Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 24-02-2014 01 Ran by Stopa at 2014-02-26 13:39:24 Run:1 Running from C:\Users\Stopa\Desktop\Nowy folder (2) Boot Mode: Safe Mode (with Networking) ============================================== Content of fixlist: ***************** HKU\S-1-5-21-2505639046-3014970737-231596729-1000\...\Run: [Java] - cmd /c cd %APPDATA%\AutoIt3 & AutoIt3.exe soundmng.txt C:\Users\Stopa\AppData\Roaming\AutoIt3 C:\Users\Stopa\AppData\Roaming\launcher.exe C:\Users\Stopa\Qtrax C:\Program Files\Smart PC Cleaner C:\END SearchScopes: HKCU - DefaultScope {0388404D-6072-4CEB-B521-8F090FEAEE57} URL = http://klit.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120210&user_guid=1EF21B380FAC4E03B27A7F934BC6B717&machine_id=55a7822bc13fc6cfa98475c1f9f52aa6&browser=IE&os=win&os_version=6.1-x86-SP0&iesrc={referrer:source} SearchScopes: HKCU - {0388404D-6072-4CEB-B521-8F090FEAEE57} URL = http://klit.startnow.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120210&user_guid=1EF21B380FAC4E03B27A7F934BC6B717&machine_id=55a7822bc13fc6cfa98475c1f9f52aa6&browser=IE&os=win&os_version=6.1-x86-SP0&iesrc={referrer:source} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FF HKLM\...\Firefox\Extensions: [hotfix@mozilla.org] - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix FF HKCU\...\Firefox\Extensions: [hotfix@mozilla.org] - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix FF Extension: Mozilla hotfix - C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix [2013-02-06] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 Ser2pl; system32\DRIVERS\ser2pl.sys [X] S3 Ser2plx86; system32\DRIVERS\ser2pl.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] U3 mbr; \??\C:\Users\Stopa\AppData\Local\Temp\mbr.sys [X] Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2" /f Reg: reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" Reg: reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" ***************** HKU\S-1-5-21-2505639046-3014970737-231596729-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Java => Value deleted successfully. C:\Users\Stopa\AppData\Roaming\AutoIt3 => Moved successfully. C:\Users\Stopa\AppData\Roaming\launcher.exe => Moved successfully. C:\Users\Stopa\Qtrax => Moved successfully. C:\Program Files\Smart PC Cleaner => Moved successfully. C:\END => Moved successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0388404D-6072-4CEB-B521-8F090FEAEE57} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0388404D-6072-4CEB-B521-8F090FEAEE57} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\Software\Mozilla\Firefox\Extensions\\hotfix@mozilla.org => Value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\hotfix@mozilla.org => Value deleted successfully. C:\Users\Stopa\AppData\Roaming\Mozilla\Firefox\Extensions\MozillaHotfix => Moved successfully. hwdatacard => Service deleted successfully. massfilter => Service deleted successfully. Ser2pl => Service deleted successfully. Ser2plx86 => Service deleted successfully. VMnetAdapter => Service deleted successfully. ZTEusbmdm6k => Service deleted successfully. ZTEusbnet => Service deleted successfully. ZTEusbnmea => Service deleted successfully. ZTEusbser6k => Service deleted successfully. mbr => Service not found. ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" ========= HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders !Do not use this registry key REG_SZ Use the SHGetFolderPath or SHGetKnownFolderPath function instead CD Burning REG_SZ C:\Users\Stopa\AppData\Local\Microsoft\Windows\Burn\Burn ========= End of Reg: ========= ========= reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" ========= HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders AppData REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming Cache REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Windows\Temporary Internet Files Cookies REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Cookies Desktop REG_EXPAND_SZ %USERPROFILE%\Desktop Favorites REG_EXPAND_SZ %USERPROFILE%\Favorites History REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Windows\History Local AppData REG_EXPAND_SZ %USERPROFILE%\AppData\Local My Music REG_EXPAND_SZ %USERPROFILE%\Music My Pictures REG_EXPAND_SZ %USERPROFILE%\Pictures My Video REG_EXPAND_SZ %USERPROFILE%\Videos NetHood REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Network Shortcuts Personal REG_EXPAND_SZ %USERPROFILE%\Documents Programs REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs Recent REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent SendTo REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\SendTo Startup REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup Start Menu REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu Templates REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Templates {374DE290-123F-4565-9164-39C4925E467B} REG_EXPAND_SZ %USERPROFILE%\Downloads PrintHood REG_EXPAND_SZ %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Printer Shortcuts CD Burning REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Windows\Burn\Burn ========= End of Reg: ========= ==== End of Fixlog ====