Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013 Ran by Zosia at 2013-10-15 11:47:30 Run:1 Running from C:\Documents and Settings\Zosia\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Documents and Settings\Zosia\Dane aplikacji\Xyqmqj.exe C:\Documents and Settings\Administrator\7f198769-8050.exe C:\Documents and Settings\Administrator\Dane aplikacji\AV Security Essentials C:\Documents and Settings\All Users\Dane aplikacji\Ask C:\Documents and Settings\All Users\Dane aplikacji\AVBHTCTSE C:\Documents and Settings\All Users\Dane aplikacji\e0be4b C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Babylon C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Common Files C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\MFAData C:\Documents and Settings\Zosia\Dane aplikacji\ArcaVirMicroScan C:\Documents and Settings\Zosia\Dane aplikacji\BabSolution C:\Documents and Settings\Zosia\Dane aplikacji\Babylon C:\Documents and Settings\Zosia\Dane aplikacji\Delta C:\Documents and Settings\Zosia\Ustawienia lokalne\Dane aplikacji\MFAData C:\Documents and Settings\Zosia\Ustawienia lokalne\Dane aplikacji\Avg2013 C:\WINDOWS\Tasks\EPUpdater.job C:\WINDOWS\005207_.tmp HKU\Administrator\...\Run: [AV Security Essentials] - C:\Documents and Settings\All Users\Dane aplikacji\e0be4b\AVe0b_8050.exe [ 2012-02-06] () HKU\Administrator\...\Run: [Skype] - "F:\Nowy folder\Phone\Skype.exe" /nosplash /minimized HKU\Administrator\...\Run: [TransBar] - C:\WINDOWS\TransBar.exe /s HKLM\...\Runonce: [] - [x] HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?affID=121845&tt=220413_d9114&babsrc=HP_ss&mntrId=DC1000E07D980FCC HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = pl.v9.com/ins/ins_1329232202_146034 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID=121845&tt=220413_d9114&babsrc=SP_ss&mntrId=DC1000E07D980FCC BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.16.16\bh\delta.dll (Delta-search.com) Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.16.16\deltaTlbr.dll (Delta-search.com) Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Xyqmqj /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java" /f ***************** Could not move "C:\Documents and Settings\Zosia\Dane aplikacji\Xyqmqj.exe" => Scheduled to move on reboot. C:\Documents and Settings\Administrator\7f198769-8050.exe => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\AV Security Essentials => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Ask => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\AVBHTCTSE => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\e0be4b => Moved successfully. C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Common Files => Moved successfully. C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\MFAData => Moved successfully. C:\Documents and Settings\Zosia\Dane aplikacji\ArcaVirMicroScan => Moved successfully. C:\Documents and Settings\Zosia\Dane aplikacji\BabSolution => Moved successfully. C:\Documents and Settings\Zosia\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\Zosia\Dane aplikacji\Delta => Moved successfully. C:\Documents and Settings\Zosia\Ustawienia lokalne\Dane aplikacji\MFAData => Moved successfully. C:\Documents and Settings\Zosia\Ustawienia lokalne\Dane aplikacji\Avg2013 => Moved successfully. C:\WINDOWS\Tasks\EPUpdater.job => Moved successfully. C:\WINDOWS\005207_.tmp => Moved successfully. HKU\Administrator\Software\Microsoft\Windows\CurrentVersion\Run\\AV Security Essentials => Value deleted successfully. HKU\Administrator\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully. HKU\Administrator\Software\Microsoft\Windows\CurrentVersion\Run\\TransBar => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => Value not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value deleted successfully. HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Key deleted successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Xyqmqj /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= =========== Result of Scheduled Files to move =========== "C:\Documents and Settings\Zosia\Dane aplikacji\Xyqmqj.exe" => File could not move. ==== End of Fixlog ====