Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-12-2014 Ran by user at 2014-12-11 14:29:52 Run:1 Running from C:\Users\user\Desktop\Wszystkie te syfy Loaded Profile: user (Available profiles: user) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: Task: {013C7181-4C7F-449B-8A05-0441D0F30D12} - System32\Tasks\UNELEVATE_26150 => C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.1374\jsdrv.exe <==== ATTENTION Task: {6AFCC415-01DD-45FC-9825-DE1294A72C50} - \SPDriver No Task File <==== ATTENTION Task: {6F23FB4F-82FE-4976-897D-8C6FCAEF3DDE} - \ShopperProJSUpd No Task File <==== ATTENTION Task: {80CD45A7-A25A-448E-85A3-DFE4C6FAAE6D} - \SPBIW_UpdateTask_Time_323238383139353933342d3755556c415a505757414a34 No Task File <==== ATTENTION Task: {EC9D6961-34B9-4BDA-BF35-52065FFA392B} - \ShopperPro No Task File <==== ATTENTION S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 EverestDriver; \??\C:\Users\user\AppData\Local\Temp\EverestDriver.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION StartMenuInternet: IEXPLORE.EXE - iexplore.exe HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\Spybot - Search & Destroy 2 C:\ProgramData\Spybot - Search & Destroy C:\ProgramData\TEMP C:\Users\user\AppData\Roaming\Systweak C:\Users\user\AppData\Roaming\VOPackage C:\Windows\System32\Tasks\Safer-Networking Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{013C7181-4C7F-449B-8A05-0441D0F30D12}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{013C7181-4C7F-449B-8A05-0441D0F30D12}" => Key deleted successfully. C:\Windows\System32\Tasks\UNELEVATE_26150 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UNELEVATE_26150" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6AFCC415-01DD-45FC-9825-DE1294A72C50}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6AFCC415-01DD-45FC-9825-DE1294A72C50}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F23FB4F-82FE-4976-897D-8C6FCAEF3DDE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F23FB4F-82FE-4976-897D-8C6FCAEF3DDE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{80CD45A7-A25A-448E-85A3-DFE4C6FAAE6D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80CD45A7-A25A-448E-85A3-DFE4C6FAAE6D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_323238383139353933342d3755556c415a505757414a34" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EC9D6961-34B9-4BDA-BF35-52065FFA392B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC9D6961-34B9-4BDA-BF35-52065FFA392B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro" => Key deleted successfully. cpuz136 => Service deleted successfully. EagleX64 => Service deleted successfully. EverestDriver => Service deleted successfully. gdrv => Service deleted successfully. GPUZ => Service deleted successfully. sptd => Service deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin" => Key deleted successfully. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully. C:\ProgramData\Spybot - Search & Destroy => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\Users\user\AppData\Roaming\Systweak => Moved successfully. C:\Users\user\AppData\Roaming\VOPackage => Moved successfully. C:\Windows\System32\Tasks\Safer-Networking => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 831.7 MB temporary data. The system needed a reboot. ==== End of Fixlog ====