Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015 Ran by user at 2015-02-02 19:42:20 Run:1 Running from C:\Users\user\Desktop\logi Loaded Profiles: user & UpdatusUser (Available profiles: user & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: S2 SPDRIVER_1483.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1483.0.0.0\jsdrv.sys [X] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com SearchScopes: HKU\S-1-5-21-1103311512-3379090863-2572892851-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Handler: WSWSVCUchrome - No CLSID Value StartMenuInternet: IEXPLORE.EXE - iexplore.exe HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe Task: {7AB4DC7B-2CA4-40D8-9D7B-46782E559CD4} - System32\Tasks\{1CC424F9-3079-4C4E-9F8E-BE92BA7B846D} => Firefox.exe http://ui.skype.com/ui/0/7.0.59.102/pl/abandoninstall?page=tsBing Task: {F103CC3C-C36C-4B35-B6DA-AA5034C6920D} - \SPBIW_UpdateTask_Time_323439313237313137362d4a375b5a5a6c783245343741 No Task File <==== ATTENTION CMD: C:\Windows\SysWOW64\regsvr32.exe /u /s C:\Windows\SysWOW64\AniGIF.ocx CMD: C:\Windows\SysWOW64\regsvr32.exe /u /s C:\Windows\SysWOW64\WSCM64.dll C:\Program Files (x86)\DAP C:\ProgramData\McAfee C:\ProgramData\Norton C:\ProgramData\SpeedBit C:\ProgramData\TEMP C:\ProgramData\Wondershare Video Converter Ultimate C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\user\AppData\Local\CrashDumps C:\Users\user\AppData\Local\NPE C:\Users\user\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} C:\Users\user\AppData\Roaming\Wondershare Video Converter Ultimate C:\Users\user\Documents\Wondershare MediaServer C:\Users\user\Documents\Wondershare Video Converter Ultimate C:\Users\Public\Documents\GOOBZO C:\Users\Public\Documents\ShopperPro C:\Users\Public\Documents\Wondershare C:\Users\Public\Documents\YTAHelper C:\Users\UpdatusUser\Desktop\My DAP Downloads.lnk C:\Windows\SysWOW64\AniGIF.ocx C:\Windows\SysWOW64\WSCM64.dll Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. SPDRIVER_1483.0.0.0 => Service deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-1103311512-3379090863-2572892851-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found. "HKCR\PROTOCOLS\Handler\WSWSVCUchrome" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Wondershare Helper Compact.exe => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\DelaypluginInstall => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7AB4DC7B-2CA4-40D8-9D7B-46782E559CD4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AB4DC7B-2CA4-40D8-9D7B-46782E559CD4}" => Key deleted successfully. C:\Windows\System32\Tasks\{1CC424F9-3079-4C4E-9F8E-BE92BA7B846D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1CC424F9-3079-4C4E-9F8E-BE92BA7B846D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F103CC3C-C36C-4B35-B6DA-AA5034C6920D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F103CC3C-C36C-4B35-B6DA-AA5034C6920D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_323439313237313137362d4a375b5a5a6c783245343741" => Key deleted successfully. ========= C:\Windows\SysWOW64\regsvr32.exe /u /s C:\Windows\SysWOW64\AniGIF.ocx ========= ========= End of CMD: ========= ========= C:\Windows\SysWOW64\regsvr32.exe /u /s C:\Windows\SysWOW64\WSCM64.dll ========= ========= End of CMD: ========= C:\Program Files (x86)\DAP => Moved successfully. C:\ProgramData\McAfee => Moved successfully. C:\ProgramData\Norton => Moved successfully. C:\ProgramData\SpeedBit => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\Wondershare Video Converter Ultimate => Moved successfully. C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\user\AppData\Local\CrashDumps => Moved successfully. C:\Users\user\AppData\Local\NPE => Moved successfully. C:\Users\user\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} => Moved successfully. C:\Users\user\AppData\Roaming\Wondershare Video Converter Ultimate => Moved successfully. C:\Users\user\Documents\Wondershare MediaServer => Moved successfully. C:\Users\user\Documents\Wondershare Video Converter Ultimate => Moved successfully. C:\Users\Public\Documents\GOOBZO => Moved successfully. C:\Users\Public\Documents\ShopperPro => Moved successfully. C:\Users\Public\Documents\Wondershare => Moved successfully. C:\Users\Public\Documents\YTAHelper => Moved successfully. C:\Users\UpdatusUser\Desktop\My DAP Downloads.lnk => Moved successfully. C:\Windows\SysWOW64\AniGIF.ocx => Moved successfully. C:\Windows\SysWOW64\WSCM64.dll => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 10.4 GB temporary data. The system needed a reboot. ==== End of Fixlog 19:43:52 ====