Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2013 01 Ran by Pateyk at 2013-12-15 12:20:49 Run:1 Running from C:\Users\Pateyk\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** URLSearchHook: HKLM-x32 - uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.) URLSearchHook: HKCU - uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {163A0588-D38A-4E5E-B968-D1741D36A3B4} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289075&CUI=UN19646711142952210&UM=1 SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = BHO-x32: uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.) Toolbar: HKLM-x32 - uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {96F454EA-9D38-474F-B504-56193E00C1A5} - No File Task: {A7637032-D81B-4D4D-BE05-E316440310B5} - System32\Tasks\BackgroundContainer Startup Task => C:\Users\Pateyk\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll [2013-10-15] (Conduit Ltd.) <==== ATTENTION C:\Users\Pateyk\AppData\Local\Conduit C:\Users\Pateyk\AppData\Local\Google C:\Users\Pateyk\AppData\Local\Temp\*.exe C:\Program Files (x86)\uTorrentControl_v6 C:\ProgramData\Conduit H:\.qf H:\qf CMD: attrib /d /s -s -h F:\* CMD: attrib /d /s -s -h H:\* Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ***************** HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{96f454ea-9d38-474f-b504-56193e00c1a5} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{96f454ea-9d38-474f-b504-56193e00c1a5} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{96f454ea-9d38-474f-b504-56193e00c1a5} => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{163A0588-D38A-4E5E-B968-D1741D36A3B4} => Key deleted successfully. HKCR\CLSID\{163A0588-D38A-4E5E-B968-D1741D36A3B4} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => Key deleted successfully. HKCR\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96f454ea-9d38-474f-b504-56193e00c1a5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{96f454ea-9d38-474f-b504-56193e00c1a5} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{96f454ea-9d38-474f-b504-56193e00c1a5} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{96f454ea-9d38-474f-b504-56193e00c1a5} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{96F454EA-9D38-474F-B504-56193E00C1A5} => Value deleted successfully. HKCR\CLSID\{96F454EA-9D38-474F-B504-56193E00C1A5} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A7637032-D81B-4D4D-BE05-E316440310B5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7637032-D81B-4D4D-BE05-E316440310B5} => Key deleted successfully. C:\Windows\System32\Tasks\BackgroundContainer Startup Task => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task => Key deleted successfully. C:\Users\Pateyk\AppData\Local\Conduit => Moved successfully. C:\Users\Pateyk\AppData\Local\Google => Moved successfully. C:\Users\Pateyk\AppData\Local\Temp\*.exe => Moved successfully. C:\Program Files (x86)\uTorrentControl_v6 => Moved successfully. C:\ProgramData\Conduit => Moved successfully. H:\.qf => Moved successfully. H:\qf => Moved successfully. ========= attrib /d /s -s -h F:\* ========= Nie mo¾na zmieni† atrybutu - F:\Autorun.inf\lpt1.UsbFix ========= End of CMD: ========= ========= attrib /d /s -s -h H:\* ========= Nie mo¾na zmieni† atrybutu - H:\Autorun.inf\lpt1.UsbFix ========= End of CMD: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====