Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Dawid at 2015-03-20 10:34:58 Run:1 Running from C:\Users\Dawid\Downloads Loaded Profiles: Dawid (Available profiles: Dawid & adrian & Damian) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 {825c5be7-672f-4c14-9929-48a3a5e1a660}w64; C:\Windows\System32\drivers\{825c5be7-672f-4c14-9929-48a3a5e1a660}w64.sys [44736 2014-09-16] (StdLib) R1 {8aa67d0b-c01c-4d37-acff-fff3e85a7686}w64; C:\Windows\System32\drivers\{8aa67d0b-c01c-4d37-acff-fff3e85a7686}w64.sys [48832 2014-11-27] (StdLib) R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64.sys [61120 2014-05-22] (StdLib) R1 {e4c6b00c-d06e-4877-9f09-d92a224047b5}w64; C:\Windows\System32\drivers\{e4c6b00c-d06e-4877-9f09-d92a224047b5}w64.sys [48832 2014-11-29] (StdLib) R1 {eb5ff5f5-0862-4d0e-b77f-65f32d94e6ab}w64; C:\Windows\System32\drivers\{eb5ff5f5-0862-4d0e-b77f-65f32d94e6ab}w64.sys [48832 2014-11-28] (StdLib) R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36936 2014-09-18] (Just Develop It) <==== ATTENTION R2 MaintainerSvc3.36.5835263; C:\ProgramData\253696b0-e9b9-4e71-87e6-dd3f97c02b2a\maintainer.exe [123680 2015-03-09] () R2 Update Rock Turner; C:\Program Files (x86)\Rock Turner\updateRockTurner.exe [414496 2015-03-09] () R2 Util Rock Turner; C:\Program Files (x86)\Rock Turner\bin\utilRockTurner.exe [414496 2015-03-09] () S2 4d349a54; "C:\Windows\system32\rundll32.exe" "c:\progra~2\gs_boo~1\AssistantSvc.dll",service S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] Task: {3FC5BF0E-BEA0-4E80-B3AE-5F119EDFD676} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe <==== ATTENTION Task: {5354A3F1-15BC-4211-9FE3-859E1B241B78} - System32\Tasks\PennyBee => C:\Users\adrian\AppData\Roaming\PennyBee\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {751AF918-0C37-4F68-8D3B-F04952019101} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION Task: {8C8A77AB-CE33-4AC3-B660-6893BE90088D} - System32\Tasks\{93CA2A29-2E54-449C-873E-2E933F16AF85} => C:\Users\Dawid\Desktop\KN Launcher.exe Task: {AD099B6B-1D6F-4B2D-AB88-7418521D9846} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe Task: {E1D9682E-4CDD-4ABD-9CE5-E2AFE59783A7} - System32\Tasks\{084981AD-B84C-451A-BFE3-7E236ADB5347} => C:\Users\adrian\Desktop\jxpiinstall.exe Task: {E7D3CF05-20C4-4FF5-91A3-C09147D5BB9C} - System32\Tasks\{C0E4C093-96E9-43CA-8E3A-DD35C57F55D5} => C:\Users\adrian\Desktop\Java-SE(13186)-dp.exe Task: C:\Windows\Tasks\PennyBee.job => C:\Users\adrian\AppData\Roaming\PennyBee\UPDATE~1\UPDATE~1.EXE <==== ATTENTION AppInit_DLLs-x32: c:\progra~2\gs_boo~1\assist~1.dll => "c:\progra~2\gs_boo~1\assist~1.dll" File Not Found Startup: C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR RestoreOnStartup: Default -> "hxxp://rts.dsrlte.com?affID=pr_9c463e7f-5d65-4289-b233-694661020215" ShortcutWithArgument: C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE ShortcutWithArgument: C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE ShortcutWithArgument: C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE ShortcutWithArgument: C:\Users\Dawid\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE ShortcutWithArgument: C:\Users\Dawid\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://rts.dsrlte.com?affID=na http://www.search.ask.com/?tpid=ORJ-ST-SPE&o=APN11467&pf=V7&trgb=CR&p2=^BED^OSJ000^YY^PL&gct=hp&apn_ptnrs=BED&apn_dtid=^OSJ000^YY^PL&apn_dbr=cr_38.0.2125.111&apn_uid=EBC246C1-4F1E-43C9-9FF0-A37F0A56880A&itbv=12.18.0.81&doi=2014-10-31&psv=&pt=tb SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} SearchScopes: HKU\S-1-5-21-1699041526-1260768229-1946834793-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1699041526-1260768229-1946834793-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE&q={searchTerms} SearchScopes: HKU\S-1-5-21-1699041526-1260768229-1946834793-1001 -> {5025A078-BCE7-40BD-A9E7-1C00FDC5DDFA} URL = http://www.search.ask.com/web?tpid=ORJ-ST-SPE&o=APN11467&pf=V7&p2=^BED^OSJ000^YY^PL&gct=&itbv=12.18.0.81&apn_uid=EBC246C1-4F1E-43C9-9FF0-A37F0A56880A&apn_ptnrs=BED&apn_dtid=^OSJ000^YY^PL&apn_dbr=cr_38.0.2125.111&doi=2014-10-31&trgb=CR&q={searchTerms}&psv=&pt=tb SearchScopes: HKU\S-1-5-21-1699041526-1260768229-1946834793-1001 -> {F6D549FA-E52C-4BAA-8130-3E0C8CEA0C90} URL = http://rts.dsrlte.com/?affID=na&q={searchTerms}&r=498 BHO: LuuckyCOuppON -> {34085CC6-3EF0-9AD2-7920-DA2AFF3FC4BB} -> C:\ProgramData\LuuckyCOuppON\JD.x64.dll [2014-09-08] () BHO: BetterPRicECheC -> {6E6B5A77-BBD0-D26F-B20E-1A27B5E45576} -> C:\ProgramData\BetterPRicECheC\Xue9cw.x64.dll [2014-09-05] () BHO: WowCooupoon -> {9BD49075-9368-A83F-0BD5-99EE911C9464} -> C:\ProgramData\WowCooupoon\sYIIUFjxO.x64.dll [2014-08-10] () BHO-x32: LuuckyCOuppON -> {34085CC6-3EF0-9AD2-7920-DA2AFF3FC4BB} -> C:\ProgramData\LuuckyCOuppON\JD.dll [2014-09-08] () BHO-x32: Rock Turner 1.0.0.7 -> {527b365c-1bd3-4a66-906f-8729805ce78c} -> C:\Program Files (x86)\Rock Turner\RockTurnerBHO.dll [2015-01-27] (Rock Turner) BHO-x32: BetterPRicECheC -> {6E6B5A77-BBD0-D26F-B20E-1A27B5E45576} -> C:\ProgramData\BetterPRicECheC\Xue9cw.dll [2014-09-05] () StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1410268049&from=wpc&uid=MaxtorX6E030L0_E12HLVDE C:\Program Files (x86)\MyPC Backup C:\Program Files (x86)\Rock Turner C:\ProgramData\253696b0-e9b9-4e71-87e6-dd3f97c02b2a C:\ProgramData\BetterPRicECheC C:\ProgramData\LuuckyCOuppON C:\ProgramData\TEMP C:\ProgramData\WowCooupoon C:\Users\adrian\AppData\Local\Gameo C:\Users\adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo.lnk C:\Users\adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo C:\Users\adrian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Play OGame.lnk C:\Users\adrian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Shiginima Launcher SE v1.lnk C:\Users\adrian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Play OGame.lnk C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup C:\Windows\System32\drivers\{825c5be7-672f-4c14-9929-48a3a5e1a660}w64.sys C:\Windows\System32\drivers\{8aa67d0b-c01c-4d37-acff-fff3e85a7686}w64.sys C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64.sys C:\Windows\System32\drivers\{e4c6b00c-d06e-4877-9f09-d92a224047b5}w64.sys C:\Windows\System32\drivers\{eb5ff5f5-0862-4d0e-b77f-65f32d94e6ab}w64.sys Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Google\Chrome\Extensions /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. {825c5be7-672f-4c14-9929-48a3a5e1a660}w64 => Service stopped successfully. {825c5be7-672f-4c14-9929-48a3a5e1a660}w64 => Service deleted successfully. {8aa67d0b-c01c-4d37-acff-fff3e85a7686}w64 => Service stopped successfully. {8aa67d0b-c01c-4d37-acff-fff3e85a7686}w64 => Service deleted successfully. {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64 => Service stopped successfully. {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64 => Service deleted successfully. {e4c6b00c-d06e-4877-9f09-d92a224047b5}w64 => Service stopped successfully. {e4c6b00c-d06e-4877-9f09-d92a224047b5}w64 => Service deleted successfully. {eb5ff5f5-0862-4d0e-b77f-65f32d94e6ab}w64 => Service stopped successfully. {eb5ff5f5-0862-4d0e-b77f-65f32d94e6ab}w64 => Service deleted successfully. BackupStack => Service deleted successfully. MaintainerSvc3.36.5835263 => Service deleted successfully. Update Rock Turner => Unable to stop service Update Rock Turner => Service deleted successfully. Util Rock Turner => Unable to stop service Util Rock Turner => Service deleted successfully. 4d349a54 => Service deleted successfully. nvlddmkm => Service deleted successfully. nvvad_WaveExtensible => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3FC5BF0E-BEA0-4E80-B3AE-5F119EDFD676}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FC5BF0E-BEA0-4E80-B3AE-5F119EDFD676}" => Key deleted successfully. C:\Windows\System32\Tasks\Optimizer Pro Schedule => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5354A3F1-15BC-4211-9FE3-859E1B241B78} => Key not found. C:\Windows\System32\Tasks\PennyBee not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PennyBee => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{751AF918-0C37-4F68-8D3B-F04952019101}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{751AF918-0C37-4F68-8D3B-F04952019101}" => Key deleted successfully. C:\Windows\System32\Tasks\LaunchSignup => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8C8A77AB-CE33-4AC3-B660-6893BE90088D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C8A77AB-CE33-4AC3-B660-6893BE90088D}" => Key deleted successfully. C:\Windows\System32\Tasks\{93CA2A29-2E54-449C-873E-2E933F16AF85} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{93CA2A29-2E54-449C-873E-2E933F16AF85}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AD099B6B-1D6F-4B2D-AB88-7418521D9846}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD099B6B-1D6F-4B2D-AB88-7418521D9846}" => Key deleted successfully. C:\Windows\System32\Tasks\Apple\AppleSoftwareUpdate => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apple\AppleSoftwareUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E1D9682E-4CDD-4ABD-9CE5-E2AFE59783A7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1D9682E-4CDD-4ABD-9CE5-E2AFE59783A7}" => Key deleted successfully. C:\Windows\System32\Tasks\{084981AD-B84C-451A-BFE3-7E236ADB5347} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{084981AD-B84C-451A-BFE3-7E236ADB5347}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E7D3CF05-20C4-4FF5-91A3-C09147D5BB9C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E7D3CF05-20C4-4FF5-91A3-C09147D5BB9C}" => Key deleted successfully. C:\Windows\System32\Tasks\{C0E4C093-96E9-43CA-8E3A-DD35C57F55D5} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C0E4C093-96E9-43CA-8E3A-DD35C57F55D5}" => Key deleted successfully. C:\Windows\Tasks\PennyBee.job not found. "c:\progra~2\gs_boo~1\assist~1.dll" => Value Data removed successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\SOFTWARE\Policies\Google => Key not found. Chrome RestoreOnStartup deleted successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk => Shortcut argument was removed successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument was restored successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => Shortcut argument was removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value deleted successfully. http://www.search.ask.com/?tpid=ORJ-ST-SPE&o=APN11467&pf=V7&trgb=CR&p2=^BED^OSJ000^YY^PL&gct=hp&apn_ptnrs=BED&apn_dtid=^OSJ000^YY^PL&apn_dbr=cr_38.0.2125.111&apn_uid=EBC246C1-4F1E-43C9-9FF0-A37F0A56880A&itbv=12.18.0.81&doi=2014-10-31&psv=&pt=tb => Error: No automatic fix found for this entry. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. "HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5025A078-BCE7-40BD-A9E7-1C00FDC5DDFA}" => Key deleted successfully. HKCR\CLSID\{5025A078-BCE7-40BD-A9E7-1C00FDC5DDFA} => Key not found. "HKU\S-1-5-21-1699041526-1260768229-1946834793-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F6D549FA-E52C-4BAA-8130-3E0C8CEA0C90}" => Key deleted successfully. HKCR\CLSID\{F6D549FA-E52C-4BAA-8130-3E0C8CEA0C90} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34085CC6-3EF0-9AD2-7920-DA2AFF3FC4BB}" => Key deleted successfully. "HKCR\CLSID\{34085CC6-3EF0-9AD2-7920-DA2AFF3FC4BB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E6B5A77-BBD0-D26F-B20E-1A27B5E45576}" => Key deleted successfully. "HKCR\CLSID\{6E6B5A77-BBD0-D26F-B20E-1A27B5E45576}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9BD49075-9368-A83F-0BD5-99EE911C9464}" => Key deleted successfully. "HKCR\CLSID\{9BD49075-9368-A83F-0BD5-99EE911C9464}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34085CC6-3EF0-9AD2-7920-DA2AFF3FC4BB}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{34085CC6-3EF0-9AD2-7920-DA2AFF3FC4BB}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{527b365c-1bd3-4a66-906f-8729805ce78c}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{527b365c-1bd3-4a66-906f-8729805ce78c}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E6B5A77-BBD0-D26F-B20E-1A27B5E45576}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{6E6B5A77-BBD0-D26F-B20E-1A27B5E45576}" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. C:\Program Files (x86)\MyPC Backup => Moved successfully. C:\Program Files (x86)\Rock Turner => Moved successfully. C:\ProgramData\253696b0-e9b9-4e71-87e6-dd3f97c02b2a => Moved successfully. C:\ProgramData\BetterPRicECheC => Moved successfully. C:\ProgramData\LuuckyCOuppON => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\WowCooupoon => Moved successfully. C:\Users\adrian\AppData\Local\Gameo => Moved successfully. C:\Users\adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo.lnk => Moved successfully. C:\Users\adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo => Moved successfully. C:\Users\adrian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Play OGame.lnk => Moved successfully. C:\Users\adrian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Shiginima Launcher SE v1.lnk => Moved successfully. C:\Users\adrian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Play OGame.lnk => Moved successfully. C:\Users\Dawid\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk => Moved successfully. C:\Users\Dawid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup => Moved successfully. C:\Windows\System32\drivers\{825c5be7-672f-4c14-9929-48a3a5e1a660}w64.sys => Moved successfully. C:\Windows\System32\drivers\{8aa67d0b-c01c-4d37-acff-fff3e85a7686}w64.sys => Moved successfully. C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64.sys => Moved successfully. C:\Windows\System32\drivers\{e4c6b00c-d06e-4877-9f09-d92a224047b5}w64.sys => Moved successfully. C:\Windows\System32\drivers\{eb5ff5f5-0862-4d0e-b77f-65f32d94e6ab}w64.sys => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Google\Chrome\Extensions /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome\Extensions /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 151.5 MB temporary data. The system needed a reboot. ==== End of Fixlog 10:41:42 ====