Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013 Ran by Bartosz at 2013-10-12 22:34:45 Run:1 Running from C:\Users\Bartosz\Desktop\frs Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [] - [x] AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll [ ] () URLSearchHook: (No Name) - {e9df9360-97f8-4690-afe6-996c80790da4} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://en.v9.com/?utm_source=b&utm_medium=bnd&utm_campaign=eXQ&utm_content=sc&from=bnd&uid=SAMSUNGXHD103SJ_S246J9EZC02859&ts=1381068392 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&utm_campaign=eXQ&utm_content=ds&from=bnd&uid=SAMSUNGXHD103SJ_S246J9EZC02859&ts=1381068394&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&utm_campaign=eXQ&utm_content=ds&from=bnd&uid=SAMSUNGXHD103SJ_S246J9EZC02859&ts=1381068394&type=default&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?src=sp&aff=67&cf=d46d0707-b1cb-11e2-a345-00112fa6f7db&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://startsear.ch/?src=sp&aff=67&cf=d46d0707-b1cb-11e2-a345-00112fa6f7db&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=AEFE00112FA6F7DB&affID=121565&tsp=5026 SearchScopes: HKCU - {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL = BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File Toolbar: HKCU - No Name - {E9DF9360-97F8-4690-AFE6-996C80790DA4} - No File FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://en.v9.com/?utm_source=b&utm_medium=bnd&utm_campaign=eXQ&utm_content=sc&from=bnd&uid=SAMSUNGXHD103SJ_S246J9EZC02859&ts=1381068392 Task: {8AA5C1C0-EB53-45C4-9F87-5ADA77DB5B78} - System32\Tasks\{410EF69F-1CCC-4EA6-8A12-F037A3553350} => C:\Users\Bartosz\Desktop\PKP\POZNAN93.EXE Task: {94072150-89C4-486B-8693-07E5312785D9} - System32\Tasks\BitGuard => Sc.exe start BitGuard Task: {B169761C-EBB0-4A4A-99F3-A1E67C9D7453} - System32\Tasks\{16562AB8-F523-43D1-8FA0-F2B5D5DA657C} => C:\Users\Bartosz\Desktop\PKP\POZNAN93.EXE Task: {C232563D-5091-4547-A85C-3A4FC0F0AE00} - System32\Tasks\EPUpdater => C:\Users\Bartosz\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe Task: {CFEEE10D-F9C4-4193-8883-FC48B7CD3D91} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] C:\Windows\SysWOW64\searchplugins C:\Users\Bartosz\AppData\Local\avgchrome C:\Users\Bartosz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard C:\ProgramData\DSearchLink C:\ProgramData\BitGuard ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{e9df9360-97f8-4690-afe6-996c80790da4} => Value deleted successfully. HKCR\CLSID\{e9df9360-97f8-4690-afe6-996c80790da4} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a5b9c0f5-5616-47cd-a95f-e43b488faccf} => Key deleted successfully. HKCR\CLSID\{a5b9c0f5-5616-47cd-a95f-e43b488faccf} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E9DF9360-97F8-4690-AFE6-996C80790DA4} => Value deleted successfully. HKCR\CLSID\{E9DF9360-97F8-4690-AFE6-996C80790DA4} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8AA5C1C0-EB53-45C4-9F87-5ADA77DB5B78} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8AA5C1C0-EB53-45C4-9F87-5ADA77DB5B78} => Key deleted successfully. C:\Windows\System32\Tasks\{410EF69F-1CCC-4EA6-8A12-F037A3553350} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{410EF69F-1CCC-4EA6-8A12-F037A3553350} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{94072150-89C4-486B-8693-07E5312785D9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94072150-89C4-486B-8693-07E5312785D9} => Key deleted successfully. C:\Windows\System32\Tasks\BitGuard => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B169761C-EBB0-4A4A-99F3-A1E67C9D7453} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B169761C-EBB0-4A4A-99F3-A1E67C9D7453} => Key deleted successfully. C:\Windows\System32\Tasks\{16562AB8-F523-43D1-8FA0-F2B5D5DA657C} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{16562AB8-F523-43D1-8FA0-F2B5D5DA657C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C232563D-5091-4547-A85C-3A4FC0F0AE00} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C232563D-5091-4547-A85C-3A4FC0F0AE00} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CFEEE10D-F9C4-4193-8883-FC48B7CD3D91} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CFEEE10D-F9C4-4193-8883-FC48B7CD3D91} => Key deleted successfully. C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar => Key deleted successfully. EagleX64 => Service deleted successfully. C:\Windows\SysWOW64\searchplugins => Moved successfully. C:\Users\Bartosz\AppData\Local\avgchrome => Moved successfully. "C:\Users\Bartosz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard" directory move: C:\Users\Bartosz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard\Uninstall BitGuard.lnk => Moved successfully. Could not move "C:\Users\Bartosz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard" directory. => Scheduled to move on reboot. C:\ProgramData\DSearchLink => Moved successfully. "C:\ProgramData\BitGuard" directory move: C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.settings => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\uninstall.exe => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22 => Moved successfully. C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23 => Moved successfully. Could not move "C:\ProgramData\BitGuard" directory. => Scheduled to move on reboot. =========== Result of Scheduled Files to move =========== "C:\Users\Bartosz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard" => Directory could not move. "C:\ProgramData\BitGuard" => Directory could not move. ==== End of Fixlog ====