Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-03-2015 Ran by Bracia at 2015-03-04 18:23:39 Run:1 Running from C:\Documents and Settings\Bracia\Pulpit\Nowy folder Loaded Profiles: Bracia (Available profiles: Daniel & Bracia & Administrator & Gość) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: DisableService: sptd S3 cleanhlp; C:\Program Files\bin\cleanhlp32.sys [50200 2015-02-24] (Emsisoft GmbH) S3 dsio; \??\C:\Program Files\Common Files\TrustPort\bin\dsio.sys [X] S4 IntelIde; No ImagePath U3 TlntSvr; No ImagePath HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avasdmft => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avas_service => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\avss_service => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tpavdrw_service => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tpmgma_service => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tpsec => ""="Driver" CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1957994488-706699826-725345543-1008\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyServer: [S-1-5-21-1957994488-706699826-725345543-1008] => http=127.0.0.1:27134 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Documents and Settings\All Users\Dane aplikacji\{5738cbfd-bef2-c9bf-5738-8cbfdbef2ff6} C:\Documents and Settings\All Users\Dane aplikacji\{b8cece8a-326b-e93f-b8ce-ece8a3263a28} C:\Documents and Settings\All Users\Dane aplikacji\17592813043391487498 C:\Documents and Settings\All Users\Dane aplikacji\f4263a4093355e0a C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\Bracia\Dane aplikacji\DAEMON Tools Lite C:\Program Files\Avant Downloader C:\Program Files\HHappy2SavEE C:\Program Files\Isaveir C:\Program Files\RobboSavEr C:\Program Files\LibreOffice 4 C:\Program Files\OpenOffice 4 C:\WINDOWS\pss\BDARemote.lnkCommon Startup Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BDARemote.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools Lite" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Report" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. sptd service was disabled cleanhlp => Service deleted successfully. dsio => Service deleted successfully. IntelIde => Service deleted successfully. TlntSvr => Service deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\avasdmft" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\avas_service" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\avss_service" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\CleanHlp" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\tpavdrw_service" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\tpmgma_service" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\tpsec" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-1957994488-706699826-725345543-1008\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-1957994488-706699826-725345543-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully. C:\Documents and Settings\All Users\Dane aplikacji\{5738cbfd-bef2-c9bf-5738-8cbfdbef2ff6} => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\{b8cece8a-326b-e93f-b8ce-ece8a3263a28} => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\17592813043391487498 => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\f4263a4093355e0a => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. C:\Documents and Settings\Bracia\Dane aplikacji\DAEMON Tools Lite => Moved successfully. C:\Program Files\Avant Downloader => Moved successfully. C:\Program Files\HHappy2SavEE => Moved successfully. C:\Program Files\Isaveir => Moved successfully. C:\Program Files\RobboSavEr => Moved successfully. C:\Program Files\LibreOffice 4 => Moved successfully. C:\Program Files\OpenOffice 4 => Moved successfully. C:\WINDOWS\pss\BDARemote.lnkCommon Startup => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BDARemote.lnk" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools Lite" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Report" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= EmptyTemp: => Removed 870.2 MB temporary data. The system needed a reboot. ==== End of Fixlog 18:25:42 ====