Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-11-2014 01 Ran by Ewa at 2014-11-14 17:40:55 Run:1 Running from F:\naprawa Loaded Profile: Ewa (Available profiles: Ewa & konto) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-10-28] (AVG Technologies) S2 vToolbarUpdater18.1.10; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.10\ToolbarUpdater.exe [X] S2 SPDRIVER_1.37.0.1375; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.1375\jsdrv.sys [X] Task: {2DEADA5F-4BB0-4572-A3D7-A5084F2C6CD5} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{B44AC835-685B-455D-A08A-B5F9C9419E29}.exe Task: {8D4BD2C2-5DD1-463D-8044-0229B63638CF} - \SPBIW_UpdateTask_Time_313139343231302d3437415a556c2a3223346c41 No Task File <==== ATTENTION Task: {B2BFE8A4-BA68-4B35-9A57-62AB2675FB5F} - System32\Tasks\UNELEVATE_7673 => C:\Program Files\ShopperPro\JSDriver\1.37.0.1375\jsdrv.exe <==== ATTENTION Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{B44AC835-685B-455D-A08A-B5F9C9419E29}.exe HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM - DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = BHO: No Name -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> No File Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File C:\$AVG C:\Program Files\AVG Web TuneUp C:\Program Files\Google C:\Program Files\mozilla firefox\browser\searchplugins\wtu-secure-search.xml C:\ProgramData\AVAST Software C:\ProgramData\AVG Web TuneUp C:\ProgramData\AVG2015 C:\ProgramData\MFAData C:\ProgramData\TEMP C:\Users\Ewa\AppData\Local\AVG Web TuneUp C:\Users\Ewa\AppData\Local\Avg2015 C:\Users\Ewa\AppData\Local\Google C:\Users\Ewa\AppData\Local\MFAData C:\Users\Ewa\AppData\Roaming\AVG2015 C:\Users\Ewa\AppData\Roaming\TuneUp Software C:\Windows\system32\drivers\avgtpx86.sys Reg: reg delete HKCU\Software\Google /f Reg: reg delete HKLM\SOFTWARE\Google /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f Reg: reg delete "HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f Reg: reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f Reg: reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f EmptyTemp: ***************** Processes closed successfully. avgtp => Service stopped successfully. avgtp => Service deleted successfully. vToolbarUpdater18.1.10 => Service deleted successfully. SPDRIVER_1.37.0.1375 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2DEADA5F-4BB0-4572-A3D7-A5084F2C6CD5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2DEADA5F-4BB0-4572-A3D7-A5084F2C6CD5}" => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D4BD2C2-5DD1-463D-8044-0229B63638CF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D4BD2C2-5DD1-463D-8044-0229B63638CF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_313139343231302d3437415a556c2a3223346c41" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B2BFE8A4-BA68-4B35-9A57-62AB2675FB5F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2BFE8A4-BA68-4B35-9A57-62AB2675FB5F}" => Key deleted successfully. C:\Windows\System32\Tasks\UNELEVATE_7673 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UNELEVATE_7673" => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => Key deleted successfully. "HKCR\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => Key not found. "HKCR\PROTOCOLS\Handler\skypec2c" => Key deleted successfully. "HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. "HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key not found. C:\$AVG => Moved successfully. C:\Program Files\AVG Web TuneUp => Moved successfully. C:\Program Files\Google => Moved successfully. C:\Program Files\mozilla firefox\browser\searchplugins\wtu-secure-search.xml => Moved successfully. C:\ProgramData\AVAST Software => Moved successfully. "C:\ProgramData\AVG Web TuneUp" => File/Directory not found. C:\ProgramData\AVG2015 => Moved successfully. C:\ProgramData\MFAData => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\Users\Ewa\AppData\Local\AVG Web TuneUp => Moved successfully. C:\Users\Ewa\AppData\Local\Avg2015 => Moved successfully. C:\Users\Ewa\AppData\Local\Google => Moved successfully. C:\Users\Ewa\AppData\Local\MFAData => Moved successfully. C:\Users\Ewa\AppData\Roaming\AVG2015 => Moved successfully. C:\Users\Ewa\AppData\Roaming\TuneUp Software => Moved successfully. C:\Windows\system32\drivers\avgtpx86.sys => Moved successfully. ========= reg delete HKCU\Software\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 460.7 MB temporary data. The system needed a reboot. ==== End of Fixlog ====