Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-01-2014 04 Ran by Emil at 2014-01-20 23:58:21 Run:13 Running from C:\Users\Emil\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** CMD: netsh winsock reset Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-12] (NVIDIA Corporation) Task: {25E617A2-F041-49E9-885A-84A1A9CB50FA} - System32\Tasks\ParetoLogic Update Version3 Startup Task => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe Task: {3E9CDD4E-FC43-485F-91B8-0F878CD40DC7} - System32\Tasks\ParetoLogic Update Version3 => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe Task: {7F432775-15E5-431F-99BB-64D287BE70E6} - System32\Tasks\RegCure Pro => C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe Task: {87628A6B-4392-4471-96F7-60C89BC2D698} - System32\Tasks\RegCure Pro Startup => C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe Task: {FE38EB8C-8D13-4A6F-A28F-6018BCE7478D} - System32\Tasks\ParetoLogic Registration3 => Rundll32.exe "C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\UUS3.dll" RunUns C:\ProgramData\ParetoLogic StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 SmbDrv; system32\DRIVERS\Smb_driver.sys [x] ***************** ========= netsh winsock reset ========= Pomy˜lnie zresetowano Winsock Catalog. Musisz ponownie uruchomi† komputer, aby ukoäczy† resetowanie. ========= End of CMD: ========= Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll Winsock: Catalog5-x64 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll "C:\\Windows\\System32\\nvinitx.dll" => Value Data removed successfully. "C:\\Windows\\SysWOW64\\nvinit.dll" => Value Data removed successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{25E617A2-F041-49E9-885A-84A1A9CB50FA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25E617A2-F041-49E9-885A-84A1A9CB50FA} => Key deleted successfully. C:\Windows\System32\Tasks\ParetoLogic Update Version3 Startup Task => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ParetoLogic Update Version3 Startup Task => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E9CDD4E-FC43-485F-91B8-0F878CD40DC7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E9CDD4E-FC43-485F-91B8-0F878CD40DC7} => Key deleted successfully. C:\Windows\System32\Tasks\ParetoLogic Update Version3 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ParetoLogic Update Version3 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7F432775-15E5-431F-99BB-64D287BE70E6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7F432775-15E5-431F-99BB-64D287BE70E6} => Key deleted successfully. C:\Windows\System32\Tasks\RegCure Pro => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegCure Pro => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87628A6B-4392-4471-96F7-60C89BC2D698} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87628A6B-4392-4471-96F7-60C89BC2D698} => Key deleted successfully. C:\Windows\System32\Tasks\RegCure Pro Startup => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegCure Pro Startup => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FE38EB8C-8D13-4A6F-A28F-6018BCE7478D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE38EB8C-8D13-4A6F-A28F-6018BCE7478D} => Key deleted successfully. C:\Windows\System32\Tasks\ParetoLogic Registration3 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ParetoLogic Registration3 => Key deleted successfully. C:\ProgramData\ParetoLogic => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. catchme => Service deleted successfully. SmbDrv => Service deleted successfully. ==== End of Fixlog ====