Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-01-2014 03 Ran by Asus at 2014-01-16 16:54:07 Run:1 Running from C:\Users\Asus\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No File Toolbar: HKCU - No Name - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No File CHR HKLM-x32\...\Chrome\Extension: [hphehadppenpmajgnkjdcopcfijjegaf] - C:\Program Files (x86)\Jump Flip\hphehadppenpmajgnkjdcopcfijjegaf.crx [2014-01-16] DPF: HKLM-x32 {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab HKU\Gość\...\Run: [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" Task: {1D0033F7-0FFF-4743-9023-A83CD2A7D5FB} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1720854903-721639992-1052711666-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {24E238C5-D358-4530-987F-543DAEA16018} - System32\Tasks\{CD9E8B49-D7EF-4321-A0CC-B224F9F04A79} => C:\Program Files (x86)\Gadu-Gadu 10\gg.exe Task: {600C2D23-CFD2-43F0-825F-29228D388218} - \DealPly No Task File Task: {8F5C2CBB-DBCB-4D6F-AECF-E53224F19CDF} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {B9A865E6-4BCB-4994-A26E-F81F6DF0DB6B} - System32\Tasks\{BDBF8BD8-8E77-4C2E-934E-EF0315049A4F} => C:\Program Files (x86)\Gadu-Gadu 10\gg.exe S2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [838528 2009-08-04] (Trend Micro Inc.) R0 pavboot; C:\Windows\System32\Drivers\pavboot64.sys [30792 2010-06-22] (Panda Security, S.L.) S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] S3 Prot6Flt; system32\DRIVERS\Prot6Flt.sys [x] C:\aaw7boot.log C:\Program Files\SkanerOnline C:\Program Files\Trend Micro C:\ProgramData\Lavasoft C:\Users\Asus\daemonprocess.txt C:\Users\Asus\AppData\Local\Tem C:\Windows\system32\ServiceFilter.ini C:\Windows\System32\Drivers\pavboot64.sys C:\Windows\System32\Tasks\{17D7BE86-F65A-4335-86FD-D92354FDBC53} C:\Windows\SysWOW64\rp_stats.dat C:\Windows\SysWOW64\rp_rules.dat Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ***************** HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Value deleted successfully. HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} => Value deleted successfully. HKCR\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} => Value deleted successfully. HKCR\CLSID\{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} => Key not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hphehadppenpmajgnkjdcopcfijjegaf => Key deleted successfully. "C:\Program Files (x86)\Jump Flip\hphehadppenpmajgnkjdcopcfijjegaf.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKU\Gość\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D0033F7-0FFF-4743-9023-A83CD2A7D5FB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D0033F7-0FFF-4743-9023-A83CD2A7D5FB} => Key deleted successfully. C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1720854903-721639992-1052711666-1000 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealUpgradeScheduledTaskS-1-5-21-1720854903-721639992-1052711666-1000 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{24E238C5-D358-4530-987F-543DAEA16018} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24E238C5-D358-4530-987F-543DAEA16018} => Key deleted successfully. C:\Windows\System32\Tasks\{CD9E8B49-D7EF-4321-A0CC-B224F9F04A79} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CD9E8B49-D7EF-4321-A0CC-B224F9F04A79} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{600C2D23-CFD2-43F0-825F-29228D388218} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{600C2D23-CFD2-43F0-825F-29228D388218} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F5C2CBB-DBCB-4D6F-AECF-E53224F19CDF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F5C2CBB-DBCB-4D6F-AECF-E53224F19CDF} => Key deleted successfully. C:\Windows\System32\Tasks\Ad-Aware Update (Weekly) => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ad-Aware Update (Weekly) => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B9A865E6-4BCB-4994-A26E-F81F6DF0DB6B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B9A865E6-4BCB-4994-A26E-F81F6DF0DB6B} => Key deleted successfully. C:\Windows\System32\Tasks\{BDBF8BD8-8E77-4C2E-934E-EF0315049A4F} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BDBF8BD8-8E77-4C2E-934E-EF0315049A4F} => Key deleted successfully. SfCtlCom => Service deleted successfully. pavboot => Service deleted successfully. ipswuio => Service deleted successfully. Prot6Flt => Service deleted successfully. C:\aaw7boot.log => Moved successfully. C:\Program Files\SkanerOnline => Moved successfully. C:\Program Files\Trend Micro => Moved successfully. C:\ProgramData\Lavasoft => Moved successfully. C:\Users\Asus\daemonprocess.txt => Moved successfully. C:\Users\Asus\AppData\Local\Tem => Moved successfully. C:\Windows\system32\ServiceFilter.ini => Moved successfully. C:\Windows\System32\Drivers\pavboot64.sys => Moved successfully. C:\Windows\System32\Tasks\{17D7BE86-F65A-4335-86FD-D92354FDBC53} => Moved successfully. C:\Windows\SysWOW64\rp_stats.dat => Moved successfully. C:\Windows\SysWOW64\rp_rules.dat => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needs a manual reboot. ==== End of Fixlog ====