Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-12-2014 Ran by Radek at 2014-12-09 23:20:35 Run:1 Running from C:\FRST Loaded Profiles: UpdatusUser & Radek (Available profiles: UpdatusUser & Radek) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120141015 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120141015 HKU\S-1-5-21-365570279-1974800031-830595484-1001\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120141015 SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-365570279-1974800031-830595484-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-365570279-1974800031-830595484-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] C:\Program Files (x86)\mozilla firefox\plugins C:\ProgramData\Temp C:\Users\Radek\AppData\Roaming\ASUS WebStorage CMD: for /d %f in (C:\Users\Radek\AppData\Local\{*}) do rd /s /q "%f" Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {B24BA351-20F9-492E-99FE-56E3EF5B7EDC} /f EmptyTemp: ***************** Processes closed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-365570279-1974800031-830595484-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. HKU\S-1-5-21-365570279-1974800031-830595484-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-365570279-1974800031-830595484-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. sptd => Service deleted successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\Radek\AppData\Roaming\ASUS WebStorage => Moved successfully. ========= for /d %f in (C:\Users\Radek\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {B24BA351-20F9-492E-99FE-56E3EF5B7EDC} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 1.2 GB temporary data. The system needed a reboot. ==== End of Fixlog ====