Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-11-2014 01 Ran by JA at 2014-11-27 09:16:55 Run:1 Running from C:\Users\JA\Desktop\do naprawiania Loaded Profile: JA (Available profiles: JA) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R2 MaintainerSvc4.07.4104264; C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be\maintainer.exe [123680 2014-11-26] () S3 e1edc438-f640-4184-a443-d2a7c37a01dc; \??\C:\Users\Administrator\Desktop\asus-wtp2.3.0-11\bin\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X] U0 msahci; No ImagePath S1 ttnfd; system32\drivers\ttnfd.sys [X] Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-1.job => C:\Program Files (x86)\CinePlus2V09.10\CinePlus2V09.10-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-11.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-11.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-2.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-2.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-3.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-3.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-4.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-4.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-5.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-5.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-5_user.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-5.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-6.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-6.exe <==== ATTENTION Task: C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-7.job => C:\Program Files (x86)\CinePlus2V09.10\35ad5ac6-37a6-448f-b56e-7dd38ede466b-7.exe <==== ATTENTION Task: C:\Windows\Tasks\5a91ef75-1c1c-4628-a059-6e4153aa7b22.job => C:\Program Files (x86)\CinePlus2V09.10\5a91ef75-1c1c-4628-a059-6e4153aa7b22.exe <==== ATTENTION Task: C:\Windows\Tasks\610386dd-4883-46eb-af28-0fd34950c8e2.job => C:\Program Files (x86)\CinePlus2V09.10\610386dd-4883-46eb-af28-0fd34950c8e2.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\Price Fountain.job => C:\Users\JA\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: PriceFountain -> {b608cc98-54de-4775-96c9-097de398500c} -> C:\Users\JA\AppData\Local\PriceFountain\PriceFountainIE.dll No File CHR HomePage: Default -> hxxp://www.sweet-page.com/?type=hp&ts=1413912910&from=cor&uid=HitachiXHTS545032A7E380_TE8413480R5GBC0R5GBCX CHR StartupUrls: Default -> "hxxp://www.sweet-page.com/?type=hp&ts=1413912910&from=cor&uid=HitachiXHTS545032A7E380_TE8413480R5GBC0R5GBCX" FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK C:\Program Files (x86)\Opera C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be C:\Users\JA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhgjpfdjhlimkkdgnecbgnefdafbcncc C:\Users\JA\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\JA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\JA\AppData\Roaming\*.exe C:\Users\JA\AppData\Roaming\sp_data.sys C:\Users\JA\AppData\Roaming\0I0M0D1F2W1G1I1F1T1Q1P1C C:\Users\JA\AppData\Roaming\ap_movie C:\Users\JA\AppData\Roaming\Opera Software C:\Users\JA\Downloads\yet_another_cleaner_*.exe C:\Users\JA\Desktop\Wyczyść rejestr za darmo!.lnk Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ASUSWebStorage" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mcui_exe" /f EmptyTemp: ***************** Processes closed successfully. MaintainerSvc4.07.4104264 => Service stopped successfully. MaintainerSvc4.07.4104264 => Service deleted successfully. e1edc438-f640-4184-a443-d2a7c37a01dc => Service deleted successfully. msahci => Service deleted successfully. ttnfd => Service deleted successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-1.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-11.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-2.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-3.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-4.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-5.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-5_user.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-6.job => Moved successfully. C:\Windows\Tasks\35ad5ac6-37a6-448f-b56e-7dd38ede466b-7.job => Moved successfully. C:\Windows\Tasks\5a91ef75-1c1c-4628-a059-6e4153aa7b22.job => Moved successfully. C:\Windows\Tasks\610386dd-4883-46eb-af28-0fd34950c8e2.job => Moved successfully. C:\Windows\Tasks\APSnotifierPP1.job => Moved successfully. C:\Windows\Tasks\APSnotifierPP2.job => Moved successfully. C:\Windows\Tasks\APSnotifierPP3.job => Moved successfully. C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\Price Fountain.job => Moved successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b608cc98-54de-4775-96c9-097de398500c}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{b608cc98-54de-4775-96c9-097de398500c}" => Key deleted successfully. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => value deleted successfully. C:\Program Files (x86)\Opera => Moved successfully. C:\ProgramData\398c0b96-ebd3-4f67-a5c7-1899a15c12be => Moved successfully. C:\Users\JA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhgjpfdjhlimkkdgnecbgnefdafbcncc => Moved successfully. C:\Users\JA\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\JA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\JA\AppData\Roaming\*.exe => Moved successfully. C:\Users\JA\AppData\Roaming\sp_data.sys => Moved successfully. C:\Users\JA\AppData\Roaming\0I0M0D1F2W1G1I1F1T1Q1P1C => Moved successfully. C:\Users\JA\AppData\Roaming\ap_movie => Moved successfully. C:\Users\JA\AppData\Roaming\Opera Software => Moved successfully. C:\Users\JA\Downloads\yet_another_cleaner_*.exe => Moved successfully. "C:\Users\JA\Desktop\Wyczyść rejestr za darmo!.lnk" => File/Directory not found. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ASUSWebStorage" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mcui_exe" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 1.6 GB temporary data. The system needed a reboot. ==== End of Fixlog ====