Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-09-2013 01 Ran by Maszek at 2013-09-21 09:56:34 Run:1 Running from C:\Users\Maszek\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Policies\Explorer\Run: [57128] - C:\ProgramData\Local Settings\Temp\msaiaiki.scr No File HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.pur-esult.info/?pid=724&r=2013/08/14&hid=999645584&lg=EN&cc=PL URLSearchHook: (No Name) - {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - No File SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pur-esult.info/?l=1&q={searchTerms}&pid=724&r=2013/08/14&hid=999645584&lg=EN&cc=PL SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pur-esult.info/?l=1&q={searchTerms}&pid=724&r=2013/08/14&hid=999645584&lg=EN&cc=PL SearchScopes: HKCU - {DBD02371-C42C-4b74-BD8D-DD9125E1BE5C} URL = http://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH SearchScopes: HKCU - {F26E41A3-C103-443f-9AC4-A1738C4C8907} URL = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV BHO-x32: savensharre - {4E8C55D3-CE03-AD4F-17D7-926BFBBE5A20} - C:\ProgramData\savensharre\yyQBgSn1.dll No File BHO-x32: Searchh-NewTTaab - {AE21E59C-1411-CD2C-EFE3-0BD70721BA1F} - C:\ProgramData\Searchh-NewTTaab\EV7.dll No File FF HKLM-x32\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}] - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} FF HKLM-x32\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}] - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} FF HKLM-x32\...\Firefox\Extensions: [{d9284e50-81fc-11da-a72b-0800200c9a66}] - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66 Task: {8729B8AC-2FC2-473D-9F48-51B71F7F73FA} - System32\Tasks\{2C1C98F2-5563-4C4C-8FEB-71922BF3165D} => C:\Users\Maszek\Downloads\Ted 2012 RMVB Lektor PL\Ted 2012 RMVB Lektor PL\Unpack.exe Task: {AEA114AB-01B9-4278-9BBD-6C28B5E1369E} - System32\Tasks\{1155CA6F-D9CF-487F-B9F6-DC6E718955E3} => C:\Users\Maszek\Downloads\Ted 2012 RMVB Lektor PL\Ted 2012 RMVB Lektor PL\Unpack.exe S3 catchme; \??\C:\ComboFix\catchme.sys [x] C:\Users\Maszek\AppData\Roaming\OpenCandy CMD: sc config "PLAY ONLINE. RunOuc" start= demand ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\57128 => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{0F3DC9E0-C459-4a40-BCF8-747BD9322E10} => Value deleted successfully. HKCR\CLSID\{0F3DC9E0-C459-4a40-BCF8-747BD9322E10} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key deleted successfully. HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DBD02371-C42C-4b74-BD8D-DD9125E1BE5C} => Key deleted successfully. HKCR\CLSID\{DBD02371-C42C-4b74-BD8D-DD9125E1BE5C} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F26E41A3-C103-443f-9AC4-A1738C4C8907} => Key deleted successfully. HKCR\CLSID\{F26E41A3-C103-443f-9AC4-A1738C4C8907} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E8C55D3-CE03-AD4F-17D7-926BFBBE5A20} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{4E8C55D3-CE03-AD4F-17D7-926BFBBE5A20} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE21E59C-1411-CD2C-EFE3-0BD70721BA1F} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{AE21E59C-1411-CD2C-EFE3-0BD70721BA1F} => Key deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} => Value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} => Value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{d9284e50-81fc-11da-a72b-0800200c9a66} => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8729B8AC-2FC2-473D-9F48-51B71F7F73FA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8729B8AC-2FC2-473D-9F48-51B71F7F73FA} => Key deleted successfully. C:\Windows\System32\Tasks\{2C1C98F2-5563-4C4C-8FEB-71922BF3165D} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2C1C98F2-5563-4C4C-8FEB-71922BF3165D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEA114AB-01B9-4278-9BBD-6C28B5E1369E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEA114AB-01B9-4278-9BBD-6C28B5E1369E} => Key deleted successfully. C:\Windows\System32\Tasks\{1155CA6F-D9CF-487F-B9F6-DC6E718955E3} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1155CA6F-D9CF-487F-B9F6-DC6E718955E3} => Key deleted successfully. catchme => Service deleted successfully. C:\Users\Maszek\AppData\Roaming\OpenCandy => Moved successfully. ========= sc config "PLAY ONLINE. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ==== End of Fixlog ====