Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 10-11-2014 Ran by madziola at 2014-11-13 13:52:34 Run:1 Running from C:\temp Loaded Profile: madziola (Available profiles: madziola) Boot Mode: Normal ============================================== Content of fixlist: ***************** [noparse]CloseProcesses: R2 MaintainerSvc4.07.4104264; C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be\maintainer.exe [123680 2014-11-11] () R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw.sys [52928 2014-06-19] (StdLib) R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}w; C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w.sys [52928 2014-06-23] (StdLib) S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] AppInit_DLLs: c:\progra~2\bitguard\271832~1.68\{c16c1~1\bitguard.dll => c:\progra~2\bitguard\271832~1.68\{c16c1~1\bitguard.dll File Not Found Task: {2AC9DCD1-04DF-4B6F-87C8-F038D8DEB958} - System32\Tasks\{8E2AD033-553E-4C15-9C68-F860947658DB} => Firefox.exe http://ui.skype.com/ui/0/6.0.0.126/pl/abandoninstall?page=tsProgressBar Task: {F34BC672-FA10-40E4-8260-B9C908A9203B} - System32\Tasks\{86976A0B-9403-4687-8BB6-E512C68DF19F} => Firefox.exe http://ui.skype.com/ui/0/6.6.0.106/pl/go/help.faq.installer?LastError=1604 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=128 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=180&d=20140620 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear BHO: Jump Flip -> {b630c560-975d-41a3-9a95-cbc23ad991e4} -> C:\Program Files\Jump Flip\JumpFlipBHO.dll (Jump Flip) Toolbar: HKLM - No Name - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - No File FF Plugin: @VideoDownloadConverter_4z.com/Plugin -> C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll No File FF Plugin: @VideoDownloadConverter_ScriptHelper.com/Plugin -> C:\Program Files\VideoDownloadConverter\npVDCPlugin.dll No File FF HKLM\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files\RelevantKnowledge\firefox C:\Program Files\Greener Web C:\Program Files\Jump Flip C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be C:\Users\madziola\AppData\Local\Google\Chrome C:\Users\madziola\AppData\Local\Torpedo C:\Users\madziola\Downloads\*_Sciagnij.pl.exe C:\Users\madziola\Downloads\TorpedoSetup.exe C:\Users\madziola\Downloads\Torpedo C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw.sys C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w.sys Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: for /d %f in (C:\Users\madziola\AppData\Local\{*}) do rd /s /q "%f" CMD: dir /a "C:\Program Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\madziola\AppData\Local CMD: dir /a C:\Users\madziola\AppData\LocalLow CMD: dir /a C:\Users\madziola\AppData\Roaming EmptyTemp:[/noparse] ***************** [noparse]CloseProcesses: => Error: No automatic fix found for this entry. MaintainerSvc4.07.4104264 => Service stopped successfully. MaintainerSvc4.07.4104264 => Service deleted successfully. {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw => Service stopped successfully. {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw => Service deleted successfully. {a3f28269-ad17-41a8-b032-3e0313ef8979}w => Service stopped successfully. {a3f28269-ad17-41a8-b032-3e0313ef8979}w => Service deleted successfully. sptd => Service deleted successfully. "c:\progra~2\bitguard\271832~1.68\{c16c1~1\bitguard.dll" => Value Data removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2AC9DCD1-04DF-4B6F-87C8-F038D8DEB958}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC9DCD1-04DF-4B6F-87C8-F038D8DEB958}" => Key deleted successfully. C:\Windows\System32\Tasks\{8E2AD033-553E-4C15-9C68-F860947658DB} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8E2AD033-553E-4C15-9C68-F860947658DB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F34BC672-FA10-40E4-8260-B9C908A9203B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F34BC672-FA10-40E4-8260-B9C908A9203B}" => Key deleted successfully. C:\Windows\System32\Tasks\{86976A0B-9403-4687-8BB6-E512C68DF19F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{86976A0B-9403-4687-8BB6-E512C68DF19F}" => Key deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b630c560-975d-41a3-9a95-cbc23ad991e4}" => Key deleted successfully. "HKCR\CLSID\{b630c560-975d-41a3-9a95-cbc23ad991e4}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{48586425-6bb7-4f51-8dc6-38c88e3ebb58} => value deleted successfully. "HKCR\CLSID\{48586425-6bb7-4f51-8dc6-38c88e3ebb58}" => Key not found. "HKLM\Software\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin" => Key deleted successfully. "HKLM\Software\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin" => Key deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A} => value deleted successfully. C:\Program Files\Greener Web => Moved successfully. C:\Program Files\Jump Flip => Moved successfully. C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be => Moved successfully. C:\Users\madziola\AppData\Local\Google\Chrome => Moved successfully. C:\Users\madziola\AppData\Local\Torpedo => Moved successfully. C:\Users\madziola\Downloads\*_Sciagnij.pl.exe => Moved successfully. C:\Users\madziola\Downloads\TorpedoSetup.exe => Moved successfully. C:\Users\madziola\Downloads\Torpedo => Moved successfully. C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw.sys => Moved successfully. C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w.sys => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= for /d %f in (C:\Users\madziola\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 6A8E-330F Katalog: C:\Program Files 2014-11-13 13:54