Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-08-2014 02 Ran by Rafał at 2014-08-24 18:23:05 Run:1 Running from C:\Users\Rafał\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** (Microsoft Corporation) C:\Windows\System32\regsvr32.exe HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\...\Run: [WebCake Desktop] => "C:\Users\RafaB\AppData\Roaming\WebCake\WebCakeDesktop.exe" HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\...\Run: [Desk 365] => "C:\Program Files (x86)\Desk 365\desk365.exe" /autorun HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\...\Run: [AVG-Secure-Search-Update_0913b] => C:\Users\RafaB\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 886b9a69cfdf47d3b6626de783eec00b-5bdf3327cb1c13c6f6ac3fae403460239c4368aa --CMPID 0913b HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\...\Run: [AtomRojl] => regsvr32.exe "C:\ProgramData\AtomRojl\AtomRojl.dat" HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\...\Policies\Explorer: [HideSCAHealth] 1 Task: {0BF364BB-E177-40B4-AE6F-3BA7110FFA3F} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe <==== ATTENTION Task: {6E0E50F6-9043-42AC-A403-E3212F522D77} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION Task: {7010CC8F-598C-431A-9821-DB9595BA77FF} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe <==== ATTENTION Task: {97A8B330-D189-410F-A73E-D8EA7B83FF71} - System32\Tasks\FreeHDSport TV-updater => C:\Program Files (x86)\FreeHDSport TV\FreeHDSport TV-updater.exe <==== ATTENTION Task: {A291D2D0-6E77-4782-B058-C9CCA0861C64} - System32\Tasks\FreeHDSport TV-enabler => C:\Program Files (x86)\FreeHDSport TV\FreeHDSport TV-enabler.exe <==== ATTENTION Task: {E1029199-7296-42DC-9131-6AF4A30136FD} - System32\Tasks\FreeHDSport TV-codedownloader => C:\Program Files (x86)\FreeHDSport TV\FreeHDSport TV-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe <==== ATTENTION Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe <==== ATTENTION Task: C:\Windows\Tasks\FreeHDSport TV-codedownloader.job => C:\Program Files (x86)\FreeHDSport TV\FreeHDSport TV-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\FreeHDSport TV-enabler.job => C:\Program Files (x86)\FreeHDSport TV\FreeHDSport TV-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\FreeHDSport TV-updater.job => C:\Program Files (x86)\FreeHDSport TV\FreeHDSport TV-updater.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=ST9500325AS_5VEDJXSKXXXX5VEDJXSK&ts=1374256136 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=ild&from=ild&uid=ST9500325AS_5VEDJXSKXXXX5VEDJXSK&ts=1374256136 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=ST9500325AS_5VEDJXSKXXXX5VEDJXSK&ts=1374256136 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=ST9500325AS_5VEDJXSKXXXX5VEDJXSK&ts=1374256136 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=ST9500325AS_5VEDJXSKXXXX5VEDJXSK&ts=1374256136 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=ild&from=ild&uid=ST9500325AS_5VEDJXSKXXXX5VEDJXSK&ts=1374256136 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO-x32: WebCake -> {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} -> C:\Program Files (x86)\WebCake\WebCakeIEClient.dll No File BHO-x32: Winamp Toolbar Loader -> {4accc990-3dc7-4456-a734-5cb4b610a7f5} -> C:\Program Files (x86)\Winamp Toolbar\winamppltb.dll No File BHO-x32: Sopcast Toolbar -> {53504356-3700-A76A-76A7-7A786E7484D7} -> "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\SPCV7\Passport.dll" No File Toolbar: HKLM-x32 - Sopcast Toolbar - {53504356-3700-A76A-76A7-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\SPCV7\Passport.dll" No File Toolbar: HKLM-x32 - Winamp Toolbar - {a0b1221c-a3ff-4f7c-a393-dc63af5301e9} - C:\Program Files (x86)\Winamp Toolbar\winamppltb.dll No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} - No File S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe /svc [X] S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe /medsvc [X] S3 GGSAFERDriver; \??\D:\Programy\Garena\safedrv.sys [X] C:\Program Files (x86)\FreeHDSport TV C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} C:\ProgramData\AtomRojl C:\Users\Rafał\AppData\Roaming\SimilarSites CMD: reg import C:\FIX.REG EmptyTemp: ***************** C:\Windows\System32\regsvr32.exe => No running process found HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WebCake Desktop => value deleted successfully. HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Desk 365 => value deleted successfully. HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_0913b => value deleted successfully. HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully. HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AtomRojl => value deleted successfully. HKU\S-1-5-21-2211548616-3766120664-3686267169-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0BF364BB-E177-40B4-AE6F-3BA7110FFA3F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BF364BB-E177-40B4-AE6F-3BA7110FFA3F}" => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6E0E50F6-9043-42AC-A403-E3212F522D77}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E0E50F6-9043-42AC-A403-E3212F522D77}" => Key deleted successfully. C:\Windows\System32\Tasks\Desk 365 RunAsStdUser => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7010CC8F-598C-431A-9821-DB9595BA77FF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7010CC8F-598C-431A-9821-DB9595BA77FF}" => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{97A8B330-D189-410F-A73E-D8EA7B83FF71}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97A8B330-D189-410F-A73E-D8EA7B83FF71}" => Key deleted successfully. C:\Windows\System32\Tasks\FreeHDSport TV-updater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FreeHDSport TV-updater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A291D2D0-6E77-4782-B058-C9CCA0861C64}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A291D2D0-6E77-4782-B058-C9CCA0861C64}" => Key deleted successfully. C:\Windows\System32\Tasks\FreeHDSport TV-enabler => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FreeHDSport TV-enabler" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E1029199-7296-42DC-9131-6AF4A30136FD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1029199-7296-42DC-9131-6AF4A30136FD}" => Key deleted successfully. C:\Windows\System32\Tasks\FreeHDSport TV-codedownloader => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FreeHDSport TV-codedownloader" => Key deleted successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\FreeHDSport TV-codedownloader.job => Moved successfully. C:\Windows\Tasks\FreeHDSport TV-enabler.job => Moved successfully. C:\Windows\Tasks\FreeHDSport TV-updater.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4accc990-3dc7-4456-a734-5cb4b610a7f5}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{4accc990-3dc7-4456-a734-5cb4b610a7f5}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53504356-3700-A76A-76A7-7A786E7484D7}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{53504356-3700-A76A-76A7-7A786E7484D7}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{53504356-3700-A76A-76A7-7A786E7484D7} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{53504356-3700-A76A-76A7-7A786E7484D7}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{a0b1221c-a3ff-4f7c-a393-dc63af5301e9} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{a0b1221c-a3ff-4f7c-a393-dc63af5301e9}" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. "HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} => value deleted successfully. "HKCR\CLSID\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9}" => Key not found. dealplylive => Service deleted successfully. dealplylivem => Service deleted successfully. GGSAFERDriver => Service deleted successfully. C:\Program Files (x86)\FreeHDSport TV => Moved successfully. C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} => Moved successfully. C:\ProgramData\AtomRojl => Moved successfully. C:\Users\Rafał\AppData\Roaming\SimilarSites => Moved successfully. ========= reg import C:\FIX.REG ========= BD: Bd otwarcia pliku. By moe wystpi bd dysku lub systemu plikw. ========= End of CMD: ========= EmptyTemp: => Removed 820.9 MB temporary data. The system needed a reboot. ==== End of Fixlog ====