Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-01-2014 01 Ran by Jarek at 2014-01-14 19:03:17 Run:2 Running from C:\Users\Jarek\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Users\Jarek\AppData\Roaming\minerd\bfgminer.exe HKLM-x32\...\Run: [] - [x] HKLM\...\Policies\Explorer\Run: [40] - C:\ProgramData\Local Settings\Temp\msvxaeq.bat [1169224 2009-07-14] ( (Microsoft Corporation)) HKCU\...\Run: [minerd] - C:\Users\Jarek\AppData\Roaming\minerd\nircmd.exe [44032 2013-08-11] (NirSoft) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Jarek\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l AppInit_DLLs: [ ] () AppInit_DLLs-x32: [ ] () Task: {0F4B240C-DB73-4BA3-92F2-4A1FA974E167} - System32\Tasks\{862DEEE0-E828-4F0E-9149-650B32354450} => C:\Program Files\astragon\European Bus Simulator 2012\Bin32\BusSimulator2012.exe Task: {A71331B3-7C75-4701-B0BD-037700AF920F} - System32\Tasks\{C3FA8E2D-B0D9-4212-BDD4-3F504102CB76} => C:\Program Files\astragon\European Bus Simulator 2012\Bin32\BusSimulator2012.exe Task: {D0E22AB6-54A8-4E12-A874-46C08237D960} - System32\Tasks\FoxTab => C:\Users\Jarek\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION\ Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Jarek\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=HitachiXHTS543225L9A300_090416FB2D00LJGVYRMBX&ts=1384001862&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=E44900FF6C56027B&affID=119357&tt=240913_238&tsp=5020 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=E44900FF6C56027B&affID=119357&tt=240913_238&tsp=5020 SearchScopes: HKCU - {3A9D58A5-86DC-4815-8E53-C9E06A84FEE7} URL = http://search.us.com/serp?guid={FA08E31B-3E63-468C-9F5A-AE3CC73A7F12}&action=default_search&serpv=5&k={searchTerms} SearchScopes: HKCU - {DE78DEF1-1CF7-4AE1-9B33-2121C3FCA9DD} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10583 BHO: No Name - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File Toolbar: HKLM-x32 - @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\Program Files (x86)\No1 Video Converter\msdxm.ocx (Microsoft Corporation) Handler: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - No File Handler-x32: vnd.ms.radio - {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Program Files (x86)\No1 Video Converter\msdxm.ocx (Microsoft Corporation) S3 usbbus; system32\DRIVERS\lgx64bus.sys [x] S3 UsbDiag; system32\DRIVERS\lgx64diag.sys [x] S3 USBModem; system32\DRIVERS\lgx64modem.sys [x] C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com C:\Program Files (x86)\BonanzaDeals C:\Program Files (x86)\BonanzaDealsLive C:\Program Files (x86)\No1 Video Converter C:\Program Files (x86)\Optimizer Pro C:\Program Files (x86)\Common Files\AVG Secure Search C:\ProgramData\AVG Security Toolbar C:\ProgramData\Local Settings\Temp\msvxaeq.bat C:\ProgramData\TEMP C:\Users\Jarek\daemonprocess.txt C:\Users\Jarek\AppData\Local\cache C:\Users\Jarek\AppData\Local\genienext C:\Users\Jarek\AppData\Local\Mobogenie C:\Users\Jarek\AppData\Roaming\Babylon C:\Users\Jarek\AppData\Roaming\Bonanza C:\Users\Jarek\AppData\Roaming\E4490028 C:\Users\Jarek\AppData\Roaming\FoxTab C:\Users\Jarek\AppData\Roaming\minerd C:\Users\Jarek\AppData\Roaming\newnext.me C:\Users\Jarek\AppData\Roaming\OpenCandy C:\Users\Jarek\Documents\Optimizer Pro C:\Users\Jarek\Downloads\drivermax_7_26_cnet.exe C:\Users\Jarek\Downloads\AOMEI-Partition-Assistant(33871).exe C:\Users\Jarek\Downloads\VIAAC97VinylStylusAudioComboDriver_downloader-a58ODvEy.exe C:\Users\Jarek\Downloads\VIAAC97VinylStylusAudioComboDriver_downloader-a58ODvEy(1).exe Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f CMD: netsh advfirewall reset ***************** C:\Users\Jarek\AppData\Roaming\minerd\bfgminer.exe => No running process found HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\40 => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\minerd => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0F4B240C-DB73-4BA3-92F2-4A1FA974E167} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F4B240C-DB73-4BA3-92F2-4A1FA974E167} => Key deleted successfully. C:\Windows\System32\Tasks\{862DEEE0-E828-4F0E-9149-650B32354450} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{862DEEE0-E828-4F0E-9149-650B32354450} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A71331B3-7C75-4701-B0BD-037700AF920F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A71331B3-7C75-4701-B0BD-037700AF920F} => Key deleted successfully. C:\Windows\System32\Tasks\{C3FA8E2D-B0D9-4212-BDD4-3F504102CB76} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C3FA8E2D-B0D9-4212-BDD4-3F504102CB76} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D0E22AB6-54A8-4E12-A874-46C08237D960} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0E22AB6-54A8-4E12-A874-46C08237D960} => Key deleted successfully. C:\Windows\System32\Tasks\FoxTab not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab => Key deleted successfully. C:\Windows\Tasks\FoxTab.job not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3A9D58A5-86DC-4815-8E53-C9E06A84FEE7} => Key deleted successfully. HKCR\CLSID\{3A9D58A5-86DC-4815-8E53-C9E06A84FEE7} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DE78DEF1-1CF7-4AE1-9B33-2121C3FCA9DD} => Key deleted successfully. HKCR\CLSID\{DE78DEF1-1CF7-4AE1-9B33-2121C3FCA9DD} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} => Key not found. HKCR\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{8E718888-423F-11D2-876E-00A0C9082467} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{8E718888-423F-11D2-876E-00A0C9082467} => Key deleted successfully. HKCR\PROTOCOLS\Handler\vnd.ms.radio => Key deleted successfully. HKCR\CLSID\{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} => Key not found. HKCR\Wow6432Node\PROTOCOLS\Handler\vnd.ms.radio => Key not found. HKCR\Wow6432Node\CLSID\{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} => Key deleted successfully. usbbus => Service deleted successfully. UsbDiag => Service deleted successfully. USBModem => Service deleted successfully. C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com => Moved successfully. "C:\Program Files (x86)\BonanzaDeals" => File/Directory not found. "C:\Program Files (x86)\BonanzaDealsLive" => File/Directory not found. C:\Program Files (x86)\No1 Video Converter => Moved successfully. "C:\Program Files (x86)\Optimizer Pro" => File/Directory not found. "C:\Program Files (x86)\Common Files\AVG Secure Search" => File/Directory not found. "C:\ProgramData\AVG Security Toolbar" => File/Directory not found. C:\ProgramData\Local Settings\Temp\msvxaeq.bat => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\Users\Jarek\daemonprocess.txt => Moved successfully. C:\Users\Jarek\AppData\Local\cache => Moved successfully. C:\Users\Jarek\AppData\Local\genienext => Moved successfully. C:\Users\Jarek\AppData\Local\Mobogenie => Moved successfully. "C:\Users\Jarek\AppData\Roaming\Babylon" => File/Directory not found. C:\Users\Jarek\AppData\Roaming\Bonanza => Moved successfully. C:\Users\Jarek\AppData\Roaming\E4490028 => Moved successfully. "C:\Users\Jarek\AppData\Roaming\FoxTab" => File/Directory not found. C:\Users\Jarek\AppData\Roaming\minerd => Moved successfully. C:\Users\Jarek\AppData\Roaming\newnext.me => Moved successfully. "C:\Users\Jarek\AppData\Roaming\OpenCandy" => File/Directory not found. "C:\Users\Jarek\Documents\Optimizer Pro" => File/Directory not found. "C:\Users\Jarek\Downloads\drivermax_7_26_cnet.exe" => File/Directory not found. "C:\Users\Jarek\Downloads\AOMEI-Partition-Assistant(33871).exe" => File/Directory not found. "C:\Users\Jarek\Downloads\VIAAC97VinylStylusAudioComboDriver_downloader-a58ODvEy.exe" => File/Directory not found. "C:\Users\Jarek\Downloads\VIAAC97VinylStylusAudioComboDriver_downloader-a58ODvEy(1).exe" => File/Directory not found. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====