Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-05-2014 Ran by Artur at 2014-05-11 10:40:04 Run:1 Running from C:\Users\Artur\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 07 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 07 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Task: {B5079FE3-B165-4DA7-875C-E43DB7FA77AE} - System32\Tasks\{A602A328-17FA-4737-A03B-9D77A45B9CA5} => D:\GRY\Worms Armageddon\Worms Armageddon\Wa.exe HKLM-x32\...\Runonce: [AvgUninstallURL] - cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMgBHADMASwAtADgANwBXAFUAVQAtADIAVABWAEgAQQAtAFgANgBEAEYAOAAtAEwANgBQAEEATgA"&"inst=NwA3AC0AMwA4ADgANQA5ADgAMQAyADEALQBGAEwAKwA5AC0AWABPADMANgArADEALQBYAE8AOQArADEALQBGADkATQA0ACsAMQAtAEQARABUACsAMQAxADAAMgA0AC0AUwBUADkAMABGAEEAUABQACsAMQAtAEQARAA5ADAARgArADEALQBGADkAMABNADEAMgBFAE4AKwAxAC0AVABCAE4AKwAxAC0AVQA5ADUAKwAxAC0ARgA5ADAAVQBVAEUAKwAzAC0ARgBVAEkAKwAyAC0ATAA5ADAATQBKACsAMQAtAEYAOQAwAE0AMQAyAEoAVAArADEALQBTAFQARgA5ADAAVQBVAEUAMQArADEALQBTAFQARgA5ADAAVQBVAEUAMgArADEA"&"prod=90"&"ver=9.0.894 [X] R0 pavboot; C:\Windows\System32\drivers\pavboot64.sys [33800 2009-06-30] (Panda Security, S.L.) C:\Windows\System32\drivers\pavboot64.sys S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () C:\Windows\SysWow64\Drivers\StarOpen.sys U3 tmlwf; U3 tmwfp; ***************** HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully. HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key not found. Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll Winsock: Catalog5 entry 000000000007\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll Winsock: Catalog5-x64 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll Winsock: Catalog5-x64 entry 000000000007\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5079FE3-B165-4DA7-875C-E43DB7FA77AE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5079FE3-B165-4DA7-875C-E43DB7FA77AE} => Key deleted successfully. C:\Windows\System32\Tasks\{A602A328-17FA-4737-A03B-9D77A45B9CA5} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A602A328-17FA-4737-A03B-9D77A45B9CA5} => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\AvgUninstallURL => Value deleted successfully. pavboot => Unable to stop service pavboot => Service deleted successfully. C:\Windows\System32\drivers\pavboot64.sys => Moved successfully. StarOpen => Service deleted successfully. C:\Windows\SysWow64\Drivers\StarOpen.sys => Moved successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. The system needed a reboot. ==== End of Fixlog ====