Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2014 Ran by Jacek at 2014-12-04 22:11:17 Run:1 Running from C:\Users\Jacek\Downloads Loaded Profile: Jacek (Available profiles: Jacek) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-1716999734-2480157188-1133812662-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140927 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140927 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140927 HKLM\...\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] => C:\ProgramData\cisCB32.exe [5181144 2014-04-16] (COMODO) S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2014-08-24] () [File not signed] S3 cpuz137; \??\C:\Windows\TEMP\cpuz137\cpuz137_x64.sys [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] C:\Program Files (x86)\AdTrustMedia C:\ProgramData\cisCB32.exe C:\Users\Jacek\Downloads\*(*)-dp*.exe C:\Windows\system32\17A.tmp C:\Windows\system32\B655.tmp C:\Windows\SysWOW64\srvany.exe Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ***************** HKU\S-1-5-21-1716999734-2480157188-1133812662-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82} => value deleted successfully. KMService => Service deleted successfully. cpuz137 => Service deleted successfully. GPUZ => Service deleted successfully. "C:\Program Files (x86)\AdTrustMedia" => File/Directory not found. "C:\ProgramData\cisCB32.exe" => File/Directory not found. C:\Users\Jacek\Downloads\*(*)-dp*.exe => Moved successfully. C:\Windows\system32\17A.tmp => Moved successfully. C:\Windows\system32\B655.tmp => Moved successfully. C:\Windows\SysWOW64\srvany.exe => Moved successfully. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====