Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 22-12-2013 01 Ran by Lectra at 2013-12-23 08:54:03 Run:1 Running from C:\Documents and Settings\Lectra\Pulpit\Czyszczenie Boot Mode: Normal ============================================== Content of fixlist: ***************** (Wsys Co., Ltd.) C:\Documents and Settings\All Users\Dane aplikacji\eSafe\eGdpSvc.exe R2 WsysSvc; C:\Documents and Settings\All Users\Dane aplikacji\eSafe\eGdpSvc.exe [1706064 2013-10-22] (Wsys Co., Ltd.) HKLM\...\Run: [] - [x] HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k HKLM\...\Policies\Explorer: [NoInternetIcon] ?? HKCU\...\Run: [SDP] - C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\FilesFrog Update Checker\update_checker.exe [208952 2013-10-17] (Somoto) MountPoints2: {1e607258-4c37-11e1-a551-806d6172696f} - explorer.exe start.html MountPoints2: {3a7f0bf1-4ab5-11e3-a6da-50e54950e200} - G:\start.exe AppInit_DLLs: [ ] () StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://pl.v9.com/?utm_source=b&utm_medium=cor SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382427503&from=cor&uid=ST320DM000-1BD14C_Z2AG4AY1XXXXZ2AG4AY1&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382427503&from=cor&uid=ST320DM000-1BD14C_Z2AG4AY1XXXXZ2AG4AY1&q={searchTerms} SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10005’ SearchScopes: HKCU - DefaultScope {FB8E544F-FAD6-45E9-82A5-6D438B8A82AF} URL = http://start.funmoods.com/results.php?f=4&a=ironto&q={searchTerms} SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.mystart.com/results.php??pr=vmn&id=mystarttb&v=3_6&ent=ch&q={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10005’ SearchScopes: HKCU - {FB8E544F-FAD6-45E9-82A5-6D438B8A82AF} URL = http://start.funmoods.com/results.php?f=4&a=ironto&q={searchTerms} BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR HKLM\...\Chrome\Extension: [cekcjpgehmohobmdiikfnopibipmgnml] - C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ CHR HKLM\...\Chrome\Extension: [fdloijijlkoblmigdofommgnheckmaki] - C:\Program Files\Funmoods\funmoods\1.5.19.3\funmoodsOEM.crx CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx C:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\Lectra\TempWmicBatchFile.bat C:\Documents and Settings\Lectra\daemonprocess.txt C:\Documents and Settings\Lectra\Moje dokumenty\Mobogenie C:\Documents and Settings\Lectra\Moje dokumenty\Optimizer Pro C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Lollipop C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Program Files\BonanzaDeals C:\Program Files\BonanzaDealsLive C:\Program Files\BrowseSmart C:\Program Files\Mobogenie C:\Program Files\Mozilla Firefox CMD: netsh firewal reset ***************** C:\Documents and Settings\All Users\Dane aplikacji\eSafe\eGdpSvc.exe => No running process found WsysSvc => Service not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInternetIcon => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\SDP => Value not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e607258-4c37-11e1-a551-806d6172696f} => Key deleted successfully. HKCR\CLSID\{1e607258-4c37-11e1-a551-806d6172696f} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3a7f0bf1-4ab5-11e3-a6da-50e54950e200} => Key deleted successfully. HKCR\CLSID\{3a7f0bf1-4ab5-11e3-a6da-50e54950e200} => Key not found. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FB8E544F-FAD6-45E9-82A5-6D438B8A82AF} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{FB8E544F-FAD6-45E9-82A5-6D438B8A82AF} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key deleted successfully. HKCR\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => Value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKLM\SOFTWARE\Google\Chrome\Extensions\cekcjpgehmohobmdiikfnopibipmgnml => Key deleted successfully. C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki => Key deleted successfully. "C:\Program Files\Funmoods\funmoods\1.5.19.3\funmoodsOEM.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn => Key deleted successfully. "C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx" => File/Directory not found. C:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. C:\Documents and Settings\Lectra\TempWmicBatchFile.bat => Moved successfully. C:\Documents and Settings\Lectra\daemonprocess.txt => Moved successfully. C:\Documents and Settings\Lectra\Moje dokumenty\Mobogenie => Moved successfully. C:\Documents and Settings\Lectra\Moje dokumenty\Optimizer Pro => Moved successfully. C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Lollipop => Moved successfully. C:\Documents and Settings\Lectra\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. C:\Program Files\BonanzaDeals => Moved successfully. C:\Program Files\BonanzaDealsLive => Moved successfully. C:\Program Files\BrowseSmart => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Program Files\Mozilla Firefox => Moved successfully. ========= netsh firewal reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====