Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-07-2013 01 Ran by adam at 2013-07-23 18:19:34 Run:2 Running from C:\Users\adam\Desktop Boot Mode: Normal ============================================== permissions for "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run" restored successfully ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\mozilla\Thunderbird\Extensions" /v eplgTb@eset.com /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= AVGIDSAgent => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\NCInstallQueue => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{381FF089-288F-4724-9EDA-EEABB5EBE09A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{381FF089-288F-4724-9EDA-EEABB5EBE09A} => Key deleted successfully. C:\Windows\System32\Tasks\avast! Emergency Update => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avast! Emergency Update => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4562BF10-FCE1-4C37-BC81-6D79E3A2B834} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4562BF10-FCE1-4C37-BC81-6D79E3A2B834} => Key deleted successfully. C:\Windows\System32\Tasks\SUPBackground => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SUPBackground => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5EF8D3A0-EDF3-427F-A613-3654F335C423} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EF8D3A0-EDF3-427F-A613-3654F335C423} => Key deleted successfully. C:\Windows\System32\Tasks\EasyBatteryManager => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EasyBatteryManager => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C4E47875-86C6-4858-A1F8-C44310615D90} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4E47875-86C6-4858-A1F8-C44310615D90} => Key deleted successfully. C:\Windows\System32\Tasks\EasySpeedUpManager => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EasySpeedUpManager => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D80AE553-A2B7-4B2B-B2A0-43BFB62AA4CD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D80AE553-A2B7-4B2B-B2A0-43BFB62AA4CD} => Key deleted successfully. C:\Windows\System32\Tasks\SamsungSupportCenter => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SamsungSupportCenter => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} => Key deleted successfully. HKCR\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully. HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found. C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml => Moved successfully. "C:\PROGRA~3\LOCALS~1\Temp\msbvoyv.com" => File/Directory not found. C:\Users\adam\AppData\Local\47603a32-4e6a-436e-bd36-8ff2d3012181 => Moved successfully. C:\Users\adam\AppData\Local\~tmp4505751983573070207.exe => Moved successfully. C:\Users\adam\AppData\Roaming\result.db => Moved successfully. C:\Users\adam\AppData\Roaming\cache.dat => Moved successfully. C:\Users\adam\AppData\Local\MFAData => Moved successfully. C:\Users\adam\AppData\Local\Avg2013 => Moved successfully. C:\ProgramData\AVG2013 => Moved successfully. C:\ProgramData\Common Files => Moved successfully. C:\ProgramData\MFAData => Moved successfully. C:\ProgramData\AVAST Software => Moved successfully. ==== End of Fixlog ====