Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01 Ran by tony at 2015-02-20 07:50:40 Run:1 Running from C:\Users\tony\Desktop Loaded Profiles: tony (Available profiles: tony) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system) R2 Security Updates Service; C:\Program Files (x86)\Security Updates Service\winupdsvc.exe [861696 2014-09-05] () [File not signed] R2 serversu; C:\Users\tony\AppData\Roaming\SoftwareUpdater\SUsrv.exe [217088 2015-02-11] () [File not signed] S1 wpnfd_1_10_0_9; system32\drivers\wpnfd_1_10_0_9.sys [X] Task: {09D8972F-7ECD-46D6-B8D4-9FD2F5BD1BED} - System32\Tasks\Taplika => C:\Users\tony\AppData\Roaming\Taplika\UpdateProc\UpdateTask.exe [2015-02-18] () <==== ATTENTION Task: {126F1177-1362-448B-B188-2891BCAE973B} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe Task: {1427930C-DC9B-4624-9054-83BC0434FF76} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: {2A3DC940-B5B2-4328-8DF8-9B70F8D26CD6} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: {4861A125-A5A9-4EAE-ABBB-322B1F59037C} - System32\Tasks\{A478F646-3406-4B08-BC83-F093C00B91CA} => pcalua.exe -a "C:\Program Files (x86)\Wajam\uninstall.exe" Task: {612D53EF-F46C-43F3-B2B3-8C8BD2436EC3} - System32\Tasks\PostPoneInstall => C:\Users\tony\AppData\Local\Temp\ce98ac2e-20c0-4a93-86f6-bdb3e61caf55.exe <==== ATTENTION Task: {AF738624-1BCE-43E9-9D16-406D740C2492} - System32\Tasks\{45B98C63-7830-4D65-ACF9-6C63439458C0} => pcalua.exe -a "C:\Program Files (x86)\WildGames\Uninstall.exe" Task: {C94C9AD5-F816-42A7-91ED-3271E641D2FC} - System32\Tasks\Run_Bobby_Browser => C:\Users\tony\AppData\Local\BoBrowser\Application\bobrowser.exe <==== ATTENTION Task: {D8564587-09DC-4B5A-8624-FE64DF7C0866} - System32\Tasks\{E5BFA09E-B581-4BF7-8FE7-E08FF47CB22C} => pcalua.exe -a C:\Users\tony\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\Taplika.job => C:\Users\tony\AppData\Roaming\Taplika\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Startup: C:\Users\tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OPTISetup.lnk Startup: C:\Users\tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\superpc_soft_partner.lnk HKLM\...\Run: [3D BubbleSound] => "C:\Program Files\BubbleSound\3D BubbleSound.exe" HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [gmsd_gb_130] => [X] HKLM-x32\...\RunOnce: [Taplika] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\tony\AppData\Roaming\Taplika\UpdateProc\bkup.dat" HKLM-x32\...\RunOnce: [SpUninstallCleanUp] => REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\...\RunOnce: [Taplika] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\tony\AppData\Roaming\Taplika\UpdateProc\bkup.dat" HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\...\MountPoints2: {40f1f7c9-b226-11e4-beb7-b888e3cfe887} - "F:\setup.exe" CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:53182;https=127.0.0.1:53182 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hppp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006 HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hppp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://taplika.com/results.php?f=4&q={searchTerms}&a=tpl_idaddy2_15_08&cd=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtA0C0F0EzzzzyByByEtD0FtN0D0Tzu0StCtCyEyEtN1L2XzutAtFyBtFtBtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtBtN1L1G1B1V1N2Y1L1Qzu2SyBtBtDyByC0E0EyDtGyByDtD0FtG0EyCtDyEtGtB0D0C0BtGtB0CtCyD0ByDtD0CtAyEyDyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DtCyCyE0AtBtB0BtG0ByCzz0AtGyEyE0EtAtGzz0F0DtCtGtCtAtDzytD0FtBtBtC0E0DyD2Q&cr=471974407&ir= SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://taplika.com/results.php?f=4&q={searchTerms}&a=tpl_idaddy2_15_08&cd=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtA0C0F0EzzzzyByByEtD0FtN0D0Tzu0StCtCyEyEtN1L2XzutAtFyBtFtBtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtBtN1L1G1B1V1N2Y1L1Qzu2SyBtBtDyByC0E0EyDtGyByDtD0FtG0EyCtDyEtGtB0D0C0BtGtB0CtCyD0ByDtD0CtAyEyDyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DtCyCyE0AtBtB0BtG0ByCzz0AtGyEyE0EtAtGzz0F0DtCtGtCtAtDzytD0FtBtBtC0E0DyD2Q&cr=471974407&ir= SearchScopes: HKLM -> {589B893E-773C-4941-88C2-0DCC718E621C} URL = http://taplika.com/results.php?f=4&q={searchTerms}&a=tpl_idaddy2_15_08&cd=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtA0C0F0EzzzzyByByEtD0FtN0D0Tzu0StCtCyEyEtN1L2XzutAtFyBtFtBtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtBtN1L1G1B1V1N2Y1L1Qzu2SyBtBtDyByC0E0EyDtGyByDtD0FtG0EyCtDyEtGtB0D0C0BtGtB0CtCyD0ByDtD0CtAyEyDyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DtCyCyE0AtBtB0BtG0ByCzz0AtGyEyE0EtAtGzz0F0DtCtGtCtAtDzytD0FtBtBtC0E0DyD2Q&cr=471974407&ir= SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = http://www.default-search.net/search?sid=498&aid=159&itype=n&ver=15446&tm=622&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=dspp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&q={searchTerms} SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = http://www.default-search.net/search?sid=498&aid=159&itype=n&ver=15446&tm=622&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3329908&octid=EB_ORIGINAL_CTID&ISID=MC2E4D316-0118-4242-81E8-F43485229BCF&SearchSource=58&CUI=&UM=2&UP=SP7432F7A1-4CC6-41B8-BEC3-A0F57B00F89E&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3329908&octid=EB_ORIGINAL_CTID&ISID=MC2E4D316-0118-4242-81E8-F43485229BCF&SearchSource=58&CUI=&UM=2&UP=SP7432F7A1-4CC6-41B8-BEC3-A0F57B00F89E&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&ts=1423694765&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&ts=1423694765&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {2DF96447-06FF-45B9-80C0-DD3762EFDB26} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&ts=1423694765&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://taplika.com/results.php?f=4&q={searchTerms}&a=tpl_idaddy2_15_08&cd=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtA0C0F0EzzzzyByByEtD0FtN0D0Tzu0StCtCyEyEtN1L2XzutAtFyBtFtBtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtBtN1L1G1B1V1N2Y1L1Qzu2SyBtBtDyByC0E0EyDtGyByDtD0FtG0EyCtDyEtGtB0D0C0BtGtB0CtCyD0ByDtD0CtAyEyDyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DtCyCyE0AtBtB0BtG0ByCzz0AtGyEyE0EtAtGzz0F0DtCtGtCtAtDzytD0FtBtBtC0E0DyD2Q&cr=471974407&ir= SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {589B893E-773C-4941-88C2-0DCC718E621C} URL = http://taplika.com/results.php?f=4&q={searchTerms}&a=tpl_idaddy2_15_08&cd=2XzuyEtN2Y1L1Qzu0Bzzzzzz0EtA0C0F0EzzzzyByByEtD0FtN0D0Tzu0StCtCyEyEtN1L2XzutAtFyBtFtBtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtBtN1L1G1B1V1N2Y1L1Qzu2SyBtBtDyByC0E0EyDtGyByDtD0FtG0EyCtDyEtGtB0D0C0BtGtB0CtCyD0ByDtD0CtAyEyDyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DtCyCyE0AtBtB0BtG0ByCzz0AtGyEyE0EtAtGzz0F0DtCtGtCtAtDzytD0FtBtBtC0E0DyD2Q&cr=471974407&ir= SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = http://www.default-search.net/search?sid=498&aid=159&itype=n&ver=15446&tm=622&src=ds&p={searchTerms} SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {DE6732B4-C9B3-4E16-BB71-2283ED5D25C5} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&ts=1423694765&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartsearch.com/web/?utm_source=b&utm_medium=smt&utm_campaign=install_ie&utm_content=ds&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T&ts=1423694765&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-4030865254-2996239518-2335188200-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms} BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File StartMenuInternet: IEXPLORE.EXE - iexplore.exe CHR StartupUrls: Default -> "hxxp://google.pl/", "hxxp://www.mystartsearch.com/?type=hppp&ts=1423694734&from=smt&uid=TOSHIBAXMQ01ABD050_92C3C1I5TXX92C3C1I5T" CHR DefaultSearchKeyword: Default -> mystartsearch CHR HKLM\...\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - No Path CHR HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\...\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - No Path CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-01-16] CHR HKLM-x32\...\Chrome\Extension: [iomphmdalfmaifjccmagmllnicjoghhk] - No Path CHR HKLM-x32\...\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - No Path HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" C:\error.txt C:\prefs.js C:\Program Files\BubbleSound C:\Program Files (x86)\FLVPlayer C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\HomeTab C:\Program Files (x86)\predm C:\Program Files (x86)\Pro PC Cleaner C:\Program Files (x86)\Reverse Page C:\Program Files (x86)\SearchProtect C:\Program Files (x86)\Security Updates Service C:\Program Files (x86)\Setup Support for SearchProtect C:\Program Files (x86)\ver1BlockAndSurf C:\Program Files (x86)\Wajam C:\Program Files (x86)\XTab C:\ProgramData\cryptoDrvUpdate.exe C:\ProgramData\{b7dcd416-2d7c-bcf7-b7dc-cd4162d75058} C:\ProgramData\{dd389746-f1b7-0d61-dd38-89746f1b5d1b} C:\ProgramData\8da1b290000036d6 C:\ProgramData\APN C:\ProgramData\Apple C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 C:\Users\tony\AppData\Local\824078 C:\Users\tony\AppData\Local\BoBrowser C:\Users\tony\AppData\Local\globalUpdate C:\Users\tony\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\iomphmdalfmaifjccmagmllnicjoghhk C:\Users\tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl C:\Users\tony\AppData\Local\Pro_PC_Cleaner C:\Users\tony\AppData\Roaming\*.log C:\Users\tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLVPlayer C:\Users\tony\AppData\Roaming\mystartsearch C:\Users\tony\AppData\Roaming\Nosibay C:\Users\tony\AppData\Roaming\SoftwareUpdater C:\Users\tony\AppData\Roaming\Store C:\Users\tony\AppData\Roaming\Taplika C:\Users\tony\AppData\Roaming\WTools C:\Users\tony\Desktop\FLVPlayer-Chrome.exe C:\Users\tony\Documents\Optimizer Pro C:\Users\tony\Documents\ProPCCleaner C:\Windows\msdownld.tmp C:\Windows\SysWOW64\${LOGFILE} Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v iTunesHelper /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v KiesTrayAgent /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. IHProtect Service => Service deleted successfully. Security Updates Service => Service deleted successfully. serversu => Service deleted successfully. wpnfd_1_10_0_9 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{09D8972F-7ECD-46D6-B8D4-9FD2F5BD1BED}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09D8972F-7ECD-46D6-B8D4-9FD2F5BD1BED}" => Key deleted successfully. C:\Windows\System32\Tasks\Taplika => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Taplika" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{126F1177-1362-448B-B188-2891BCAE973B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{126F1177-1362-448B-B188-2891BCAE973B}" => Key deleted successfully. C:\Windows\System32\Tasks\ProPCCleaner_Start => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Start" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1427930C-DC9B-4624-9054-83BC0434FF76}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1427930C-DC9B-4624-9054-83BC0434FF76}" => Key deleted successfully. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A3DC940-B5B2-4328-8DF8-9B70F8D26CD6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A3DC940-B5B2-4328-8DF8-9B70F8D26CD6}" => Key deleted successfully. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4861A125-A5A9-4EAE-ABBB-322B1F59037C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4861A125-A5A9-4EAE-ABBB-322B1F59037C}" => Key deleted successfully. C:\Windows\System32\Tasks\{A478F646-3406-4B08-BC83-F093C00B91CA} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A478F646-3406-4B08-BC83-F093C00B91CA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{612D53EF-F46C-43F3-B2B3-8C8BD2436EC3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{612D53EF-F46C-43F3-B2B3-8C8BD2436EC3}" => Key deleted successfully. C:\Windows\System32\Tasks\PostPoneInstall => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PostPoneInstall" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AF738624-1BCE-43E9-9D16-406D740C2492}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AF738624-1BCE-43E9-9D16-406D740C2492}" => Key deleted successfully. C:\Windows\System32\Tasks\{45B98C63-7830-4D65-ACF9-6C63439458C0} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{45B98C63-7830-4D65-ACF9-6C63439458C0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C94C9AD5-F816-42A7-91ED-3271E641D2FC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C94C9AD5-F816-42A7-91ED-3271E641D2FC}" => Key deleted successfully. C:\Windows\System32\Tasks\Run_Bobby_Browser => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_Bobby_Browser" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D8564587-09DC-4B5A-8624-FE64DF7C0866}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8564587-09DC-4B5A-8624-FE64DF7C0866}" => Key deleted successfully. C:\Windows\System32\Tasks\{E5BFA09E-B581-4BF7-8FE7-E08FF47CB22C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E5BFA09E-B581-4BF7-8FE7-E08FF47CB22C}" => Key deleted successfully. C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\Taplika.job => Moved successfully. C:\Users\tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OPTISetup.lnk => Moved successfully. C:\Users\tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\superpc_soft_partner.lnk => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\3D BubbleSound => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LManager => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_gb_130 => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Taplika => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\SpUninstallCleanUp => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Taplika => value deleted successfully. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{40f1f7c9-b226-11e4-beb7-b888e3cfe887}" => Key deleted successfully. HKCR\CLSID\{40f1f7c9-b226-11e4-beb7-b888e3cfe887} => Key not found. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{589B893E-773C-4941-88C2-0DCC718E621C}" => Key deleted successfully. HKCR\CLSID\{589B893E-773C-4941-88C2-0DCC718E621C} => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}" => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => Key not found. HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully. HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => Key deleted successfully. HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2DF96447-06FF-45B9-80C0-DD3762EFDB26}" => Key deleted successfully. HKCR\CLSID\{2DF96447-06FF-45B9-80C0-DD3762EFDB26} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{589B893E-773C-4941-88C2-0DCC718E621C}" => Key deleted successfully. HKCR\CLSID\{589B893E-773C-4941-88C2-0DCC718E621C} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}" => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DE6732B4-C9B3-4E16-BB71-2283ED5D25C5}" => Key deleted successfully. HKCR\CLSID\{DE6732B4-C9B3-4E16-BB71-2283ED5D25C5} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => Key deleted successfully. HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => Key not found. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => Key deleted successfully. HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSearchKeyword deleted successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\lfkjojacgdjkninepeghaamnapdjmlfn" => Key deleted successfully. "HKU\S-1-5-21-4030865254-2996239518-2335188200-1001\SOFTWARE\Google\Chrome\Extensions\lfkjojacgdjkninepeghaamnapdjmlfn" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck" => Key deleted successfully. Could not move "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx" => Scheduled to move on reboot. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\iomphmdalfmaifjccmagmllnicjoghhk" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lfkjojacgdjkninepeghaamnapdjmlfn" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc" => Key deleted successfully. C:\error.txt => Moved successfully. C:\prefs.js => Moved successfully. C:\Program Files\BubbleSound => Moved successfully. "C:\Program Files (x86)\FLVPlayer" => File/Directory not found. "C:\Program Files (x86)\globalUpdate" => File/Directory not found. C:\Program Files (x86)\HomeTab => Moved successfully. C:\Program Files (x86)\predm => Moved successfully. "C:\Program Files (x86)\Pro PC Cleaner" => File/Directory not found. C:\Program Files (x86)\Reverse Page => Moved successfully. C:\Program Files (x86)\SearchProtect => Moved successfully. C:\Program Files (x86)\Security Updates Service => Moved successfully. C:\Program Files (x86)\Setup Support for SearchProtect => Moved successfully. C:\Program Files (x86)\ver1BlockAndSurf => Moved successfully. "C:\Program Files (x86)\Wajam" => File/Directory not found. C:\Program Files (x86)\XTab => Moved successfully. C:\ProgramData\cryptoDrvUpdate.exe => Moved successfully. C:\ProgramData\{b7dcd416-2d7c-bcf7-b7dc-cd4162d75058} => Moved successfully. C:\ProgramData\{dd389746-f1b7-0d61-dd38-89746f1b5d1b} => Moved successfully. C:\ProgramData\8da1b290000036d6 => Moved successfully. C:\ProgramData\APN => Moved successfully. C:\ProgramData\Apple => Moved successfully. C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 => Moved successfully. C:\Users\tony\AppData\Local\824078 => Moved successfully. "C:\Users\tony\AppData\Local\BoBrowser" => File/Directory not found. C:\Users\tony\AppData\Local\globalUpdate => Moved successfully. C:\Users\tony\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\iomphmdalfmaifjccmagmllnicjoghhk => Moved successfully. C:\Users\tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl => Moved successfully. C:\Users\tony\AppData\Local\Pro_PC_Cleaner => Moved successfully. C:\Users\tony\AppData\Roaming\*.log => Moved successfully. "C:\Users\tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLVPlayer" => File/Directory not found. "C:\Users\tony\AppData\Roaming\mystartsearch" => File/Directory not found. C:\Users\tony\AppData\Roaming\Nosibay => Moved successfully. C:\Users\tony\AppData\Roaming\SoftwareUpdater => Moved successfully. C:\Users\tony\AppData\Roaming\Store => Moved successfully. C:\Users\tony\AppData\Roaming\Taplika => Moved successfully. C:\Users\tony\AppData\Roaming\WTools => Moved successfully. C:\Users\tony\Desktop\FLVPlayer-Chrome.exe => Moved successfully. C:\Users\tony\Documents\Optimizer Pro => Moved successfully. C:\Users\tony\Documents\ProPCCleaner => Moved successfully. C:\Windows\msdownld.tmp => Moved successfully. C:\Windows\SysWOW64\${LOGFILE} => Moved successfully. ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v iTunesHelper /f ========= Operacja ukonczona pomyslnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 /v KiesTrayAgent /f ========= Operacja ukonczona pomyslnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukonczona pomyslnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukonczona pomyslnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukonczona pomyslnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukonczona pomyslnie. ========= End of Reg: ========= EmptyTemp: => Removed 4 GB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-02-20 07:53:36)<= "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx" => File could not move. ==== End of Fixlog 07:53:36 ====