Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 02-03-2015 Ran by Administrator at 2015-03-03 16:56:59 Run:2 Running from C:\Documents and Settings\Administrator\Pulpit Loaded Profiles: Administrator (Available profiles: UpdatusUser & Administrator) Boot Mode: Safe Mode (minimal) ============================================== Content of fixlist: ***************** CloseProcesses: Winsock: Missing Catalog5 entry, broken internet access. <===== ATTENTION. Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [94208] (Apple Computer, Inc.) S3 AntiZeroAccess; C:\WINDOWS\system32\drivers\ZeroAccess.sys [17800 2013-09-09] (PrevX Research) HKLM\...\RunOnce: [Del C:\Documents and Settings\Administrator\Moje dokumenty\Sports Interactive\Football Manager 2014\uploads\Sunderland 3 - 2 Peterborough - Skroty meczu.ogv OnNextReboot] => C:\Documents and Settings\Administrator\Moje dokumenty\Sports Interactive\Football Manager 2014\uploads\Sunderland 3 - 2 Peterborough - Skroty meczu.ogv [20792054 2014-11-24] () HKLM\...\RunOnce: [Del C:\Documents and Settings\Administrator\Moje dokumenty\Sports Interactive\Football Manager 2014\uploads\Burnley 1 - 3 Sunderland - Skroty meczu.ogv OnNextReboot] => C:\Documents and Settings\Administrator\Moje dokumenty\Sports Interactive\Football Manager 2014\uploads\Burnley 1 - 3 Sunderland - Skroty meczu.ogv [16842694 2015-02-09] () HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "http://www.google.com" <======= ATTENTION DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab C:\Documents and Settings\Administrator\Dane aplikacji\QuickScan C:\Documents and Settings\Administrator\Menu Start\Programy\WapSter C:\Documents and Settings\Administrator\Pulpit\Muzyka\Pasjonaci - Pasjonaci 2 (2012) [Maciek1981].lnk C:\Documents and Settings\Administrator\Pulpit\Programy - inne\AccurateBurn MP3 Audio CD Maker.lnk C:\Documents and Settings\Administrator\Pulpit\Programy - inne\dBpoweramp Music Converter.lnk C:\Documents and Settings\Administrator\Pulpit\Programy - inne\FastStone Image Viewer.lnk C:\Documents and Settings\Administrator\Pulpit\Programy - inne\LogMeIn Hamachi.lnk C:\Documents and Settings\Administrator\Pulpit\Programy - inne\Opera.lnk C:\Documents and Settings\Administrator\Pulpit\Programy - inne\Your Uninstaller!.lnk C:\Documents and Settings\Administrator\Pulpit\Zdjęcia\Zdjęcie0290.jpg.lnk C:\Documents and Settings\All Users\Dane aplikacji\1425386007.bdinstall.bin C:\Documents and Settings\All Users\Dane aplikacji\bdch C:\Documents and Settings\All Users\Dane aplikacji\BDLogging C:\Documents and Settings\All Users\Dane aplikacji\MFAData C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Windows\GameExplorer\{899CF70A-A52B-4CB5-B4F1-EFCD5A325B1F} C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Windows\GameExplorer\{8C7E6248-C1D1-492D-83A0-DCB42039B276} C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Windows\GameExplorer\{B9B63F5C-AC06-4342-86F3-F684535F6703} C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Windows\GameExplorer\{C32DE581-07FB-420E-B09D-C6A8009F3B46} C:\Documents and Settings\All Users\Menu Start\Programy\Empire Interactive C:\Documents and Settings\Default User\Menu Start\eBay.lnk C:\Documents and Settings\LocalService\Dane aplikacji\QuickScan C:\Documents and Settings\UpdatusUser\Dane aplikacji\QuickScan C:\Documents and Settings\UpdatusUser\Ustawienia lokalne\Dane aplikacji\bdch C:\Program Files\GUT5E.tmp C:\Program Files\Bitdefender C:\Program Files\Common Files\Bitdefender C:\Program Files\Google\Desktop C:\Program Files\Mozilla Firefox\extensions C:\Program Files\Mozilla Firefox\plugins C:\WINDOWS\system32\bdsandboxuiskin.dll C:\WINDOWS\system32\bdsandboxuh.dll C:\WINDOWS\system32\drivers\ZeroAccess.sys C:\WINDOWS\system32\drivers\Msft_Kernel_avchv_01009.Wdf Hosts: Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AQQ" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG_UI" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ChomikBox" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Expressivo" /f Reg: reg delete HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /f Reg: reg delete HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /f Reg: reg delete HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent /f Reg: reg delete HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Winsock: Missing Catalog5 entry, broken internet access. <===== ATTENTION. => Winsock will be renumbered. "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004" => Key deleted successfully. AntiZeroAccess => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del C:\Documents and Settings\Administrator\Moje dokumenty\Sports Interactive\Football Manager 2014\uploads\Sunderland 3 - 2 Peterborough - Skroty meczu.ogv OnNextReboot => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del C:\Documents and Settings\Administrator\Moje dokumenty\Sports Interactive\Football Manager 2014\uploads\Burnley 1 - 3 Sunderland - Skroty meczu.ogv OnNextReboot => value deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => Key deleted successfully.