Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01 Ran by daria1 at 2015-01-28 11:27:45 Run:1 Running from C:\Users\daria1\Downloads Loaded Profiles: daria1 (Available profiles: daria1) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: Task: {045FE7F2-8CF9-4DF9-B824-8D379766DC39} - System32\Tasks\{3079D775-01E7-4D1A-A066-6C73EB729E8B} => pcalua.exe -a "C:\Users\daria1\Downloads\CDM v2.12.00 WHQL Certified.exe" -d C:\Users\daria1\Downloads Task: {0B378213-A571-421F-8844-2AEA1AD894AC} - System32\Tasks\QDWVEM => C:\Users\daria1\AppData\Roaming\QDWVEM.exe <==== ATTENTION Task: {41892EF8-896E-4F0F-AE9A-EE483B600B04} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION Task: {4D7F08FF-BD02-465C-B851-D86CF52621A9} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\WSCStub.exe Task: {54B16C43-7700-4CBA-BA07-760B631997F0} - System32\Tasks\Inst_Rep => C:\Users\daria1\AppData\Local\Installer\Install_7967\DCytdieamo_amodc_setup.exe [2015-01-26] () Task: {9F006367-734C-4969-A181-D0E4E1344908} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\SymErr.exe Task: {AC3CCE51-E85F-46D8-A9B6-FE4F8E6C701C} - System32\Tasks\{01B2E54B-F654-4981-B799-7D6AB13C3EBE} => pcalua.exe -a "C:\Users\daria1\Downloads\CDM v2.12.00 WHQL Certified (1).exe" -d C:\Users\daria1\Downloads Task: {C5EEA6B8-ED3C-49A4-9F68-AB3AD56D2C9C} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION Task: {ED82E5F8-3ECE-40A2-9843-5ED1A76D1C48} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\SymErr.exe Task: {EFB1E031-2818-4CAA-81B6-14705F5018F3} - \SPBIW_UpdateTask_Time_323635393433333037302d7837235a576c4a3241345041 No Task File <==== ATTENTION Task: C:\WINDOWS\Tasks\QDWVEM.job => C:\Users\daria1\AppData\Roaming\QDWVEM.exe <==== ATTENTION S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X] ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File BHO: Cinemax -> {11111111-1111-1111-1111-110711011101} -> C:\Program Files (x86)\Cinemax\Cinemax-bho64.dll No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKU\S-1-5-21-2870285692-4238083046-3277192755-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-2870285692-4238083046-3277192755-1001\...\Policies\Explorer: [NofolderOptions] 0 C:\ProgramData\Temp C:\Users\daria1\AppData\Local\CrashDumps C:\Users\daria1\AppData\Roaming\QDWVEM C:\Users\daria1\AppData\Roaming\Opera Software\Opera Stable\Local Storage\*localstorage* C:\Users\daria1\Desktop\dk\pcmscan.exe — skrót.lnk C:\Users\Public\Documents\ShopperPro C:\Windows\System32\Tasks\Norton Internet Security Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\user\AppData\Local CMD: dir /a C:\Users\user\AppData\LocalLow CMD: dir /a C:\Users\user\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{045FE7F2-8CF9-4DF9-B824-8D379766DC39}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{045FE7F2-8CF9-4DF9-B824-8D379766DC39}" => Key deleted successfully. C:\Windows\System32\Tasks\{3079D775-01E7-4D1A-A066-6C73EB729E8B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3079D775-01E7-4D1A-A066-6C73EB729E8B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0B378213-A571-421F-8844-2AEA1AD894AC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0B378213-A571-421F-8844-2AEA1AD894AC}" => Key deleted successfully. C:\Windows\System32\Tasks\QDWVEM => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QDWVEM" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{41892EF8-896E-4F0F-AE9A-EE483B600B04}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41892EF8-896E-4F0F-AE9A-EE483B600B04}" => Key deleted successfully. C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\SMupdate2" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4D7F08FF-BD02-465C-B851-D86CF52621A9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D7F08FF-BD02-465C-B851-D86CF52621A9}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton WSC Integration => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{54B16C43-7700-4CBA-BA07-760B631997F0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{54B16C43-7700-4CBA-BA07-760B631997F0}" => Key deleted successfully. C:\Windows\System32\Tasks\Inst_Rep => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Inst_Rep" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F006367-734C-4969-A181-D0E4E1344908}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F006367-734C-4969-A181-D0E4E1344908}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Processor => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Processor" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC3CCE51-E85F-46D8-A9B6-FE4F8E6C701C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC3CCE51-E85F-46D8-A9B6-FE4F8E6C701C}" => Key deleted successfully. C:\Windows\System32\Tasks\{01B2E54B-F654-4981-B799-7D6AB13C3EBE} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{01B2E54B-F654-4981-B799-7D6AB13C3EBE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C5EEA6B8-ED3C-49A4-9F68-AB3AD56D2C9C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5EEA6B8-ED3C-49A4-9F68-AB3AD56D2C9C}" => Key deleted successfully. C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED82E5F8-3ECE-40A2-9843-5ED1A76D1C48}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED82E5F8-3ECE-40A2-9843-5ED1A76D1C48}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Analyzer => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Analyzer" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EFB1E031-2818-4CAA-81B6-14705F5018F3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFB1E031-2818-4CAA-81B6-14705F5018F3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_323635393433333037302d7837235a576c4a3241345041" => Key deleted successfully. C:\WINDOWS\Tasks\QDWVEM.job => Moved successfully. VBoxNetFlt => Service deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110711011101}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110711011101}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-2870285692-4238083046-3277192755-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => value deleted successfully. HKU\S-1-5-21-2870285692-4238083046-3277192755-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NofolderOptions => value deleted successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\daria1\AppData\Local\CrashDumps => Moved successfully. C:\Users\daria1\AppData\Roaming\QDWVEM => Moved successfully. C:\Users\daria1\AppData\Roaming\Opera Software\Opera Stable\Local Storage\*localstorage* => Moved successfully. C:\Users\daria1\Desktop\dk\pcmscan.exe — skrót.lnk => Moved successfully. C:\Users\Public\Documents\ShopperPro => Moved successfully. C:\Windows\System32\Tasks\Norton Internet Security => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is 04F6-3C5A Directory of C:\Program Files 2015-01-27 18:02