Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-01-2014 01 Ran by Katarzyna at 2014-02-03 00:06:04 Run:1 Running from D:\Moje dokumenty\Pobieranie Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: C:\WINDOWS\Tasks\EPUpdater.job => C:\DOCUME~1\KATARZ~1\DANEAP~1\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKCU\...\Run: [Apps Hat] - C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\WebPlayer\AppsHat\WebPlayer.exe HKCU\...\Run: [NextLive] - C:\Documents and Settings\Katarzyna\Dane aplikacji\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe) MountPoints2: {48aa2cd5-8b58-11e2-a049-bd8cf93df324} - F:\AutoRun.exe AppInit_DLLs: C:\PROGRA~1\MOVIES~1\SAFETY~1\SAFETY~2.DLL => File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\safetynut\x64\safetycrt.dll HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.tb.ask.com/index.jhtml?n=77FD35DB&p2=^AYY^xdm007^S06949^pl&ptb=322A4F43-A7A0-4CAB-AC4A-BAF924795321&si=CM73ws3O4bkCFche3god9x8A-g SearchScopes: HKLM - DefaultScope {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm007^S06949^pl&si=CM73ws3O4bkCFche3god9x8A-g&ptb=322A4F43-A7A0-4CAB-AC4A-BAF924795321&ind=2013092309&n=77fd59d5&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKLM - {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=102&systemid=473&v=n9602-149&apn_uid=8305672278134416&apn_dtid=BND473&o=APN10640&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKLM - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm007^S06949^pl&si=CM73ws3O4bkCFche3god9x8A-g&ptb=322A4F43-A7A0-4CAB-AC4A-BAF924795321&ind=2013092309&n=77fd59d5&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {52db1893-8a90-4192-aede-08e00b8f8473} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear SearchScopes: HKCU - {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION C:\Documents and Settings\Katarzyna\.android C:\Documents and Settings\Katarzyna\daemonprocess.txt C:\Documents and Settings\Katarzyna\Dane aplikacji\newnext.me C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\Apps Hat Mini C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Program Files\DiVapton ***************** C:\WINDOWS\Tasks\EPUpdater.job => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Apps Hat => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48aa2cd5-8b58-11e2-a049-bd8cf93df324} => Key deleted successfully. HKCR\CLSID\{48aa2cd5-8b58-11e2-a049-bd8cf93df324} => Key not found. "C:\\PROGRA~1\\MOVIES~1\\SAFETY~1\\SAFETY~2.DLL" => Value Data removed successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe => Key deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{52db1893-8a90-4192-aede-08e00b8f8473} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{52db1893-8a90-4192-aede-08e00b8f8473} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{75b4241f-171e-44a3-bf44-23613b6e3e03} => Key not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. C:\Documents and Settings\Katarzyna\.android => Moved successfully. C:\Documents and Settings\Katarzyna\daemonprocess.txt => Moved successfully. C:\Documents and Settings\Katarzyna\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\Apps Hat Mini => Moved successfully. C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\Katarzyna\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. C:\Program Files\DiVapton => Moved successfully. ==== End of Fixlog ====