Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by ocznik1986 at 2015-03-21 13:39:23 Run:3 Running from C:\Users\ocznik1986\Desktop\FRST Loaded Profiles: UpdatusUser & ocznik1986 (Available profiles: UpdatusUser & ocznik1986) Boot Mode: Normal ============================================== Content of fixlist: ***************** CreateRestorePoint: R1 {1601c372-fdd4-4d07-81cb-8d80cd533a89}Gw64; C:\Windows\System32\drivers\{1601c372-fdd4-4d07-81cb-8d80cd533a89}Gw64.sys [48792 2015-03-18] (StdLib) R1 {7edae523-2f47-48a4-be5c-2db16c2cad61}Gw64; C:\Windows\System32\drivers\{7edae523-2f47-48a4-be5c-2db16c2cad61}Gw64.sys [48792 2015-03-15] (StdLib) R1 {af159d03-4801-4284-bdcb-4497403da962}Gw64; C:\Windows\System32\drivers\{af159d03-4801-4284-bdcb-4497403da962}Gw64.sys [48792 2015-03-13] (StdLib) S1 qrnfd_1_10_0_9; system32\drivers\qrnfd_1_10_0_9.sys [X] Task: {6D0C6D48-A3AF-4800-A3E9-50CBA37E6DBE} - System32\Tasks\MaxigetMasterUpdate => C:\Users\ocznik1986\AppData\Roaming\Maxiget\Master\Updater\MasterUpdater.exe HKLM-x32\...\Run: [gmsd_pl_55] => [X] HKU\S-1-5-21-2702095170-3591425996-2869741432-1002\...\Run: [MaxigetMasterUpdate] => "C:\Users\ocznik1986\AppData\Roaming\Maxiget\Master\Updater\MasterUpdater.exe" -autorun HKU\S-1-5-21-2702095170-3591425996-2869741432-1002\...\Run: [EpicScale] => [X] Startup: C:\Users\ocznik1986\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\superpc_soft_partner.lnk ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://do-search.com/?type=hp&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://do-search.com/?type=hp&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://do-search.com/?type=hp&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://do-search.com/?type=hp&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1426509524&from=cor&uid=ST1000LM014-SSHD-8GB_W381RH3BXXXXW381RH3B&q={searchTerms} HKU\S-1-5-21-2702095170-3591425996-2869741432-1002\Software\Microsoft\Internet Explorer\Main,Start Page = C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\Primary Result C:\ProgramData\{6eee2b1e-e01b-3c56-6eee-e2b1ee01ac7b} C:\ProgramData\{7e510603-95ef-ca8d-7e51-1060395e180e} C:\ProgramData\{caac1a9c-8aa9-1d9a-caac-c1a9c8aa6a72} C:\ProgramData\{f07ed24d-8c9d-c41b-f07e-ed24d8c94936} C:\ProgramData\{fd421ffc-f5c7-3260-fd42-21ffcf5c7ff3} C:\ProgramData\AVAST Software C:\Users\ocznik1986\AppData\Local\Google C:\Users\ocznik1986\AppData\Local\GGEmpire C:\Users\ocznik1986\AppData\Local\WorldofTanks C:\Users\ocznik1986\AppData\Roaming\do-search C:\Users\ocznik1986\AppData\Roaming\Maxiget C:\Users\ocznik1986\AppData\Roaming\WorldofTanks C:\Users\ocznik1986\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk C:\Users\ocznik1986\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! antivirus.lnk C:\Users\ocznik1986\Downloads\*(*)-dp*.exe C:\Windows\System32\drivers\{1601c372-fdd4-4d07-81cb-8d80cd533a89}Gw64.sys C:\Windows\System32\drivers\{7edae523-2f47-48a4-be5c-2db16c2cad61}Gw64.sys C:\Windows\System32\drivers\{af159d03-4801-4284-bdcb-4497403da962}Gw64.sys C:\Windows\system32\drivers\Msft_Kernel_webTinstMK_01009.Wdf Reg: reg delete HKCU\Software\Google /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg delete "HKU\S-1-5-21-2702095170-3591425996-2869741432-1001\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-21-2702095170-3591425996-2869741432-1001\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Restore point was successfully created. {1601c372-fdd4-4d07-81cb-8d80cd533a89}Gw64 => Service not found. {7edae523-2f47-48a4-be5c-2db16c2cad61}Gw64 => Service not found. {af159d03-4801-4284-bdcb-4497403da962}Gw64 => Service not found. qrnfd_1_10_0_9 => Service not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D0C6D48-A3AF-4800-A3E9-50CBA37E6DBE} => Key not found. C:\Windows\System32\Tasks\MaxigetMasterUpdate not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MaxigetMasterUpdate => Key not found. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_pl_55 => Value not found. HKU\S-1-5-21-2702095170-3591425996-2869741432-1002\Software\Microsoft\Windows\CurrentVersion\Run\\MaxigetMasterUpdate => value deleted successfully. HKU\S-1-5-21-2702095170-3591425996-2869741432-1002\Software\Microsoft\Windows\CurrentVersion\Run\\EpicScale => Value not found. C:\Users\ocznik1986\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\superpc_soft_partner.lnk not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => Key not found. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found. "C:\WINDOWS\system32\GroupPolicy\Machine" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-2702095170-3591425996-2869741432-1002\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "C:\Program Files (x86)\Mozilla Firefox" => File/Directory not found. "C:\Program Files (x86)\Primary Result" => File/Directory not found. "C:\ProgramData\{6eee2b1e-e01b-3c56-6eee-e2b1ee01ac7b}" => File/Directory not found. "C:\ProgramData\{7e510603-95ef-ca8d-7e51-1060395e180e}" => File/Directory not found. "C:\ProgramData\{caac1a9c-8aa9-1d9a-caac-c1a9c8aa6a72}" => File/Directory not found. "C:\ProgramData\{f07ed24d-8c9d-c41b-f07e-ed24d8c94936}" => File/Directory not found. "C:\ProgramData\{fd421ffc-f5c7-3260-fd42-21ffcf5c7ff3}" => File/Directory not found. "C:\ProgramData\AVAST Software" => File/Directory not found. "C:\Users\ocznik1986\AppData\Local\Google" => File/Directory not found. "C:\Users\ocznik1986\AppData\Local\GGEmpire" => File/Directory not found. "C:\Users\ocznik1986\AppData\Local\WorldofTanks" => File/Directory not found. "C:\Users\ocznik1986\AppData\Roaming\do-search" => File/Directory not found. "C:\Users\ocznik1986\AppData\Roaming\Maxiget" => File/Directory not found. "C:\Users\ocznik1986\AppData\Roaming\WorldofTanks" => File/Directory not found. "C:\Users\ocznik1986\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WorldofTanks.lnk" => File/Directory not found. "C:\Users\ocznik1986\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! antivirus.lnk" => File/Directory not found. "C:\Users\ocznik1986\Downloads\*(*)-dp*.exe" => File/Directory not found. "C:\Windows\System32\drivers\{1601c372-fdd4-4d07-81cb-8d80cd533a89}Gw64.sys" => File/Directory not found. "C:\Windows\System32\drivers\{7edae523-2f47-48a4-be5c-2db16c2cad61}Gw64.sys" => File/Directory not found. "C:\Windows\System32\drivers\{af159d03-4801-4284-bdcb-4497403da962}Gw64.sys" => File/Directory not found. "C:\Windows\system32\drivers\Msft_Kernel_webTinstMK_01009.Wdf" => File/Directory not found. ========= reg delete HKCU\Software\Google /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2702095170-3591425996-2869741432-1001\Software\Microsoft\Internet Explorer\Main" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-21-2702095170-3591425996-2869741432-1001\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= EmptyTemp: => Removed 16.2 MB temporary data. The system needed a reboot. ==== End of Fixlog 13:40:07 ====