Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:01-05-2014 Ran by Admin at 2014-05-03 15:14:10 Run:1 Running from C:\Users\Admin\Desktop\Diagnostyka\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [Copy Handler] => [X] HKU\S-1-5-21-2631689147-4000948806-3686541712-1000\...\Run: [] => [X] URLSearchHook: HKCU - (No Name) - {5c81f57f-3cf7-4785-b4ef-11ace31aec4f} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {614C7A8F-AE70-4A3D-BC76-05E194768672} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} SearchScopes: HKCU - {7E4E3281-DF2A-4CE6-8CBB-14DDEE358EA7} URL = http://websearch.ask.com/redirect?client=ie&tb=FF&o=14594&src=kw&q={searchTerms}&locale=&apn_ptnrs=FV&apn_dtid=YYYYYYYYPL&apn_uid=6C0554D1-0F58-4BEE-BE84-B75413F5D40D&apn_sauid=5FDCE095-D4B0-4B23-A099-C9C3A6AD6766& BHO: No Name - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No File Toolbar: HKCU - No Name - {5C81F57F-3CF7-4785-B4EF-11ACE31AEC4F} - No File FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 C:\Program Files\Mozilla Firefox\extensions C:\Program Files\mozilla firefox\plugins Unlock: HKLM\SYSTEM\CurrentControlSet\Services\sptd S2 .EsetTrialReset; C:\Windows\system32\regedt32.exe [9216 2009-07-14] (Microsoft Corporation) S3 Proficy Driver Runtime; C:\Program Files\GE Fanuc\Proficy Machine Edition\fxView\Runtime\ProficyDrivers\Win32\GefPdfOpc.exe [X] U2 BHDrvx86; S3 fgddrpob; \??\C:\Users\Admin\AppData\Local\Temp\fgddrpob.sys [X] S4 sptd; System32\Drivers\sptd.sys [X] U3 mbr; \??\C:\Users\Admin\AppData\Local\Temp\mbr.sys [X] Task: {45BA81C0-1959-42BD-B789-70616B7351BE} - System32\Tasks\{1D971E29-69FD-4BF9-80DE-038D6B6B5D02} => C:\Users\Admin\Desktop\MineFox NoPremium\MineFox NoPremium.exe [2012-02-08] (AnjoCaido) Task: {7263A631-8C41-4451-A5BF-170CE9F24536} - System32\Tasks\{A656FBB2-C4C9-4064-AC36-91F278731506} => Firefox.exe http://ui.skype.com/ui/0/5.1.0.104.259/pl/abandoninstall?source=lightinstaller&page=tsDownload&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;userlevelpresent Task: {B0A2AAD4-F6AE-4682-884E-26ABD92536CC} - System32\Tasks\{01E96499-92B0-4BDA-91C6-296EE8ECE461} => C:\Users\Admin\Desktop\MineFox NoPremium\MineFox NoPremium.exe [2012-02-08] (AnjoCaido) Task: {E9055C73-6A44-4DBD-B63F-8D0F62143B1B} - System32\Tasks\systems => C:\Users\Admin\AppData\Roaming\ifebd.exe C:\ProgramData\Adtrustmedia C:\Users\Admin\AppData\Local\AdTrustMedia C:\Users\Admin\AppData\Roaming\ESET C:\Users\Remote\AppData\Roaming\ESET Reg: reg delete HKLM\SOFTWARE\Mozilla\Thunderbird /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Copy Handler => Value deleted successfully. HKU\S-1-5-21-2631689147-4000948806-3686541712-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{5c81f57f-3cf7-4785-b4ef-11ace31aec4f} => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{614C7A8F-AE70-4A3D-BC76-05E194768672} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{614C7A8F-AE70-4A3D-BC76-05E194768672} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7E4E3281-DF2A-4CE6-8CBB-14DDEE358EA7} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7E4E3281-DF2A-4CE6-8CBB-14DDEE358EA7} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} => Key deleted successfully. HKCR\CLSID\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5C81F57F-3CF7-4785-B4EF-11ACE31AEC4F} => Value deleted successfully. HKCR\CLSID\{5C81F57F-3CF7-4785-B4EF-11ACE31AEC4F} => Key not found. HKLM\Software\Mozilla\Firefox\Extensions\\smartwebprinting@hp.com => Value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\smartwebprinting@hp.com => Value deleted successfully. C:\Program Files\Mozilla Firefox\extensions => Moved successfully. C:\Program Files\Mozilla Firefox\plugins => Moved successfully. "HKLM\SYSTEM\CurrentControlSet\Services\sptd" => Error unlocking key. .EsetTrialReset => Service deleted successfully. Proficy Driver Runtime => Service deleted successfully. BHDrvx86 => Service deleted successfully. fgddrpob => Service deleted successfully. sptd => Service not found. mbr => Service not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{45BA81C0-1959-42BD-B789-70616B7351BE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{45BA81C0-1959-42BD-B789-70616B7351BE} => Key deleted successfully. C:\Windows\System32\Tasks\{1D971E29-69FD-4BF9-80DE-038D6B6B5D02} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1D971E29-69FD-4BF9-80DE-038D6B6B5D02} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7263A631-8C41-4451-A5BF-170CE9F24536} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7263A631-8C41-4451-A5BF-170CE9F24536} => Key deleted successfully. C:\Windows\System32\Tasks\{A656FBB2-C4C9-4064-AC36-91F278731506} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A656FBB2-C4C9-4064-AC36-91F278731506} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B0A2AAD4-F6AE-4682-884E-26ABD92536CC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0A2AAD4-F6AE-4682-884E-26ABD92536CC} => Key deleted successfully. C:\Windows\System32\Tasks\{01E96499-92B0-4BDA-91C6-296EE8ECE461} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{01E96499-92B0-4BDA-91C6-296EE8ECE461} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E9055C73-6A44-4DBD-B63F-8D0F62143B1B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E9055C73-6A44-4DBD-B63F-8D0F62143B1B} => Key deleted successfully. C:\Windows\System32\Tasks\systems => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\systems => Key deleted successfully. C:\ProgramData\Adtrustmedia => Moved successfully. C:\Users\Admin\AppData\Local\AdTrustMedia => Moved successfully. C:\Users\Admin\AppData\Roaming\ESET => Moved successfully. C:\Users\Remote\AppData\Roaming\ESET => Moved successfully. ========= reg delete HKLM\SOFTWARE\Mozilla\Thunderbird /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====