Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-01-2015 Ran by Agata at 2015-01-09 16:05:35 Run:1 Running from C:\Documents and Settings\Agata\Moje dokumenty\Downloads\2015-01-08 Loaded Profile: Agata (Available profiles: Agata & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CustomCLSID: HKU\S-1-5-21-2017020554-2505807170-1683698369-1005_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\DOCUME~1\Agata\USTAWI~1\Temp\dc1F7d5B5\temp\Ukraine Crisis_ Death and destruction continues in Ea (the data entry has 45 more characters). S2 24c54e38; "C:\WINDOWS\system32\rundll32.exe" "c:\Program Files\DeltaFix\DeltaFix.dll",serv <==== ATTENTION S3 ALSysIO; \??\C:\DOCUME~1\Agata\USTAWI~1\Temp\ALSysIO.sys [X] S3 Tosrfcom; No ImagePath S3 TpChoice; system32\DRIVERS\TpChoice.sys [X] C:\Documents and Settings\All Users\Dane aplikacji\pbphckkhomkgbgpgcgpkpncmdmkfkbnk C:\Documents and Settings\Agata\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Preferences C:\Documents and Settings\Agata\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Program Files\YOutUbeAAdBlOcke C:\Program Files\uNisaliees C:\Program Files\Unuisaloes Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{24c54e38} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKU\S-1-5-21-2017020554-2505807170-1683698369-1005_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}" => Key deleted successfully. 24c54e38 => Service deleted successfully. ALSysIO => Service deleted successfully. Tosrfcom => Service deleted successfully. TpChoice => Service deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\pbphckkhomkgbgpgcgpkpncmdmkfkbnk => Moved successfully. C:\Documents and Settings\Agata\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Documents and Settings\Agata\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Program Files\YOutUbeAAdBlOcke => Moved successfully. C:\Program Files\uNisaliees => Moved successfully. C:\Program Files\Unuisaloes => Moved successfully. ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{24c54e38} /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= EmptyTemp: => Removed 2.2 GB temporary data. The system needed a reboot. ==== End of Fixlog 16:06:32 ====