Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-01-2014 04 Ran by Michał at 2014-01-23 23:07:29 Run:1 Running from D:\wykłady\Książki\programy\czyszczen ie kompa\wirusy\raporty Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {59980D98-D9FC-4AF5-B33A-30CD9D738C0E} - System32\Tasks\{8601AF29-6B96-499F-9939-FE31557EB205} => C:\Program Files (x86)\Grupa IMAGE\Prawo Jazdy ABCDT - egzamin wewnetrzny\Testy.exe Task: {71524B29-068D-4D13-B76E-1A1B15668703} - System32\Tasks\Hoolapp For Android => C:\Users\MICHA~1\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {8A56123B-767E-43AC-BBAB-2BC2427F0FD6} - \DealPly No Task File Task: {9594CF39-BB9E-411A-BC10-1922341C536A} - System32\Tasks\Hoolapp Init => C:\Users\MICHA~1\AppData\Roaming\HOOLAP~1\Hoolapp.exe Task: {B7D42B51-3989-4AEE-A9EE-4CF4FEAA09C4} - \DSite No Task File Task: {BA7D7E63-F9D2-4742-95D8-944D5154FF83} - \GoforFilesUpdate No Task File Task: {C9B7B662-2222-4819-BA6A-21913D074814} - \MetaCrawler No Task File Task: {F6BDD0B6-3C26-452B-AF4E-667E3C146437} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{DC9C5689-338A-4E65-9AE0-E3BDDD593105}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{DC9C5689-338A-4E65-9AE0-E3BDDD593105}.exe HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKCU\...\Run: [Hoolapp Android] - "C:\Users\MICHA~1\AppData\Roaming\HOOLAP~1\Hoolapp.exe" /Minimized AppInit_DLLs: => File Not Found AppInit_DLLs-x32: c:\progra~3\bitguard\271832~1.68\{c16c1~1\bitguard.dll => File Not Found URLSearchHook: HKLM-x32 - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871} URLSearchHook: HKCU - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {5C98EEB0-364B-4A52-A0CF-94AA5A52A605} URL = SearchScopes: HKCU - ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± vË°!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁwľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)x­ä­ URL = S2 Kmm4xNT; C:\Windows\SysWow64\Drivers\Kmm4xNT.sys [95484 2000-11-25] (DATOM Dariusz Cielebąk) S2 TVicPort; C:\Windows\SysWow64\Drivers\TVicPort.sys [14544 2005-03-30] (EnTech Taiwan) S2 matlabserver; C:\MATLAAB\webserver\bin\win32\matlabserver.exe [x] S2 IOPort; \??\C:\Windows\system32\DRIVERS\IOPORT.SYS [x] C:\Windows\SysWow64\Drivers\Kmm4xNT.sys C:\Windows\SysWow64\Drivers\TVicPort.sys Reg: reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v Startup /t REG_SZ /d "C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{5C98EEB0-364B-4A52-A0CF-94AA5A52A605}" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{59980D98-D9FC-4AF5-B33A-30CD9D738C0E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59980D98-D9FC-4AF5-B33A-30CD9D738C0E} => Key deleted successfully. C:\Windows\System32\Tasks\{8601AF29-6B96-499F-9939-FE31557EB205} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8601AF29-6B96-499F-9939-FE31557EB205} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71524B29-068D-4D13-B76E-1A1B15668703} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71524B29-068D-4D13-B76E-1A1B15668703} => Key deleted successfully. C:\Windows\System32\Tasks\Hoolapp For Android => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hoolapp For Android => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A56123B-767E-43AC-BBAB-2BC2427F0FD6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A56123B-767E-43AC-BBAB-2BC2427F0FD6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{9594CF39-BB9E-411A-BC10-1922341C536A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9594CF39-BB9E-411A-BC10-1922341C536A} => Key deleted successfully. C:\Windows\System32\Tasks\Hoolapp Init => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hoolapp Init => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7D42B51-3989-4AEE-A9EE-4CF4FEAA09C4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7D42B51-3989-4AEE-A9EE-4CF4FEAA09C4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BA7D7E63-F9D2-4742-95D8-944D5154FF83} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA7D7E63-F9D2-4742-95D8-944D5154FF83} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C9B7B662-2222-4819-BA6A-21913D074814} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9B7B662-2222-4819-BA6A-21913D074814} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MetaCrawler => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F6BDD0B6-3C26-452B-AF4E-667E3C146437} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6BDD0B6-3C26-452B-AF4E-667E3C146437} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Hoolapp Android => Value deleted successfully. "AppInit_DLLs: => File Not Found" => Value Data not found. "c:\\progra~3\\bitguard\\271832~1.68\\{c16c1~1\\bitguard.dll" => Value Data removed successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5C98EEB0-364B-4A52-A0CF-94AA5A52A605} => Key deleted successfully. HKCR\CLSID\{5C98EEB0-364B-4A52-A0CF-94AA5A52A605} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± vË°!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁwľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)x­ä­ => Key not found. HKCR\CLSID\ŰźĆîZ§’2ąŢpv¨IÍá*X(Ž2s(ŰÎŔJşÔÓµť± vË°!×—(äĽ48иpatm6ęo^Mp`Ëő÷_iŁwľ!„Áű†x˘8€ŮjŔ˙ţ ´Ń;áa´[¦†8 ş~ŹRŮxśňÜ8'Ł-)x­ä­ => Key not found. Kmm4xNT => Service deleted successfully. TVicPort => Service deleted successfully. matlabserver => Service deleted successfully. IOPort => Service deleted successfully. C:\Windows\SysWow64\Drivers\Kmm4xNT.sys => Moved successfully. C:\Windows\SysWow64\Drivers\TVicPort.sys => Moved successfully. ========= reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v Startup /t REG_SZ /d "C:\Users\Michał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{5C98EEB0-364B-4A52-A0CF-94AA5A52A605}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====