Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 30-09-2014 Ran by user at 2014-10-01 18:53:16 Run:1 Running from C:\FRST Loaded Profile: user (Available profiles: user & Gość) Boot Mode: Normal ============================================== Content of fixlist: ***************** [noparse]CloseProcesses: HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=NG1V5&o=101787&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=N0&apn_dtid=YYYYYYYYPL&apn_uid=CDA74BC7-91D8-447A-9602-18DEFD03B5E4&apn_sauid=B0FF95AB-88F8-4B8E-BBD9-65A0FCB6454A SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=NG1V5&o=101787&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=N0&apn_dtid=YYYYYYYYPL&apn_uid=CDA74BC7-91D8-447A-9602-18DEFD03B5E4&apn_sauid=B0FF95AB-88F8-4B8E-BBD9-65A0FCB6454A SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Task: {33232835-86B2-483E-AB78-3C6F0A7B30C1} - System32\Tasks\{8C7A0C0D-3AB0-470B-8579-5C1AC36526AD} => C:\Games\Worms Armageddon - New Edition\WA.exe Task: {34BF9932-5814-49E5-BEDF-F367F697EDC0} - System32\Tasks\{98D3D13F-ABBA-45BD-90E5-13E09D6A60B0} => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe Task: {4AFE0ABD-F26E-42B5-807E-A4BDFDFCB7A9} - System32\Tasks\{CFDADA79-E4F6-4BAE-BC04-CAE1A4C14BD4} => C:\Program Files (x86)\Tomb Raider Legenda\trl.exe Task: {52B03227-92EB-4D13-97D1-B975A9C2CB64} - System32\Tasks\{E9D99713-D258-4D81-850A-F4113A8BF7F1} => C:\Program Files (x86)\Microsoft Office\Office\EXCEL.EXE Task: {59DABAEE-8DE3-4B71-9032-BBA43C3DDD3C} - System32\Tasks\{1AE060DD-D5D2-4DCE-8FED-94D603790A6B} => C:\Games\Worms Armageddon - New Edition\WA.exe Task: {BF7E09D3-3176-401A-A517-B5581B2DCC38} - System32\Tasks\{4EC7FF1E-24E8-4EDC-99A1-F677C772674E} => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe Task: {C3CD3756-46D7-489D-B7E4-F2EA32AB0876} - System32\Tasks\{829CD741-D8EE-4377-AF7E-7CC4143E49EB} => C:\Games\Worms Armageddon - New Edition\WA.exe U3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 RtlWlanu; system32\DRIVERS\rtwlanu.sys [X] S2 Sentinel; \SystemRoot\System32\Drivers\SENTINEL.SYS [X] U3 tmlwf; No ImagePath U3 tmwfp; No ImagePath C:\Program Files (x86)\Mozilla Firefox C:\ProgramData\Temp C:\Users\user\AppData\Roaming\Mozilla C:\Windows\SysWow64\sho*.tmp DeleteKey: HKCU\Software\Mozilla DeleteKey: HKCU\Software\MozillaPlugins DeleteKey: HKLM\SOFTWARE\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\mozilla.org DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins EmptyTemp:[/noparse] ***************** [noparse]CloseProcesses: => Error: No automatic fix found for this entry. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Setwallpaper => value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}" => Key deleted successfully. "HKCR\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}" => Key deleted successfully. "HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully. "HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{33232835-86B2-483E-AB78-3C6F0A7B30C1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{33232835-86B2-483E-AB78-3C6F0A7B30C1}" => Key deleted successfully. C:\Windows\System32\Tasks\{8C7A0C0D-3AB0-470B-8579-5C1AC36526AD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8C7A0C0D-3AB0-470B-8579-5C1AC36526AD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{34BF9932-5814-49E5-BEDF-F367F697EDC0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{34BF9932-5814-49E5-BEDF-F367F697EDC0}" => Key deleted successfully. C:\Windows\System32\Tasks\{98D3D13F-ABBA-45BD-90E5-13E09D6A60B0} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{98D3D13F-ABBA-45BD-90E5-13E09D6A60B0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4AFE0ABD-F26E-42B5-807E-A4BDFDFCB7A9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AFE0ABD-F26E-42B5-807E-A4BDFDFCB7A9}" => Key deleted successfully. C:\Windows\System32\Tasks\{CFDADA79-E4F6-4BAE-BC04-CAE1A4C14BD4} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CFDADA79-E4F6-4BAE-BC04-CAE1A4C14BD4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{52B03227-92EB-4D13-97D1-B975A9C2CB64}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52B03227-92EB-4D13-97D1-B975A9C2CB64}" => Key deleted successfully. C:\Windows\System32\Tasks\{E9D99713-D258-4D81-850A-F4113A8BF7F1} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E9D99713-D258-4D81-850A-F4113A8BF7F1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{59DABAEE-8DE3-4B71-9032-BBA43C3DDD3C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59DABAEE-8DE3-4B71-9032-BBA43C3DDD3C}" => Key deleted successfully. C:\Windows\System32\Tasks\{1AE060DD-D5D2-4DCE-8FED-94D603790A6B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1AE060DD-D5D2-4DCE-8FED-94D603790A6B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BF7E09D3-3176-401A-A517-B5581B2DCC38}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF7E09D3-3176-401A-A517-B5581B2DCC38}" => Key deleted successfully. C:\Windows\System32\Tasks\{4EC7FF1E-24E8-4EDC-99A1-F677C772674E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4EC7FF1E-24E8-4EDC-99A1-F677C772674E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C3CD3756-46D7-489D-B7E4-F2EA32AB0876}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3CD3756-46D7-489D-B7E4-F2EA32AB0876}" => Key deleted successfully. C:\Windows\System32\Tasks\{829CD741-D8EE-4377-AF7E-7CC4143E49EB} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{829CD741-D8EE-4377-AF7E-7CC4143E49EB}" => Key deleted successfully. catchme => Service deleted successfully. RtlWlanu => Service deleted successfully. Sentinel => Service deleted successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\user\AppData\Roaming\Mozilla => Moved successfully. C:\Windows\SysWow64\sho*.tmp => Moved successfully. HKCU\Software\Mozilla => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Mozilla => Key Deleted Successfully. HKCU\Software\MozillaPlugins => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\MozillaPlugins => Key Deleted Successfully. HKLM\SOFTWARE\MozillaPlugins => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\MozillaPlugins => Key Deleted Successfully. HKLM\SOFTWARE\Wow6432Node\Mozilla => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\Mozilla => Key Deleted Successfully. HKLM\SOFTWARE\Wow6432Node\mozilla.org => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\mozilla.org => Key Deleted Successfully. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => Key Deleted Successfully. EmptyTemp: => Removed 704.2 MB temporary data. The system needed a reboot. ==== End of Fixlog ====