Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-11-2014 Ran by Maciej Skrzypiec at 2014-11-06 12:06:14 Run:1 Running from H:\instalki\RATUNKOWE Loaded Profile: Maciej Skrzypiec (Available profiles: Maciej Skrzypiec) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CMD: ipconfig /flushdns Reg: reg query "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" /s HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyServer: localhost:8080 BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll No File FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL No File FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File Task: {1DEC1943-4208-4DEF-BBF6-093DC14E8A8E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {943B5257-30C9-4D45-B829-8DAA21AE3DFF} - System32\Tasks\{423CA1DB-DBA8-4466-A874-9BF303C5D2A3} => C:\Program Files (x86)\Reason\Should I Remove It\ShouldIRemoveIt.exe BootExecute: autocheck autochk * sdnclean64.exe S3 btmaux; system32\DRIVERS\btmaux.sys [X] S3 CtClsFlt; system32\DRIVERS\CtClsFlt.sys [X] S3 intaud_WaveExtensible; system32\drivers\intelaud.sys [X] S3 iwdbus; system32\DRIVERS\iwdbus.sys [X] S4 NVHDA; system32\drivers\nvhda64v.sys [X] S3 NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [X] S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X] S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X AlternateDataStreams: C:\Program Files\Common Files\Microsoft Shared:A03fO0CG8Z2xc4OPOJMs AlternateDataStreams: C:\ProgramData\Microsoft:IoH0vafAntLUCSYvq93Bcj AlternateDataStreams: C:\ProgramData\Microsoft:kcsfiNCXziUY4Ym0oKuS8ebCp4 AlternateDataStreams: C:\Users\Maciej Skrzypiec\AppData\Local\Temp:Dn5bA7i8kvgo2aNls C:\Program Files\AVAST Software C:\Program Files (x86)\Elex-tech C:\Program Files (x86)\Google C:\Program Files (x86)\Spybot - Search & Destroy 2 C:\ProgramData\AVAST Software C:\ProgramData\Spybot - Search & Destroy C:\ProgramData\YTD Video Downloader C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader C:\Users\Maciej Skrzypiec\AppData\Local\23694 C:\Users\Maciej Skrzypiec\AppData\Local\Google C:\windows\system32\log C:\windows\system32\Drivers\etc\hosts.*.backup C:\windows\System32\Tasks\Safer-Networking C:\windows\SysWOW64\sqlite3.dll Hosts: EmptyTemp: ***************** Processes closed successfully. ========= ipconfig /flushdns ========= Konfiguracja IP systemu Windows Pomy˜lnie opr¢¾niono pami©† podr©czn¥ programu rozpoznawania nazw DNS. ========= End of CMD: ========= ========= reg query "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Infodelivery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions NoUpdateCheck REG_DWORD 0x1 ========= End of Reg: ========= "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key not found. "HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3" => Key deleted successfully. "HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. "HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DEC1943-4208-4DEF-BBF6-093DC14E8A8E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DEC1943-4208-4DEF-BBF6-093DC14E8A8E}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{943B5257-30C9-4D45-B829-8DAA21AE3DFF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{943B5257-30C9-4D45-B829-8DAA21AE3DFF}" => Key deleted successfully. C:\Windows\System32\Tasks\{423CA1DB-DBA8-4466-A874-9BF303C5D2A3} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{423CA1DB-DBA8-4466-A874-9BF303C5D2A3}" => Key deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. btmaux => Service deleted successfully. CtClsFlt => Service deleted successfully. intaud_WaveExtensible => Service deleted successfully. iwdbus => Service deleted successfully. NVHDA => Service deleted successfully. NvStreamKms => Service deleted successfully. RSUSBSTOR => Service deleted successfully. sptd => Service deleted successfully. C:\Program Files\Common Files\Microsoft Shared => ":A03fO0CG8Z2xc4OPOJMs" ADS removed successfully. C:\ProgramData\Microsoft => ":IoH0vafAntLUCSYvq93Bcj" ADS removed successfully. C:\ProgramData\Microsoft => ":kcsfiNCXziUY4Ym0oKuS8ebCp4" ADS removed successfully. C:\Users\Maciej Skrzypiec\AppData\Local\Temp => ":Dn5bA7i8kvgo2aNls" ADS removed successfully. C:\Program Files\AVAST Software => Moved successfully. C:\Program Files (x86)\Elex-tech => Moved successfully. C:\Program Files (x86)\Google => Moved successfully. C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully. C:\ProgramData\AVAST Software => Moved successfully. C:\ProgramData\Spybot - Search & Destroy => Moved successfully. C:\ProgramData\YTD Video Downloader => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader => Moved successfully. C:\Users\Maciej Skrzypiec\AppData\Local\23694 => Moved successfully. C:\Users\Maciej Skrzypiec\AppData\Local\Google => Moved successfully. C:\windows\system32\log => Moved successfully. C:\windows\system32\Drivers\etc\hosts.*.backup => Moved successfully. C:\windows\System32\Tasks\Safer-Networking => Moved successfully. C:\windows\SysWOW64\sqlite3.dll => Moved successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 197.2 MB temporary data. The system needed a reboot. ==== End of Fixlog ====