Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-12-2014 Ran by User at 2014-12-04 01:01:39 Run:1 Running from C:\Users\User\Desktop Loaded Profiles: User & UpdatusUser (Available profiles: User & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk S2 Winmgmt; C:\PROGRA~3\DF3A289.dot [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\32514631.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\32514631.sys => ""="Driver" HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-2404353190-3791358401-3653376951-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp1 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp1 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe CMD: sc config NvStreamSvc start= disabled CMD: dir /a C:\ProgramData EmptyTemp: ***************** Processes closed successfully. C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\program.lnk => Moved successfully. Winmgmt => Service restored successfully. cpuz136 => Service deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\32514631.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\32514631.sys" => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-2404353190-3791358401-3653376951-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. ========= sc config NvStreamSvc start= disabled ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 2619-4A9A Katalog: C:\ProgramData 2014-12-03 20:15 . 2014-12-03 20:15 .. 2014-07-11 09:48 Adobe 2014-11-20 13:48 57 Ament.ini 2009-07-14 06:08 Application Data [C:\ProgramData] 2014-07-11 08:59 Dane aplikacji [C:\ProgramData] 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2014-07-11 08:59 Dokumenty [C:\Users\Public\Documents] 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2014-07-11 18:43 Google 2014-11-20 13:48 HP 2014-07-11 09:15 Intel 2014-12-03 17:27 Malwarebytes 2014-07-11 08:59 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-08-25 22:58 Microsoft 2014-12-04 00:55 NVIDIA 2014-07-11 09:33 NVIDIA Corporation 2014-07-31 21:18 Oracle 2014-07-11 08:59 Pulpit [C:\Users\Public\Desktop] 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-07-11 09:46 Sun 2014-07-11 08:59 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2014-07-11 08:59 Ulubione [C:\Users\Public\Favorites] 2014-07-14 11:51 WA-PRO 1 plik(¢w) 57 bajt¢w 25 katalog(¢w) 130ÿ623ÿ447ÿ040 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 1 GB temporary data. The system needed a reboot. ==== End of Fixlog ====