Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-11-2014 Ran by Pawel at 2014-11-14 19:47:48 Run:1 Running from C:\Users\Pawel\Desktop Loaded Profile: Pawel (Available profiles: Pawel & Kuba & Tata) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: Task: {87AC9404-D465-4CE2-ACC9-220CECB5CD90} - System32\Tasks\ASP => C:\Program Files (x86)\RCP\systweakasp.exe HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2024800 2014-06-04] (Wondershare) HKU\S-1-5-21-2615021221-2235552605-2224125913-1000\...\Run: [MX Skype Recorder] => "C:\ProgramData\MXSkypeRecorder\MXSkypeRecorder.exe" /autorun HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp220141019 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp220141019 C:\Program Files (x86)\Common Files\Wondershare C:\Program Files\Wondershare C:\ProgramData\APN C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Editor 4.5 C:\Users\Kuba\AppData\Local\Wondershare C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDF Editor 4.5 C:\Users\Kuba\AppData\Roaming\Wondershare C:\Users\Kuba\AppData\Roaming\Systweak C:\Users\Kuba\Downloads\*(*)-dp*.exe C:\Users\Kuba\Desktop\PDF Editor 4.5.lnk C:\Users\Tata\Desktop\PDF Editor 4.5.lnk C:\Users\Pawel\AppData\Local\Wondershare C:\Users\Public\Documents\Wondershare C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP C:\Windows\system32\roboot64.exe C:\Windows\system32\WSMonEditor.dll C:\Windows\SysWOW64\tmp*.tmp Folder: C:\Users\Pawel\AppData\Roaming\Steam EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{87AC9404-D465-4CE2-ACC9-220CECB5CD90}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87AC9404-D465-4CE2-ACC9-220CECB5CD90}" => Key deleted successfully. C:\Windows\System32\Tasks\ASP => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASP" => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Wondershare Helper Compact.exe => value deleted successfully. HKU\S-1-5-21-2615021221-2235552605-2224125913-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MX Skype Recorder => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. C:\Program Files (x86)\Common Files\Wondershare => Moved successfully. C:\Program Files\Wondershare => Moved successfully. C:\ProgramData\APN => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Editor 4.5 => Moved successfully. C:\Users\Kuba\AppData\Local\Wondershare => Moved successfully. C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDF Editor 4.5 => Moved successfully. C:\Users\Kuba\AppData\Roaming\Wondershare => Moved successfully. C:\Users\Kuba\AppData\Roaming\Systweak => Moved successfully. C:\Users\Kuba\Downloads\*(*)-dp*.exe => Moved successfully. C:\Users\Kuba\Desktop\PDF Editor 4.5.lnk => Moved successfully. C:\Users\Tata\Desktop\PDF Editor 4.5.lnk => Moved successfully. C:\Users\Pawel\AppData\Local\Wondershare => Moved successfully. C:\Users\Public\Documents\Wondershare => Moved successfully. C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP => Moved successfully. C:\Windows\system32\roboot64.exe => Moved successfully. C:\Windows\system32\WSMonEditor.dll => Moved successfully. C:\Windows\SysWOW64\tmp*.tmp => Moved successfully. ========================= Folder: C:\Users\Pawel\AppData\Roaming\Steam ======================== 2014-11-08 01:50 - 2014-11-08 01:50 - 0000000 ____D () C:\Users\Pawel\AppData\Roaming\Steam\CODEX 2014-11-08 01:50 - 2014-11-08 01:50 - 0000000 ____D () C:\Users\Pawel\AppData\Roaming\Steam\CODEX\209660 2014-11-08 01:50 - 2014-11-08 01:50 - 0000032 _____ () C:\Users\Pawel\AppData\Roaming\Steam\CODEX\209660\achievements.ini 2014-11-08 01:50 - 2014-11-08 01:50 - 0000032 _____ () C:\Users\Pawel\AppData\Roaming\Steam\CODEX\209660\leaderboards.ini 2014-11-08 01:50 - 2014-11-08 01:50 - 0000000 ____D () C:\Users\Pawel\AppData\Roaming\Steam\CODEX\209660\local 2014-11-08 01:50 - 2014-11-08 01:50 - 0000000 ____D () C:\Users\Pawel\AppData\Roaming\Steam\CODEX\209660\remote ====== End of Folder: ====== EmptyTemp: => Removed 1.3 GB temporary data. The system needed a reboot. ==== End of Fixlog ====