Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-12-2014 Ran by bumbel at 2014-12-18 16:21:36 Run:1 Running from C:\Users\bumbel\Desktop\frst Loaded Profile: bumbel (Available profiles: bumbel) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: (Microsoft Corporation) C:\Windows\explorer.exe HKU\S-1-5-21-1762714656-3261685716-1016323744-1000\...\CurrentVersion\Windows: [Load] C:\Windows\system32\Microsoft.com <===== ATTENTION HKU\S-1-5-21-1762714656-3261685716-1016323744-1000\...\Winlogon: [Shell] explorer.exe, C:\Program Files (x86)\Microsoft Services\symgr.exe <==== ATTENTION Startup: C:\Users\bumbel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\98a832f5a83b6c04035dbea2feaee7c3.exe () Startup: C:\Users\bumbel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Photoshopsetup.exe (Hewlett-Packard) Task: {44CABA34-D2CC-4D94-AE14-CA8881CFFE58} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: {5C5309EC-770B-4E0F-B7D1-592F400BC028} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask No Task File <==== ATTENTION Task: {6C269CCB-60D3-44E7-858D-964B417BED35} - System32\Tasks\{484AE7CC-3BF9-4173-BA2C-A8BAA0CF1E3B} => pcalua.exe -a E:\autorun.exe -d E:\ Task: {8276BD8B-6D23-40F4-871B-7CB991C1C85C} - System32\Tasks\{187B816C-50FC-467A-BFAB-1DC743EB59A2} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\2\SSM_Uninstall.exe Task: {970FA293-E178-40B4-8237-5BACC74A20E0} - System32\Tasks\{CADA324B-F34D-4A1D-96BD-C15414407279} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\3\SSCDUninstall.exe Task: {C64C3B33-4304-49FD-9868-667F976D3005} - System32\Tasks\{F34EE469-7FB7-4AA2-86BC-BCBDF2D590BC} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\1\SS_Uninstall.exe Task: {D64AF338-74B8-4C80-A80D-C39D5EB8D921} - System32\Tasks\Windows Update Check - 0x0BB102C9 => C:\ProgramData\svchost\qpqpdndnn.exe Task: {D7209499-68E3-46B8-8308-1126A9BFF65A} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe Task: {DAB0A679-2F31-4729-93B0-FF35041704E4} - System32\Tasks\{83836A8F-50B9-42ED-9CD7-216AA8F3A71C} => pcalua.exe -a G:\RTG-2014-01-06\RTG\ax98.d309.daq\LDV.exe -d G:\RTG-2014-01-06\RTG\ax98.d309.daq Task: {EFCBBE80-CE8B-4489-A556-B27A541120BA} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline No Task File <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X] S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed] R3 cpuz136; \??\C:\Users\bumbel\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] S4 NVHDA; system32\drivers\nvhda64v.sys [X] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp HKU\S-1-5-21-1762714656-3261685716-1016323744-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/?src01=dp FF Homepage: www.wp.pl/?src01=dp C:\Program Files (x86)\HDD Health C:\Program Files (x86)\Microsoft Services C:\Program Files (x86)\Opera C:\Program Files (x86)\Razer C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Editor 4.0 C:\ProgramData\svchost C:\Users\bumbel\AppData\Local\*.exe C:\Users\bumbel\AppData\Local\Opera Software C:\Users\bumbel\AppData\Roaming\*.exe C:\Users\bumbel\AppData\Roaming\Winrar.exe.tmp C:\Users\bumbel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed C:\Users\bumbel\AppData\Roaming\Opera Software C:\Users\bumbel\Desktop\programy\Opera.lnk C:\Users\bumbel\Desktop\programy\Revo Uninstaller Pro.lnk C:\Users\bumbel\Desktop\programy\Total Commander 64 bit.lnk C:\Users\bumbel\Desktop\duperele\Battlefield 3.lnk C:\Users\bumbel\Desktop\duperele\Razer Comms.lnk C:\Users\Public\Desktop\GRIDAutosport.lnk C:\Windows\system32\Microsoft.com C:\Windows\SysWow64\*.tmp C:\Windows\SysWow64\Drivers\StarOpen.sys Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\AdobeFlashPlayerUpdateSvc" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Razer Comms" /f CMD: netsh advfirewall reset EmptyTemp: ***************** Processes closed successfully. [1508] C:\Windows\explorer.exe => Process closed successfully. HKU\S-1-5-21-1762714656-3261685716-1016323744-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => Value was restored successfully. HKU\S-1-5-21-1762714656-3261685716-1016323744-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully. C:\Users\bumbel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\98a832f5a83b6c04035dbea2feaee7c3.exe => Moved successfully. C:\Users\bumbel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Photoshopsetup.exe => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{44CABA34-D2CC-4D94-AE14-CA8881CFFE58}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44CABA34-D2CC-4D94-AE14-CA8881CFFE58}" => Key deleted successfully. C:\Windows\System32\Tasks\Adobe Flash Player Updater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C5309EC-770B-4E0F-B7D1-592F400BC028}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C5309EC-770B-4E0F-B7D1-592F400BC028}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C269CCB-60D3-44E7-858D-964B417BED35}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C269CCB-60D3-44E7-858D-964B417BED35}" => Key deleted successfully. C:\Windows\System32\Tasks\{484AE7CC-3BF9-4173-BA2C-A8BAA0CF1E3B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{484AE7CC-3BF9-4173-BA2C-A8BAA0CF1E3B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8276BD8B-6D23-40F4-871B-7CB991C1C85C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8276BD8B-6D23-40F4-871B-7CB991C1C85C}" => Key deleted successfully. C:\Windows\System32\Tasks\{187B816C-50FC-467A-BFAB-1DC743EB59A2} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{187B816C-50FC-467A-BFAB-1DC743EB59A2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{970FA293-E178-40B4-8237-5BACC74A20E0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{970FA293-E178-40B4-8237-5BACC74A20E0}" => Key deleted successfully. C:\Windows\System32\Tasks\{CADA324B-F34D-4A1D-96BD-C15414407279} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CADA324B-F34D-4A1D-96BD-C15414407279}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C64C3B33-4304-49FD-9868-667F976D3005}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C64C3B33-4304-49FD-9868-667F976D3005}" => Key deleted successfully. C:\Windows\System32\Tasks\{F34EE469-7FB7-4AA2-86BC-BCBDF2D590BC} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F34EE469-7FB7-4AA2-86BC-BCBDF2D590BC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D64AF338-74B8-4C80-A80D-C39D5EB8D921}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D64AF338-74B8-4C80-A80D-C39D5EB8D921}" => Key deleted successfully. C:\Windows\System32\Tasks\Windows Update Check - 0x0BB102C9 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Update Check - 0x0BB102C9" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D7209499-68E3-46B8-8308-1126A9BFF65A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7209499-68E3-46B8-8308-1126A9BFF65A}" => Key deleted successfully. C:\Windows\System32\Tasks\Launch HTC Sync Loader => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Launch HTC Sync Loader" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DAB0A679-2F31-4729-93B0-FF35041704E4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DAB0A679-2F31-4729-93B0-FF35041704E4}" => Key deleted successfully. C:\Windows\System32\Tasks\{83836A8F-50B9-42ED-9CD7-216AA8F3A71C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{83836A8F-50B9-42ED-9CD7-216AA8F3A71C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EFCBBE80-CE8B-4489-A556-B27A541120BA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFCBBE80-CE8B-4489-A556-B27A541120BA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline" => Key deleted successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully. Winstep Xtreme Service => Service deleted successfully. StarOpen => Service deleted successfully. cpuz136 => Service deleted successfully. gdrv => Service deleted successfully. GPUZ => Service deleted successfully. MSICDSetup => Service deleted successfully. NTIOLib_1_0_4 => Service deleted successfully. NTIOLib_1_0_C => Service deleted successfully. NVHDA => Service deleted successfully. nvlddmkm => Service deleted successfully. nvvad_WaveExtensible => Service deleted successfully. VGPU => Service deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-1762714656-3261685716-1016323744-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. Firefox homepage deleted successfully. C:\Program Files (x86)\HDD Health => Moved successfully. "C:\Program Files (x86)\Microsoft Services" => File/Directory not found. C:\Program Files (x86)\Opera => Moved successfully. C:\Program Files (x86)\Razer => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Editor 4.0 => Moved successfully. "C:\ProgramData\svchost" => File/Directory not found. "C:\Users\bumbel\AppData\Local\*.exe" => File/Directory not found. C:\Users\bumbel\AppData\Local\Opera Software => Moved successfully. C:\Users\bumbel\AppData\Roaming\*.exe => Moved successfully. C:\Users\bumbel\AppData\Roaming\Winrar.exe.tmp => Moved successfully. C:\Users\bumbel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed => Moved successfully. C:\Users\bumbel\AppData\Roaming\Opera Software => Moved successfully. C:\Users\bumbel\Desktop\programy\Opera.lnk => Moved successfully. C:\Users\bumbel\Desktop\programy\Revo Uninstaller Pro.lnk => Moved successfully. C:\Users\bumbel\Desktop\programy\Total Commander 64 bit.lnk => Moved successfully. C:\Users\bumbel\Desktop\duperele\Battlefield 3.lnk => Moved successfully. C:\Users\bumbel\Desktop\duperele\Razer Comms.lnk => Moved successfully. C:\Users\Public\Desktop\GRIDAutosport.lnk => Moved successfully. "C:\Windows\system32\Microsoft.com" => File/Directory not found. C:\Windows\SysWow64\*.tmp => Moved successfully. C:\Windows\SysWow64\Drivers\StarOpen.sys => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\AdobeFlashPlayerUpdateSvc" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Razer Comms" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= EmptyTemp: => Removed 230.9 MB temporary data. The system needed a reboot. ==== End of Fixlog ====