Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-04-2014 01 Ran by Kinguń at 2014-04-13 11:16:07 Run:1 Running from C:\Users\Kinguń\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Folder: C:\Windows\PolicyDefinitions HKU\S-1-5-21-1593099923-3472938015-3572154625-1002\...\Run: [Mobile Partner] - C:\Program Files (x86)\PLAY Web partner\PLAY Web partner StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File U3 catchme; \??\C:\ComboFix\catchme.sys [X] C:\windows\system32\Ꙁí C:\windows\system32\Ꙁã C:\windows\SysWOW64\sho*.tmp Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** ========================= Folder: C:\Windows\PolicyDefinitions ======================== 2014-04-13 11:13 - 2009-06-10 22:50 - 0002391 _____ () C:\Windows\PolicyDefinitions\DeviceRedirection.admx 2014-04-13 11:13 - 2009-06-10 22:40 - 0005097 _____ () C:\Windows\PolicyDefinitions\EnhancedStorage.admx 2014-04-13 11:13 - 2014-01-13 05:08 - 1601204 _____ () C:\Windows\PolicyDefinitions\inetres.admx 2014-04-13 11:13 - 2009-06-10 22:34 - 0003615 _____ () C:\Windows\PolicyDefinitions\NCSI.admx 2014-04-13 11:13 - 2009-06-10 23:08 - 0001273 _____ () C:\Windows\PolicyDefinitions\RacWmiProv.admx 2014-04-13 11:13 - 2009-06-10 22:52 - 0001236 _____ () C:\Windows\PolicyDefinitions\ReAgent.admx 2014-04-13 11:13 - 2009-06-10 22:48 - 0002519 _____ () C:\Windows\PolicyDefinitions\sdiageng.admx 2014-04-13 11:13 - 2009-06-10 22:49 - 0002027 _____ () C:\Windows\PolicyDefinitions\sdiagschd.admx 2014-04-13 11:13 - 2009-06-10 22:34 - 0043882 _____ () C:\Windows\PolicyDefinitions\Search.admx 2014-04-13 11:13 - 2009-06-10 23:01 - 0001254 _____ () C:\Windows\PolicyDefinitions\WindowsMediaDRM.admx 2014-04-13 11:13 - 2009-06-10 23:01 - 0022974 _____ () C:\Windows\PolicyDefinitions\WindowsMediaPlayer.admx 2014-04-13 11:13 - 2014-04-13 11:13 - 0000000 ____D () C:\Windows\PolicyDefinitions\en-US 2014-04-13 11:13 - 2014-01-13 05:09 - 0393813 _____ () C:\Windows\PolicyDefinitions\en-US\InetRes.adml 2014-04-13 11:13 - 2014-04-13 11:13 - 0000000 ____D () C:\Windows\PolicyDefinitions\es-ES 2014-04-13 11:13 - 2014-01-13 05:15 - 0466850 _____ () C:\Windows\PolicyDefinitions\es-ES\InetRes.adml 2014-04-13 11:13 - 2014-04-13 11:13 - 0000000 ____D () C:\Windows\PolicyDefinitions\pl-PL 2014-04-13 11:13 - 2010-09-02 07:16 - 0003520 _____ () C:\Windows\PolicyDefinitions\pl-PL\DeviceRedirection.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0007451 _____ () C:\Windows\PolicyDefinitions\pl-PL\EnhancedStorage.adml 2014-04-13 11:13 - 2014-01-13 05:11 - 0474070 _____ () C:\Windows\PolicyDefinitions\pl-PL\InetRes.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0005180 _____ () C:\Windows\PolicyDefinitions\pl-PL\NCSI.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0001133 _____ () C:\Windows\PolicyDefinitions\pl-PL\RacWmiProv.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0002114 _____ () C:\Windows\PolicyDefinitions\pl-PL\ReAgent.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0004256 _____ () C:\Windows\PolicyDefinitions\pl-PL\sdiageng.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0002989 _____ () C:\Windows\PolicyDefinitions\pl-PL\sdiagschd.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0066156 _____ () C:\Windows\PolicyDefinitions\pl-PL\Search.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0002238 _____ () C:\Windows\PolicyDefinitions\pl-PL\WindowsMediaDRM.adml 2014-04-13 11:13 - 2010-09-02 07:16 - 0024689 _____ () C:\Windows\PolicyDefinitions\pl-PL\WindowsMediaPlayer.adml 2014-04-13 11:13 - 2014-04-13 11:13 - 0000000 ____D () C:\Windows\PolicyDefinitions\pt-PT 2014-04-13 11:13 - 2014-01-13 05:13 - 0465102 _____ () C:\Windows\PolicyDefinitions\pt-PT\InetRes.adml ====== End of Folder: ====== HKU\S-1-5-21-1593099923-3472938015-3572154625-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Mobile Partner => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. catchme => Service deleted successfully. C:\windows\system32\Ꙁí => Moved successfully. C:\windows\system32\Ꙁã => Moved successfully. C:\windows\SysWOW64\sho*.tmp => Moved successfully. ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====