Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-10-2014 01 Ran by XxX at 2014-10-20 21:38:42 Run:3 Running from C:\Users\XxX\Downloads Loaded Profile: XxX (Available profiles: XxX) Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pl.yahoo.com?fr=fp-comodo HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = http://pl.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo S2 PredatorACE; "C:\Program Files\Predator2\PredatorACE.exe" [X] R4 cmdGuard; system32\DRIVERS\cmdguard.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] HKLM\...\Run: [] => [X] Task: {0DA0DE1C-F374-487E-9A25-43AFD858F1E3} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\XxX\AppData\Local\FilesFrog Update Checker\update_checker.exe <==== ATTENTION Task: {27066F87-E7FD-471A-9936-D8416A98A12C} - System32\Tasks\{88218742-3E7D-4FA5-B83F-B7556C8D1AF8} => D:\Program Files\THQ\Metro 2033\metro2033.exe Task: {3D5E7AEC-B6DD-408F-ABC0-23E9B4AEE331} - System32\Tasks\{C2F3BB20-5621-4E2D-A612-00BDDE4DB27D} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/pl/abandoninstall?page=tsProgressBar Task: {5D957DAB-065D-4238-BBA0-2F0784F93770} - System32\Tasks\GS.Enabler-S-1824435291 => c:\programdata\house of soft\gs.enabler\GS.Enabler.exe <==== ATTENTION Task: {942C9D6F-5812-4B57-A687-01BAE89A6F00} - System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82} => C:\ProgramData\cis9666.exe [2014-04-16] (COMODO) Task: C:\Windows\Tasks\GS.Enabler-S-1824435291.job => c:\programdata\house of soft\gs.enabler\GS.Enabler.exe <==== ATTENTION HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 DeleteKey: HKCU\Software\Google DeleteKey: HKLM\SOFTWARE\Google DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\CmdAgent DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\cmdvirth DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\COMODO Internet Security DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ComodoFSChrome DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesAirMessage DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPreload DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogMeIn Hamachi Ui DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PrivDogService DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Unified Remote v2 C:\Program Files\PennyBee C:\ProgramData\cis9666.exe C:\Users\HomeGroupUser$ C:\Users\Administrator C:\Users\Gość C:\Users\XxX\halo.exe C:\Users\XxX\AppData\Local\Google C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\idstore.* C:\Windows\system32\Drivers\sfi.dat Reboot: ***************** C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}" => Key deleted successfully. "HKCR\CLSID\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}" => Key not found. PredatorACE => Service deleted successfully. cmdGuard => Unable to stop service cmdGuard => Service deleted successfully. EagleXNt => Service deleted successfully. VBoxNetFlt => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0DA0DE1C-F374-487E-9A25-43AFD858F1E3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DA0DE1C-F374-487E-9A25-43AFD858F1E3}" => Key deleted successfully. C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{27066F87-E7FD-471A-9936-D8416A98A12C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27066F87-E7FD-471A-9936-D8416A98A12C}" => Key deleted successfully. C:\Windows\System32\Tasks\{88218742-3E7D-4FA5-B83F-B7556C8D1AF8} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{88218742-3E7D-4FA5-B83F-B7556C8D1AF8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D5E7AEC-B6DD-408F-ABC0-23E9B4AEE331}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D5E7AEC-B6DD-408F-ABC0-23E9B4AEE331}" => Key deleted successfully. C:\Windows\System32\Tasks\{C2F3BB20-5621-4E2D-A612-00BDDE4DB27D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C2F3BB20-5621-4E2D-A612-00BDDE4DB27D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5D957DAB-065D-4238-BBA0-2F0784F93770}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D957DAB-065D-4238-BBA0-2F0784F93770}" => Key deleted successfully. C:\Windows\System32\Tasks\GS.Enabler-S-1824435291 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GS.Enabler-S-1824435291" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{942C9D6F-5812-4B57-A687-01BAE89A6F00}" => Key not found. C:\Windows\System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82} not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}" => Key not found. C:\Windows\Tasks\GS.Enabler-S-1824435291.job => Moved successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys" => Key deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 => Key Deleted Successfully. HKCU\Software\Google => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Google => Key Deleted Successfully. HKLM\SOFTWARE\Google => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Google => Key Deleted Successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\CmdAgent => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\cmdvirth => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\COMODO Internet Security => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ComodoFSChrome => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesAirMessage => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesPreload => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogMeIn Hamachi Ui => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PrivDogService => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Unified Remote v2 => Key Deleted successfully. C:\Program Files\PennyBee => Moved successfully. "C:\ProgramData\cis9666.exe" => File/Directory not found. C:\Users\HomeGroupUser$ => Moved successfully. C:\Users\Administrator => Moved successfully. C:\Users\Gość => Moved successfully. C:\Users\XxX\halo.exe => Moved successfully. C:\Users\XxX\AppData\Local\Google => Moved successfully. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\idstore.* => Moved successfully. C:\Windows\system32\Drivers\sfi.dat => Moved successfully. The system needed a reboot. ==== End of Fixlog ====