Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-05-2014 Ran by Kolbe at 2014-05-23 11:32:01 Run:1 Running from C:\Users\Kolbe\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {C507CCFA-2A70-4A09-AC54-3095DB815AFD} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms} Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll No File S1 aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz134; \??\C:\Users\Kolbe\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] Task: {99E77C41-19DC-41A1-B561-D06FC7F50B4B} - System32\Tasks\{59278CFA-8759-4369-9C11-E205765C2367} => H:\Gry\FINAL FANTASY VII\ff7_en.exe Task: {F0B86B6E-06CC-4048-B080-194CE023ADEA} - System32\Tasks\{C6684A3A-373D-42E3-A4DB-157355E02FEA} => C:\Users\Kolbe\Desktop\vfd21-080206\vfdwin.exe AlternateDataStreams: C:\Windows:{4B9A1497-0817-47C4-9612-D6A1C53ACF57} AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1 AlternateDataStreams: C:\Users\Kolbe\Ustawienia lokalne:dVN5DgGGU4zccna0nq6l5K AlternateDataStreams: C:\Users\Kolbe\AppData\Local:dVN5DgGGU4zccna0nq6l5K AlternateDataStreams: C:\Users\Kolbe\AppData\Local\Dane aplikacji:dVN5DgGGU4zccna0nq6l5K AlternateDataStreams: C:\Users\Kolbe\AppData\Local\Temporary Internet Files:UJKslb48ts5WSVDf C:\Program Files (x86)\Spybot - Search & Destroy 2 C:\ProgramData\Spybot - Search & Destroy C:\Windows\System32\Tasks\Safer-Networking C:\Windows\SysWOW64\RegFile3.txt C:\Windows\SysWOW64\sqlite3.dll CMD: sfc /scanfile=C:\Windows\system32\Wat\WatAdminSvc.exe CMD: ipconfig /flushdns CMD: C:\Users\Kolbe\Downloads\ComboFix.exe /uninstall ***************** HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C507CCFA-2A70-4A09-AC54-3095DB815AFD} => Key deleted successfully. HKCR\CLSID\{C507CCFA-2A70-4A09-AC54-3095DB815AFD} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Value deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Value deleted successfully. HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. HKLM\Software\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf => Key deleted successfully. C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@nitropdf.com/NitroPDF => Key deleted successfully. C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll not found. aswTdi => Error deleting Service catchme => Service deleted successfully. cpuz134 => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99E77C41-19DC-41A1-B561-D06FC7F50B4B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99E77C41-19DC-41A1-B561-D06FC7F50B4B} => Key deleted successfully. C:\Windows\System32\Tasks\{59278CFA-8759-4369-9C11-E205765C2367} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{59278CFA-8759-4369-9C11-E205765C2367} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F0B86B6E-06CC-4048-B080-194CE023ADEA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F0B86B6E-06CC-4048-B080-194CE023ADEA} => Key deleted successfully. C:\Windows\System32\Tasks\{C6684A3A-373D-42E3-A4DB-157355E02FEA} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C6684A3A-373D-42E3-A4DB-157355E02FEA} => Key deleted successfully. "C:\Windows" => ":{4B9A1497-0817-47C4-9612-D6A1C53ACF57}" ADS not found. C:\ProgramData\TEMP => ":D1B5B4F1" ADS removed successfully. "C:\Users\Kolbe\Ustawienia lokalne" => ":dVN5DgGGU4zccna0nq6l5K" ADS not found. C:\Users\Kolbe\AppData\Local => ":dVN5DgGGU4zccna0nq6l5K" ADS removed successfully. "C:\Users\Kolbe\AppData\Local\Dane aplikacji" => ":dVN5DgGGU4zccna0nq6l5K" ADS not found. "C:\Users\Kolbe\AppData\Local\Temporary Internet Files" => ":UJKslb48ts5WSVDf" ADS not found. C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully. C:\ProgramData\Spybot - Search & Destroy => Moved successfully. C:\Windows\System32\Tasks\Safer-Networking => Moved successfully. C:\Windows\SysWOW64\RegFile3.txt => Moved successfully. C:\Windows\SysWOW64\sqlite3.dll => Moved successfully. ========= sfc /scanfile=C:\Windows\system32\Wat\WatAdminSvc.exe ========= Funkcja Ochrona zasob¢w systemu Windows nie mo¾e wykona† ¾¥danej operacji. ========= End of CMD: ========= ========= ipconfig /flushdns ========= Konfiguracja IP systemu Windows Pomy˜lnie opr¢¾niono pami©† podr©czn¥ programu rozpoznawania nazw DNS. ========= End of CMD: ========= ========= C:\Users\Kolbe\Downloads\ComboFix.exe /uninstall =========