Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-04-2014 01 Ran by Andrzej at 2014-04-26 08:50:30 Run:1 Running from C:\Users\Andrzej\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** S2 ProtectMonitor; C:\Program Files\PCDApp\StartHelp.exe [97007 2014-04-10] () Task: {2020C67F-0B06-4D54-81A6-8D0D50453A32} - \AmiUpdXp No Task File <==== ATTENTION Task: {2892487D-CAC7-4652-B4B5-8008569FBD10} - \BrowserProtect No Task File <==== ATTENTION Task: {E3A5E69E-355C-4927-BD58-54C3DE3DF02E} - \Desk 365 RunAsStdUser No Task File <==== ATTENTION S3 andnetndis; system32\DRIVERS\lgandnetndis64.sys [X] S3 TDPIPE; system32\drivers\tdpipe.sys [X] S3 TDTCP; system32\drivers\tdtcp.sys [X] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CLPSLS => ""="Service" HKU\S-1-5-21-832274295-3953399043-1981563008-1000\...\Run: [LG LinkAir] => [X] StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = http://pl.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo BHO-x32: No Name - {6F91A936-734D-4EE7-9320-50718870285D} - No File CHR HKLM-x32\...\Chrome\Extension: [aaaailpifkkekipiachodfkfmgmiapmp] - C:\ProgramData\AskPartnerNetwork\Toolbar\SGT-V7\CRX\ToolbarCR.crx [2013-04-28] FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.118.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.138.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF C:\Program Files (x86)\Mozilla Firefox\extensions C:\Program Files\A C:\ProgramData\pclunst.exe C:\ProgramData\AskPartnerNetwork C:\Users\Andrzej\Desktop\Kontynuuj instalację Hamachi.lnk C:\Users\Andrzej\Downloads\gta5monex.downloader__5546_il1209.exe C:\Windows\SysWOW64\sqlite3.dll Folder: C:\Users\Andrzej\AppData\Roaming\library_dir CMD: reg import C:\Users\Andrzej\Desktop\FIX.REG Reboot: ***************** ProtectMonitor => Unable to delete service HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2020C67F-0B06-4D54-81A6-8D0D50453A32} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2020C67F-0B06-4D54-81A6-8D0D50453A32} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AmiUpdXp => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2892487D-CAC7-4652-B4B5-8008569FBD10} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2892487D-CAC7-4652-B4B5-8008569FBD10} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserProtect => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E3A5E69E-355C-4927-BD58-54C3DE3DF02E} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3A5E69E-355C-4927-BD58-54C3DE3DF02E} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Error deleting key andnetndis => Unable to delete service TDPIPE => Unable to delete service TDTCP => Unable to delete service HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS => Unable to delete key HKLM\System\CurrentControlSet\Control\SafeBoot\Network\CLPSLS => Unable to delete key HKU\S-1-5-21-832274295-3953399043-1981563008-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LG LinkAir => Unable to delete value HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Error setting value. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A} => Key deleted successfully. HKCR\CLSID\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F91A936-734D-4EE7-9320-50718870285D} => Unable to delete key HKCR\Wow6432Node\CLSID\{6F91A936-734D-4EE7-9320-50718870285D} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\aaaailpifkkekipiachodfkfmgmiapmp => Key deleted successfully. "C:\ProgramData\AskPartnerNetwork\Toolbar\SGT-V7\CRX\ToolbarCR.crx" => File/Directory not found. HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=1.110.0 => Key deleted successfully. C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=1.118.0 => Key deleted successfully. C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=1.138.0 => Key deleted successfully. C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.1.4 => Key deleted successfully. C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\wrc@avast.com => Value deleted successfully. C:\Program Files (x86)\Mozilla Firefox\extensions => Moved successfully. C:\Program Files\A => Moved successfully. Could not move "C:\ProgramData\pclunst.exe" => Scheduled to move on reboot. "C:\ProgramData\AskPartnerNetwork" => File/Directory not found. Could not move "C:\Users\Andrzej\Desktop\Kontynuuj instalację Hamachi.lnk" => Scheduled to move on reboot. Could not move "C:\Users\Andrzej\Downloads\gta5monex.downloader__5546_il1209.exe" => Scheduled to move on reboot. Could not move "C:\Windows\SysWOW64\sqlite3.dll" => Scheduled to move on reboot. ========================= Folder: C:\Users\Andrzej\AppData\Roaming\library_dir ======================== 2014-02-14 15:21 - 2014-02-14 15:21 - 0000000 ____D () C:\Users\Andrzej\AppData\Roaming\library_dir\win32com 2014-02-14 15:21 - 2014-02-14 15:21 - 0000000 ____D () C:\Users\Andrzej\AppData\Roaming\library_dir\win32com\gen_py ====== End of Folder: ====== ========= reg import C:\Users\Andrzej\Desktop\FIX.REG ========= BD: Bd dostpu do rejestru. ========= End of CMD: ========= => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-04-26 09:18:01)<= ==> ATTENTION: System is not rebooted. C:\ProgramData\pclunst.exe => Moved successfully. C:\Users\Andrzej\Desktop\Kontynuuj instalację Hamachi.lnk => Moved successfully. C:\Users\Andrzej\Downloads\gta5monex.downloader__5546_il1209.exe => Moved successfully. C:\Windows\SysWOW64\sqlite3.dll => Moved successfully. ==== End of Fixlog ====