Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01 Ran by Andrzej Jankowski at 2014-03-17 19:44:15 Run:1 Running from C:\Documents and Settings\Andrzej Jankowski\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\WINDOWS\system32\dmwu.exe () C:\WINDOWS\system32\jmdp\stij.exe R2 IBUpdaterService; C:\WINDOWS\system32\dmwu.exe [1633072 2014-03-11] () S2 ADILOADER; System32\Drivers\adildr.sys [X] S3 adiusbaw; system32\DRIVERS\adiusbaw.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] U1 eabfiltr; S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X] HKLM\...\Run: [SunJavaUpdateSched] - "C:\Program Files\Java\jre6\bin\jusched.exe" SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={20349920-CFB8-4131-8282-4C6F85F87FC6}&&st=23 Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\WINDOWS\TEMP\{B3A38CF6-39AB-48B6-9018-B396CC764251}.exe Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\WINDOWS\TEMP\{61F7CB0B-D468-4EAE-858D-2ED0935D2993}.exe C:\Documents and Settings\All Users\*.exe C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\Andrzej Jankowski\Dane aplikacji\hellomoto C:\Documents and Settings\Andrzej Jankowski\Dane aplikacji\PCToolsFirewallPlus C:\Documents and Settings\Mirka Jankowska\Dane aplikacji\PCToolsFirewallPlus C:\WINDOWS\system32\dmwu.exe CMD: netsh firewall reset Reboot: ***************** [552] C:\WINDOWS\system32\dmwu.exe => Process closed successfully. [1532] C:\WINDOWS\system32\jmdp\stij.exe => Process closed successfully. IBUpdaterService => Service deleted successfully. ADILOADER => Service deleted successfully. adiusbaw => Service deleted successfully. catchme => Service deleted successfully. eabfiltr => Service deleted successfully. UIUSys => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => Value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully. C:\WINDOWS\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Documents and Settings\All Users\*.exe => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. C:\Documents and Settings\Andrzej Jankowski\Dane aplikacji\hellomoto => Moved successfully. C:\Documents and Settings\Andrzej Jankowski\Dane aplikacji\PCToolsFirewallPlus => Moved successfully. C:\Documents and Settings\Mirka Jankowska\Dane aplikacji\PCToolsFirewallPlus => Moved successfully. C:\WINDOWS\system32\dmwu.exe => Moved successfully. ========= netsh firewall reset ========= Ok. ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ====