Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-09-2013 04 Ran by Asia at 2013-09-14 13:45:30 Run:1 Running from C:\Documents and Settings\Asia\Moje dokumenty\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Winlogon: [Userinit] C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe, BootExecute: autocheck autochk * rmvirut.nt S3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe [167264 2011-11-10] () R2 BtwSvc; C:\WINDOWS\system32\BtwSvc.dll [45568 2001-10-26] (module attribute) R2 peresvc; C:\WINDOWS\system32\PereSvc.exe [34304 2001-10-26] (Netopsystems AG) S2 vToolbarUpdater15.3.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [x] R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [37664 2013-06-27] (AVG Technologies) S1 iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys [x] S3 protect; System32\drivers\protect.sys [x] NETSVC: BtwSvc -> C:\WINDOWS\system32\BtwSvc.dll (module attribute) NETSVC: BtwSrv -> No Registry Path. NETSVC: EvdoServer -> No Registry Path. URLSearchHook: (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\v9.xml FF HKLM\...\Firefox\Extensions: [avg@igeared] - C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared FF Extension: No Name - C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared C:\WINDOWS\system32\sdra64.exe C:\WINDOWS\system32\BtwSvc.dll C:\WINDOWS\system32\PereSvc.exe C:\WINDOWS\System32\lowsec C:\WINDOWS\System32\Extensions C:\WINDOWS\System32\searchplugins C:\WINDOWS\system32\drivers\avgtpx86.sys C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job C:\Documents and Settings\Asia\Dane aplikacji\eCyber C:\Documents and Settings\Asia\Dane aplikacji\iSafe C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\avgchrome C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\AVG Security Toolbar C:\Program Files\AVG\AVG8\Toolbar C:\Program Files\iSafe C:\Program Files\FreeTime CMD: netsh firewall reset ***************** HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. AVG Security Toolbar Service => Service deleted successfully. BtwSvc => Service deleted successfully. peresvc => Service deleted successfully. vToolbarUpdater15.3.0 => Service deleted successfully. avgtp => Service deleted successfully. iSafeNetFilter => Service deleted successfully. protect => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs BtwSvc => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs BtwSrv => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs EvdoServer => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => Value deleted successfully. HKCR\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. C:\Program Files\mozilla firefox\browser\searchplugins\v9.xml => Moved successfully. HKLM\Software\Mozilla\Firefox\Extensions\\avg@igeared => Value deleted successfully. C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared => Moved successfully. C:\WINDOWS\system32\sdra64.exe => Moved successfully. C:\WINDOWS\system32\BtwSvc.dll => Moved successfully. C:\WINDOWS\system32\PereSvc.exe => Moved successfully. C:\WINDOWS\System32\lowsec => Moved successfully. C:\WINDOWS\System32\Extensions => Moved successfully. C:\WINDOWS\System32\searchplugins => Moved successfully. C:\WINDOWS\system32\drivers\avgtpx86.sys => Moved successfully. C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Documents and Settings\Asia\Dane aplikacji\eCyber => Moved successfully. C:\Documents and Settings\Asia\Dane aplikacji\iSafe => Moved successfully. C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\avgchrome => Moved successfully. "C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\AVG Security Toolbar" => File/Directory not found. C:\Program Files\AVG\AVG8\Toolbar => Moved successfully. C:\Program Files\iSafe => Moved successfully. C:\Program Files\FreeTime => Moved successfully. ========= netsh firewall reset ========= Ok. ========= End of CMD: ========= The system needs a manual reboot. ==== End of Fixlog ====