Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-07-2013 02 Ran by Igor at 2013-07-18 21:44:14 Run:1 Running from D:\Programy Boot Mode: Normal ============================================== ========= del "\\?\C:\Windows\System32\ " ========= ========= End of CMD: ========= "C:\Program Files\Microsoft Security Client" => Deleting reparse point and unlocking started. "C:\Program Files\Microsoft Security Client\Backup" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\DbgHelp.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\Drivers" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\en-us" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\EppManifest.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpAsDesc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpClient.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpCmdRun.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpCommu.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\mpevmsg.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpOAv.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpRTP.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MpSvc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MSESysprep.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpCom.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpEng.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpLics.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsMpRes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\msseces.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\msseoobe.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\msseooberes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\MsseWat.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisIpsPlugin.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisLog.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisSrv.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\NisWFP.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\pl-pl" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\Setup.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SetupRes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\shellext.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SqmApi.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SymSrv.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client\SymSrv.yes" => Deleting reparse point and unlocking done. "C:\Program Files\Microsoft Security Client" => Deleting reparse point and unlocking completed. "C:\Program Files\Windows Defender" => Deleting reparse point and unlocking started. "C:\Program Files\Windows Defender\MpAsDesc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpClient.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpCmdRun.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpCommu.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpEvMsg.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpOAV.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpRTP.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MpSvc.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MSASCui.exe" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpCom.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpLics.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\MsMpRes.dll" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender\pl-PL" => Deleting reparse point and unlocking done. "C:\Program Files\Windows Defender" => Deleting reparse point and unlocking completed. C:\Windows\Installer\{bb362e9b-49ab-c408-940e-10e1a8cdaccd} => Moved successfully. C:\Program Files (x86)\x264 Video Codec => Moved successfully. C:\Users\Igor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\x264 Video Codec => Moved successfully. C:\Users\Igor\AppData\Local\SwvUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FD9728C4-991C-46BC-A1B3-611BB3705E34} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FD9728C4-991C-46BC-A1B3-611BB3705E34} => Key deleted successfully. C:\Windows\System32\Tasks\AmiUpdXp => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AmiUpdXp => Key deleted successfully. C:\Windows\Tasks\AmiUpdXp.job => Moved successfully. Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll Winsock: Catalog5 entry 000000000005\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll Winsock: Catalog5-x64 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll Winsock: Catalog5-x64 entry 000000000005\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /t REG_SZ /d c:\windows\syswow64\nvinit.dll /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v MSC /t REG_SZ /d "\"C:\Program Files\Microsoft Security Client\msseces.exe\" -hide -runkey" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t REG_SZ /d about:blank /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v bProtectorDefaultScope /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ALLUpdate => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SMessaging => Value deleted successfully. gvmvkgic => Service deleted successfully. The system needs a manual reboot. ==== End of Fixlog ====