Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-01-2014 03 Ran by Wlasciciel at 2014-01-12 12:08:12 Run:1 Running from C:\Documents and Settings\Wlasciciel\Moje dokumenty\Pobieranie Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\fst_pl_30\upfst_pl_30.exe () C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\temp\GPUTemp.exe HKLM\...\Run: [upfst_pl_30.exe] - C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\fst_pl_30\upfst_pl_30.exe [3153904 2014-01-02] () HKLM\...\Run: [GPUTemp] - C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\temp\GPUTemp.exe [1305312 2014-01-08] () <===== ATTENTION HKCU\...\Run: [NextLive] - C:\Documents and Settings\Wlasciciel\Dane aplikacji\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe) HKU\Default User\...\RunOnce: [NeroHomeFirstStart] - C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.packbarre.com/index.php?id_msg=50 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File CHR HKLM\...\Chrome\Extension: [gdnafjfahbdfphihncgadbegiaebehio] - C:\Program Files\SquirrelWeb\gdnafjfahbdfphihncgadbegiaebehio.crx [2013-12-30] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml C:\Program Files\predm C:\Program Files\VLC Player GPU+ C:\Documents and Settings\All Users\Dane aplikacji\Ask C:\Documents and Settings\All Users\Dane aplikacji\Common Files C:\Documents and Settings\Wlasciciel\.android C:\Documents and Settings\Wlasciciel\daemonprocess.txt C:\Documents and Settings\Wlasciciel\Dane aplikacji\0C1I1L1R1J0M1P0I1G C:\Documents and Settings\Wlasciciel\Dane aplikacji\Babylon C:\Documents and Settings\Wlasciciel\Dane aplikacji\newnext.me C:\Documents and Settings\Wlasciciel\Dane aplikacji\systweak C:\Documents and Settings\Wlasciciel\Moje dokumenty\Mobogenie C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\AnyProtectScannerSetup.exe C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\Setup(5).exe C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\fst_pl_30 C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\temp\GPUTemp.exe C:\WINDOWS\system32\roboot.exe ***************** [372] C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\fst_pl_30\upfst_pl_30.exe => Process closed successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\temp\GPUTemp.exe => No running process found HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upfst_pl_30.exe => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\GPUTemp => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKU\Default User\Software\Microsoft\Windows\CurrentVersion\RunOnce\\NeroHomeFirstStart => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\gdnafjfahbdfphihncgadbegiaebehio => Key not found. "C:\Program Files\SquirrelWeb\gdnafjfahbdfphihncgadbegiaebehio.crx" => File/Directory not found. C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\babylon.xml => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\VLC Player GPU+ => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Ask => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Common Files => Moved successfully. C:\Documents and Settings\Wlasciciel\.android => Moved successfully. C:\Documents and Settings\Wlasciciel\daemonprocess.txt => Moved successfully. C:\Documents and Settings\Wlasciciel\Dane aplikacji\0C1I1L1R1J0M1P0I1G => Moved successfully. C:\Documents and Settings\Wlasciciel\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\Wlasciciel\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\Wlasciciel\Dane aplikacji\systweak => Moved successfully. C:\Documents and Settings\Wlasciciel\Moje dokumenty\Mobogenie => Moved successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\AnyProtectScannerSetup.exe => Moved successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\Setup(5).exe => Moved successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\fst_pl_30 => Moved successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. C:\Documents and Settings\Wlasciciel\Ustawienia lokalne\temp\GPUTemp.exe => Moved successfully. C:\WINDOWS\system32\roboot.exe => Moved successfully. ==== End of Fixlog ====