Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-02-2015 Ran by Agata at 2015-03-01 20:22:00 Run:1 Running from C:\Users\Agata\Desktop Loaded Profiles: Agata (Available profiles: UpdatusUser & Agata) Boot Mode: Normal ============================================== Content of fixlist: ***************** BHO-x32: Strong Signal -> {c723a437-2eaf-466d-a95b-3fa0966bf88c} -> C:\Program Files (x86)\Strong Signal\Extensions\c723a437-2eaf-466d-a95b-3fa0966bf88c.dll No File C:\Program Files (x86)\Strong Signal FF Extension: Strong Signal - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\p4x1b0o6.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi [2015-02-20] C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce C:\ProgramData\86998342-aefb-4bdb-96ce-74be1e808b51 Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f HKU\S-1-5-21-764476694-2557174591-1451818591-1002\...\Run: [Power2GoExpress] => NA HKU\S-1-5-21-764476694-2557174591-1451818591-1002\...\Policies\Explorer: [] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION SearchScopes: HKU\S-1-5-21-764476694-2557174591-1451818591-1002 -> DefaultScope {F31DF832-D5AC-4EAC-9CC4-AAE9A662776D} URL = SearchScopes: HKU\S-1-5-21-764476694-2557174591-1451818591-1002 -> {F31DF832-D5AC-4EAC-9CC4-AAE9A662776D} URL = FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\mcafee\msc\npMcSnFFPl64.dll No File FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll No File FF SearchPlugin: C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\p4x1b0o6.default\searchplugins\conduit-search.xml FF Extension: uTorrentControl_v6 - C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\p4x1b0o6.default\Extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} [2013-12-29] R2 MaintainerSvc2.48.1114611; C:\ProgramData\86998342-aefb-4bdb-96ce-74be1e808b51\maintainer.exe [123632 2015-03-01] () R1 {2169981c-4403-4a8d-a144-e936eff23fce}Gw64; C:\Windows\System32\drivers\{2169981c-4403-4a8d-a144-e936eff23fce}Gw64.sys [48784 2014-10-29] (StdLib) R1 {3d0ff4a0-421f-4b33-a4ec-b4f95b34c8de}Gw64; C:\Windows\System32\drivers\{3d0ff4a0-421f-4b33-a4ec-b4f95b34c8de}Gw64.sys [48784 2014-10-25] (StdLib) R1 {bb095371-c900-4f52-bddd-25e46ecbe406}Gw64; C:\Windows\System32\drivers\{bb095371-c900-4f52-bddd-25e46ecbe406}Gw64.sys [48784 2014-10-26] (StdLib) R1 {e0c89f91-0178-4464-8daf-bec566dd2d9a}Gw64; C:\Windows\System32\drivers\{e0c89f91-0178-4464-8daf-bec566dd2d9a}Gw64.sys [48784 2014-11-01] (StdLib) C:\Users\Agata\Downloads\WinRAR(12398)-dp(1).exe C:\Users\Agata\Downloads\WinRAR(12398)-dp.exe EmptyTemp: ***************** "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c723a437-2eaf-466d-a95b-3fa0966bf88c}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{c723a437-2eaf-466d-a95b-3fa0966bf88c}" => Key deleted successfully. "C:\Program Files (x86)\Strong Signal" => File/Directory not found. C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\p4x1b0o6.default\Extensions\{b0831b08-26e0-4e79-be2c-d45ab7387aaf}.xpi => Moved successfully. "C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce" => File/Directory not found. C:\ProgramData\86998342-aefb-4bdb-96ce-74be1e808b51 => Moved successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= HKU\S-1-5-21-764476694-2557174591-1451818591-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Power2GoExpress => value deleted successfully. HKU\S-1-5-21-764476694-2557174591-1451818591-1002\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value deleted successfully. C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully. C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKU\S-1-5-21-764476694-2557174591-1451818591-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-764476694-2557174591-1451818591-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F31DF832-D5AC-4EAC-9CC4-AAE9A662776D}" => Key deleted successfully. HKCR\CLSID\{F31DF832-D5AC-4EAC-9CC4-AAE9A662776D} => Key not found. "HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/MSC,version=10" => Key deleted successfully. "C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\p4x1b0o6.default\searchplugins\conduit-search.xml" => not found. C:\Users\Agata\AppData\Roaming\Mozilla\Firefox\Profiles\p4x1b0o6.default\Extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} => Moved successfully. MaintainerSvc2.48.1114611 => Service not found. {2169981c-4403-4a8d-a144-e936eff23fce}Gw64 => Service not found. {3d0ff4a0-421f-4b33-a4ec-b4f95b34c8de}Gw64 => Service not found. {bb095371-c900-4f52-bddd-25e46ecbe406}Gw64 => Service not found. {e0c89f91-0178-4464-8daf-bec566dd2d9a}Gw64 => Service not found. C:\Users\Agata\Downloads\WinRAR(12398)-dp(1).exe => Moved successfully. C:\Users\Agata\Downloads\WinRAR(12398)-dp.exe => Moved successfully. EmptyTemp: => Removed 7.5 GB temporary data. The system needed a reboot. ==== End of Fixlog 20:24:28 ====