Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-12-2013 01 Ran by gd at 2013-12-13 14:28:58 Run:1 Running from D:\Moje dokumenty\Pobieranie Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [fst_pl_6] - [x] HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1386336275&from=cor&uid=WDCXWD1600AVJS-63SWA0_WD-WMAP9C94827348273&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1386336275&from=cor&uid=WDCXWD1600AVJS-63SWA0_WD-WMAP9C94827348273&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1386336275&from=cor&uid=WDCXWD1600AVJS-63SWA0_WD-WMAP9C94827348273&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1386336275&from=cor&uid=WDCXWD1600AVJS-63SWA0_WD-WMAP9C94827348273&q={searchTerms} URLSearchHook: HKCU - Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://aartemis.com/?type=sc&ts=1386336275&from=cor&uid=WDCXWD1600AVJS-63SWA0_WD-WMAP9C94827348273 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.aartemis.com/web/?type=ds&ts=1386336275&from=cor&uid=WDCXWD1600AVJS-63SWA0_WD-WMAP9C94827348273&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.aartemis.com/web/?type=ds&ts=1386336275&from=cor&uid=WDCXWD1600AVJS-63SWA0_WD-WMAP9C94827348273&q={searchTerms} SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=17&barid={15C9A1D0-0703-455B-AAF2-CDE137FB471E} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\Extensions.rdf FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\installed-extensions-processed.txt CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S2 ADILOADER; System32\Drivers\adildr.sys [x] S3 adiusbaw; system32\DRIVERS\adiusbaw.sys [x] S1 soqwx32; \??\C:\WINDOWS\system32\drivers\soqwx32.sys [x] C:\WINDOWS\Tasks\Norton Security Scan for gd.job C:\WINDOWS\system32\roboot.exe C:\Program Files\MyPC Backup C:\Program Files\predm C:\Program Files\Mobogenie C:\Documents and Settings\All Users\Dane aplikacji\ESET C:\Documents and Settings\All Users\Dane aplikacji\SweetIM C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\GD\daemonprocess.txt C:\Documents and Settings\GD\Dane aplikacji\0F1F1C2Y1H1P1C0I0T C:\Documents and Settings\GD\Dane aplikacji\aartemis C:\Documents and Settings\GD\Dane aplikacji\ESET C:\Documents and Settings\GD\Dane aplikacji\MetaCrawler C:\Documents and Settings\GD\Dane aplikacji\OpenCandy C:\Documents and Settings\GD\Dane aplikacji\systweak CMD: netsh firewall reset ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\fst_pl_6 => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{08C06D61-F1F3-4799-86F8-BE1A89362C85} => Value deleted successfully. HKCR\CLSID\{08C06D61-F1F3-4799-86F8-BE1A89362C85} => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => Value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{41564D57-9980-0010-8000-00AA00389B71} => Key deleted successfully. HKCR\CLSID\{41564D57-9980-0010-8000-00AA00389B71} => Key not found. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKCR\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7} => Key deleted successfully. HKCR\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7} => Key not found. C:\Program Files\Mozilla Firefox\extensions\Extensions.rdf => Moved successfully. C:\Program Files\Mozilla Firefox\extensions\installed-extensions-processed.txt => Moved successfully. HKCU\SOFTWARE\Policies\Google => Key deleted successfully. ADILOADER => Service deleted successfully. adiusbaw => Service deleted successfully. soqwx32 => Service deleted successfully. C:\WINDOWS\Tasks\Norton Security Scan for gd.job => Moved successfully. C:\WINDOWS\system32\roboot.exe => Moved successfully. C:\Program Files\MyPC Backup => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\ESET => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\SweetIM => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. C:\Documents and Settings\GD\daemonprocess.txt => Moved successfully. C:\Documents and Settings\GD\Dane aplikacji\0F1F1C2Y1H1P1C0I0T => Moved successfully. C:\Documents and Settings\GD\Dane aplikacji\aartemis => Moved successfully. C:\Documents and Settings\GD\Dane aplikacji\ESET => Moved successfully. C:\Documents and Settings\GD\Dane aplikacji\MetaCrawler => Moved successfully. C:\Documents and Settings\GD\Dane aplikacji\OpenCandy => Moved successfully. C:\Documents and Settings\GD\Dane aplikacji\systweak => Moved successfully. ========= netsh firewall reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====