Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-12-2014 Ran by angelus at 2015-01-02 23:46:53 Run:1 Running from D:\Programy Loaded Profile: angelus (Available profiles: UpdatusUser & angelus) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM\...\Run: [] => [X] HKU\S-1-5-21-3852529065-1270474106-2815750484-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AdobeBridge] => [X] CHR HKU\S-1-5-21-3852529065-1270474106-2815750484-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKU\S-1-5-21-3852529065-1270474106-2815750484-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-3852529065-1270474106-2815750484-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nasze.fm/ Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File oolbar: HKU\S-1-5-21-3852529065-1270474106-2815750484-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-3852529065-1270474106-2815750484-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-3852529065-1270474106-2815750484-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} http://kitchenplanner.ikea.com/PL/Core/Player/2020PlayerAX_IKEA_Win32.cab CHR HomePage: Default -> hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=08E49C4E36AEF2B9&affID=128235&tsp=5143 CHR StartupUrls: Default -> "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=08E49C4E36AEF2B9&affID=128235&tsp=5143", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=HGSTXHTS725050A7E630_TF755AWHG638UMG638UMX&ts=1376249585" CHR DefaultSearchKeyword: Default -> qvo6 CHR DefaultSearchURL: Default -> http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=HGSTXHTS725050A7E630_TF755AWHG638UMG638UMX&ts=1376249585&type=default&q={searchTerms} S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X] U2 ccEvtMgr; No ImagePath U2 ccSetMgr; No ImagePath U3 navapsvc; No ImagePath U3 SAVRT; No ImagePath U1 SAVRTPEL; No ImagePath S2 smihlp2; \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [X] U3 TlntSvr; No ImagePath U3 kxtdapob; \??\C:\Users\T530\AppData\Local\Temp\kxtdapob.sys [X] Task: {60CB00F4-E41C-4296-9C24-C5A92C707604} - \YourFile DownloaderUpdate No Task File <==== ATTENTION EmptyTemp: ***************** Processes closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-3852529065-1270474106-2815750484-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value not found. "HKU\S-1-5-21-3852529065-1270474106-2815750484-1001\SOFTWARE\Policies\Google" => Key deleted successfully. HKU\S-1-5-21-3852529065-1270474106-2815750484-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Google => Key not found. HKU\S-1-5-21-3852529065-1270474106-2815750484-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found. oolbar: HKU\S-1-5-21-3852529065-1270474106-2815750484-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File => Error: No automatic fix found for this entry. HKU\S-1-5-21-3852529065-1270474106-2815750484-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKU\S-1-5-21-3852529065-1270474106-2815750484-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\Toolbar: HKU\S-1-5-21-3852529065-1270474106-2815750484-1001-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value not found. HKCR\CLSID\Toolbar: HKU\S-1-5-21-3852529065-1270474106-2815750484-1001-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{1ABA5FAC-1417-422B-BA82-45C35E2C908B}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{1ABA5FAC-1417-422B-BA82-45C35E2C908B}" => Key deleted successfully. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSearchKeyword deleted successfully. Chrome DefaultSearchURL deleted successfully. AvastVBoxSvc => Service deleted successfully. ccEvtMgr => Service deleted successfully. ccSetMgr => Service deleted successfully. navapsvc => Service deleted successfully. SAVRT => Service deleted successfully. SAVRTPEL => Service deleted successfully. smihlp2 => Service deleted successfully. TlntSvr => Service deleted successfully. kxtdapob => Service not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{60CB00F4-E41C-4296-9C24-C5A92C707604}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60CB00F4-E41C-4296-9C24-C5A92C707604}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile DownloaderUpdate" => Key deleted successfully. EmptyTemp: => Removed 6.1 GB temporary data. The system needed a reboot. ==== End of Fixlog 23:47:17 ====