Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-02-2015 01 Ran by User at 2015-02-28 17:46:55 Run:1 Running from C:\Users\User\Downloads Loaded Profiles: User & UpdatusUser (Available profiles: User & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X] Task: {62F60561-2450-4CD7-8730-23B85B256831} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {A1DE6D55-DC28-49A1-B11F-16DB299A0D31} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SN.Booster-S-615019665.job => c:\programdata\miniapp\sn.booster\SN.Booster.exeE/schedule /profile c:\programdata\miniapp\sn.booster\615019665.iniUserSN.Boo <==== ATTENTION AppInit_DLLs-x32: c:\progra~2\sn0310~1.boo => "c:\progra~2\sn0310~1.boo" File Not Found HKLM-x32\...\Run: [SessionLogon] => C:\ExpressGateUtil\SessionLogon.exe HKLM-x32\...\Run: [NWEReboot] => [X] HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe" HKU\S-1-5-21-1637351539-915756313-3180054859-1000\...\Run: [ALLPlayer WiFi Remote] => C:\Program Files (x86)\ALLPlayer Remote\ALLPlayerRemoteControl.exe HKU\S-1-5-21-1637351539-915756313-3180054859-1000\Software\Classes\.exe: => <===== ATTENTION! CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com SearchScopes: HKU\S-1-5-21-1637351539-915756313-3180054859-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} SearchScopes: HKU\S-1-5-21-1637351539-915756313-3180054859-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: PopBlocker Class -> {7648AC4A-76F6-4d95-B2C4-F0DBD88E5DD5} -> C:\Windows\SysWow64\wmvploc.dll No File BHO-x32: IplexToALLPlayer -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL No File CustomCLSID: HKU\S-1-5-21-1637351539-915756313-3180054859-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File C:\Program Files (x86)\Mozilla Firefox\extensions C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Burger Island C:\ProgramData\Temp C:\Users\User\AppData\Local\Google C:\Users\User\AppData\Roaming\error.log C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Reg: reg delete HKCU\Software\Google /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. gupdate => Service not found. gupdatem => Service not found. pccsmcfd => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{62F60561-2450-4CD7-8730-23B85B256831} => Key not found. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1DE6D55-DC28-49A1-B11F-16DB299A0D31} => Key not found. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA => Key not found. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job not found. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job not found. C:\Windows\Tasks\SN.Booster-S-615019665.job => Moved successfully. "c:\progra~2\sn0310~1.boo" => Value Data removed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SessionLogon => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NWEReboot => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\WinampAgent => value deleted successfully. HKU\S-1-5-21-1637351539-915756313-3180054859-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ALLPlayer WiFi Remote => value deleted successfully. "HKU\S-1-5-21-1637351539-915756313-3180054859-1000\Software\Classes\.exe" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-1637351539-915756313-3180054859-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\ToolbarSearchProviderProgress => value deleted successfully. HKU\S-1-5-21-1637351539-915756313-3180054859-1004\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7648AC4A-76F6-4d95-B2C4-F0DBD88E5DD5}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{7648AC4A-76F6-4d95-B2C4-F0DBD88E5DD5}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}" => Key deleted successfully. "HKU\S-1-5-21-1637351539-915756313-3180054859-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => Key deleted successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3 => Key not found. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9 => Key not found. C:\Program Files (x86)\Mozilla Firefox\extensions => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Burger Island => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\User\AppData\Local\Google => Moved successfully. C:\Users\User\AppData\Roaming\error.log => Moved successfully. "C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk" => File/Directory not found. ========= reg delete HKCU\Software\Google /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 720.4 MB temporary data. The system needed a reboot. ==== End of Fixlog 17:47:40 ====