Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013 Ran by szczepan at 2013-10-11 22:04:44 Run:2 Running from C:\Users\szczepan\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,userinit.exe HKCU\...\Run: [Easy Speed PC] - C:\Program Files\Probit Software\Easy Speed PC\ESPCLauncher.exe [148272 2013-03-18] (Probit Software LTD) SearchScopes: HKCU - URL http://isearch.babylon.com/?q={searchTerms}&affID=119370&babsrc=SP_ss_Btisdt4&mntrId=8CC9EE39DF59DA98 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {70BA3E6B-1059-2266-0B2C-40E4A85231B8} URL = http://www.ddlstart.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=750&product_id=872&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=PL&install_date=20120807&user_guid=47C0BF5EB06D450784CD0AC13F04F835&machine_id=f9a75c26771e596bca21e9ed38394831&browser=IE&os=win&os_version=6.1-x86-SP1&iesrc={referrer:source} CHR HKLM\...\Chrome\Extension: [gjokjdicpfckeiihaniimbbmhadclefc] - C:\Users\szczepan\AppData\Local\Google\Chrome\User Data\Default\Extensions\novo_price_comparison.crx CHR HKLM\...\Chrome\Extension: [hnofepcmbghfcimfbjicplikedjcnalm] - C:\Users\szczepan\AppData\Local\CouponsMalibu.crx CHR HKLM\...\Chrome\Extension: [kidmhllhjmmmnpbiaihafgchacpmokof] - C:\Program Files\Lyrmix\133.crx Task: {322A009B-E4BD-4B5E-981B-E70A62077289} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: {81722868-8104-405E-AD19-BC1766931BEC} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: {82276078-1D16-4F5F-966B-28FB8431FB7A} - System32\Tasks\BonanzaDealsUpdate => C:\Program Task: {85B0894E-EC46-453F-B65C-C8BBE798C7B6} - System32\Tasks\{32B95237-3F4D-4C8D-B03D-759F78D729C8} => C:\Users\szczepan\Desktop\Nowy folder (2)\StarCraft.exe Task: {8D542CD7-55E3-40FE-9493-684E9FF551C2} - System32\Tasks\{6A23AFE4-82E2-4176-AC8D-FA27E0547E32} => C:\Program Files\blueconnect\blueconnect.exe Task: {C750BD83-A54F-4885-94FB-DCC62DD597F3} - System32\Tasks\{85D5A970-15AE-4670-9EA8-EC2DB9A237AD} => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe Task: {EBE7EC39-B864-4A70-ACEB-B4220B59AE12} - System32\Tasks\Norton Security Scan for szczepan => C:\PROGRA~1\NORTON~2\Engine\351~1.6\Nss.exe [2012-04-03] (Symantec Corporation) Task: C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\windows\Tasks\Norton Security Scan for szczepan.job => C:\PROGRA~1\NORTON~2\Engine\351~1.6\Nss.exe HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x] S3 usbbus; system32\DRIVERS\lgusbbus.sys [x] C:\Program Files\4Shared Toolbar C:\Users\szczepan\AppData\Local\avgchrome C:\Users\szczepan\AppData\Local\CouponsMalibu.crx C:\Users\szczepan\Desktop\Search.lnk C:\Users\szczepan\Downloads\VuuPC_Setup.exe C:\Users\szczepan\AppData\Roaming\mozilla C:\Program Files\mozilla firefox Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\&4shared Search" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&4shared Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "BrowserMngr Start Page" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v Default_Search_URL /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Search Bar" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Search Page" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page Restore" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh advfirewall reset ***************** HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Easy Speed PC => Value not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => Value not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCR\Wow6432Node\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{70BA3E6B-1059-2266-0B2C-40E4A85231B8} => Key not found. HKCR\Wow6432Node\CLSID\{70BA3E6B-1059-2266-0B2C-40E4A85231B8} => Key not found. HKLM\SOFTWARE\Google\Chrome\Extensions\gjokjdicpfckeiihaniimbbmhadclefc => Key not found. "C:\Users\szczepan\AppData\Local\Google\Chrome\User Data\Default\Extensions\novo_price_comparison.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\hnofepcmbghfcimfbjicplikedjcnalm => Key not found. "C:\Users\szczepan\AppData\Local\CouponsMalibu.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\kidmhllhjmmmnpbiaihafgchacpmokof => Key not found. "C:\Program Files\Lyrmix\133.crx" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{322A009B-E4BD-4B5E-981B-E70A62077289} => Key not found. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81722868-8104-405E-AD19-BC1766931BEC} => Key not found. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82276078-1D16-4F5F-966B-28FB8431FB7A} => Key not found. C:\Windows\System32\Tasks\BonanzaDealsUpdate not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85B0894E-EC46-453F-B65C-C8BBE798C7B6} => Key not found. C:\Windows\System32\Tasks\{32B95237-3F4D-4C8D-B03D-759F78D729C8} not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{32B95237-3F4D-4C8D-B03D-759F78D729C8} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D542CD7-55E3-40FE-9493-684E9FF551C2} => Key not found. C:\Windows\System32\Tasks\{6A23AFE4-82E2-4176-AC8D-FA27E0547E32} not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6A23AFE4-82E2-4176-AC8D-FA27E0547E32} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C750BD83-A54F-4885-94FB-DCC62DD597F3} => Key not found. C:\Windows\System32\Tasks\{85D5A970-15AE-4670-9EA8-EC2DB9A237AD} not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{85D5A970-15AE-4670-9EA8-EC2DB9A237AD} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EBE7EC39-B864-4A70-ACEB-B4220B59AE12} => Key not found. C:\Windows\System32\Tasks\Norton Security Scan for szczepan not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Security Scan for szczepan => Key not found. C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job not found. C:\windows\Tasks\Norton Security Scan for szczepan.job not found. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => Key not found. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => Key not found. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => Key not found. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MCODS => Key not found. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MpfService => Key not found. hwdatacard => Service not found. hwusbdev => Service not found. usbbus => Service not found. "C:\Program Files\4Shared Toolbar" => File/Directory not found. "C:\Users\szczepan\AppData\Local\avgchrome" => File/Directory not found. "C:\Users\szczepan\AppData\Local\CouponsMalibu.crx" => File/Directory not found. "C:\Users\szczepan\Desktop\Search.lnk" => File/Directory not found. "C:\Users\szczepan\Downloads\VuuPC_Setup.exe" => File/Directory not found. "C:\Users\szczepan\AppData\Roaming\mozilla" => File/Directory not found. "C:\Program Files\mozilla firefox" => File/Directory not found. ========= reg delete HKCU\Software\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\mozilla.org /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\&4shared Search" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&4shared Search" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "BrowserMngr Start Page" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v Default_Page_URL /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v Default_Search_URL /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Search Bar" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Search Page" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page Restore" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====