Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-02-2014 Ran by Kamil at 2014-02-21 23:23:40 Run:1 Running from C:\Users\Kamil\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {751F8D90-E6C8-4813-A71A-EDD158D4B8A8} - System32\Tasks\Express Files Updater => C:\Program Files (x86)\ExpressFiles\EFupdater.exe <==== ATTENTION Task: {A17F4D2E-5A6D-4C29-B1C5-BC5FFF28946D} - System32\Tasks\{C97D6622-47F7-4BC2-989A-3CF970C5E660} => Firefox.exe http://ui.skype.com/ui/0/5.3.0.120/pl/abandoninstall?page=tsChrome&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-notinstalled Task: {D6B3E868-B687-4240-A9C5-CBB5689DBE40} - System32\Tasks\{6A8CFC1E-016F-442F-B1B2-CBA6D3ACA6D7} => Firefox.exe http://ui.skype.com/ui/0/6.0.0.126/pl/abandoninstall?source=lightinstaller&page=tsProgressBar StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] C:\Program Files\Enigma Software Group C:\Program Files (x86)\Spybot - Search & Destroy 2 C:\ProgramData\Doctor Web C:\ProgramData\McAfee C:\ProgramData\Spybot - Search & Destroy C:\Users\Kamil\Doctor Web C:\Users\Kamil\AppData\Local\Google C:\Users\Kamil\AppData\Roaming\TuneUp Software C:\Users\Kamil\Downloads\Mozilla_Firefox_26_instalator_sciagnij.exe C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: C:\Users\Kamil\Downloads\ComboFix.exe /uninstall ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{751F8D90-E6C8-4813-A71A-EDD158D4B8A8} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{751F8D90-E6C8-4813-A71A-EDD158D4B8A8} => Key deleted successfully. C:\Windows\System32\Tasks\Express Files Updater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Express Files Updater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A17F4D2E-5A6D-4C29-B1C5-BC5FFF28946D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A17F4D2E-5A6D-4C29-B1C5-BC5FFF28946D} => Key deleted successfully. C:\Windows\System32\Tasks\{C97D6622-47F7-4BC2-989A-3CF970C5E660} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C97D6622-47F7-4BC2-989A-3CF970C5E660} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D6B3E868-B687-4240-A9C5-CBB5689DBE40} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D6B3E868-B687-4240-A9C5-CBB5689DBE40} => Key deleted successfully. C:\Windows\System32\Tasks\{6A8CFC1E-016F-442F-B1B2-CBA6D3ACA6D7} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6A8CFC1E-016F-442F-B1B2-CBA6D3ACA6D7} => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. pccsmcfd => Service deleted successfully. C:\Program Files\Enigma Software Group => Moved successfully. C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully. C:\ProgramData\Doctor Web => Moved successfully. C:\ProgramData\McAfee => Moved successfully. C:\ProgramData\Spybot - Search & Destroy => Moved successfully. C:\Users\Kamil\Doctor Web => Moved successfully. C:\Users\Kamil\AppData\Local\Google => Moved successfully. C:\Users\Kamil\AppData\Roaming\TuneUp Software => Moved successfully. C:\Users\Kamil\Downloads\Mozilla_Firefox_26_instalator_sciagnij.exe => Moved successfully. C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= C:\Users\Kamil\Downloads\ComboFix.exe /uninstall =========