Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-12-2013 01 Ran by Pietras at 2013-12-17 13:50:31 Run:1 Running from C:\Users\Pietras\Downloads\Naprawa ! Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {4D2498BB-1EAF-4140-AC68-A111F4628A47} - System32\Tasks\0 => Iexplore.exe Task: {582BF65F-597B-4EC1-84FE-66C78D85D508} - System32\Tasks\BrowserDefendert => Sc.exe start BrowserDefendert Task: {B92C94AC-97B8-4433-AEC6-440BB6C8C98F} - System32\Tasks\4909 => C:\Users\Pietras\AppData\Local\Temp\launchie.vbs //B HKLM-x32\...\Run: [] - [x] AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll [ ] () HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=A22C1C6F6547FCEB&affID=119357&tsp=4973 SearchScopes: HKCU - DefaultScope {4266364D-E863-41b1-8ECD-DCB2AFF6A868} URL = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBD SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = SearchScopes: HKCU - {4266364D-E863-41b1-8ECD-DCB2AFF6A868} URL = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBD S3 GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS [x] U2 wuaserv; C:\Users\Pietras\AppData\Local\Temp\launchie.vbs C:\Users\Pietras\AppData\Roaming\Babylon C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\idstore.* CMD: sc start PNRPsvc Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{10A0B737-33AA-4521-9C25-62FB676FC3C7}" /f ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4D2498BB-1EAF-4140-AC68-A111F4628A47} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D2498BB-1EAF-4140-AC68-A111F4628A47} => Key deleted successfully. C:\Windows\System32\Tasks\0 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{582BF65F-597B-4EC1-84FE-66C78D85D508} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{582BF65F-597B-4EC1-84FE-66C78D85D508} => Key deleted successfully. C:\Windows\System32\Tasks\BrowserDefendert => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B92C94AC-97B8-4433-AEC6-440BB6C8C98F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B92C94AC-97B8-4433-AEC6-440BB6C8C98F} => Key deleted successfully. C:\Windows\System32\Tasks\4909 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4909 => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4266364D-E863-41b1-8ECD-DCB2AFF6A868} => Key deleted successfully. HKCR\CLSID\{4266364D-E863-41b1-8ECD-DCB2AFF6A868} => Key not found. GMSIPCI => Service deleted successfully. wuaserv => Service deleted successfully. "C:\Users\Pietras\AppData\Local\Temp\launchie.vbs" => File/Directory not found. C:\Users\Pietras\AppData\Roaming\Babylon => Moved successfully. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\idstore.* => Moved successfully. ========= sc start PNRPsvc ========= SERVICE_NAME: PNRPsvc TYPE : 20 WIN32_SHARE_PROCESS STATE : 2 START_PENDING (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN) WIN32_EXIT_CODE : 0 (0x0) SERVICE_EXIT_CODE : 0 (0x0) CHECKPOINT : 0x0 WAIT_HINT : 0x0 PID : 4772 FLAGS : ========= End of CMD: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{10A0B737-33AA-4521-9C25-62FB676FC3C7}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====