Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-09-2013 01 Ran by Michał Szczerba at 2013-09-12 00:10:13 Run:1 Running from G:\Programy\Programy do usówania wirusów Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [NPSStartup] - [x] HKLM\...\Run: [UserFaultCheck] - %systemroot%\system32\dumprep 0 -u HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k MountPoints2: {5d0ac082-9377-11df-9b5d-0026821539c1} - 09lf.exe MountPoints2: {ca4ad88c-bdf4-11e0-9cd1-0026821539c1} - keyboard/flash.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=119998&babsrc=HP_ss&mntrId=3c4f16fa0000000000000026821539c1 URLSearchHook: NCH Toolbar - {c2db4fe6-8409-45ce-8010-189a7b5cce86} - E:\Program Files\NCH\prxtbNCH.dll (Conduit Ltd.) BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - E:\Documents and Settings\Michał Szczerba\Dane aplikacji\Complitly\Complitly.dll (SimplyGen) BHO: NCH Toolbar - {c2db4fe6-8409-45ce-8010-189a7b5cce86} - E:\Program Files\NCH\prxtbNCH.dll (Conduit Ltd.) Toolbar: HKLM - NCH Toolbar - {c2db4fe6-8409-45ce-8010-189a7b5cce86} - E:\Program Files\NCH\prxtbNCH.dll (Conduit Ltd.) Toolbar: HKCU -NCH Toolbar - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - E:\Program Files\NCH\prxtbNCH.dll (Conduit Ltd.) FF SearchPlugin: E:\Program Files\mozilla firefox\searchplugins\babylon.xml Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Google" /f Reg: reg delete "HKCU\Software\Google" /f CMD: rd /s /q "%userprofile%\Ustawienia lokalne\Dane aplikacji\Google" CMD: del /q "%userprofile%\Pulpit\Dr.WEB-CureIt(12976).exe" ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d0ac082-9377-11df-9b5d-0026821539c1} => Key deleted successfully. HKCR\CLSID\{5d0ac082-9377-11df-9b5d-0026821539c1} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ca4ad88c-bdf4-11e0-9cd1-0026821539c1} => Key deleted successfully. HKCR\CLSID\{ca4ad88c-bdf4-11e0-9cd1-0026821539c1} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{c2db4fe6-8409-45ce-8010-189a7b5cce86} => Value deleted successfully. HKCR\CLSID\{c2db4fe6-8409-45ce-8010-189a7b5cce86} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0} => Key deleted successfully. HKCR\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2db4fe6-8409-45ce-8010-189a7b5cce86} => Key deleted successfully. HKCR\CLSID\{c2db4fe6-8409-45ce-8010-189a7b5cce86} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{c2db4fe6-8409-45ce-8010-189a7b5cce86} => Value deleted successfully. HKCR\CLSID\{c2db4fe6-8409-45ce-8010-189a7b5cce86} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C2DB4FE6-8409-45CE-8010-189A7B5CCE86} => Value deleted successfully. HKCR\CLSID\{C2DB4FE6-8409-45CE-8010-189A7B5CCE86} => Key not found. E:\Program Files\mozilla firefox\searchplugins\babylon.xml => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Google" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKCU\Software\Google" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= rd /s /q "%userprofile%\Ustawienia lokalne\Dane aplikacji\Google" ========= ========= End of CMD: ========= ========= del /q "%userprofile%\Pulpit\Dr.WEB-CureIt(12976).exe" ========= ========= End of CMD: ========= ==== End of Fixlog ====