Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-12-2014 01 Ran by user at 2014-12-07 22:46:51 Run:2 Running from E:\Pobieranie Loaded Profile: user (Available profiles: user & Gość) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM Group Policy restriction on software: C:\Program Files\Common Files\Symantec Shared <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\ESET <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Agnitum <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\AVG <====== ATTENTION S2 vToolbarUpdater18.1.10; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.10\ToolbarUpdater.exe [X] HKU\S-1-5-21-436374069-602162358-725345543-1003\...\Run: [GameXN GO] => "C:\Documents and Settings\All Users\Dane aplikacji\GameXN\GameXNGO.exe" /startup HKU\S-1-5-21-436374069-602162358-725345543-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKU\S-1-5-21-436374069-602162358-725345543-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm SearchScopes: HKU\S-1-5-21-436374069-602162358-725345543-1003 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={F0D664B6-39B9-479A-B597-4B7B62F8E53E}&mid=83b4ea7a936047d2a7e2d158054456a9-414d4818d856a5889f90ff84e1a594766956dc38&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-11-09 14:47:00&v=4.0.0.19&pid=wtu&sg=&sap=dsp&q={searchTerms} Toolbar: HKU\S-1-5-21-436374069-602162358-725345543-1003 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File C:\Documents and Settings\All Users\Dane aplikacji\Agnitum C:\Documents and Settings\All Users\Dane aplikacji\AVG2014 C:\Documents and Settings\All Users\Dane aplikacji\IiddeNafom C:\Documents and Settings\All Users\Dane aplikacji\n7-89-o9-3r-4t-r9 C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software C:\Documents and Settings\Default User\Dane aplikacji\TuneUp Software C:\Documents and Settings\user\Dane aplikacji\Alawar C:\Documents and Settings\user\Dane aplikacji\TuneUp Software C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension Hosts: Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdVantage" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogitechVideoRepair" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogitechVideoTray" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. vToolbarUpdater18.1.10 => Service not found. HKU\S-1-5-21-436374069-602162358-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\GameXN GO => Value not found. HKU\S-1-5-21-436374069-602162358-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value not found. HKU\S-1-5-21-436374069-602162358-725345543-1003\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Bar => Value not found. "HKU\S-1-5-21-436374069-602162358-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. HKU\S-1-5-21-436374069-602162358-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value not found. "HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => Key not found. "C:\Documents and Settings\All Users\Dane aplikacji\Agnitum" => File/Directory not found. "C:\Documents and Settings\All Users\Dane aplikacji\AVG2014" => File/Directory not found. "C:\Documents and Settings\All Users\Dane aplikacji\IiddeNafom" => File/Directory not found. "C:\Documents and Settings\All Users\Dane aplikacji\n7-89-o9-3r-4t-r9" => File/Directory not found. "C:\Documents and Settings\All Users\Dane aplikacji\TEMP" => File/Directory not found. "C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software" => File/Directory not found. "C:\Documents and Settings\Default User\Dane aplikacji\TuneUp Software" => File/Directory not found. "C:\Documents and Settings\user\Dane aplikacji\Alawar" => File/Directory not found. "C:\Documents and Settings\user\Dane aplikacji\TuneUp Software" => File/Directory not found. "C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" => File/Directory not found. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdVantage" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogitechVideoRepair" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogitechVideoTray" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= EmptyTemp: => Removed 1.6 GB temporary data. The system needed a reboot. ==== End of Fixlog ====