Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014 Ran by cwirek at 2014-01-08 09:51:00 Run:3 Running from D:\ Boot Mode: Normal ============================================== Content of fixlist: ***************** Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccuac.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ComboFix.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hijackthis.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\keyscrambler.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spybotsd.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wireshark.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zlclient.exe" /f BHO: No Name - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - No File BHO-x32: No Name - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - No File C:\kleaner.tmp C:\ProgramData\Kaspersky Lab ***************** ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccuac.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ComboFix.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hijackthis.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\keyscrambler.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spybotsd.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wireshark.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zlclient.exe" /f ========= Bť¤D: Odmowa dost©pu. ========= End of Reg: ========= HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} => Key deleted successfully. HKCR\CLSID\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} => Key not found. C:\kleaner.tmp => Moved successfully. C:\ProgramData\Kaspersky Lab => Moved successfully. ==== End of Fixlog ====