Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-02-2015 Ran by XX at 2015-02-03 12:29:28 Run:2 Running from C:\ Loaded Profiles: XX (Available profiles: XX) Boot Mode: Safe Mode (with Networking) ============================================== Content of fixlist: ***************** CloseProcesses: Task: C:\Windows\Tasks\1014avUpdateInfo.job => C:\ProgramData\Avg_Update_1014av\1014av_AVG-Secure-Search-Update.exe Hosts: C:\ProgramData\Avg_Update_1014av C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\XX\AppData\LocalLow\CertifiedToolbar C:\Users\XX\AppData\Roaming\.minecraft C:\Users\XX\AppData\Roaming\Adetymwu C:\Users\XX\AppData\Roaming\avidemux C:\Users\XX\AppData\Roaming\Audacity C:\Users\XX\AppData\Roaming\Balmora.pl C:\Users\XX\AppData\Roaming\DVD Flick C:\Users\XX\AppData\Roaming\FileZilla C:\Users\XX\AppData\Roaming\com.w3i.FlipToast C:\Users\XX\AppData\Roaming\Gadu-Gadu 10 C:\Users\XX\AppData\Roaming\GoldenGate C:\Users\XX\AppData\Roaming\Igosonne C:\Users\XX\AppData\Roaming\Local Store C:\Users\XX\AppData\Roaming\Mozilla C:\Users\XX\AppData\Roaming\OpenFM C:\Users\XX\AppData\Roaming\Opera C:\Users\XX\AppData\Roaming\SteelSeries C:\Users\XX\AppData\Roaming\Ubkafo C:\Users\XX\AppData\Roaming\wargaming.net C:\Users\XX\AppData\Roaming\WordToPDF C:\Users\XX\AppData\Roaming\Ynehcaac C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\*.LNK C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.bmp C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.txt C:\Windows\system32\Drivers\1DF1592B.sys C:\Windows\system32\Drivers\2F6C59A4.sys C:\Windows\system32\Drivers\5EFA3319.sys C:\Windows\system32\Drivers\61C35F4E.sys C:\Windows\system32\Drivers\2F9C5F72.sys CMD: sc config WinDefend start= demand Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f Reg: reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg query "HKCU\Control Panel\Desktop" Reg: reg query "HKCU\Software\Microsoft\Internet Explorer\Desktop" /s Reg: reg query "HKLM\Software\Microsoft\Internet Explorer\Desktop" /s Reg: reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System Reg: reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files\Common Files" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\XX\AppData\Local CMD: dir /a C:\Users\XX\AppData\LocalLow CMD: dir /a C:\Users\XX\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. C:\Windows\Tasks\1014avUpdateInfo.job => Moved successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. C:\ProgramData\Avg_Update_1014av => Moved successfully. C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\XX\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\XX\AppData\LocalLow\CertifiedToolbar => Moved successfully. "C:\Users\XX\AppData\Roaming\.minecraft" => File/Directory not found. C:\Users\XX\AppData\Roaming\Adetymwu => Moved successfully. C:\Users\XX\AppData\Roaming\avidemux => Moved successfully. C:\Users\XX\AppData\Roaming\Audacity => Moved successfully. C:\Users\XX\AppData\Roaming\Balmora.pl => Moved successfully. C:\Users\XX\AppData\Roaming\DVD Flick => Moved successfully. C:\Users\XX\AppData\Roaming\FileZilla => Moved successfully. C:\Users\XX\AppData\Roaming\com.w3i.FlipToast => Moved successfully. C:\Users\XX\AppData\Roaming\Gadu-Gadu 10 => Moved successfully. C:\Users\XX\AppData\Roaming\GoldenGate => Moved successfully. C:\Users\XX\AppData\Roaming\Igosonne => Moved successfully. C:\Users\XX\AppData\Roaming\Local Store => Moved successfully. C:\Users\XX\AppData\Roaming\Mozilla => Moved successfully. C:\Users\XX\AppData\Roaming\OpenFM => Moved successfully. C:\Users\XX\AppData\Roaming\Opera => Moved successfully. C:\Users\XX\AppData\Roaming\SteelSeries => Moved successfully. C:\Users\XX\AppData\Roaming\Ubkafo => Moved successfully. C:\Users\XX\AppData\Roaming\wargaming.net => Moved successfully. C:\Users\XX\AppData\Roaming\WordToPDF => Moved successfully. C:\Users\XX\AppData\Roaming\Ynehcaac => Moved successfully. C:\Users\XX\AppData\Roaming\Microsoft\Office\Niedawny\*.LNK => Moved successfully. C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade => Moved successfully. C:\Users\XX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SteelSeries => Moved successfully. C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.bmp => Moved successfully. C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.txt => Moved successfully. C:\Windows\system32\Drivers\1DF1592B.sys => Moved successfully. C:\Windows\system32\Drivers\2F6C59A4.sys => Moved successfully. C:\Windows\system32\Drivers\5EFA3319.sys => Moved successfully. C:\Windows\system32\Drivers\61C35F4E.sys => Moved successfully. C:\Windows\system32\Drivers\2F9C5F72.sys => Moved successfully. ========= sc config WinDefend start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\AboutURLs" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchURI" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchUrl" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg query "HKCU\Control Panel\Desktop" ========= HKEY_CURRENT_USER\Control Panel\Desktop ScreenSaveActive REG_SZ 1 ActiveWndTrackTimeout REG_DWORD 0x0 BlockSendInputResets REG_SZ 0 CaretWidth REG_DWORD 0x1 ClickLockTime REG_DWORD 0x4b0 CoolSwitchColumns REG_SZ 7 CoolSwitchRows REG_SZ 3 CursorBlinkRate REG_SZ 600 DockMoving REG_SZ 1 DragFromMaximize REG_SZ 1 DragFullWindows REG_SZ 0 DragHeight REG_SZ 4 DragWidth REG_SZ 4 FocusBorderHeight REG_DWORD 0x1 FocusBorderWidth REG_DWORD 0x1 FontSmoothing REG_SZ 0 FontSmoothingGamma REG_DWORD 0x0 FontSmoothingOrientation REG_DWORD 0x1 FontSmoothingType REG_DWORD 0x2 ForegroundFlashCount REG_DWORD 0x7 ForegroundLockTimeout REG_DWORD 0x12eb7c LeftOverlapChars REG_SZ 3 MenuShowDelay REG_SZ 400 PaintDesktopVersion REG_DWORD 0x0 RightOverlapChars REG_SZ 3 SnapSizing REG_SZ 1 TileWallpaper REG_SZ 0 WallpaperOriginX REG_DWORD 0x0 WallpaperOriginY REG_DWORD 0x0 WallpaperStyle REG_SZ 0 WheelScrollChars REG_SZ 3 WheelScrollLines REG_SZ 3 WindowArrangementActive REG_SZ 1 UserPreferencesMask REG_BINARY 9012018010000000 Wallpaper REG_SZ C:\Users\XX\Documents\Decrypt-All-Files-kcirdgd.bmp Pattern Upgrade REG_SZ TRUE ScreenSaveTimeOut REG_SZ 300 ScreenSaverIsSecure REG_SZ 0 LogPixels REG_DWORD 0x60 HKEY_CURRENT_USER\Control Panel\Desktop\Colors HKEY_CURRENT_USER\Control Panel\Desktop\LanguageConfiguration HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics HKEY_CURRENT_USER\Control Panel\Desktop\MuiCached ========= End of Reg: ========= ========= reg query "HKCU\Software\Microsoft\Internet Explorer\Desktop" /s ========= HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\components HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General WallpaperSource REG_SZ ========= End of Reg: ========= ========= reg query "HKLM\Software\Microsoft\Internet Explorer\Desktop" /s ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System ========= ========= End of Reg: ========= ========= reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System ConsentPromptBehaviorAdmin REG_DWORD 0x0 ConsentPromptBehaviorUser REG_DWORD 0x3 EnableInstallerDetection REG_DWORD 0x1 EnableLUA REG_DWORD 0x0 EnableSecureUIAPaths REG_DWORD 0x1 EnableUIADesktopToggle REG_DWORD 0x0 EnableVirtualization REG_DWORD 0x1 PromptOnSecureDesktop REG_DWORD 0x0 ValidateAdminCodeSignatures REG_DWORD 0x0 dontdisplaylastusername REG_DWORD 0x0 legalnoticecaption REG_SZ legalnoticetext REG_SZ scforceoption REG_DWORD 0x0 shutdownwithoutlogon REG_DWORD 0x1 undockwithoutlogon REG_DWORD 0x1 FilterAdministratorToken REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\UIPI ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 13AA-F385 Katalog: C:\Program Files 2015-02-03 11:47