Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-11-2014 02 Ran by ŁukiAsia at 2014-11-14 16:04:37 Run:1 Running from C:\Users\ŁukiAsia\Desktop Loaded Profile: ŁukiAsia (Available profiles: ŁukiAsia) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1451179296-2106293565-644611054-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?tpid=ORJ-SPE&o=APN11406&pf=V7&trgb=IE&p2=^BBE^OSJ000^YY^PL&gct=hp&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^PL&apn_dbr=ie_9.0.8112.16421&apn_uid=B68612DB-77D3-4EFD-BA96-CC96D74DCCC2&itbv=12.18.0.82&doi=2014-11-12&psv=&pt=tb SearchScopes: HKCU - DefaultScope {F2D2F428-F865-46BD-9731-9152F7D0C003} URL = http://www.search.ask.com/web?tpid=ORJ-SPE&o=APN11406&pf=V7&p2=^BBE^OSJ000^YY^PL&gct=&itbv=12.18.0.82&apn_uid=B68612DB-77D3-4EFD-BA96-CC96D74DCCC2&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^PL&apn_dbr=ie_9.0.8112.16421&doi=2014-11-12&trgb=IE&q={searchTerms}&psv=&pt=tb SearchScopes: HKCU - {F2D2F428-F865-46BD-9731-9152F7D0C003} URL = http://www.search.ask.com/web?tpid=ORJ-SPE&o=APN11406&pf=V7&p2=^BBE^OSJ000^YY^PL&gct=&itbv=12.18.0.82&apn_uid=B68612DB-77D3-4EFD-BA96-CC96D74DCCC2&apn_ptnrs=BBE&apn_dtid=^OSJ000^YY^PL&apn_dbr=ie_9.0.8112.16421&doi=2014-11-12&trgb=IE&q={searchTerms}&psv=&pt=tb Task: {0CCCEC38-5A6B-4EE5-B435-2E7D41A63D42} - System32\Tasks\{9976A63E-2E01-4FD8-A661-8B9737905E5A} => Iexplore.exe http://ui.skype.com/ui/0/6.16.0.105/pl/abandoninstall?page=tsProgressBar C:\ProgramData\*.bdinstall.bin C:\Users\ŁukiAsia\AppData\Roaming\AVG C:\Users\ŁukiAsia\AppData\Roaming\OpenCandy C:\Users\ŁukiAsia\AppData\Roaming\QuickScan C:\Users\Public\Desktop\Software Deals.url Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: sc config "PLAY ONLINE. RunOuc" start= demand EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-1451179296-2106293565-644611054-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F2D2F428-F865-46BD-9731-9152F7D0C003}" => Key deleted successfully. "HKCR\CLSID\{F2D2F428-F865-46BD-9731-9152F7D0C003}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0CCCEC38-5A6B-4EE5-B435-2E7D41A63D42}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0CCCEC38-5A6B-4EE5-B435-2E7D41A63D42}" => Key deleted successfully. C:\Windows\System32\Tasks\{9976A63E-2E01-4FD8-A661-8B9737905E5A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9976A63E-2E01-4FD8-A661-8B9737905E5A}" => Key deleted successfully. C:\ProgramData\*.bdinstall.bin => Moved successfully. C:\Users\ŁukiAsia\AppData\Roaming\AVG => Moved successfully. C:\Users\ŁukiAsia\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\ŁukiAsia\AppData\Roaming\QuickScan => Moved successfully. C:\Users\Public\Desktop\Software Deals.url => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "PLAY ONLINE. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= EmptyTemp: => Removed 949.6 MB temporary data. The system needed a reboot. ==== End of Fixlog ====