Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-02-2015 01 Ran by Agata at 2015-02-11 23:39:59 Run:1 Running from C:\Users\Agata\Desktop\GMER Loaded Profiles: Agata (Available profiles: Agata) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: Task: {3423ECCE-86CA-4DBC-8774-8F1D68E5731B} - System32\Tasks\Norton AntiVirus\Norton Error Processor => C:\Program Files (x86)\Norton AntiVirus\Engine\21.6.0.32\SymErr.exe Task: {4AB33E58-B899-4BE5-B4A0-212A7FBFF280} - System32\Tasks\tiffeug => C:\Users\Agata\AppData\Local\Temp\dqeepnc.exe <==== ATTENTION Task: {57D30F7A-0741-4A87-898A-ED947C312CB2} - System32\Tasks\Norton AntiVirus\Norton Error Analyzer => C:\Program Files (x86)\Norton AntiVirus\Engine\21.6.0.32\SymErr.exe Task: {7CCFD004-3403-4860-AE88-4BE585894CA6} - System32\Tasks\{7D07DB52-3A60-4D5A-9745-E2C0347C47CA} => Chrome.exe http://ui.skype.com/ui/0/6.6.0.106/pl/abandoninstall?page=tsBing Task: {DBA0212D-A0D4-46DE-94AE-661FA5042C3C} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton AntiVirus\Engine\21.6.0.32\WSCStub.exe U1 eabfiltr; No ImagePath S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S3 SymIMMP; system32\DRIVERS\SymIM.sys [X] HKLM-x32\...\Run: [hpqSRMon] => [X] HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe" HKLM-x32\...\Run: [] => [X] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION SearchScopes: HKLM -> DefaultScope value is missing. SearchScopes: HKLM-x32 -> DefaultScope value is missing. BHO-x32: No Name -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> No File BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-3558287341-2231117270-3972338399-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File C:\Program Files (x86)\Ask.com C:\Program Files (x86)\Java C:\ProgramData\dqacswg.html C:\ProgramData\LuUninstall.LiveUpdate C:\ProgramData\AOL C:\ProgramData\Malwarebytes C:\ProgramData\NCOTEMP C:\ProgramData\Norton C:\Users\Agata\AppData\Local\AOL OCP C:\Users\Agata\AppData\Local\APN C:\Users\Agata\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Agata\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\Agata\Desktop\FB\Agnieszka\DSCN6864 - Shortcut.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\blueconnect\User Manual.lnk C:\Users\Agata\Downloads\SpyHunter*.exe C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\Windows\System32\Tasks\Norton AntiVirus Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete HKCU\Software\Mozilla\Firefox /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3423ECCE-86CA-4DBC-8774-8F1D68E5731B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3423ECCE-86CA-4DBC-8774-8F1D68E5731B}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton AntiVirus\Norton Error Processor => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton AntiVirus\Norton Error Processor" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4AB33E58-B899-4BE5-B4A0-212A7FBFF280}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AB33E58-B899-4BE5-B4A0-212A7FBFF280}" => Key deleted successfully. C:\Windows\System32\Tasks\tiffeug => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\tiffeug" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{57D30F7A-0741-4A87-898A-ED947C312CB2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57D30F7A-0741-4A87-898A-ED947C312CB2}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton AntiVirus\Norton Error Analyzer => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton AntiVirus\Norton Error Analyzer" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7CCFD004-3403-4860-AE88-4BE585894CA6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7CCFD004-3403-4860-AE88-4BE585894CA6}" => Key deleted successfully. C:\Windows\System32\Tasks\{7D07DB52-3A60-4D5A-9745-E2C0347C47CA} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7D07DB52-3A60-4D5A-9745-E2C0347C47CA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DBA0212D-A0D4-46DE-94AE-661FA5042C3C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DBA0212D-A0D4-46DE-94AE-661FA5042C3C}" => Key deleted successfully. C:\Windows\System32\Tasks\Norton WSC Integration => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration" => Key deleted successfully. eabfiltr => Service deleted successfully. MBAMSwissArmy => Service deleted successfully. SymIMMP => Service not found. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\hpqSRMon => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\WinampAgent => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} => Key not found. HKCR\Wow6432Node\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value not found. HKCR\Wow6432Node\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. HKU\S-1-5-21-3558287341-2231117270-3972338399-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. C:\Program Files (x86)\Ask.com => Moved successfully. C:\Program Files (x86)\Java => Moved successfully. C:\ProgramData\dqacswg.html => Moved successfully. "C:\ProgramData\LuUninstall.LiveUpdate" => File/Directory not found. C:\ProgramData\AOL => Moved successfully. C:\ProgramData\Malwarebytes => Moved successfully. C:\ProgramData\NCOTEMP => Moved successfully. C:\ProgramData\Norton => Moved successfully. C:\Users\Agata\AppData\Local\AOL OCP => Moved successfully. C:\Users\Agata\AppData\Local\APN => Moved successfully. C:\Users\Agata\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Agata\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\Agata\Desktop\FB\Agnieszka\DSCN6864 - Shortcut.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\blueconnect\User Manual.lnk => Moved successfully. C:\Users\Agata\Downloads\SpyHunter*.exe => Moved successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\Windows\System32\Tasks\Norton AntiVirus => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla\Firefox /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= The operation completed successfully. ========= End of Reg: ========= EmptyTemp: => Removed 4.6 GB temporary data. The system needed a reboot. ==== End of Fixlog 23:46:40 ====