Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-11-2014 01 Ran by ja at 2014-11-25 21:26:47 Run:1 Running from G:\ps3 Loaded Profile: ja (Available profiles: ja) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: S2 fc67e7a0; "C:\Windows\system32\rundll32.exe" "c:\program files (x86)\DeltaFix\DeltaFix.dll",serv S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S3 avchv; \SystemRoot\system32\DRIVERS\avchv.sys [X] S3 dcdbas; \SystemRoot\System32\drivers\dcdbas64.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S2 SPDRIVER_1.37.0.1390; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.1390\jsdrv.sys [X] Task: {1703254E-577D-49D9-8544-2F194C53670E} - System32\Tasks\Installer_sense => C:\Users\ja\AppData\Local\Installer\Installsense_20461\delay.exe <==== ATTENTION Task: {37E92B47-93B1-423C-9A64-62CC68596203} - \SPBIW_UpdateTask_Time_3533393736323933332d232d783232575b5a34452d2a No Task File <==== ATTENTION Task: {4DC026B3-1D1E-4525-9320-BCB396891C2C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {743BA98E-D148-4C8F-85ED-DC4B29A15F08} - \Installer_iwebar No Task File <==== ATTENTION Task: {76E47D0A-CC68-4D0E-85F6-BA670738EF9E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {EA7F0DCC-B2C9-419B-8FD9-F220B885FA41} - \Microsoft\Windows\Shell\FamilySafetyUpload No Task File <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll No File FF Plugin HKU\S-1-5-21-527024006-3297479484-4194791215-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ja\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mystartsearch.xml C:\Program Files (x86)\DeltaFix C:\Program Files (x86)\Google C:\ProgramData\6d276c3130bd3996 C:\ProgramData\Malwarebytes C:\ProgramData\TEMP C:\Users\ja\scan_results C:\Users\ja\AppData\Local\Comodo C:\Users\ja\AppData\Local\Google C:\Users\ja\AppData\Roaming\AVG C:\Users\ja\AppData\Roaming\driver C:\Users\ja\AppData\Roaming\Genieo C:\Users\ja\AppData\Roaming\LavasoftStatistics C:\Users\ja\AppData\Roaming\Opera Software C:\Users\ja\AppData\Roaming\Orbit C:\Users\ja\AppData\Roaming\ProgSense C:\Users\ja\Downloads\*_downloader-*.exe C:\Users\Administrator C:\Users\Gość C:\Users\HomeGroupUser$ C:\Windows\msdownld.tmp C:\Windows\SysWOW64\GroupPolicy\GPT.INI Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Google /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\ja\AppData\Local CMD: dir /a C:\Users\ja\AppData\LocalLow CMD: dir /a C:\Users\ja\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. fc67e7a0 => Service deleted successfully. gupdate => Service deleted successfully. gupdatem => Service deleted successfully. avchv => Service deleted successfully. dcdbas => Service deleted successfully. MBAMSwissArmy => Service deleted successfully. SPDRIVER_1.37.0.1390 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1703254E-577D-49D9-8544-2F194C53670E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1703254E-577D-49D9-8544-2F194C53670E}" => Key deleted successfully. C:\Windows\System32\Tasks\Installer_sense => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_sense" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{37E92B47-93B1-423C-9A64-62CC68596203}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{37E92B47-93B1-423C-9A64-62CC68596203}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3533393736323933332d232d783232575b5a34452d2a" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4DC026B3-1D1E-4525-9320-BCB396891C2C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4DC026B3-1D1E-4525-9320-BCB396891C2C}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{743BA98E-D148-4C8F-85ED-DC4B29A15F08}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{743BA98E-D148-4C8F-85ED-DC4B29A15F08}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_iwebar" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{76E47D0A-CC68-4D0E-85F6-BA670738EF9E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76E47D0A-CC68-4D0E-85F6-BA670738EF9E}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA7F0DCC-B2C9-419B-8FD9-F220B885FA41}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA7F0DCC-B2C9-419B-8FD9-F220B885FA41}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Shell\FamilySafetyUpload" => Key deleted successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully. "HKU\S-1-5-21-527024006-3297479484-4194791215-1002\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0" => Key deleted successfully. C:\Users\ja\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll not found. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mystartsearch.xml => Moved successfully. C:\Program Files (x86)\DeltaFix => Moved successfully. C:\Program Files (x86)\Google => Moved successfully. C:\ProgramData\6d276c3130bd3996 => Moved successfully. C:\ProgramData\Malwarebytes => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\Users\ja\scan_results => Moved successfully. C:\Users\ja\AppData\Local\Comodo => Moved successfully. C:\Users\ja\AppData\Local\Google => Moved successfully. C:\Users\ja\AppData\Roaming\AVG => Moved successfully. C:\Users\ja\AppData\Roaming\driver => Moved successfully. C:\Users\ja\AppData\Roaming\Genieo => Moved successfully. C:\Users\ja\AppData\Roaming\LavasoftStatistics => Moved successfully. C:\Users\ja\AppData\Roaming\Opera Software => Moved successfully. C:\Users\ja\AppData\Roaming\Orbit => Moved successfully. C:\Users\ja\AppData\Roaming\ProgSense => Moved successfully. C:\Users\ja\Downloads\*_downloader-*.exe => Moved successfully. C:\Users\Administrator => Moved successfully. C:\Users\Gość => Moved successfully. C:\Users\HomeGroupUser$ => Moved successfully. C:\Windows\msdownld.tmp => Moved successfully. C:\Windows\SysWOW64\GroupPolicy\GPT.INI => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Volume in drive C is 8 Volume Serial Number is BA59-A6C1 Directory of C:\Program Files 2014-11-20 14:15