Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-05-2014 02 Ran by Tomek at 2014-05-29 15:24:42 Run:1 Running from C:\Users\Tomek\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe HKU\S-1-5-21-906435108-3439195025-2073306531-1000\...\Run: [svchost] => regsvr32 /s "C:\Temp:026EB853.dat" URLSearchHook: HKCU - (No Name) - {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {64511A76-362E-4551-8000-BA43A8F82AAF} URL = http://search.babylon.com/?q={searchTerms}&AF=100478&babsrc=SP_ss&mntrId=36a0fad500000000000068a3c44e539c SearchScopes: HKCU - {B5DF8EE5-D8B8-4C31-8858-311463CDB647} URL = Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKCU - No Name - {5C5B9468-D672-4EB7-B52F-B5AFABF28C5B} - No File C:\Program Files (x86)\mozilla firefox\plugins FF HKLM-x32\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files (x86)\RelevantKnowledge\firefox Task: {097E3930-62E5-4088-AB43-09011B8A24FA} - System32\Tasks\{120FB32D-A916-4D55-AEF5-40C40B5C7E3D} => C:\Users\Tomek\Desktop\LeagueofLegends.exe Task: {53F0AA64-4F75-4EE9-BEC2-5C508A81C4DC} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION Task: {558FF4C4-5B80-4CED-9D6C-4476A19E2D20} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {7A5C515D-2D24-4A3D-BC9A-0EC2BC168092} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION Task: {898EAD81-BA3B-4D97-97B8-15E2E4B0871D} - System32\Tasks\{672535B5-AC22-4EC4-BE6A-7D68116F801D} => C:\Users\Tomek\Documents\LeagueofLegends.exe S3 ALSysIO; \??\C:\Users\Tomek\AppData\Local\Temp\ALSysIO64.sys [X] C:\Temp C:\Users\Tomek\AppData\Local\Temp\*.dll C:\Users\Tomek\AppData\Local\Temp\*.exe C:\Users\Tomek\AppData\Roaming\ProgSense C:\Users\Tomek\Desktop\AVG-PC-TuneUp(21136).exe C:\Users\Tomek\Documents\aTube-Catcher(21622).exe C:\Users\Tomek\Downloads\*.tmp Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search the Web" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MenuExt\Search the Web" /f Reboot: ***************** C:\Windows\SysWOW64\explorer.exe => No running process found C:\Windows\SysWOW64\explorer.exe => No running process found C:\Windows\SysWOW64\explorer.exe => No running process found C:\Windows\SysWOW64\explorer.exe => No running process found HKU\S-1-5-21-906435108-3439195025-2073306531-1000\Software\Microsoft\Windows\CurrentVersion\Run\\svchost => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b} => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{64511A76-362E-4551-8000-BA43A8F82AAF} => Key deleted successfully. HKCR\CLSID\{64511A76-362E-4551-8000-BA43A8F82AAF} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B5DF8EE5-D8B8-4C31-8858-311463CDB647} => Key deleted successfully. HKCR\CLSID\{B5DF8EE5-D8B8-4C31-8858-311463CDB647} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Value deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Value deleted successfully. HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5C5B9468-D672-4EB7-B52F-B5AFABF28C5B} => Value deleted successfully. HKCR\CLSID\{5C5B9468-D672-4EB7-B52F-B5AFABF28C5B} => Key not found. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A} => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{097E3930-62E5-4088-AB43-09011B8A24FA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{097E3930-62E5-4088-AB43-09011B8A24FA} => Key deleted successfully. C:\Windows\System32\Tasks\{120FB32D-A916-4D55-AEF5-40C40B5C7E3D} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{120FB32D-A916-4D55-AEF5-40C40B5C7E3D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{53F0AA64-4F75-4EE9-BEC2-5C508A81C4DC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53F0AA64-4F75-4EE9-BEC2-5C508A81C4DC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Program aktualizacji online firmy Adobe. => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{558FF4C4-5B80-4CED-9D6C-4476A19E2D20} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{558FF4C4-5B80-4CED-9D6C-4476A19E2D20} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7A5C515D-2D24-4A3D-BC9A-0EC2BC168092} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A5C515D-2D24-4A3D-BC9A-0EC2BC168092} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{898EAD81-BA3B-4D97-97B8-15E2E4B0871D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{898EAD81-BA3B-4D97-97B8-15E2E4B0871D} => Key deleted successfully. C:\Windows\System32\Tasks\{672535B5-AC22-4EC4-BE6A-7D68116F801D} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{672535B5-AC22-4EC4-BE6A-7D68116F801D} => Key deleted successfully. ALSysIO => Service deleted successfully. C:\Temp => Moved successfully. C:\Users\Tomek\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Tomek\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\Tomek\AppData\Roaming\ProgSense => Moved successfully. C:\Users\Tomek\Desktop\AVG-PC-TuneUp(21136).exe => Moved successfully. C:\Users\Tomek\Documents\aTube-Catcher(21622).exe => Moved successfully. C:\Users\Tomek\Downloads\*.tmp => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sweetpacks Communicator" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search the Web" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MenuExt\Search the Web" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====