Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-07-2013 Ran by Alex at 2013-07-02 14:35:47 Run:1 Running from C:\Users\Alex\Desktop\usb fake Boot Mode: Normal ============================================== HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\59796 => Value not found. HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => Error setting value. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ALLUpdate => Value deleted successfully. C:\Windows\DeleteOnReboot.bat => Moved successfully. C:\Users\Alex\Documents\APNSetup1.exe => Moved successfully. C:\MSI => Moved successfully. F:\autorun.inf => File/Directory not found. F:\4#BKMHXAELUTLKRO.ini => File/Directory not found. F:\desktop.ini => File/Directory not found. F:\Thumbs.db => File/Directory not found. F:\USB DISK (4GB).lnk => File/Directory not found. G:\autorun.inf => File/Directory not found. G:\4#YEEGFHYX.ini => File/Directory not found. G:\desktop.ini => File/Directory not found. G:\Thumbs.db => File/Directory not found. G:\TOSHIBA 8GB (8GB).lnk => File/Directory not found. ========= attrib /d /s -s -h F:\* ========= Nie mo¾na odnale«† ˜cie¾ki - F:\. ========= End of CMD: ========= ========= attrib /d /s -s -h G:\* ========= Nie mo¾na odnale«† ˜cie¾ki - G:\. ========= End of CMD: ========= ========= reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v "Default Scope" /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /v "Default Scope" /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v "Default Scope" /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1100182F-6956-4598-BB2D-5CC50155C194} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1100182F-6956-4598-BB2D-5CC50155C194} => Key deleted successfully. C:\Windows\System32\Tasks\{81FB999B-6968-49E8-8C52-0BE2AF335D2B} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{81FB999B-6968-49E8-8C52-0BE2AF335D2B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{561B61D4-F93A-414B-893D-810884567BEF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{561B61D4-F93A-414B-893D-810884567BEF} => Key deleted successfully. C:\Windows\System32\Tasks\{CEA9E291-502F-49BD-AFE0-F12EE721AB48} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CEA9E291-502F-49BD-AFE0-F12EE721AB48} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{75F96ED6-B6A3-4DC9-BF56-6E66D745EB9D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F96ED6-B6A3-4DC9-BF56-6E66D745EB9D} => Key deleted successfully. C:\Windows\System32\Tasks\{DC1CA97C-2224-4C6D-AE9C-BF6A3DD21516} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DC1CA97C-2224-4C6D-AE9C-BF6A3DD21516} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87674AC3-B446-428E-B924-BC2E94B726DD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87674AC3-B446-428E-B924-BC2E94B726DD} => Key deleted successfully. C:\Windows\System32\Tasks\{A54AD1E6-8BCA-4170-B969-20D028B208E6} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A54AD1E6-8BCA-4170-B969-20D028B208E6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{935FE923-AE40-4915-8CE6-D918143A957A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{935FE923-AE40-4915-8CE6-D918143A957A} => Key deleted successfully. C:\Windows\System32\Tasks\{5E607AEF-ACD4-4D00-B9F4-BA6C2BB7B15F} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5E607AEF-ACD4-4D00-B9F4-BA6C2BB7B15F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B4061C4B-6764-4CC7-8C13-8BDB9B2C2A6F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4061C4B-6764-4CC7-8C13-8BDB9B2C2A6F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\RVLKL\RVLKL => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C704AFA1-2044-4B1E-A9B1-C890B1CF486B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C704AFA1-2044-4B1E-A9B1-C890B1CF486B} => Key deleted successfully. C:\Windows\System32\Tasks\{1F98F5EF-CD6C-481B-A1B6-1D98F43D39FF} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1F98F5EF-CD6C-481B-A1B6-1D98F43D39FF} => Key deleted successfully. ==== End of Fixlog ====