Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-02-2014 Ran by Daniel at 2014-02-21 19:55:48 Run:1 Running from C:\Users\Daniel\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie URLSearchHook: HKCU - (No Name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={84DEF224-EB6B-4B42-83AE-8E6EA340AFC9}&mid=24004ae50d7a47d6a7f5d156806c4916-2dc6982b7568081f90c514ef7a0b89703d856f35&lang=pl&ds=AVG&pr=fr&d=2011-11-21 17:24:26&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={84DEF224-EB6B-4B42-83AE-8E6EA340AFC9}&mid=24004ae50d7a47d6a7f5d156806c4916-2dc6982b7568081f90c514ef7a0b89703d856f35&lang=pl&ds=AVG&pr=fr&d=2011-11-21 17:24:26&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms} Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2552856 2014-02-06] () HKU\S-1-5-21-3952292846-3212615212-848792422-1001\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe [1266712 2013-06-03] (AVG Secure Search) HKU\S-1-5-21-3952292846-3212615212-848792422-500\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe [1266712 2013-06-03] (AVG Secure Search) HKU\S-1-5-21-3952292846-3212615212-848792422-1000\...\Run: [AdobeBridge] - [X] HKU\S-1-5-21-3952292846-3212615212-848792422-1000\...\MountPoints2: {07c89c34-3791-11e0-9767-001fc688a0e5} - L:\Setup.exe HKU\S-1-5-21-3952292846-3212615212-848792422-1000\...\MountPoints2: {b7ccd15b-daf9-11e0-8338-001fc688a0e5} - M:\blank.exe HKU\S-1-5-21-3952292846-3212615212-848792422-1001\...\MountPoints2: {76e158d8-1b67-11e0-844f-001fc688a0e5} - K:\install.exe Unlock: HKLM\SYSTEM\CurrentControlSet\Services\sptd S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [X] S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X] S4 sptd; System32\Drivers\sptd.sys [X] S3 XDva397; \??\C:\Windows\system32\XDva397.sys [X] Task: {01719A20-7E16-431F-974C-762764C404E9} - System32\Tasks\{170528A4-3334-410D-946A-9464E21273B0} => D:\Diablo 2\Diablo II.exe Task: {04381E46-14E2-4935-B7C8-804700F7C8DD} - System32\Tasks\{E3B5FDE5-A47C-4F30-B1AE-B78748B53C6F} => C:\Program Files\Kolekcja Klasyki\Blitzkrieg 2 Złota Edycja\EXE\bin\splash.exe Task: {045DF0BA-2F76-408D-AA5D-6DA384BD2D81} - System32\Tasks\{EC0DFC8F-449D-438C-B867-609CDC2CB330} => C:\Program Files\Kolekcja Klasyki\Blitzkrieg 2 Złota Edycja\EXE\bin\Game.exe Task: {1D524971-5D8E-4269-931E-8340B5FC7C2F} - System32\Tasks\{3B5BC0D7-63FC-4F4F-BCF6-09E64B7A22AF} => D:\Diablo 2\Diablo II.exe Task: {35BD9BD2-3E8C-4509-9440-8EA076620B03} - System32\Tasks\{EEE0AA61-384D-4080-A8C0-72F4AC2B3B2E} => D:\WWE Impact 2010 v2\WWE Impact.exe Task: {450725A5-3E68-45CF-A1D0-31F4D208FE11} - System32\Tasks\{FAA323FB-A7F8-4587-9D2B-ED63B5167A45} => D:\Diablo 2\Diablo II.exe Task: {4B86798C-DA57-40E3-8449-DBB2DC608B2E} - System32\Tasks\{03CB6BA7-DCFD-4770-BAB2-62E783FEF7D8} => D:\WWE Impact 2010 v2\WWE Impact.exe Task: {4F788AAC-E5C7-415A-B614-528A86FC052F} - System32\Tasks\{801A25AA-4CE2-4AD3-84D1-3C67BC50B7A2} => E:\AutoRun.exe Task: {7774BCC1-6386-4D1C-87A2-66F59186A284} - System32\Tasks\{185EBFC9-0C64-4CBA-9BC7-A194B217439A} => C:\Program Files\Kolekcja Klasyki\Blitzkrieg 2 Złota Edycja\EXE\bin\splash.exe Task: {C7848410-6575-42EB-9F22-D59E71D1830A} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{1891A318-998D-451C-9CC2-6B98DD12EA8B}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{1891A318-998D-451C-9CC2-6B98DD12EA8B}.exe C:\Program Files\is.dat C:\Program Files\uik.dat N:\*.lnk N:\*.vbs N:\autorun.inf N:\RECYCLER CMD: netsh advfirewall reset ***************** HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Value deleted successfully. HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Value deleted successfully. HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\vProt => Value deleted successfully. HKU\S-1-5-21-3952292846-3212615212-848792422-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_JUNE2013_TB => Value deleted successfully. HKU\S-1-5-21-3952292846-3212615212-848792422-500\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_JUNE2013_TB => Value deleted successfully. HKU\S-1-5-21-3952292846-3212615212-848792422-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{07c89c34-3791-11e0-9767-001fc688a0e5} => Key not found. HKCR\CLSID\{07c89c34-3791-11e0-9767-001fc688a0e5} => Key not found. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7ccd15b-daf9-11e0-8338-001fc688a0e5} => Key not found. HKCR\CLSID\{b7ccd15b-daf9-11e0-8338-001fc688a0e5} => Key not found. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{76e158d8-1b67-11e0-844f-001fc688a0e5} => Key not found. HKCR\CLSID\{76e158d8-1b67-11e0-844f-001fc688a0e5} => Key not found. "HKLM\SYSTEM\CurrentControlSet\Services\sptd" => Key unlocked successfully. EagleNT => Service deleted successfully. FairplayKD => Service deleted successfully. sptd => Service deleted successfully. XDva397 => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{01719A20-7E16-431F-974C-762764C404E9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01719A20-7E16-431F-974C-762764C404E9} => Key deleted successfully. C:\Windows\System32\Tasks\{170528A4-3334-410D-946A-9464E21273B0} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{170528A4-3334-410D-946A-9464E21273B0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{04381E46-14E2-4935-B7C8-804700F7C8DD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04381E46-14E2-4935-B7C8-804700F7C8DD} => Key deleted successfully. C:\Windows\System32\Tasks\{E3B5FDE5-A47C-4F30-B1AE-B78748B53C6F} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E3B5FDE5-A47C-4F30-B1AE-B78748B53C6F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{045DF0BA-2F76-408D-AA5D-6DA384BD2D81} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{045DF0BA-2F76-408D-AA5D-6DA384BD2D81} => Key deleted successfully. C:\Windows\System32\Tasks\{EC0DFC8F-449D-438C-B867-609CDC2CB330} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EC0DFC8F-449D-438C-B867-609CDC2CB330} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D524971-5D8E-4269-931E-8340B5FC7C2F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D524971-5D8E-4269-931E-8340B5FC7C2F} => Key deleted successfully. C:\Windows\System32\Tasks\{3B5BC0D7-63FC-4F4F-BCF6-09E64B7A22AF} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3B5BC0D7-63FC-4F4F-BCF6-09E64B7A22AF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{35BD9BD2-3E8C-4509-9440-8EA076620B03} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35BD9BD2-3E8C-4509-9440-8EA076620B03} => Key deleted successfully. C:\Windows\System32\Tasks\{EEE0AA61-384D-4080-A8C0-72F4AC2B3B2E} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EEE0AA61-384D-4080-A8C0-72F4AC2B3B2E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{450725A5-3E68-45CF-A1D0-31F4D208FE11} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{450725A5-3E68-45CF-A1D0-31F4D208FE11} => Key deleted successfully. C:\Windows\System32\Tasks\{FAA323FB-A7F8-4587-9D2B-ED63B5167A45} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FAA323FB-A7F8-4587-9D2B-ED63B5167A45} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4B86798C-DA57-40E3-8449-DBB2DC608B2E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B86798C-DA57-40E3-8449-DBB2DC608B2E} => Key deleted successfully. C:\Windows\System32\Tasks\{03CB6BA7-DCFD-4770-BAB2-62E783FEF7D8} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{03CB6BA7-DCFD-4770-BAB2-62E783FEF7D8} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4F788AAC-E5C7-415A-B614-528A86FC052F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F788AAC-E5C7-415A-B614-528A86FC052F} => Key deleted successfully. C:\Windows\System32\Tasks\{801A25AA-4CE2-4AD3-84D1-3C67BC50B7A2} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{801A25AA-4CE2-4AD3-84D1-3C67BC50B7A2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7774BCC1-6386-4D1C-87A2-66F59186A284} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7774BCC1-6386-4D1C-87A2-66F59186A284} => Key deleted successfully. C:\Windows\System32\Tasks\{185EBFC9-0C64-4CBA-9BC7-A194B217439A} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{185EBFC9-0C64-4CBA-9BC7-A194B217439A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C7848410-6575-42EB-9F22-D59E71D1830A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7848410-6575-42EB-9F22-D59E71D1830A} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Program Files\is.dat => Moved successfully. C:\Program Files\uik.dat => Moved successfully. N:\*.lnk => Moved successfully. N:\*.vbs => Moved successfully. N:\autorun.inf => Moved successfully. "N:\RECYCLER" directory move: Could not move "N:\RECYCLER\S-4-6-84-5712450311-6487104632-553445371-4643ę¶wßě-\lnrHFMPf.exe" => Scheduled to move on reboot. Could not move "N:\RECYCLER" directory. => Scheduled to move on reboot. ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-02-21 19:58:38)<= "N:\RECYCLER\S-4-6-84-5712450311-6487104632-553445371-4643ę¶wßě-\lnrHFMPf.exe" => File could not move. N:\RECYCLER => Is moved successfully. ==== End of Fixlog ====