Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 15-04-2015 04 Ran by A at 2015-04-16 23:00:13 Run:3 Running from C:\Users\A\Desktop Loaded Profiles: A (Available profiles: A & Gość) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Program Files\SiteLookup C:\ProgramData\Innovative Solutions C:\ProgramData\speedypc software C:\ProgramData\Trymedia C:\ProgramData\Uniblue C:\Users\A\Appdata\Local\Innovative Solutions C:\Users\A\Appdata\LocalLow\HPAppData C:\Users\A\Appdata\Roaming\cacaoweb C:\Users\A\Appdata\Roaming\download Manager C:\Users\A\Appdata\Roaming\DriverCure C:\Users\A\Appdata\Roaming\Innovative Solutions C:\Users\A\Appdata\Roaming\speedypc software C:\Users\A\Appdata\Roaming\Systweak Reg: reg add HKCR\Unknown\shell\openas\command /ve /t REG_EXPAND_SZ /d "%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1" /f Reg: reg add HKCR\Unknown\shell\opendlg\command /ve /t REG_EXPAND_SZ /d "%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1" /f Reg: reg delete HKCR\Unknown\shell\openas\command /v sfa_backup /f Reg: reg delete HKCR\Unknown\shell\opendlg\command /v sfa_backup /f Reg: reg delete HKCU\Software\cacaoweb /f Reg: reg delete HKCU\Software\InstallCore /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Smart File Advisor_is1" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyOverride /f Reg: reg delete HKCU\Software\Mozilla\Extends /f Reg: reg delete "HKCU\Software\Myfree Codec" /f Reg: reg delete "HKCU\Software\speedypc software" /f Reg: reg delete HKCU\Software\systweak /f Reg: reg delete HKCU\Software\YahooPartnerToolbar /f Reg: reg delete "HKLM\SOFTWARE\AVG Secure Search" /f Reg: reg delete HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} /f Reg: reg delete HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} /f Reg: reg delete HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj /f Reg: reg delete HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1 /f Reg: reg delete HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} /f Reg: reg delete HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D} /f Reg: reg delete HKLM\SOFTWARE\do-searchSoftware /f Reg: reg delete "HKLM\SOFTWARE\dt soft\daemon tools toolbar" /f Reg: reg delete HKLM\SOFTWARE\IHProtect /f Reg: reg delete HKLM\SOFTWARE\OpenCandy /f Reg: reg delete "HKLM\SOFTWARE\speedypc software" /f Reg: reg delete HKLM\SOFTWARE\SupDp /f Reg: reg delete HKLM\SOFTWARE\SupTab /f Reg: reg delete HKLM\SOFTWARE\systweak /f Reg: reg delete "HKLM\SOFTWARE\Tarma Installer" /f Reg: reg delete HKLM\SOFTWARE\Uniblue /f Reg: reg delete HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect /f ***************** C:\Program Files\SiteLookup => Moved successfully. C:\ProgramData\Innovative Solutions => Moved successfully. C:\ProgramData\speedypc software => Moved successfully. C:\ProgramData\Trymedia => Moved successfully. C:\ProgramData\Uniblue => Moved successfully. C:\Users\A\Appdata\Local\Innovative Solutions => Moved successfully. C:\Users\A\Appdata\LocalLow\HPAppData => Moved successfully. C:\Users\A\Appdata\Roaming\cacaoweb => Moved successfully. C:\Users\A\Appdata\Roaming\download Manager => Moved successfully. C:\Users\A\Appdata\Roaming\DriverCure => Moved successfully. C:\Users\A\Appdata\Roaming\Innovative Solutions => Moved successfully. C:\Users\A\Appdata\Roaming\speedypc software => Moved successfully. C:\Users\A\Appdata\Roaming\Systweak => Moved successfully. ========= reg add HKCR\Unknown\shell\openas\command /ve /t REG_EXPAND_SZ /d "%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add HKCR\Unknown\shell\opendlg\command /ve /t REG_EXPAND_SZ /d "%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCR\Unknown\shell\openas\command /v sfa_backup /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCR\Unknown\shell\opendlg\command /v sfa_backup /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\cacaoweb /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\InstallCore /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Smart File Advisor_is1" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyOverride /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla\Extends /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Myfree Codec" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\speedypc software" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\systweak /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\YahooPartnerToolbar /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\AVG Secure Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\do-searchSoftware /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\dt soft\daemon tools toolbar" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\IHProtect /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\OpenCandy /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\speedypc software" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\SupDp /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\SupTab /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\systweak /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Tarma Installer" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Uniblue /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog 23:00:21 ====