Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 16-10-2014 Ran by XxX at 2014-10-18 11:43:03 Run:1 Running from C:\Users\XxX\Downloads Loaded Profile: XxX (Available profiles: XxX) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R2 PennyBee; C:\Program Files\PennyBee\PennyBee.exe [57856 2014-07-30] () [File not signed] S2 PredatorACE; "C:\Program Files\Predator2\PredatorACE.exe" [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] HKLM\...\Run: [] => [X] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pl.yahoo.com?fr=fp-comodo HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = http://pl.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-09-25] BHO: WinToFlash Suggestor -> {FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD} -> C:\Program Files\WinToFlash Suggestor\WinToFlashSuggestor.dll (Novicorp LLC) Task: {0DA0DE1C-F374-487E-9A25-43AFD858F1E3} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\XxX\AppData\Local\FilesFrog Update Checker\update_checker.exe <==== ATTENTION Task: {27066F87-E7FD-471A-9936-D8416A98A12C} - System32\Tasks\{88218742-3E7D-4FA5-B83F-B7556C8D1AF8} => D:\Program Files\THQ\Metro 2033\metro2033.exe Task: {3D5E7AEC-B6DD-408F-ABC0-23E9B4AEE331} - System32\Tasks\{C2F3BB20-5621-4E2D-A612-00BDDE4DB27D} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/pl/abandoninstall?page=tsProgressBar Task: {5D957DAB-065D-4238-BBA0-2F0784F93770} - System32\Tasks\GS.Enabler-S-1824435291 => c:\programdata\house of soft\gs.enabler\GS.Enabler.exe <==== ATTENTION Task: {C17AC5FB-8848-41FF-B550-D6EDC95E3D3B} - System32\Tasks\Math Problem Solver CPU => C:\Users\XxX\AppData\Local\Math Problem Solver\cpu\Solve.exe <==== ATTENTION Task: C:\Windows\Tasks\GS.Enabler-S-1824435291.job => c:\programdata\house of soft\gs.enabler\GS.Enabler.exe <==== ATTENTION HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKCU\Software\Google DeleteKey: HKLM\SOFTWARE\Google C:\Users\XxX\halo.exe C:\Users\XxX\AppData\Local\*Bron*.bin C:\Users\XxX\AppData\Local\Google C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\idstore.* C:\Windows\grep.exe C:\Windows\MBR.exe C:\Windows\PEV.exe C:\Windows\sed.exe C:\Windows\zip.exe EmptyTemp: ***************** Processes closed successfully. PennyBee => Service not found. PredatorACE => Service deleted successfully. EagleXNt => Service deleted successfully. VBoxNetFlt => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value not found. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}" => Key deleted successfully. "HKCR\CLSID\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}" => Key not found. C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD}" => Key not found. "HKCR\CLSID\{FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0DA0DE1C-F374-487E-9A25-43AFD858F1E3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DA0DE1C-F374-487E-9A25-43AFD858F1E3}" => Key deleted successfully. C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27066F87-E7FD-471A-9936-D8416A98A12C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27066F87-E7FD-471A-9936-D8416A98A12C}" => Key deleted successfully. C:\Windows\System32\Tasks\{88218742-3E7D-4FA5-B83F-B7556C8D1AF8} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{88218742-3E7D-4FA5-B83F-B7556C8D1AF8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D5E7AEC-B6DD-408F-ABC0-23E9B4AEE331}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D5E7AEC-B6DD-408F-ABC0-23E9B4AEE331}" => Key deleted successfully. C:\Windows\System32\Tasks\{C2F3BB20-5621-4E2D-A612-00BDDE4DB27D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C2F3BB20-5621-4E2D-A612-00BDDE4DB27D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D957DAB-065D-4238-BBA0-2F0784F93770}" => Key not found. C:\Windows\System32\Tasks\GS.Enabler-S-1824435291 not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GS.Enabler-S-1824435291" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C17AC5FB-8848-41FF-B550-D6EDC95E3D3B}" => Key not found. C:\Windows\System32\Tasks\Math Problem Solver CPU not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Math Problem Solver CPU" => Key not found. C:\Windows\Tasks\GS.Enabler-S-1824435291.job not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys" => Key deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Key Deleted Successfully. HKCU\Software\Google => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Google => Key Deleted Successfully. HKLM\SOFTWARE\Google => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Google => Key Deleted Successfully. C:\Users\XxX\halo.exe => Moved successfully. "C:\Users\XxX\AppData\Local\*Bron*.bin" => File/Directory not found. C:\Users\XxX\AppData\Local\Google => Moved successfully. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\idstore.* => Moved successfully. C:\Windows\grep.exe => Moved successfully. C:\Windows\MBR.exe => Moved successfully. C:\Windows\PEV.exe => Moved successfully. C:\Windows\sed.exe => Moved successfully. C:\Windows\zip.exe => Moved successfully. EmptyTemp: => Removed 607.1 MB temporary data. The system needed a reboot. ==== End of Fixlog ====