Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by oem at 2015-03-25 19:04:27 Run:1 Running from F:\ Loaded Profiles: oem (Available profiles: oem) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X] SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM -> {357E9B8F-605E-4AFF-CADA-4DFCF6DD3856} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=HitachiXHTS547550A9E384_J2160051D69U8DD69U8DX&ts=1382182851&type=default&q={searchTerms} SearchScopes: HKLM-x32 -> {65E10DB0-FBF8-37EE-D6B6-2F31696E5398} URL = SearchScopes: HKU\S-1-5-21-1862378328-319157339-1045187305-1000 -> {357E9B8F-605E-4AFF-CADA-4DFCF6DD3856} URL = SearchScopes: HKU\S-1-5-21-1862378328-319157339-1045187305-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File Toolbar: HKLM-x32 - No Name - {7EACAC38-B7F6-4514-9DC1-3428A7964ABD} - No File Toolbar: HKU\S-1-5-21-1862378328-319157339-1045187305-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-1862378328-319157339-1045187305-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR HKLM-x32\...\Chrome\Extension: [pgafcinpmmpklohkojmllohdhomoefph] - C:\ProgramData\PC Performer Manager\2.3.811.154\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\pcpmngr.crx [Not Found] FF user.js: detected! => C:\Users\oem\AppData\Roaming\Mozilla\Firefox\Profiles\wbhnga9w.default\user.js [2015-03-17] Task: {088BB6DE-D020-4267-8303-3049A9A6D194} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1862378328-319157339-1045187305-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {4904BA0C-61FE-4467-A895-E87499848FAD} - System32\Tasks\{FF96E42F-164E-4585-91FD-DFB4393033D9} => Iexplore.exe http://ui.skype.com/ui/0/5.1.0.104.161/pl/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled Task: {60C0ED64-E8EB-493A-BDD0-EC8E75DE7D3A} - System32\Tasks\{3E5A2958-EED8-4F9F-B8B5-24727EFBBCA5} => Iexplore.exe http://ui.skype.com/ui/0/6.6.0.106/pl/abandoninstall?page=tsProgressBar Task: {7204C0C1-C84A-41D7-84C8-E0D4AEC34EB7} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1862378328-319157339-1045187305-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TUTO4PC C:\Users\oem\AppData\Local\{92B86CAD-DF93-4BB9-AD98-5B98501B4462} C:\Users\oem\AppData\Local\AnyProtectScannerSetup.exe C:\Users\Public\Desktop\Mozilla Firefox.lnk C:\Windows\SysWOW64\ezSharedSvcHost.exe Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\GTA: San Andreas Trailer Packages" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => value deleted successfully. ezSharedSvc => Service deleted successfully. MozillaMaintenance => Service not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{357E9B8F-605E-4AFF-CADA-4DFCF6DD3856}" => Key deleted successfully. HKCR\CLSID\{357E9B8F-605E-4AFF-CADA-4DFCF6DD3856} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{65E10DB0-FBF8-37EE-D6B6-2F31696E5398}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{65E10DB0-FBF8-37EE-D6B6-2F31696E5398} => Key not found. "HKU\S-1-5-21-1862378328-319157339-1045187305-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{357E9B8F-605E-4AFF-CADA-4DFCF6DD3856}" => Key deleted successfully. HKCR\CLSID\{357E9B8F-605E-4AFF-CADA-4DFCF6DD3856} => Key not found. "HKU\S-1-5-21-1862378328-319157339-1045187305-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key deleted successfully. HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7EACAC38-B7F6-4514-9DC1-3428A7964ABD} => value deleted successfully. HKCR\Wow6432Node\CLSID\{7EACAC38-B7F6-4514-9DC1-3428A7964ABD} => Key not found. HKU\S-1-5-21-1862378328-319157339-1045187305-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. HKU\S-1-5-21-1862378328-319157339-1045187305-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph" => Key deleted successfully. C:\Users\oem\AppData\Roaming\Mozilla\Firefox\Profiles\wbhnga9w.default\user.js => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{088BB6DE-D020-4267-8303-3049A9A6D194}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{088BB6DE-D020-4267-8303-3049A9A6D194}" => Key deleted successfully. C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1862378328-319157339-1045187305-1000 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeLogonTaskS-1-5-21-1862378328-319157339-1045187305-1000" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4904BA0C-61FE-4467-A895-E87499848FAD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4904BA0C-61FE-4467-A895-E87499848FAD}" => Key deleted successfully. C:\Windows\System32\Tasks\{FF96E42F-164E-4585-91FD-DFB4393033D9} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FF96E42F-164E-4585-91FD-DFB4393033D9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60C0ED64-E8EB-493A-BDD0-EC8E75DE7D3A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60C0ED64-E8EB-493A-BDD0-EC8E75DE7D3A}" => Key deleted successfully. C:\Windows\System32\Tasks\{3E5A2958-EED8-4F9F-B8B5-24727EFBBCA5} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3E5A2958-EED8-4F9F-B8B5-24727EFBBCA5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7204C0C1-C84A-41D7-84C8-E0D4AEC34EB7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7204C0C1-C84A-41D7-84C8-E0D4AEC34EB7}" => Key deleted successfully. C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1862378328-319157339-1045187305-1000 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1862378328-319157339-1045187305-1000" => Key deleted successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk" => File/Directory not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TUTO4PC" => File/Directory not found. C:\Users\oem\AppData\Local\{92B86CAD-DF93-4BB9-AD98-5B98501B4462} => Moved successfully. C:\Users\oem\AppData\Local\AnyProtectScannerSetup.exe => Moved successfully. "C:\Users\Public\Desktop\Mozilla Firefox.lnk" => File/Directory not found. C:\Windows\SysWOW64\ezSharedSvcHost.exe => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\GTA: San Andreas Trailer Packages" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 101.2 MB temporary data. The system needed a reboot. ==== End of Fixlog 19:05:10 ====