Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-02-2015 01 Ran by Michał&Damian at 2015-02-20 15:33:59 Run:1 Running from C:\Users\Michał&Damian\Desktop\frst Loaded Profiles: Michał&Damian (Available profiles: Michał&Damian) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-09-01] () [File not signed] <==== ATTENTION S2 e81a9dc1; "C:\Windows\system32\rundll32.exe" "c:\progra~2\gs-ena~1\AssistantSvc.dll",service S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.) S3 AmUStor; system32\drivers\AmUStor.SYS [X] S2 eamonm; system32\DRIVERS\eamonm.sys [X] U3 tmlwf; No ImagePath U3 tmwfp; No ImagePath Task: {12CCB40B-4EA4-4F13-B1B0-35CAF7DF8492} - System32\Tasks\GS-Enabler-S-1622525965 => c:\programdata\softwarehouse\gs-enabler\GS-Enabler.exe <==== ATTENTION Task: {13006454-2935-4E0A-81BE-6926E45633E7} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {131080F2-0EE4-411A-82F5-03F663BA6025} - \BitGuard No Task File <==== ATTENTION Task: {15FE6C86-6295-4ED7-A40A-AED45A512747} - \BonanzaDealsLiveUpdateTaskMachineUA No Task File <==== ATTENTION Task: {16AB82D6-442F-4249-9315-DF0CB572169F} - System32\Tasks\{792CA22F-5207-45BF-A090-84A149118BDE} => pcalua.exe -a "D:\Damian\fotki\Adobe Photoshop CS2 v9.0 FinaL + KeyGeN & Activator==\Photoshop_CS2_tryout\Photoshop CS2\Setup.exe" -d "D:\Damian\fotki\Adobe Photoshop CS2 v9.0 FinaL + KeyGeN & Activator==\Photoshop_CS2_tryout\Photoshop CS2" Task: {33E4E90C-F0D2-4656-8CEA-90BC795DAC3D} - \DealPly No Task File <==== ATTENTION Task: {34CAB034-9467-4020-99C6-F36E4C92069F} - System32\Tasks\GS.Enabler-S-926685765 => c:\programdata\softwarehouse\gs.enabler\GS.Enabler.exe <==== ATTENTION Task: {37C7F7E6-95AE-4A8E-BD43-A0A1499F0A6E} - \DealPlyUpdate No Task File <==== ATTENTION Task: {4B968CB4-D34B-4287-81D8-8AF203AC1419} - \BonanzaDealsUpdate No Task File <==== ATTENTION Task: {6A160AF0-19D4-4ADB-AA18-514B4C3E41BE} - \Scheduled Update for Ask Toolbar No Task File <==== ATTENTION Task: {7B7E10FA-A4D1-4A08-8644-5CD8140CFCDB} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION Task: {88560304-D041-41D8-8D87-9B4F28BD5950} - System32\Tasks\{3A077835-5C56-4916-AEF5-611C15D70641} => c:\program files (x86)\opera 11.10 beta\opera.exe [2012-11-16] (Opera Software) Task: {CF69CCBF-B737-4C0C-AAAF-2AA2015642A9} - \EPUpdater No Task File <==== ATTENTION Task: {D3DFA30C-2FF2-4BE9-A0C4-00E6A88316FD} - \BonanzaDealsLiveUpdateTaskMachineCore No Task File <==== ATTENTION Task: {F75FD957-079F-4396-B134-0F38E25310A6} - System32\Tasks\{E80DC9CB-8211-49D7-9E3F-5EE24B5ECC94} => pcalua.exe -a "D:\Róża [DVDRip] [XviD] [PL].avi\DivX Plus Codecs.exe" -d "D:\Róża [DVDRip] [XviD] [PL].avi" Task: C:\Windows\Tasks\GS-Enabler-S-1622525965.job => c:\programdata\softwarehouse\gs-enabler\GS-Enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\GS.Enabler-S-926685765.job => c:\programdata\softwarehouse\gs.enabler\GS.Enabler.exe <==== ATTENTION HKU\S-1-5-21-342266629-1139831834-1673432305-1000\...\CurrentVersion\Windows: [Load] <===== ATTENTION HKLM-x32\...\Run: [] => [X] Startup: C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SLIC ToolKit V3.2.lnk BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit GroupPolicy: Group Policy on Chrome detected <======= ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150212 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://google.atcomet.com/b/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} SearchScopes: HKLM-x32 - {B2A69A26-654E-4DA3-B024-25FBB670D4CF} URL = http://startsear.ch/?aff=2&src=sp&cf=2dd65210-3644-11e1-918e-f382060710dd&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?aff=1&src=sp&cf=2dd65210-3644-11e1-918e-f382060710dd&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} SearchScopes: HKCU - {523BD156-F9C9-43BC-9C47-7E1342902D7E} URL = http://search.babylon.com/?q={searchTerms}&AF=110000&babsrc=SP_ss&mntrId=18cace40000000000000485b391770d9 SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {B2A69A26-654E-4DA3-B024-25FBB670D4CF} URL = http://startsear.ch/?aff=2&src=sp&cf=2dd65210-3644-11e1-918e-f382060710dd&q={searchTerms} BHO-x32: Positive Finds -> {30c85a3d-1d96-4589-b63f-91fb7ef45a41} -> C:\Program Files (x86)\Positive Finds\Extensions\30c85a3d-1d96-4589-b63f-91fb7ef45a41.dll No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File C:\Program Files (x86)\Google\Chrome C:\Program Files (x86)\GS.Enabler C:\Program Files (x86)\GS_x64.Enabler C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\My Company Name C:\Program Files (x86)\Opera C:\Program Files (x86)\Tor C:\Program Files (x86)\UNiDeals C:\ProgramData\{d0ddc317-1050-f890-d0dd-dc3171050c5c} C:\ProgramData\1060043881227038852 C:\ProgramData\87b00c80000014ac C:\ProgramData\Mozilla C:\ProgramData\Opera C:\ProgramData\Temp C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asprate C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FBReader for Windows C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Internet Security C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs C:\Users\Michał&Damian\AppData\Local\*.html C:\Users\Michał&Damian\AppData\Local\Google\Chrome C:\Users\Michał&Damian\AppData\Local\Mozilla C:\Users\Michał&Damian\AppData\Local\Opera C:\Users\Michał&Damian\AppData\Local\Seven Zip C:\Users\Michał&Damian\AppData\Roaming\mservice32_t.exe C:\Users\Michał&Damian\AppData\Roaming\removeAllComponents.bat C:\Users\Michał&Damian\AppData\Roaming\tibiavplayer.ini C:\Users\Michał&Damian\AppData\Roaming\.ACEStream C:\Users\Michał&Damian\AppData\Roaming\ACEStream C:\Users\Michał&Damian\AppData\Roaming\Asus WebStorage C:\Users\Michał&Damian\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\*.lnk C:\Users\Michał&Damian\AppData\Roaming\Mozilla C:\Users\Michał&Damian\AppData\Roaming\OpenCandy C:\Users\Michał&Damian\AppData\Roaming\Opera C:\Users\Michał&Damian\AppData\Roaming\Security System 2 C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\FoxTab PDF Creator C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video Related Programs C:\Users\Michał&Damian\Downloads\*(*)-dp*.exe C:\Users\Michał&Damian\Downloads\SLIC ToolKit V3.2.exe C:\Windows\System32\DRIVERS\PSKMAD.sys Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\ABBYY.Licensing.FineReader.Professional.11.0" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\BackupStack" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\BBSvc" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\Update Mega Browse" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\Util Mega Browse" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EeeStorageBackup" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop_03281748" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Google\Chrome /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg delete HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce /f Reg: reg delete HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. tor => Service deleted successfully. e81a9dc1 => Service deleted successfully. PSKMAD => Service deleted successfully. AmUStor => Service deleted successfully. eamonm => Service deleted successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{12CCB40B-4EA4-4F13-B1B0-35CAF7DF8492}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12CCB40B-4EA4-4F13-B1B0-35CAF7DF8492}" => Key deleted successfully. C:\Windows\System32\Tasks\GS-Enabler-S-1622525965 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GS-Enabler-S-1622525965" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{13006454-2935-4E0A-81BE-6926E45633E7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13006454-2935-4E0A-81BE-6926E45633E7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{131080F2-0EE4-411A-82F5-03F663BA6025}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{131080F2-0EE4-411A-82F5-03F663BA6025}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15FE6C86-6295-4ED7-A40A-AED45A512747}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15FE6C86-6295-4ED7-A40A-AED45A512747}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{16AB82D6-442F-4249-9315-DF0CB572169F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{16AB82D6-442F-4249-9315-DF0CB572169F}" => Key deleted successfully. C:\Windows\System32\Tasks\{792CA22F-5207-45BF-A090-84A149118BDE} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{792CA22F-5207-45BF-A090-84A149118BDE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{33E4E90C-F0D2-4656-8CEA-90BC795DAC3D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{33E4E90C-F0D2-4656-8CEA-90BC795DAC3D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{34CAB034-9467-4020-99C6-F36E4C92069F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{34CAB034-9467-4020-99C6-F36E4C92069F}" => Key deleted successfully. C:\Windows\System32\Tasks\GS.Enabler-S-926685765 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GS.Enabler-S-926685765" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{37C7F7E6-95AE-4A8E-BD43-A0A1499F0A6E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{37C7F7E6-95AE-4A8E-BD43-A0A1499F0A6E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4B968CB4-D34B-4287-81D8-8AF203AC1419}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B968CB4-D34B-4287-81D8-8AF203AC1419}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A160AF0-19D4-4ADB-AA18-514B4C3E41BE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A160AF0-19D4-4ADB-AA18-514B4C3E41BE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7B7E10FA-A4D1-4A08-8644-5CD8140CFCDB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B7E10FA-A4D1-4A08-8644-5CD8140CFCDB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{88560304-D041-41D8-8D87-9B4F28BD5950}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88560304-D041-41D8-8D87-9B4F28BD5950}" => Key deleted successfully. C:\Windows\System32\Tasks\{3A077835-5C56-4916-AEF5-611C15D70641} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3A077835-5C56-4916-AEF5-611C15D70641}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CF69CCBF-B737-4C0C-AAAF-2AA2015642A9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF69CCBF-B737-4C0C-AAAF-2AA2015642A9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D3DFA30C-2FF2-4BE9-A0C4-00E6A88316FD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3DFA30C-2FF2-4BE9-A0C4-00E6A88316FD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F75FD957-079F-4396-B134-0F38E25310A6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F75FD957-079F-4396-B134-0F38E25310A6}" => Key deleted successfully. C:\Windows\System32\Tasks\{E80DC9CB-8211-49D7-9E3F-5EE24B5ECC94} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E80DC9CB-8211-49D7-9E3F-5EE24B5ECC94}" => Key deleted successfully. C:\Windows\Tasks\GS-Enabler-S-1622525965.job => Moved successfully. C:\Windows\Tasks\GS.Enabler-S-926685765.job => Moved successfully. HKU\S-1-5-21-342266629-1139831834-1673432305-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => Value was restored successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SLIC ToolKit V3.2.lnk => Moved successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} => Value not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} => Value not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} => Value not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM-x32 - {B2A69A26-654E-4DA3-B024-25FBB670D4CF} URL = http://startsear.ch/?aff=2&src=sp&cf=2dd65210-3644-11e1-918e-f382060710dd&q={searchTerms} => Value not found. \\SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} => Value not found. \\SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} => Value not found. \\SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?aff=1&src=sp&cf=2dd65210-3644-11e1-918e-f382060710dd&q={searchTerms} => Value not found. \\SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartsearch.com/web/?type=ds&ts=1423747685&from=wpc&uid=3219913727_67194_18CACE40&q={searchTerms} => Value not found. \\SearchScopes: HKCU - {523BD156-F9C9-43BC-9C47-7E1342902D7E} URL = http://search.babylon.com/?q={searchTerms}&AF=110000&babsrc=SP_ss&mntrId=18cace40000000000000485b391770d9 => Value not found. \\SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = => Value not found. \\SearchScopes: HKCU - {B2A69A26-654E-4DA3-B024-25FBB670D4CF} URL = http://startsear.ch/?aff=2&src=sp&cf=2dd65210-3644-11e1-918e-f382060710dd&q={searchTerms} => Value not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30c85a3d-1d96-4589-b63f-91fb7ef45a41}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{30c85a3d-1d96-4589-b63f-91fb7ef45a41}" => Key deleted successfully. \\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value not found. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. "C:\Program Files (x86)\Google\Chrome" => File/Directory not found. C:\Program Files (x86)\GS.Enabler => Moved successfully. C:\Program Files (x86)\GS_x64.Enabler => Moved successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\Program Files (x86)\My Company Name => Moved successfully. C:\Program Files (x86)\Opera => Moved successfully. C:\Program Files (x86)\Tor => Moved successfully. C:\Program Files (x86)\UNiDeals => Moved successfully. C:\ProgramData\{d0ddc317-1050-f890-d0dd-dc3171050c5c} => Moved successfully. C:\ProgramData\1060043881227038852 => Moved successfully. C:\ProgramData\87b00c80000014ac => Moved successfully. C:\ProgramData\Mozilla => Moved successfully. "C:\ProgramData\Opera" => File/Directory not found. C:\ProgramData\Temp => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video Editor.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asprate => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FBReader for Windows => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite => Moved successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Internet Security" => File/Directory not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs => Moved successfully. C:\Users\Michał&Damian\AppData\Local\*.html => Moved successfully. "C:\Users\Michał&Damian\AppData\Local\Google\Chrome" => File/Directory not found. C:\Users\Michał&Damian\AppData\Local\Mozilla => Moved successfully. C:\Users\Michał&Damian\AppData\Local\Opera => Moved successfully. C:\Users\Michał&Damian\AppData\Local\Seven Zip => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\mservice32_t.exe => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\removeAllComponents.bat => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\tibiavplayer.ini => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\.ACEStream => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\ACEStream => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\Asus WebStorage => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\Canon\MP Navigator EX V40\history\sc\*.lnk => Moved successfully. "C:\Users\Michał&Damian\AppData\Roaming\Mozilla" => File/Directory not found. C:\Users\Michał&Damian\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\Opera => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\Security System 2 => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\FoxTab PDF Creator => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite => Moved successfully. C:\Users\Michał&Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video Related Programs => Moved successfully. C:\Users\Michał&Damian\Downloads\*(*)-dp*.exe => Moved successfully. C:\Users\Michał&Damian\Downloads\SLIC ToolKit V3.2.exe => Moved successfully. C:\Windows\System32\DRIVERS\PSKMAD.sys => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\ABBYY.Licensing.FineReader.Professional.11.0" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\BackupStack" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\BBSvc" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\Update Mega Browse" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\Util Mega Browse" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EeeStorageBackup" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop_03281748" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Update\ClientState\{8A69D345-D564-463C-AFF1-A69D9E530F96} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 4.9 GB temporary data. The system needed a reboot. ==== End of Fixlog 15:44:02 ====