Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 14-12-2013 Ran by Justyna at 2013-12-14 14:00:21 Run:1 Running from C:\Documents and Settings\Justyna\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [NextLive] - C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Justyna\Dane aplikacji\newnext.me\nengine.dll",EntryPoint -m l HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhoome.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myhoome.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhoome.com/ SearchScopes: HKLM - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^pl&si=pconverter&ptb=1B8632E9-3165-4726-94DA-5EADBFE2696D&ind=2013111918&n=77fda66e&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - DefaultScope {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^pl&si=pconverter&ptb=1B8632E9-3165-4726-94DA-5EADBFE2696D&ind=2013111918&n=77fda66e&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - 7C2CD7A42C4F4ADCBD6049E0685AD0BE URL = http://szukaj.gazeta.pl/portalSearch.do?s.si(navigation).navigationEnabled=true&s.sm.query={searchTerms} SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm073^YYA^pl&si=pconverter&ptb=1B8632E9-3165-4726-94DA-5EADBFE2696D&ind=2013111918&n=77fda66e&psa=&st=sb&searchfor={searchTerms} S3 catchme; \??\C:\DOCUME~1\Justyna\USTAWI~1\Temp\catchme.sys [x] S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] U3 TlntSvr; S3 vtany; \??\C:\WINDOWS\vtany.sys [x] S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [x] C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP C:\Windows\Tasks\At1.job C:\Windows\Tasks\At2.job C:\Program Files\RegClean Pro C:\Program Files\tuto4pc_pl_32 C:\Program Files\tuto4pc_pl_31 C:\Program Files\tuto4pc_pl_20 C:\Program Files\MyPC Backup C:\Program Files\VLC Player GPU+ C:\Program Files\windealist C:\Program Files\Enigma Software Group C:\Program Files\VideoDownloadConverter C:\Program Files\VideoDownloadConverter_4z C:\Documents and Settings\All Users\Dane aplikacji\Babylon C:\Documents and Settings\All Users\Dane aplikacji\IBUpdaterService C:\Documents and Settings\All Users\Dane aplikacji\Temp C:\Documents and Settings\Justyna\daemonprocess.txt C:\Documents and Settings\Justyna\Dane aplikacji\0C1I1L1R1J0M1P0I1G C:\Documents and Settings\Justyna\Dane aplikacji\BabSolution C:\Documents and Settings\Justyna\Dane aplikacji\Babylon C:\Documents and Settings\Justyna\Dane aplikacji\Mipony C:\Documents and Settings\Justyna\Dane aplikacji\newnext.me C:\Documents and Settings\Justyna\Dane aplikacji\PerformerSoft C:\Documents and Settings\Justyna\Dane aplikacji\VideoDownloadConverter_4z C:\Documents and Settings\Justyna\Moje dokumenty\Mobogenie C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\Ares C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\tuto4pc_pl_20 C:\Documents and Settings\Justyna\Dane aplikacji\VideoDownloadConverter_4z C:\Documents and Settings\Justyna\Ustawienia lokalne\Temp*.html Reg: reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6C33149F-330C-49EA-981D-EE2C8BE31DD2}" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77649DF6-82C9-47C0-8728-6B1A2A3F80BA}" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\7C2CD7A42C4F4ADCBD6049E0685AD0BE => Key deleted successfully. HKCR\Wow6432Node\CLSID\7C2CD7A42C4F4ADCBD6049E0685AD0BE => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} => Key not found. catchme => Service deleted successfully. EagleXNt => Service deleted successfully. esgiguard => Service deleted successfully. TlntSvr => Service deleted successfully. vtany => Service deleted successfully. xhunter1 => Service deleted successfully. C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP => Moved successfully. C:\Windows\Tasks\At1.job => Moved successfully. C:\Windows\Tasks\At2.job => Moved successfully. C:\Program Files\RegClean Pro => Moved successfully. C:\Program Files\tuto4pc_pl_32 => Moved successfully. C:\Program Files\tuto4pc_pl_31 => Moved successfully. C:\Program Files\tuto4pc_pl_20 => Moved successfully. C:\Program Files\MyPC Backup => Moved successfully. C:\Program Files\VLC Player GPU+ => Moved successfully. "C:\Program Files\windealist" => File/Directory not found. C:\Program Files\Enigma Software Group => Moved successfully. C:\Program Files\VideoDownloadConverter => Moved successfully. C:\Program Files\VideoDownloadConverter_4z => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\IBUpdaterService => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Temp => Moved successfully. C:\Documents and Settings\Justyna\daemonprocess.txt => Moved successfully. "C:\Documents and Settings\Justyna\Dane aplikacji\0C1I1L1R1J0M1P0I1G" => File/Directory not found. C:\Documents and Settings\Justyna\Dane aplikacji\BabSolution => Moved successfully. C:\Documents and Settings\Justyna\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\Justyna\Dane aplikacji\Mipony => Moved successfully. C:\Documents and Settings\Justyna\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\Justyna\Dane aplikacji\PerformerSoft => Moved successfully. "C:\Documents and Settings\Justyna\Dane aplikacji\VideoDownloadConverter_4z" => File/Directory not found. C:\Documents and Settings\Justyna\Moje dokumenty\Mobogenie => Moved successfully. C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\Ares => Moved successfully. C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. C:\Documents and Settings\Justyna\Ustawienia lokalne\Dane aplikacji\tuto4pc_pl_20 => Moved successfully. "C:\Documents and Settings\Justyna\Dane aplikacji\VideoDownloadConverter_4z" => File/Directory not found. C:\Documents and Settings\Justyna\Ustawienia lokalne\Temp*.html => Moved successfully. ========= reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6C33149F-330C-49EA-981D-EE2C8BE31DD2}" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77649DF6-82C9-47C0-8728-6B1A2A3F80BA}" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ==== End of Fixlog ====