Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by Zarządca at 2014-03-20 16:08:41 Run:3 Running from D:\Programy\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {53806F50-16D8-4316-BD81-5A9610724EE1} - System32\Tasks\At1 => C:\Users\Zarządca\Desktop\mccleanup.exe Task: {85517C08-E333-43DE-8198-5EB4D63A6253} - System32\Tasks\At2 => C:\Users\Zarządca\Desktop\mccleanup.exe Task: C:\windows\Tasks\At1.job => C:\Users\Zarzdca\Desktop\mccleanup.exe Task: C:\windows\Tasks\At2.job => C:\Users\Zarzdca\Desktop\mccleanup.exe S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] AlternateDataStreams: C:\ProgramData\Temp:373E1720 C:\Program Files\Enigma Software Group C:\Program Files (x86)\Free Window Registry Repair C:\Program Files (x86)\Google C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml C:\ProgramData\McAfee C:\Users\Zarządca\AppData\Local\Mozilla C:\Users\Zarządca\AppData\Roaming\Mozilla C:\windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP C:\windows\SysWOW64\sho*.tmp C:\windows\SysWOW64\GroupPolicy\GPT.INI Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{53806F50-16D8-4316-BD81-5A9610724EE1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53806F50-16D8-4316-BD81-5A9610724EE1} => Key deleted successfully. C:\Windows\System32\Tasks\At1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\At1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{85517C08-E333-43DE-8198-5EB4D63A6253} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85517C08-E333-43DE-8198-5EB4D63A6253} => Key deleted successfully. C:\Windows\System32\Tasks\At2 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\At2 => Key deleted successfully. C:\windows\Tasks\At1.job => Moved successfully. C:\windows\Tasks\At2.job => Moved successfully. esgiguard => Service deleted successfully. C:\ProgramData\Temp => ":373E1720" ADS removed successfully. C:\Program Files\Enigma Software Group => Moved successfully. C:\Program Files (x86)\Free Window Registry Repair => Moved successfully. C:\Program Files (x86)\Google => Moved successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml => Moved successfully. C:\ProgramData\McAfee => Moved successfully. C:\Users\Zarządca\AppData\Local\Mozilla => Moved successfully. C:\Users\Zarządca\AppData\Roaming\Mozilla => Moved successfully. C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP => Moved successfully. C:\windows\SysWOW64\sho*.tmp => Moved successfully. C:\windows\SysWOW64\GroupPolicy\GPT.INI => Moved successfully. ========= reg delete HKCU\Software\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====