Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:09-06-2014 03 Ran by webasia at 2014-06-10 16:17:44 Run:1 Running from C:\Users\webasia\Desktop\czyszczenie kompa\czyszczenie Boot Mode: Normal ============================================== Content of fixlist: ***************** S4 igfx; system32\DRIVERS\igdkmd32.sys [X] S4 IntcHdmiAddService; system32\drivers\IntcHdmi.sys [X] Task: {079D2ED5-17FC-4282-8C40-31DCF559EF9D} - System32\Tasks\SuperEasyDriverUpdaterRunAtStartup => C:\Program Files\SuperEasy Software\Driver Updater\supereasydu.exe Task: {1F866622-08AE-4A1F-A5E0-1E860CADCB5C} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe [2013-03-25] (Bitberry Software) Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ProxyServer: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL = http://speedial.com/results.php?f=4&q={searchTerms}&a=spd_ir_14_23_ch&cd=2XzuyEtN2Y1L1QzutDtBtDzztAyEtAtAzzyBtDtC0AyEzzzytN0D0Tzu0SzzzzzytN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0F0AtBtCtD0AtBtGyD0F0ByEtGzzyB0EyDtG0ByEzz0EtGyBtC0CtCtBtAyBzzyC0D0Bzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0Dzy0EtA0BtAtCtG0AzzyDzytGyEzz0EtAtG0CtAyByDtGyBzzzzyByDtCyD0FyDyBtAtA2Q&cr=2031896909&ir= SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = http://speedial.com/results.php?f=4&q={searchTerms}&a=spd_ir_14_23_ch&cd=2XzuyEtN2Y1L1QzutDtBtDzztAyEtAtAzzyBtDtC0AyEzzzytN0D0Tzu0SzzzzzytN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0F0AtBtCtD0AtBtGyD0F0ByEtGzzyB0EyDtG0ByEzz0EtGyBtC0CtCtBtAyBzzyC0D0Bzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0Dzy0EtA0BtAtCtG0AzzyDzytGyEzz0EtAtG0CtAyByDtGyBzzzzyByDtCyD0FyDyBtAtA2Q&cr=2031896909&ir= AlternateDataStreams: C:\ProgramData\TEMP:07BF512B FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ C:\Program Files\Mozilla Firefox\extensions C:\ProgramData\pclunst.exe C:\ProgramData\ba79b1d18ecd4343 C:\ProgramData\InstallMate C:\ProgramData\TEMP C:\Users\webasia\AppData\Local\Comodo C:\Users\webasia\AppData\Roaming\SuperEasy Software C:\Users\webasia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk C:\Users\webasia\Desktop\Continue GNU Image Manipulation Program Free Download Installation.lnk C:\Users\Administrator C:\Users\ASPNET C:\Users\Guest C:\Users\QBDataServiceUser23\AppData\Local\Comodo C:\Users\QBDataServiceUser23\AppData\Local\Google C:\Windows\system32\sqlite3.dll C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NTRedirect" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Image Editor Packages" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** igfx => Service deleted successfully. IntcHdmiAddService => Service deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{079D2ED5-17FC-4282-8C40-31DCF559EF9D}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{079D2ED5-17FC-4282-8C40-31DCF559EF9D}' => Key deleted successfully. C:\Windows\System32\Tasks\SuperEasyDriverUpdaterRunAtStartup => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SuperEasyDriverUpdaterRunAtStartup' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1F866622-08AE-4A1F-A5E0-1E860CADCB5C}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F866622-08AE-4A1F-A5E0-1E860CADCB5C}' => Key deleted successfully. C:\Windows\System32\Tasks\FreeFileViewerUpdateChecker => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FreeFileViewerUpdateChecker' => Key deleted successfully. C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => value deleted successfully. 'HKCU\SOFTWARE\Policies\Google' => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{31090377-0740-419E-BEFC-A56E50500D5B}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{31090377-0740-419E-BEFC-A56E50500D5B}'=> Key not found. C:\ProgramData\TEMP => ":07BF512B" ADS removed successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. C:\Program Files\Mozilla Firefox\extensions => Moved successfully. C:\ProgramData\pclunst.exe => Moved successfully. C:\ProgramData\ba79b1d18ecd4343 => Moved successfully. C:\ProgramData\InstallMate => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\Users\webasia\AppData\Local\Comodo => Moved successfully. C:\Users\webasia\AppData\Roaming\SuperEasy Software => Moved successfully. C:\Users\webasia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk => Moved successfully. C:\Users\webasia\Desktop\Continue GNU Image Manipulation Program Free Download Installation.lnk => Moved successfully. C:\Users\Administrator => Moved successfully. C:\Users\ASPNET => Moved successfully. C:\Users\Guest => Moved successfully. C:\Users\QBDataServiceUser23\AppData\Local\Comodo => Moved successfully. C:\Users\QBDataServiceUser23\AppData\Local\Google => Moved successfully. C:\Windows\system32\sqlite3.dll => Moved successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NTRedirect" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Image Editor Packages" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ==== End of Fixlog ====