Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-11-2014 Ran by komodore at 2014-11-09 13:37:29 Run:1 Running from D:\Adam\axpan\FRST Loaded Profiles: komodore & Adam & Mateusz (Available profiles: komodore & Adam & Mateusz) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: GroupPolicyUsers\S-1-5-21-2694031699-52744628-1130330716-1002\User: Group Policy restriction detected <======= ATTENTION S2 vToolbarUpdater3.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.2.0\ToolbarUpdater.exe [X] HKU\S-1-5-21-2694031699-52744628-1130330716-1000\...\Run: [] => [X] Task: {41FE3FE3-6851-439E-A5F1-70F29F6B9154} - System32\Tasks\e-pity2013_kwiecien => C:\Program Files\e-file\e-pity2013\Assets\signxml.exe Task: {EFF9019A-7152-424A-BE4F-7DF8C11D789A} - System32\Tasks\e-pity2013_styczen => C:\Program Files\e-file\e-pity2013\Assets\signxml.exe FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\ProgramData\*.bdinstall.bin C:\Program Files\Bitdefender C:\Users\Mateusz\Downloads\UnityWebPlayer*.exe RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\FRST\Quarantine EmptyTemp: ***************** Processes closed successfully. C:\Windows\system32\GroupPolicyUsers\S-1-5-21-2694031699-52744628-1130330716-1002\User => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. vToolbarUpdater3.2.0 => Service deleted successfully. HKU\S-1-5-21-2694031699-52744628-1130330716-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41FE3FE3-6851-439E-A5F1-70F29F6B9154}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41FE3FE3-6851-439E-A5F1-70F29F6B9154}" => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2013_kwiecien => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2013_kwiecien" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EFF9019A-7152-424A-BE4F-7DF8C11D789A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFF9019A-7152-424A-BE4F-7DF8C11D789A}" => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2013_styczen => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2013_styczen" => Key deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\ProgramData\*.bdinstall.bin => Moved successfully. C:\Program Files\Bitdefender => Moved successfully. C:\Users\Mateusz\Downloads\UnityWebPlayer*.exe => Moved successfully. "C:\AdwCleaner" => Removed successfully. "C:\FRST\Quarantine" => Removed successfully. EmptyTemp: => Removed 95.7 MB temporary data. The system needed a reboot. ==== End of Fixlog ====