Fix result of Farbar Recovery Scan Tool (x86) Version: 28-06-2015 01 Ran by Jacek at 2015-07-01 15:22:31 Run:1 Running from C:\Users\Jacek\Desktop\Nowy folder Loaded Profiles: Jacek (Available Profiles: Jacek) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-2142848797-1288730675-1259261558-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKU\S-1-5-21-2142848797-1288730675-1259261558-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie SearchScopes: HKU\S-1-5-21-2142848797-1288730675-1259261558-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF S2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [X] S3 FUTUREX; \??\C:\Program Files\AIDA32 - Enterprise System Information\aida32.sys [X] Task: {4CF4A269-48D2-49AA-AE9B-31AE7228606E} - System32\Tasks\{D74D2581-69BC-44B1-8808-19FA0AC407E7} => Firefox.exe Task: {7EC4643E-9779-44FE-823C-26138681FE00} - System32\Tasks\{4584820B-B919-4F75-9B07-63EFA2BFE678} => Firefox.exe Task: {C0A7C676-90F3-4A3D-8257-C81C2E5B1636} - System32\Tasks\{D638BBFD-6D5E-4AA2-9C29-A6A49CE6EAAC} => Firefox.exe Task: {FF9DF52B-E8A0-4C77-BDDB-09BE90819CAA} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh advfirewall reset EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. C:\Windows\system32\GroupPolicy\Machine => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Policies\Google" => key removed successfully. HKU\S-1-5-21-2142848797-1288730675-1259261558-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully. HKU\S-1-5-21-2142848797-1288730675-1259261558-1001\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully "HKU\S-1-5-21-2142848797-1288730675-1259261558-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => key removed successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => value removed successfully. "HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}" => key removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully. HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\Software\Mozilla\Firefox\Extensions\\wrc@avast.com => value not found. avast! Antivirus => Service not found. FUTUREX => Service removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4CF4A269-48D2-49AA-AE9B-31AE7228606E}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CF4A269-48D2-49AA-AE9B-31AE7228606E}" => key removed successfully. C:\Windows\System32\Tasks\{D74D2581-69BC-44B1-8808-19FA0AC407E7} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D74D2581-69BC-44B1-8808-19FA0AC407E7}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7EC4643E-9779-44FE-823C-26138681FE00}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7EC4643E-9779-44FE-823C-26138681FE00}" => key removed successfully. C:\Windows\System32\Tasks\{4584820B-B919-4F75-9B07-63EFA2BFE678} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4584820B-B919-4F75-9B07-63EFA2BFE678}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C0A7C676-90F3-4A3D-8257-C81C2E5B1636}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0A7C676-90F3-4A3D-8257-C81C2E5B1636}" => key removed successfully. C:\Windows\System32\Tasks\{D638BBFD-6D5E-4AA2-9C29-A6A49CE6EAAC} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D638BBFD-6D5E-4AA2-9C29-A6A49CE6EAAC}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FF9DF52B-E8A0-4C77-BDDB-09BE90819CAA}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF9DF52B-E8A0-4C77-BDDB-09BE90819CAA}" => key removed successfully. C:\Windows\System32\Tasks\avast! Emergency Update => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avast! Emergency Update" => key removed successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= EmptyTemp: => 1.2 GB temporary data Removed. The system needed a reboot. ==== End of Fixlog 15:23:18 ====