Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-07-2013 Ran by Marta at 2013-07-04 13:51:01 Run:1 Running from C:\Users\Marta\Desktop\Programy Boot Mode: Normal ============================================== HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key deleted successfully. HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKCR\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{776339FC-C55F-E3A8-67CD-1F793A747BA6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{776339FC-C55F-E3A8-67CD-1F793A747BA6} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} => Key deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Yontoo Desktop] "C:\Users\Marta\AppData\Roaming\Yontoo\YontooDesktop.exe" [42784 2013-05-01 => Value not found. Yontoo Desktop Updater => Service deleted successfully. BrowserProtect => Service deleted successfully. SpyHunter 4 Service => Service deleted successfully. catchme => Service deleted successfully. ewusbmbb => Service deleted successfully. ew_hwusbdev => Service deleted successfully. ew_usbenumfilter => Service deleted successfully. huawei_enumerator => Service deleted successfully. hwdatacard => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{05B8D652-6EEF-4276-9789-863DD537E504} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05B8D652-6EEF-4276-9789-863DD537E504} => Key deleted successfully. C:\Windows\System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sony Corporation\VAIO Smart Network\VSN Logon Start => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{21CD3934-8A32-491F-BEA1-1027E5776751} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21CD3934-8A32-491F-BEA1-1027E5776751} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25C886B3-0463-46D0-97E5-A8730DD79401} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25C886B3-0463-46D0-97E5-A8730DD79401} => Key deleted successfully. C:\Windows\System32\Tasks\GoforFilesUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{52B5D090-68B3-454A-BA00-3DAA44438D85} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52B5D090-68B3-454A-BA00-3DAA44438D85} => Key deleted successfully. C:\Windows\System32\Tasks\YourFile DownloaderUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile DownloaderUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6301EBBB-F931-4D6F-ADD0-6C6747CEBCC7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6301EBBB-F931-4D6F-ADD0-6C6747CEBCC7} => Key deleted successfully. C:\Windows\System32\Tasks\VHDInformationCheck => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\VHDInformationCheck => Key deleted successfully. ========= reg add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t REG_SZ /d about:blank /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "bProtector Start Page" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v bProtectorDefaultScope /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Mozilla" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\MozillaPlugins" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\MozillaPlugins" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Mozilla" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\mozilla.org" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\MozillaPlugins" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= C:\Program Files\Enigma Software Group => Moved successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. "C:\Program Files (x86)\Yontoo" => File/Directory not found. C:\ProgramData\BrowserProtect => Moved successfully. C:\ProgramData\InstallMate => Moved successfully. C:\ProgramData\McAfee => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee => Moved successfully. C:\Users\Marta\AppData\Roaming\BabSolution => Moved successfully. C:\Users\Marta\AppData\Roaming\Babylon => Moved successfully. C:\Users\Marta\AppData\Roaming\Complitly => Moved successfully. C:\Users\Marta\AppData\Roaming\File Scout => Moved successfully. C:\Users\Marta\AppData\Roaming\GoforFiles => Moved successfully. C:\Users\Marta\AppData\Roaming\mozilla => Moved successfully. C:\Users\Marta\AppData\Roaming\SendSpace => Moved successfully. C:\Users\Marta\AppData\Roaming\Yontoo => Moved successfully. C:\Users\Marta\AppData\Roaming\YourFileDownloader => Moved successfully. "C:\Users\Marta\Downloads\Safari(13196).exe" => File/Directory not found. "C:\Users\Marta\Downloads\1.3.2 (1) (2).crx" => File/Directory not found. "C:\Users\Marta\Downloads\Niepotwierdzony 684217.crdownload" => File/Directory not found. "C:\Users\Marta\Downloads\1.3.2 (1) (1).crx" => File/Directory not found. "C:\Users\Marta\Downloads\1.3.2.crx" => File/Directory not found. "C:\Users\Marta\Downloads\1370615499_359.data" => File/Directory not found. C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP => Moved successfully. ==== End of Fixlog ====