Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-12-2014 01 Ran by Piotrek at 2014-12-12 17:41:39 Run:1 Running from C:\Users\Piotrek\Downloads Loaded Profile: Piotrek (Available profiles: Piotrek) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe, BootExecute: sdnclean64.exe Task: {35C8EE8E-92FA-4D66-BF2C-38F6686ACFFF} - System32\Tasks\YTAUpdate => C:\PROGRA~2\YOUTUB~1\Updater.exe <==== ATTENTION Task: {90DE61AD-050D-49A9-84DB-BBACCDB7FF50} - \SPBIW_UpdateTask_Time_313632313735373139352d3437415a556c2a3223346c41 No Task File <==== ATTENTION Task: {FEA5E0A5-444E-4D3B-9D3D-8D857B19CB93} - System32\Tasks\{0E17CBB5-02A4-4DE9-9B0E-021218A495FE} => C:\Program Files (x86)\Encore Software\Williams Pinball Classics\ARABIAN\pinball.exe Task: C:\Windows\Tasks\KWQTCOG.job => C:\Users\Piotrek\AppData\Roaming\KWQTCOG.exe <==== ATTENTION Task: C:\Windows\Tasks\VOVUZ.job => C:\Users\Piotrek\AppData\Roaming\VOVUZ.exe <==== ATTENTION S2 AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X] S2 AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X] S2 SPDRIVER_1.38.0.1436; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1436\jsdrv.sys [X] HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\S-1-5-21-601007357-3713406717-2957266076-1000 -> {6AB37345-FCD8-4B72-A774-E855600D0656} URL = https://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=201117&p={searchTerms} FF SearchPlugin: C:\Users\Piotrek\AppData\Roaming\Mozilla\Firefox\Profiles\hlo9b4dc.default\searchplugins\yahoo_ff.xml C:\Program Files (x86)\mozilla firefox\plugins C:\Program Files (x86)\a85fb5ad-f03a-4348-ad3c-6889747e6eb5 C:\Program Files (x86)\f7372bc6-c8ca-4f7e-bba8-c6b15838d03c C:\Program Files (x86)\SensePlus C:\Program Files\OO Software C:\ProgramData\Auslogics C:\ProgramData\Freemake C:\ProgramData\HitmanPro C:\ProgramData\Raxco C:\ProgramData\Spybot - Search & Destroy C:\ProgramData\TEMP C:\Users\Piotrek\AppData\Local\FreemakeVideoConverter C:\Users\Piotrek\AppData\Local\O&O C:\Users\Piotrek\AppData\Local\Opera Software C:\Users\Piotrek\AppData\Roaming\Opera Software C:\Windows\system32\oodag C:\Windows\System32\Tasks\Safer-Networking DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSC" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OODefragTray" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{35C8EE8E-92FA-4D66-BF2C-38F6686ACFFF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35C8EE8E-92FA-4D66-BF2C-38F6686ACFFF}" => Key deleted successfully. C:\Windows\System32\Tasks\YTAUpdate => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTAUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{90DE61AD-050D-49A9-84DB-BBACCDB7FF50}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90DE61AD-050D-49A9-84DB-BBACCDB7FF50}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_313632313735373139352d3437415a556c2a3223346c41" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FEA5E0A5-444E-4D3B-9D3D-8D857B19CB93}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEA5E0A5-444E-4D3B-9D3D-8D857B19CB93}" => Key deleted successfully. C:\Windows\System32\Tasks\{0E17CBB5-02A4-4DE9-9B0E-021218A495FE} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0E17CBB5-02A4-4DE9-9B0E-021218A495FE}" => Key deleted successfully. C:\Windows\Tasks\KWQTCOG.job => Moved successfully. C:\Windows\Tasks\VOVUZ.job => Moved successfully. AODDriver4.2.0 => Service deleted successfully. AODDriver4.3 => Service deleted successfully. nvlddmkm => Service deleted successfully. SPDRIVER_1.38.0.1436 => Service deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKU\S-1-5-21-601007357-3713406717-2957266076-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6AB37345-FCD8-4B72-A774-E855600D0656}" => Key deleted successfully. "HKCR\CLSID\{6AB37345-FCD8-4B72-A774-E855600D0656}" => Key not found. C:\Users\Piotrek\AppData\Roaming\Mozilla\Firefox\Profiles\hlo9b4dc.default\searchplugins\yahoo_ff.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. C:\Program Files (x86)\a85fb5ad-f03a-4348-ad3c-6889747e6eb5 => Moved successfully. C:\Program Files (x86)\f7372bc6-c8ca-4f7e-bba8-c6b15838d03c => Moved successfully. C:\Program Files (x86)\SensePlus => Moved successfully. C:\Program Files\OO Software => Moved successfully. C:\ProgramData\Auslogics => Moved successfully. C:\ProgramData\Freemake => Moved successfully. C:\ProgramData\HitmanPro => Moved successfully. C:\ProgramData\Raxco => Moved successfully. C:\ProgramData\Spybot - Search & Destroy => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\Users\Piotrek\AppData\Local\FreemakeVideoConverter => Moved successfully. C:\Users\Piotrek\AppData\Local\O&O => Moved successfully. C:\Users\Piotrek\AppData\Local\Opera Software => Moved successfully. C:\Users\Piotrek\AppData\Roaming\Opera Software => Moved successfully. C:\Windows\system32\oodag => Moved successfully. C:\Windows\System32\Tasks\Safer-Networking => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking => Key Deleted Successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSC" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OODefragTray" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 960 MB temporary data. The system needed a reboot. ==== End of Fixlog ====