:\Users\Wojtuq\AppData\Local\Facebook C:\Users\Wojtuq\AppData\Local\Google\Chrome C:\Users\Wojtuq\AppData\Local\Mozilla C:\Users\Wojtuq\AppData\Roaming\gameboxsetup.exe C:\Users\Wojtuq\AppData\Roaming\Mozilla C:\Users\Wojtuq\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GoodGameEmpire.lnk C:\Users\Wojtuq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire C:\Users\Wojtuq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton C:\Users\Wojtuq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PrivitizeVPN C:\Users\Wojtuq\AppData\Roaming\Microsoft\Word\bewerbung%20Dectblatt304214260053183420\bewerbung%20Dectblatt.docx.lnk C:\Users\Wojtuq\AppData\Roaming\Microsoft\Word\Lebenslauf%20Wojtek%20Traczyk%201304211700470070862\Lebenslauf%20Wojtek%20Traczyk%201.doc.lnk C:\Users\Wojtuq\Desktop\Programy\CDBurnerXP.lnk C:\Users\Wojtuq\Desktop\Programy\Estelar PDF Unlock Tool.lnk C:\Users\Wojtuq\Start Menu\Programs\VideoPerformer C:\Windows\System32\Tasks\Norton Management C:\Windows\SysWOW64\DRIVERS\kqemu.sys DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Management Reg: reg delete HKCU\Software\Clients\StartMenuInternet\Opera /f Reg: reg delete HKCU\Software\Google\Chrome /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\MozillaMaintenance" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\RealNetworks Downloader Resolver Service" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\SamsungAllShareV2.0" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\SimpleSlideShowServer" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AllShareAgent" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Browser Infrastructure Helper" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Facebook Update" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesAirMessage" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPreload" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PrivitizeVPN" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetIM" /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F7D739D1-B597-4802-A4CB-E1FBF326C9B0} /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PrivitizeVPN /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. AppMgmt => Service deleted successfully. kqemu => Service deleted successfully. MWAC => Service not found. catchme => Service not found. MBAMSwissArmy => Service not found. NTIOLib_1_0_4 => Service not found. usj => Service not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{106FA3BD-95F7-4731-9294-B54A677ED16E} => Key not found. C:\Windows\System32\Tasks\Norton Management\Norton Error Analyzer not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Management\Norton Error Analyzer => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3033ABA6-AC2E-4CAD-BFAD-1F1043B80D6C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3033ABA6-AC2E-4CAD-BFAD-1F1043B80D6C}" => Key deleted successfully. C:\Windows\System32\Tasks\{E119F1B4-AEE2-464F-8771-C6570DC8D568} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E119F1B4-AEE2-464F-8771-C6570DC8D568}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3A8129C7-8FDA-4EA6-99E4-B7A635E9F279}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A8129C7-8FDA-4EA6-99E4-B7A635E9F279}" => Key deleted successfully. C:\Windows\System32\Tasks\{0246BC4A-7A55-4363-AD5D-67EF758CEA83} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0246BC4A-7A55-4363-AD5D-67EF758CEA83}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3B8FC219-DD61-49B8-8FE3-BF2148DB9894}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B8FC219-DD61-49B8-8FE3-BF2148DB9894}" => Key deleted successfully. C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001Core => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001Core" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{45902C7C-F777-41B0-8EEB-EBF112542153}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{45902C7C-F777-41B0-8EEB-EBF112542153}" => Key deleted successfully. C:\Windows\System32\Tasks\{664AA5A3-0CF3-4CCB-88CB-3EB39BD46504} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{664AA5A3-0CF3-4CCB-88CB-3EB39BD46504}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{509886A8-38CA-4EB1-AFA6-F12D8F7D25EC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{509886A8-38CA-4EB1-AFA6-F12D8F7D25EC}" => Key deleted successfully. C:\Windows\System32\Tasks\{98556B1C-C28B-4521-A443-DD906C0F6E38} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{98556B1C-C28B-4521-A443-DD906C0F6E38}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65563870-5609-4610-BF29-46A856B37A38}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65563870-5609-4610-BF29-46A856B37A38}" => Key deleted successfully. C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001UA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001UA" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1101349-DC3B-4769-8206-DA8EF73D394F} => Key not found. C:\Windows\System32\Tasks\Norton Management\Norton Error Processor not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Management\Norton Error Processor => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF5BD6AE-E0A6-4FAA-9148-1B3B47B28A16} => Key not found. C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1603038381-1674390504-77248367-1001 not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealDownloaderDownloaderScheduledTaskS-1-5-21-1603038381-1674390504-77248367-1001 => Key not found. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001Core.job => Moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1603038381-1674390504-77248367-1001UA.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value not found. HKU\S-1-5-21-1603038381-1674390504-77248367-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay1 => Key not found. HKCR\CLSID\{E68D0A50-3C40-4712-B90D-DCFA93FF2534} => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay2 => Key not found. HKCR\CLSID\{E68D0A51-3C40-4712-B90D-DCFA93FF2534} => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay3 => Key not found. HKCR\CLSID\{E68D0A52-3C40-4712-B90D-DCFA93FF2534} => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay4 => Key not found. HKCR\CLSID\{E68D0A53-3C40-4712-B90D-DCFA93FF2534} => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncBackedUp => Key not found. HKCR\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncPending => Key not found. HKCR\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncRoot => Key not found. HKCR\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351} => Key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncShared => Key not found. HKCR\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51} => Key not found. "C:\Windows\system32\GroupPolicy\Machine" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key not found. HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => Key not found. HKU\S-1-5-21-1603038381-1674390504-77248367-1001\SOFTWARE\Policies\Microsoft\Internet Explorer => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-1603038381-1674390504-77248367-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-1603038381-1674390504-77248367-1001\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. "C:\Program Files (x86)\PrivitizeVPN" => File/Directory not found. C:\Users\Wojtuq\AppData\Local\Facebook => Moved successfully. "C:\Users\Wojtuq\AppData\Local\Google\Chrome" => File/Directory not found. C:\Users\Wojtuq\AppData\Local\Mozilla => Moved successfully. C:\Users\Wojtuq\AppData\Roaming\gameboxsetup.exe => Moved successfully. C:\Users\Wojtuq\AppData\Roaming\Mozilla => Moved successfully. "C:\Users\Wojtuq\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GoodGameEmpire.lnk" => File/Directory not found. C:\Users\Wojtuq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire => Moved successfully. C:\Users\Wojtuq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton => Moved successfully. "C:\Users\Wojtuq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PrivitizeVPN" => File/Directory not found. C:\Users\Wojtuq\AppData\Roaming\Microsoft\Word\bewerbung%20Dectblatt304214260053183420\bewerbung%20Dectblatt.docx.lnk => Moved successfully. C:\Users\Wojtuq\AppData\Roaming\Microsoft\Word\Lebenslauf%20Wojtek%20Traczyk%201304211700470070862\Lebenslauf%20Wojtek%20Traczyk%201.doc.lnk => Moved successfully. C:\Users\Wojtuq\Desktop\Programy\CDBurnerXP.lnk => Moved successfully. C:\Users\Wojtuq\Desktop\Programy\Estelar PDF Unlock Tool.lnk => Moved successfully. C:\Users\Wojtuq\Start Menu\Programs\VideoPerformer => Moved successfully. C:\Windows\System32\Tasks\Norton Management => Moved successfully. C:\Windows\SysWOW64\DRIVERS\kqemu.sys => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Management => Key Deleted successfully. ========= reg delete HKCU\Software\Clients\StartMenuInternet\Opera /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\MozillaMaintenance" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\RealNetworks Downloader Resolver Service" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\SamsungAllShareV2.0" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\SimpleSlideShowServer" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AllShareAgent" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Browser Infrastructure Helper" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Facebook Update" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GG" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesAirMessage" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPreload" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PrivitizeVPN" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetIM" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F7D739D1-B597-4802-A4CB-E1FBF326C9B0} /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PrivitizeVPN /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 527.3 MB temporary data. The system needed a reboot. ==== End of Fixlog 19:14:40 ====