Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-11-2014 01 Ran by Agata at 2014-11-11 17:51:55 Run:13 Running from D:\Programy do naprawy sys FRST Loaded Profile: Agata (Available profiles: Agata) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: IFEO: [Debugger] svchost.exe Task: {0DBB631F-9983-42BD-99E7-A644AC5B0FEA} - \HDvid Codec V1-enabler No Task File <==== ATTENTION Task: {C8347A1B-C6B0-4C4D-B767-0A9CA98A7E77} - \HDvid Codec V1-updater No Task File <==== ATTENTION Task: {E22003B4-E3EE-4296-8D57-27B663B9B9BF} - \HDvid Codec V1-codedownloader No Task File <==== ATTENTION Task: {F01377D5-FEE3-4AFA-87DB-4C17EACCD54E} - System32\Tasks\{BFF62FED-5B99-48E1-ABB6-EA7461A0AD9C} => C:\Corel\Graphics8\programs\photopnt.exe Task: {FC11F483-B35F-41EA-9E61-5DAADDB9403D} - System32\Tasks\{770B2EC5-9253-4CF6-8090-F270E01BF1A7} => C:\Corel\Graphics8\programs\photopnt.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx?ctid=CT3323737&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SPD6FDE2BD-096C-4EB9-967D-D49D14D72155&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File FF Plugin: @java.com/DTPlugin -> C:\Program Files\Java\jre6\bin\npDeployJava1.dll No File FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 C:\Program Files (x86)\mozilla firefox\plugins C:\ProgramData\Temp C:\Users\Agata\aushelper.dll C:\Users\Agata\AppData\Local\Google C:\Users\Agata\Downloads\adwcleaner*.exe C:\Windows\pss\*.CommonStartup C:\Windows\pss\*.Startup RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\FRST\Quarantine EmptyTemp: ***************** Processes closed successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\\Debugger => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0DBB631F-9983-42BD-99E7-A644AC5B0FEA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DBB631F-9983-42BD-99E7-A644AC5B0FEA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDvid Codec V1-enabler" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C8347A1B-C6B0-4C4D-B767-0A9CA98A7E77}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8347A1B-C6B0-4C4D-B767-0A9CA98A7E77}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDvid Codec V1-updater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E22003B4-E3EE-4296-8D57-27B663B9B9BF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E22003B4-E3EE-4296-8D57-27B663B9B9BF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDvid Codec V1-codedownloader" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F01377D5-FEE3-4AFA-87DB-4C17EACCD54E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F01377D5-FEE3-4AFA-87DB-4C17EACCD54E}" => Key deleted successfully. C:\Windows\System32\Tasks\{BFF62FED-5B99-48E1-ABB6-EA7461A0AD9C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BFF62FED-5B99-48E1-ABB6-EA7461A0AD9C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC11F483-B35F-41EA-9E61-5DAADDB9403D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC11F483-B35F-41EA-9E61-5DAADDB9403D}" => Key deleted successfully. C:\Windows\System32\Tasks\{770B2EC5-9253-4CF6-8090-F270E01BF1A7} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{770B2EC5-9253-4CF6-8090-F270E01BF1A7}" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2}" => Key deleted successfully. "HKCR\CLSID\{80c554b9-c7f8-4a21-9471-06d606da78a2}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key not found. "HKCR\PROTOCOLS\Filter\text/xml" => Key Deleted successfully. "HKCR\CLSID\{807553E5-5146-11D5-A672-00B0D022E945}" => Key not found. "HKLM\Software\MozillaPlugins\@java.com/DTPlugin" => Key deleted successfully. "HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect" => Key deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\smartwebprinting@hp.com => value deleted successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\Agata\aushelper.dll => Moved successfully. C:\Users\Agata\AppData\Local\Google => Moved successfully. C:\Users\Agata\Downloads\adwcleaner*.exe => Moved successfully. C:\Windows\pss\*.CommonStartup => Moved successfully. C:\Windows\pss\*.Startup => Moved successfully. "C:\AdwCleaner" => Removed successfully. "C:\FRST\Quarantine" => Removed successfully. EmptyTemp: => Removed 49 MB temporary data. The system needed a reboot. ==== End of Fixlog ====