Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-05-2014 Ran by Łukasz at 2014-05-05 19:46:48 Run:2 Running from C:\Users\Łukasz\Desktop\bla bla Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [fst_pl_110] => [X] HKU\S-1-5-21-2007790560-3427396280-4121097112-1002\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\Łukasz\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=5a106ea949d247d3a1ea314fa05b3cd0-85b27e6fb2e9431dd2eb958e7cc9fffab9aab408 /CMPID=1213b HKU\S-1-5-21-2007790560-3427396280-4121097112-1002\...\Run: [AVG-Secure-Search-Update_0414c] => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2725912 2014-04-26] () Task: {455CD436-63A4-47AA-AFD6-8F09A8E42110} - System32\Tasks\AVG-Secure-Search-Update_0414c_rel => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-26] () Task: {A2E4C4D4-7504-43A8-9DAE-14EAD7A2EF92} - System32\Tasks\AVG-Secure-Search-Update_0414c_rmv => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-26] () Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rel.job => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rmv.job => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mysearch.avg.com?cid={19D7A829-4B02-4BCE-8756-69DB2E4662B9}&mid=5a106ea949d247d3a1ea314fa05b3cd0-85b27e6fb2e9431dd2eb958e7cc9fffab9aab408&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2013-12-25 16:16:43&v=18.1.0.443&pid=safeguard&sg=&sap=hp CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Łukasz\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-11-26] C:\Program Files (x86)\Amazon C:\Program Files (x86)\Avg Secure Update Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla\Thunderbird /f CMD: del /q C:\WINDOWS\SysWOW64\sqlite3.dll ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_110 => Value deleted successfully. HKU\S-1-5-21-2007790560-3427396280-4121097112-1002\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_1213b => Value deleted successfully. HKU\S-1-5-21-2007790560-3427396280-4121097112-1002\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_0414c => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{455CD436-63A4-47AA-AFD6-8F09A8E42110} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{455CD436-63A4-47AA-AFD6-8F09A8E42110} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0414c_rel => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_0414c_rel => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A2E4C4D4-7504-43A8-9DAE-14EAD7A2EF92} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A2E4C4D4-7504-43A8-9DAE-14EAD7A2EF92} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0414c_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_0414c_rmv => Key deleted successfully. C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rel.job => Moved successfully. C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rmv.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp => Key deleted successfully. "C:\Users\Łukasz\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx" => File/Directory not found. C:\Program Files (x86)\Amazon => Moved successfully. C:\Program Files (x86)\Avg Secure Update => Moved successfully. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla\Thunderbird /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= del /q C:\WINDOWS\SysWOW64\sqlite3.dll ========= ========= End of CMD: ========= ==== End of Fixlog ====