Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-09-2013 04 Ran by Braszki at 2013-09-02 17:58:18 Run:1 Running from C:\Users\Braszki\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** 2013-08-14 02:00 - 2013-08-14 02:00 - 00000165 _____ C:\ProgramData\awbbvhfndhrskjyruar.reg 2013-08-14 02:00 - 2013-08-14 02:00 - 00000070 _____ C:\ProgramData\awbbvhfndhrskjyruar.bat 2013-08-11 12:51 - 2013-08-11 12:52 - 16247640 _____ C:\Users\Braszki\Downloads\.zip[1] HKLM-x32\...\Winlogon: [Shell] C:\PROGRA~3\awbbvhfndhrskjyruar.bat [x ] () <=== ATTENTION HKCU\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent [x] Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File S4 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [x] Task: {5C10DCA7-A78B-40FB-80DC-FB98B0DA2A50} - System32\Tasks\{5A1E4E8D-66FF-457B-8778-8E721066CF46} => C:\Program Files (x86)\Play\Symulator Smiglowcow Ratunkowych\SSR.exe No File Task: {B5CE7BDF-D108-45E1-845E-F87859CD39A6} - System32\Tasks\{EDF5E0E1-FBC0-4A5F-9F5D-A469F031D312} => C:\Program Files (x86)\Play\Symulator Smiglowcow Ratunkowych\SSR.exe No File Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** C:\ProgramData\awbbvhfndhrskjyruar.reg => Moved successfully. C:\ProgramData\awbbvhfndhrskjyruar.bat => Moved successfully. C:\Users\Braszki\Downloads\.zip[1] => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value was restored successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\EA Core => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. AdobeFlashPlayerUpdateSvc => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C10DCA7-A78B-40FB-80DC-FB98B0DA2A50} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C10DCA7-A78B-40FB-80DC-FB98B0DA2A50} => Key deleted successfully. C:\Windows\System32\Tasks\{5A1E4E8D-66FF-457B-8778-8E721066CF46} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5A1E4E8D-66FF-457B-8778-8E721066CF46} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5CE7BDF-D108-45E1-845E-F87859CD39A6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5CE7BDF-D108-45E1-845E-F87859CD39A6} => Key deleted successfully. C:\Windows\System32\Tasks\{EDF5E0E1-FBC0-4A5F-9F5D-A469F031D312} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EDF5E0E1-FBC0-4A5F-9F5D-A469F031D312} => Key deleted successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====