Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-11-2013 01 Ran by Ja at 2013-11-22 20:10:34 Run:2 Running from C:\Users\Ja\Documents\Antywirusy Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [Mntktw] - C:\Users\Ja\AppData\Roaming\Microsoft\Mntktw.exe HKCU\...\Run: [t4q] - C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe HKCU\...\Run: [ca40229dd] - C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-15555590\cafef9.exe HKCU\...\Run: [Screen Saver Pro 3.1] - C:\Users\Ja\AppData\Roaming\ScreenSaverPro.scr HKCU\...\Run: [Dntktn] - C:\Users\Ja\AppData\Roaming\Microsoft\Dntktn.exe HKCU\...\Run: [Intkts] - C:\Users\Ja\AppData\Roaming\Microsoft\Intkts.exe HKCU\...\Run: [fjpdqz] - C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-11609\fjpdqz.exe HKCU\...\Run: [Tntktd] - C:\Users\Ja\AppData\Roaming\Microsoft\Tntktd.exe HKCU\...\Winlogon: [Shell] C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-11609\fjpdqz.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-15555590\cafef9.exe,C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-46689\24naq.exe,explorer.exe <==== ATTENTION Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [223232] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x] ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Mntktw => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\t4q => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ca40229dd => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Screen Saver Pro 3.1 => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Dntktn => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Intkts => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\fjpdqz => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Tntktd => Value deleted successfully. HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully. Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll EagleXNt => Service deleted successfully. ==== End of Fixlog ====