Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-02-2014 Ran by Marek at 2014-02-17 21:09:09 Run:2 Running from C:\Users\Marek\Desktop\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** (Microsoft Corporation) C:\Windows\System32\wscript.exe (Microsoft Corporation) C:\Windows\System32\wscript.exe HKLM\...\Run: [tmp4DF1] - C:\Users\Marek\AppData\Local\Temp\tmp4DF1.tmp.vbs [156060 2014-02-06] () HKU\S-1-5-21-263107825-2801771057-2943010423-1001\...\Run: [tmpD0A8] - C:\Users\Marek\AppData\Roaming\tmpD0A8.tmp.update.vbs [281787 2014-01-16] () HKU\S-1-5-21-263107825-2801771057-2943010423-1001\...\Run: [oloixtuelf] - C:\Users\Marek\AppData\Local\Temp\oloixtuelf.Firfox.vbs [653150 2014-02-06] () HKU\S-1-5-21-263107825-2801771057-2943010423-1001\...\Run: [tmp4DF1] - C:\Users\Marek\AppData\Local\Temp\tmp4DF1.tmp.vbs [156060 2014-02-06] () HKU\S-1-5-21-263107825-2801771057-2943010423-1001\...\Run: [DVDclone] - C:\Users\Marek\AppData\Local\Temp\DVDclone.vbs [653150 2014-02-06] () Startup: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DVDclone.vbs () Startup: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google () Startup: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Link.vbs () Startup: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\oloixtuelf.Firfox.vbs () Startup: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tmp4DF1.tmp.vbs () Startup: C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tmpD0A8.tmp.update.vbs () StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Marek\AppData\Local\Google C:\Users\Marek\AppData\Roaming\tmpD0A8.tmp.update.vbs C:\Users\Marek\Downloads\Total-Commander(12316).exe Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f CMD: netsh advfirewall reset ***************** C:\Windows\System32\wscript.exe => No running process found C:\Windows\System32\wscript.exe => No running process found HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\tmp4DF1 => Unable to delete value HKU\S-1-5-21-263107825-2801771057-2943010423-1001\Software\Microsoft\Windows\CurrentVersion\Run\\tmpD0A8 => Unable to delete value HKU\S-1-5-21-263107825-2801771057-2943010423-1001\Software\Microsoft\Windows\CurrentVersion\Run\\oloixtuelf => Unable to delete value HKU\S-1-5-21-263107825-2801771057-2943010423-1001\Software\Microsoft\Windows\CurrentVersion\Run\\tmp4DF1 => Unable to delete value HKU\S-1-5-21-263107825-2801771057-2943010423-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DVDclone => Unable to delete value C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DVDclone.vbs not found. "C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google" => Could not move. C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Link.vbs not found. C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\oloixtuelf.Firfox.vbs not found. C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tmp4DF1.tmp.vbs not found. C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tmpD0A8.tmp.update.vbs not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "C:\Users\Marek\AppData\Local\Google" => File/Directory not found. "C:\Users\Marek\AppData\Roaming\tmpD0A8.tmp.update.vbs" => File/Directory not found. "C:\Users\Marek\Downloads\Total-Commander(12316).exe" => File/Directory not found. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====