Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-12-2014 Ran by Piotrek at 2014-12-17 17:38:29 Run:2 Running from C:\Users\Piotrek\Downloads Loaded Profile: Piotrek (Available profiles: Piotrek) Boot Mode: Normal ============================================== Content of fixlist: ***************** Folder: C:\Program Files\Windows Defender Folder: C:\Program Files (x86)\Windows Defender Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows Defender" /s Reg: reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender" /s ***************** ========================= Folder: C:\Program Files\Windows Defender ======================== 2009-07-14 00:53 - 2009-07-14 02:41 - 0010752 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpAsDesc.dll 2014-09-15 12:32 - 2013-05-27 06:50 - 0571904 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpClient.dll 2009-07-14 00:53 - 2009-07-14 02:39 - 0190976 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe 2014-09-15 12:32 - 2013-05-27 06:50 - 0314880 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpCommu.dll 2009-07-14 00:53 - 2009-07-14 02:29 - 0052224 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpEvMsg.dll 2009-07-14 00:53 - 2009-07-14 02:41 - 0052224 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpOAV.dll 2009-07-14 00:53 - 2009-07-14 02:41 - 0200192 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpRTP.dll 2014-09-15 12:32 - 2013-05-27 06:50 - 1011712 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MpSvc.dll 2009-07-14 00:53 - 2009-07-14 02:39 - 0961024 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe 2014-09-15 05:19 - 2010-11-20 14:27 - 0060928 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpCom.dll 2009-07-14 00:53 - 2009-07-14 02:29 - 0004608 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpLics.dll 2009-07-14 00:53 - 2009-07-14 02:41 - 0487936 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpRes.dll 2014-12-12 19:15 - 2014-12-12 19:15 - 0000000 ____D () C:\Program Files\Windows Defender\pl-PL 2009-07-14 18:55 - 2009-07-14 18:55 - 0041472 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\pl-PL\MpAsDesc.dll.mui 2009-07-14 18:55 - 2009-07-14 18:55 - 0017920 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\pl-PL\MpEvMsg.dll.mui 2009-07-14 18:55 - 2009-07-14 18:55 - 0053248 _____ (Microsoft Corporation) C:\Program Files\Windows Defender\pl-PL\MsMpRes.dll.mui ====== End of Folder: ====== ========================= Folder: C:\Program Files (x86)\Windows Defender ======================== 2014-09-15 12:32 - 2013-05-27 04:15 - 0009216 _____ (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MpAsDesc.dll 2014-09-15 12:32 - 2013-05-27 05:57 - 0392704 _____ (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MpClient.dll 2014-09-15 12:32 - 2013-05-27 05:57 - 0054784 _____ (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MpOAV.dll 2014-09-15 12:32 - 2013-05-27 05:57 - 0004608 _____ (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\MsMpLics.dll 2009-07-14 18:55 - 2009-07-14 18:55 - 0000000 ____D () C:\Program Files (x86)\Windows Defender\pl-PL 2009-07-14 18:55 - 2009-07-14 18:55 - 0041472 _____ (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\pl-PL\MpAsDesc.dll.mui 2009-07-14 18:55 - 2009-07-14 18:55 - 0017920 _____ (Microsoft Corporation) C:\Program Files (x86)\Windows Defender\pl-PL\MpEvMsg.dll.mui ====== End of Folder: ====== ========= reg query "HKLM\SOFTWARE\Microsoft\Windows Defender" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender DisableAntiSpyware REG_DWORD 0x0 DisableRoutinelyTakingAction REG_DWORD 0x0 ProductStatus REG_DWORD 0x0 InstallTime REG_BINARY 7EDABF6F49CBCF01 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Quarantine HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Reporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Scan CheckForSignaturesBeforeRunningScan REG_DWORD 0x1 SFCLastUpdatedTime REG_BINARY 2018A3AFF5D0CF01 LastScanType REG_DWORD 0x1 LastScanRun REG_BINARY D931E9771608D001 LastQuickScanID REG_SZ {70A18AA4-2D71-48E6-A155-060B2D0DBC5F} LastQuickScanResourceCount REG_BINARY B265070000000000 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Signature Updates EngineVersion REG_SZ 1.1.11202.0 ASSignatureVersion REG_SZ 1.189.1675.0 ASSignatureApplied REG_BINARY 0066C70B4613D001 SignatureLocation REG_SZ C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{02D459AF-3B27-40DE-A8B7-C8656E2036F7} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\SpyNet SpyNetReporting REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatTypeDefaultAction HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\UX Configuration ========= End of Reg: ========= ========= reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Defender DisableAntiSpyware REG_DWORD 0x0 DisableRoutinelyTakingAction REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Scan CheckForSignaturesBeforeRunningScan REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Spynet SpyNetReporting REG_DWORD 0x0 ========= End of Reg: ========= ==== End of Fixlog ====