Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Dariusz at 2015-04-02 22:38:12 Run:3 Running from C:\Users\Dariusz\Downloads Loaded Profiles: UpdatusUser & Dariusz (Available profiles: UpdatusUser & Dariusz) Boot Mode: Normal ============================================== Content of fixlist: ***************** Reg: reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /s ***************** ========= reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /s ========= HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon LegalNoticeText REG_SZ Shell REG_SZ explorer.exe LegalNoticeCaption REG_SZ DebugServerCommand REG_SZ no ForceUnlockLogon REG_DWORD 0x0 ReportBootOk REG_SZ 1 VMApplet REG_SZ SystemPropertiesPerformance.exe /pagefile AutoRestartShell REG_DWORD 0x1 PowerdownAfterShutdown REG_SZ 0 ShutdownWithoutLogon REG_SZ 0 Background REG_SZ 0 0 0 PasswordExpiryWarning REG_DWORD 0x5 CachedLogonsCount REG_SZ 10 WinStationsDisabled REG_SZ 0 PreCreateKnownFolders REG_SZ {A520A1A4-1780-4FF6-BD18-167343C5AF16} scremoveoption REG_SZ 0 ShutdownFlags REG_DWORD 0x7 EnableFirstLogonAnimation REG_DWORD 0x1 AutoLogonSID REG_SZ S-1-5-32 LastUsedUsername REG_SZ Userinit REG_SZ C:\Windows\System32\Userinit.exe, AutoAdminLogon REG_SZ 0 DefaultUserName REG_SZ MicrosoftAccount\dariuisz-dop@wp.pl DisableCad REG_DWORD 0x1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AlternateShells HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63} (Default) REG_SZ Wireless Group Policy DllName REG_EXPAND_SZ wlgpclnt.dll GenerateGroupPolicy REG_SZ GenerateWLANPolicy ProcessGroupPolicyEx REG_SZ ProcessWLANPolicyEx NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @wlgpclnt.dll,-100 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{16be69fa-4209-4250-88cb-716cf41954e0} (Default) REG_SZ Central Access Policy Configuration DllName REG_EXPAND_SZ auditcse.dll GenerateGroupPolicy REG_SZ GenerateGroupPolicyCap ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExCap ForceRefreshFG REG_DWORD 0x0 MaxNoGPOListChangesInterval REG_DWORD 0x78 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @auditcse.dll,-4000 EnableAsynchronousProcessing REG_DWORD 0x1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861} (Default) REG_SZ Folder Redirection DllName REG_EXPAND_SZ fdeploy.dll GenerateGroupPolicy REG_SZ GenerateGroupPolicy NoSlowLink REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx NoGPOListChanges REG_DWORD 0x0 EventSources REG_MULTI_SZ (Folder Redirection,Application) NoMachinePolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @fdeploy.dll,-261 PerUserLocalSettings REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2} HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66} (Default) REG_SZ Microsoft Disk Quota ProcessGroupPolicy REG_SZ ProcessGroupPolicy DllName REG_EXPAND_SZ %SystemRoot%\System32\dskquota.dll RequiresSuccessfulRegistry REG_DWORD 0x1 NoSlowLink REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 NoMachinePolicy REG_DWORD 0x0 DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\dskquota.dll,-100 PerUserLocalSettings REG_DWORD 0x0 EnableAsynchronousProcessing REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39} (Default) REG_SZ QoS Packet Scheduler ProcessGroupPolicy REG_SZ ProcessPSCHEDPolicy DllName REG_EXPAND_SZ gptext.dll NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @gptext.dll,-201 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d} (Default) REG_SZ Remote Desktop USB Redirection DllName REG_EXPAND_SZ %SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll RequiresSuccessfulRegistry REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll,-100 NoBackgroundPolicy REG_DWORD 0x0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3} (Default) REG_SZ Internet Explorer Zonemapping ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap DllName REG_SZ C:\Windows\System32\iedkcs32.dll RequiresSuccessfulRegistry REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4D2F9B6F-1E52-4711-A382-6A8B1A003DE6} DllName REG_SZ C:\Windows\System32\tsworkspace.dll ProcessGroupPolicyEx REG_SZ RADCProcessGroupPolicyEx NoMachinePolicy REG_DWORD 0x1 PerUserLocalSettings REG_DWORD 0x1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4d968b55-cac2-4ff5-983f-0a54603781a3} (Default) REG_SZ Work Folders ProcessGroupPolicy REG_SZ ProcessGroupPolicy DllName REG_EXPAND_SZ WorkFoldersGPExt.dll RequiresSuccessfulRegistry REG_DWORD 0x1 NoSlowLink REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 DisplayName REG_EXPAND_SZ @WorkFoldersGPExt.dll,-261 PerUserLocalSettings REG_DWORD 0x0 EnableAsynchronousProcessing REG_DWORD 0x0 NoBackgroundPolicy REG_DWORD 0x0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93} (Default) REG_SZ Windows Search Group Policy Extension ProcessGroupPolicy REG_SZ ProcessGroupPolicy DllName REG_EXPAND_SZ %SystemRoot%\System32\srchadmin.dll RequiresSuccessfulRegistry REG_DWORD 0x1 NoSlowLink REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 PerUserLocalSettings REG_DWORD 0x0 EnableAsynchronousProcessing REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE} (Default) REG_SZ Internet Explorer User Accelerators ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities DllName REG_SZ C:\Windows\System32\iedkcs32.dll RequiresSuccessfulRegistry REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx NoGPOListChanges REG_DWORD 0x1 DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A} (Default) REG_SZ Security ExtensionRsopPlanningDebugLevel REG_DWORD 0x1 ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO DllName REG_EXPAND_SZ scecli.dll GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx NoGPOListChanges REG_DWORD 0x1 MaxNoGPOListChangesInterval REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @(runtime.system32)\scecli.dll,-7650 ExtensionDebugLevel REG_DWORD 0x0 EnableAsynchronousProcessing REG_DWORD 0x1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{8A28E2C5-8D06-49A4-A08C-632DAA493E17} (Default) REG_SZ Deployed Printer Connections ProcessGroupPolicy REG_SZ PrinterProcessGroupPolicy DllName REG_EXPAND_SZ %systemroot%\system32\gpprnext.dll GenerateGroupPolicy REG_SZ PrinterGenerateGroupPolicy RequiresSuccessfulRegistry REG_DWORD 0x0 ExtensionEventSource REG_SZ NoSlowLink REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ PrinterProcessGroupPolicyEx MaxNoGPOListChangesInterval REG_DWORD 0x0 NoGPOListChanges REG_DWORD 0x0 NotifyLinkTransition REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x0 NoMachinePolicy REG_DWORD 0x0 DisplayName REG_EXPAND_SZ @%systemroot%\system32\gpprnext.dll,-1 PerUserLocalSettings REG_DWORD 0x0 EnableAsynchronousProcessing REG_DWORD 0x1 NoBackgroundPolicy REG_DWORD 0x0 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053} (Default) REG_SZ 802.3 Group Policy DllName REG_EXPAND_SZ dot3gpclnt.dll GenerateGroupPolicy REG_SZ GenerateLANPolicy ProcessGroupPolicyEx REG_SZ ProcessLANPolicyEx NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @dot3gpclnt.dll,-100 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BA649533-0AAC-4E04-B9BC-4DBAE0325B12} (Default) REG_SZ Windows To Go Startup Options ProcessGroupPolicy REG_SZ ProcessLauncherGroupPolicy DllName REG_EXPAND_SZ pwlauncher.dll RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C34B2751-1CF4-44F5-9262-C3FC39666591} (Default) REG_SZ Windows To Go Hibernate Options ProcessGroupPolicy REG_SZ ProcessHibernateGroupPolicy DllName REG_EXPAND_SZ pwlauncher.dll RequiresSuccessfulRegistry REG_DWORD 0x1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{cdeafc3d-948d-49dd-ab12-e578ba4af7aa} (Default) REG_SZ TCPIP ProcessGroupPolicy REG_SZ ProcessTCPIPPolicy DllName REG_EXPAND_SZ gptext.dll RequiresSuccessfulRegistry REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @gptext.dll,-204 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} (Default) REG_SZ Internet Explorer Machine Accelerators ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities DllName REG_SZ C:\Windows\System32\iedkcs32.dll RequiresSuccessfulRegistry REG_DWORD 0x1 ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx NoGPOListChanges REG_DWORD 0x1 DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27} (Default) REG_SZ IP Security DllName REG_EXPAND_SZ %SystemRoot%\System32\polstore.dll GenerateGroupPolicy REG_SZ GenerateIPSECPolicy ProcessGroupPolicyEx REG_SZ ProcessIPSECPolicyEx NoGPOListChanges REG_DWORD 0x0 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @C:\Windows\System32\polstore.dll,-5012 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a} (Default) REG_SZ Audit Policy Configuration DllName REG_EXPAND_SZ auditcse.dll GenerateGroupPolicy REG_SZ GenerateGroupPolicy ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx ForceRefreshFG REG_DWORD 0x0 MaxNoGPOListChangesInterval REG_DWORD 0x3c0 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @auditcse.dll,-3000 EnableAsynchronousProcessing REG_DWORD 0x1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C} (Default) REG_SZ Enterprise QoS ProcessGroupPolicy REG_SZ ProcessEQoSPolicy DllName REG_EXPAND_SZ gptext.dll RequiresSuccessfulRegistry REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @gptext.dll,-203 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f} (Default) REG_SZ CP ProcessGroupPolicy REG_SZ ProcessConnectivityPlatformPolicy DllName REG_EXPAND_SZ gptext.dll RequiresSuccessfulRegistry REG_DWORD 0x1 NoGPOListChanges REG_DWORD 0x1 NoUserPolicy REG_DWORD 0x1 DisplayName REG_EXPAND_SZ @gptext.dll,-205 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui (Default) REG_SZ DLLName REG_SZ igfxdev.dll Asynchronous REG_DWORD 0x1 Impersonate REG_DWORD 0x1 Unlock REG_SZ WinlogonUnlockEvent HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoLogonChecked ========= End of Reg: ========= ==== End of Fixlog 22:38:13 ====