Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 30-08-2013 01 Ran by Leszek at 2013-08-31 15:00:08 Run:1 Running from D:\Leszek\Documents\Z_Internetu\!_Diagnostyka www.fixtpc.pl\03_Farbar Recovery Scan Tool_FRST_ Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {0BF7AF5A-9C18-4A18-A079-AAED48EC5F98} - System32\Tasks\Updater26766.exe => C:\Users\Leszek\AppData\Local\Updater26766\Updater26766.exe [2013-04-28] (Innovative Apps) Task: {29E8A7D0-E243-4782-BBB1-B411D64625C4} - System32\Tasks\EPUpdater => C:\Users\Leszek\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [2013-08-04] () Task: {44DD896C-F8DD-4614-BFE9-BEAA64703F26} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{86AA4C4D-2311-4165-9FAC-DFB8C03C0045}.exe No File Task: {4F8BEB20-17F0-4529-9DC7-02C0E4131FEF} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{83E0D5A4-D9C6-4259-9990-863978F9841E}.exe No File Task: {C2305494-FF68-478D-ADC9-246085C64CCB} - System32\Tasks\DSite => C:\Users\Leszek\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [2013-08-31] () Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{83E0D5A4-D9C6-4259-9990-863978F9841E}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{86AA4C4D-2311-4165-9FAC-DFB8C03C0045}.exe Task: C:\Windows\Tasks\DSite.job => C:\Users\Leszek\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE HKCU\...\Run: [] - [x] HKCU\...\Run: [NTRedirect] - C:\Users\Leszek\AppData\Roaming\BabSolution\Shared\enhancedNT.dll [187888 2013-08-22] () HKCU\...\Runonce: [Del5544500] - cmd.exe /Q /D /c del "C:\Users\Leszek\AppData\Local\Temp\0.del" [x] HKLM\...\Runonce: [Del5544500] - cmd.exe /Q /D /c del "C:\Users\Leszek\AppData\Local\Temp\0.del" [x] HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=6433001E101F82A0&affID=119357&tsp=4991 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=vlt&from=vlt&uid=ST3250823AS_3ND1MG3S____3ND1MG3S&ts=1351463222 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=6433001E101F82A0&affID=119357&tsp=4991 SearchScopes: HKLM - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm073YYpl&ptnrS=HJxdm073YYpl&si=pconverter&ptb=1C287CA9-E314-4BEA-BBB7-B6F181ABF07A&ind=2012110200&n=77ee5d78&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=6433001E101F82A0&affID=119357&tsp=4991 SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=6433001E101F82A0&affID=119357&tsp=4991 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={1561FCCC-7DB1-425E-81DB-0137A7047536}&mid=5a9b3c72dab3480db8d203db7ebf2128-06217255473e678a0327a943cf1f87f9c4774acd&lang=pl&ds=ax011&pr=&d=2012-11-02 06:00:51&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm073YYpl&ptnrS=HJxdm073YYpl&si=pconverter&ptb=1C287CA9-E314-4BEA-BBB7-B6F181ABF07A&ind=2012110200&n=77ee5d78&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb203?a=6PQO2IHPTu&search={searchTerms}&i=26 FF Plugin: @VideoDownloadConverter_4z.com/Plugin - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll (MindSpark) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\IB Updater\Firefox FF HKLM\...\Firefox\Extensions: [4zffxtbr@VideoDownloadConverter_4z.com] C:\Program Files\VideoDownloadConverter_4z\bar\1.bin FF HKLM\...\Firefox\Extensions: [avg@toolbar] C:\ProgramData\AVG Secure Search\FireFoxExt\15.5.0.2 FF HKLM\...\Firefox\Extensions: [{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}] C:\Program Files\IB Updater\Firefox FF HKCU\...\Firefox\Extensions: [{58bd07eb-0ee0-4df0-8121-dc9b693373df}] C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx CHR HKLM\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Leszek\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM\...\Chrome\Extension: [ieakfmpjhljbpbfpldjkddkjmmgjmgon] - C:\Program Files\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\15.5.0.2\avg.crx CHR HKLM\...\Chrome\Extension: [pgafcinpmmpklohkojmllohdhomoefph] - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.crx S3 catchme; \??\C:\Users\Leszek\AppData\Local\Temp\catchme.sys [x] C:\Users\Leszek\AppData\Local\Updater26766 C:\Users\Leszek\AppData\Roaming\BabSolution C:\Users\Leszek\AppData\Roaming\DSite ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BF7AF5A-9C18-4A18-A079-AAED48EC5F98} => Key not found. C:\Windows\System32\Tasks\Updater26766.exe not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater26766.exe => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29E8A7D0-E243-4782-BBB1-B411D64625C4} => Key not found. C:\Windows\System32\Tasks\EPUpdater not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{44DD896C-F8DD-4614-BFE9-BEAA64703F26} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44DD896C-F8DD-4614-BFE9-BEAA64703F26} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4F8BEB20-17F0-4529-9DC7-02C0E4131FEF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F8BEB20-17F0-4529-9DC7-02C0E4131FEF} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C2305494-FF68-478D-ADC9-246085C64CCB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2305494-FF68-478D-ADC9-246085C64CCB} => Key deleted successfully. C:\Windows\System32\Tasks\DSite => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Windows\Tasks\DSite.job => Moved successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NTRedirect => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del5544500 => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del5544500 => Value not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key not found. HKLM\Software\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin => Key not found. C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll not found. "C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml" => not found. "C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml" => not found. HKLM\Software\Mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} => Value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\4zffxtbr@VideoDownloadConverter_4z.com => Value not found. HKLM\Software\Mozilla\Firefox\Extensions\\avg@toolbar => Value not found. HKLM\Software\Mozilla\Firefox\Extensions\\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052} => Value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\{58bd07eb-0ee0-4df0-8121-dc9b693373df} => Value not found. HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd => Key deleted successfully. "C:\Program Files\IB Updater\source.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde => Key not found. "C:\Users\Leszek\AppData\Roaming\BabSolution\CR\Delta.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon => Key not found. "C:\Program Files\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof => Key not found. "C:\ProgramData\AVG Secure Search\ChromeExt\15.5.0.2\avg.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph => Key not found. "C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.crx" => File/Directory not found. catchme => Service deleted successfully. "C:\Users\Leszek\AppData\Local\Updater26766" => File/Directory not found. "C:\Users\Leszek\AppData\Roaming\BabSolution" => File/Directory not found. "C:\Users\Leszek\AppData\Roaming\DSite" directory move: C:\Users\Leszek\AppData\Roaming\DSite\UpdateProc\config.dat => Moved successfully. C:\Users\Leszek\AppData\Roaming\DSite\UpdateProc\TTL.DAT => Moved successfully. Could not move "C:\Users\Leszek\AppData\Roaming\DSite" directory. => Scheduled to move on reboot. =========== Result of Scheduled Files to move =========== "C:\Users\Leszek\AppData\Roaming\DSite" => Directory could not move. ==== End of Fixlog ====