Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-02-2015 Ran by Adrian at 2015-02-14 15:02:50 Run:1 Running from C:\Users\Adrian\Downloads Loaded Profiles: Adrian (Available profiles: Adrian) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM-x32\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot HKLM-x32\...\Run: [gmsd_pl_11] => [X] HKU\S-1-5-21-3483416149-639397455-693731436-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Adrian\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-3483416149-639397455-693731436-1000\...\Run: [AdobeBridge] => [X] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150209 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150209 HKU\S-1-5-21-3483416149-639397455-693731436-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp120150209 SearchScopes: HKU\S-1-5-21-3483416149-639397455-693731436-1000 -> {szukaj.gazeta.pl} URL = http://szukaj.gazeta.pl/internet/0,0.html?slowo={searchTerms} C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgohmfhlbipbcmmpdonacmkpibfghppn R1 {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64; C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys [48784 2015-02-08] (StdLib) R1 {8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64; C:\Windows\System32\drivers\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64.sys [48792 2015-01-04] (StdLib) R1 {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64; C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys [48792 2015-01-08] (StdLib) S3 gdrv; \??\C:\Windows\gdrv.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] Task: {F35CDFF4-8123-491E-A817-E7697B8DEA4E} - System32\Tasks\LSGKZOLJ => C:\Users\Adrian\AppData\Roaming\LSGKZOLJ.exe <==== ATTENTION Task: {B8A7BC3F-D264-40E5-A11B-3438C8218F23} - System32\Tasks\{6C8F44F4-7038-4B1C-B7E2-D2407974B639} => pcalua.exe -a "C:\Program Files (x86)\ShopperPro\SPremove.exe" <==== ATTENTION Task: {5FF5D0E7-2DD9-4F47-BE57-7438D4CBB0D0} - System32\Tasks\{1D808979-1191-485E-9EF6-CB5C51EBD8C2} => pcalua.exe -a C:\Users\Adrian\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=brd <==== ATTENTION Task: {1D573DFF-FF70-411F-9543-E95158410EE6} - System32\Tasks\{AFB3E263-E29D-45CD-82F7-5639C369BE75} => pcalua.exe -a "C:\Program Files (x86)\TheFreeHD-Sport TV V10\Uninstall.exe" -c /fcp=1 EmptyTemp: ***************** Processes closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_11 => value deleted successfully. HKU\S-1-5-21-3483416149-639397455-693731436-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => value deleted successfully. HKU\S-1-5-21-3483416149-639397455-693731436-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-3483416149-639397455-693731436-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "HKU\S-1-5-21-3483416149-639397455-693731436-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{szukaj.gazeta.pl}" => Key deleted successfully. HKCR\CLSID\{szukaj.gazeta.pl} => Key not found. C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgohmfhlbipbcmmpdonacmkpibfghppn => Moved successfully. {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64 => Service stopped successfully. {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64 => Service deleted successfully. {8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64 => Service stopped successfully. {8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64 => Service deleted successfully. {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64 => Service stopped successfully. {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64 => Service deleted successfully. gdrv => Service deleted successfully. Synth3dVsc => Service deleted successfully. tsusbhub => Service deleted successfully. VGPU => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F35CDFF4-8123-491E-A817-E7697B8DEA4E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F35CDFF4-8123-491E-A817-E7697B8DEA4E}" => Key deleted successfully. C:\Windows\System32\Tasks\LSGKZOLJ => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LSGKZOLJ" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B8A7BC3F-D264-40E5-A11B-3438C8218F23}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B8A7BC3F-D264-40E5-A11B-3438C8218F23}" => Key deleted successfully. C:\Windows\System32\Tasks\{6C8F44F4-7038-4B1C-B7E2-D2407974B639} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6C8F44F4-7038-4B1C-B7E2-D2407974B639}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5FF5D0E7-2DD9-4F47-BE57-7438D4CBB0D0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FF5D0E7-2DD9-4F47-BE57-7438D4CBB0D0}" => Key deleted successfully. C:\Windows\System32\Tasks\{1D808979-1191-485E-9EF6-CB5C51EBD8C2} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1D808979-1191-485E-9EF6-CB5C51EBD8C2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D573DFF-FF70-411F-9543-E95158410EE6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D573DFF-FF70-411F-9543-E95158410EE6}" => Key deleted successfully. C:\Windows\System32\Tasks\{AFB3E263-E29D-45CD-82F7-5639C369BE75} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AFB3E263-E29D-45CD-82F7-5639C369BE75}" => Key deleted successfully. EmptyTemp: => Removed 501.9 MB temporary data. The system needed a reboot. ==== End of Fixlog 15:03:11 ====