Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-12-2013 01 Ran by Kamil at 2013-12-31 16:33:50 Run:1 Running from C:\Users\Kamil\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKCU\...\Run: [Badoo Desktop] - C:\ProgramData\Badoo\Badoo Desktop\1.6.55.1183\Badoo.Desktop.exe HKCU\...\Run: [IGagnant] - C:\Users\Kamil\Downloads\LaBarre-Gagnante.exe HKCU\...\Run: [ALLUpdate] - "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" HKCU\...\Run: [urlspace] - C:\Users\Kamil\Downloads\jingling.exe -h HKCU\...\Run: [EV_Autowatcher_Download-Carbon0x] - C:\Users\Kamil\Downloads\Enhanceviews Autowatcher v2.42 (1).exe HKCU\...\Run: [ChomikBox] - C:\Program Files (x86)\ChomikBox\chomikbox.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2481033 URLSearchHook: HKCU - (No Name) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No File SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={B5EF2649-5CF7-48D0-AB89-0A837D0A1237}&mid=c4faa7c1bed747d0958f6939b2bfc1ce-0b6efb5e10a63851d08195547a4fa56067759ac4&lang=pl&ds=st011&pr=sa&d=2012-04-17 22:34:00&v=10.2.0.3&sap=dsp&q={searchTerms} SearchScopes: HKCU - {283F304B-CD4D-4F05-93E1-676D447DD528} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {6C06F506-5BB4-4781-869B-4B41BC282D5B} URL = http://websearch.ask.com/redirect?client=ie&tb=SPC2&o=15000&src=crm&q={searchTerms}&locale=&apn_ptnrs=PV&apn_dtid=YYYYYYYYPL&apn_uid=CD11EB0D-1DAD-4AC3-AFAE-9286790C4DFE&apn_sauid=566137FF-DFAB-4896-B758-1D20F369CA10 SearchScopes: HKCU - {794594C8-6278-4876-BA66-5BB7E4394529} URL = SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/startpage/?source=bsb&q={searchTerms} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={B5EF2649-5CF7-48D0-AB89-0A837D0A1237}&mid=c4faa7c1bed747d0958f6939b2bfc1ce-0b6efb5e10a63851d08195547a4fa56067759ac4&lang=pl&ds=st011&pr=sa&d=2012-04-17 22:34:00&v=10.2.0.3&sap=dsp&q={searchTerms} BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - No File FF Plugin-x32: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml Task: {4745F5C6-9F19-4A27-9ECD-799FCBAAABA4} - System32\Tasks\{9E13F412-C9B3-43F0-8B8E-136B9C467FA8} => Firefox.exe http://ui.skype.com/ui/0/6.3.0.107/pl/abandoninstall?source=lightinstaller&page=tsProgressBar C:\ProgramData\dsgsdgdsgdsgw.pad Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: sc config "PLAY ONLINE. RunOuc" start= demand CMD: md C:\Users\Kamil\Desktop\Upload CMD: copy C:\Users\Kamil\AppData\Roaming\Mozilla\Firefox\Profiles\wy6lrnw3.default-1383729895541\Extensions\{6BBAF055-8EB1-4987-832A-45171690B0D6}.xpi C:\Users\Kamil\Desktop\Upload ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Badoo Desktop => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\IGagnant => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ALLUpdate => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\urlspace => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\EV_Autowatcher_Download-Carbon0x => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ChomikBox => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{283F304B-CD4D-4F05-93E1-676D447DD528} => Key deleted successfully. HKCR\CLSID\{283F304B-CD4D-4F05-93E1-676D447DD528} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6C06F506-5BB4-4781-869B-4B41BC282D5B} => Key deleted successfully. HKCR\CLSID\{6C06F506-5BB4-4781-869B-4B41BC282D5B} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{794594C8-6278-4876-BA66-5BB7E4394529} => Key deleted successfully. HKCR\CLSID\{794594C8-6278-4876-BA66-5BB7E4394529} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B} => Key deleted successfully. HKCR\CLSID\{8A244612-A1F7-11E0-95C0-E71F4824019B} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKCR\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Value deleted successfully. HKCR\CLSID\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Key not found. HKLM\Software\Wow6432Node\MozillaPlugins\@pages.tvunetworks.com/WebPlayer => Key deleted successfully. C:\Windows\system32\TVUAx\npTVUAx.dll not found. C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4745F5C6-9F19-4A27-9ECD-799FCBAAABA4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4745F5C6-9F19-4A27-9ECD-799FCBAAABA4} => Key deleted successfully. C:\Windows\System32\Tasks\{9E13F412-C9B3-43F0-8B8E-136B9C467FA8} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9E13F412-C9B3-43F0-8B8E-136B9C467FA8} => Key deleted successfully. C:\ProgramData\dsgsdgdsgdsgw.pad => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "PLAY ONLINE. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= md C:\Users\Kamil\Desktop\Upload ========= ========= End of CMD: ========= ========= copy C:\Users\Kamil\AppData\Roaming\Mozilla\Firefox\Profiles\wy6lrnw3.default-1383729895541\Extensions\{6BBAF055-8EB1-4987-832A-45171690B0D6}.xpi C:\Users\Kamil\Desktop\Upload ========= Liczba skopiowanych plik�w: 1. ========= End of CMD: ========= ==== End of Fixlog ====