Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-02-2014 Ran by kUlka at 2014-02-05 08:13:20 Run:1 Running from C:\Documents and Settings\kUlka\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\YourFile DownloaderUpdate.job => C:\Program Files\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.qooqlle.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhoome.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhoome.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myhoome.com/ SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope 241433449C2C40FBAB5CC8929A5B3533 URL = http://mystart.incredibar.com/mb203?a=6PQWPYpgc3&search={searchTerms}&i=26 SearchScopes: HKCU - 241433449C2C40FBAB5CC8929A5B3533 URL = http://mystart.incredibar.com/mb203?a=6PQWPYpgc3&search={searchTerms}&i=26 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {3DFAB2B5-06E7-44C1-98D8-137B4EEBA75B} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=86E3FCA1-C622-41A0-9EA6-4FED90173C81&apn_sauid=7C2EE6B1-2287-457F-BDFC-51E99C71A73C SearchScopes: HKCU - {42168F92-DA71-42E6-BC7F-132EAC1F1899} URL = http://www.google.com/cse?cx=partner-pub-5462406484424654%3A8q0sn8-w2ss&ie=ISO-8859-1&q={searchTerms}&sa=Search&siteurl=qooqlle.com%2F <===== ATTENTION BHO: No Name - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - No File Toolbar: HKLM - No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No File Toolbar: HKCU - No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No File CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKLM\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\DOCUME~1\kUlka\USTAWI~1\Temp\ccex.crx [2013-08-14] S3 CiSvc; %SystemRoot%\system32\cisvc.exe [X] S2 ERSvc; %SystemRoot%\System32\ersvc.dll [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S1 iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys [X] R4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] U3 uxddqpog; \??\C:\DOCUME~1\kUlka\USTAWI~1\Temp\uxddqpog.sys [X] C:\Documents and Settings\kUlka\Dane aplikacji\Toolbar4 C:\WINDOWS\Tasks\YourFile DownloaderUpdate.job C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job C:\Documents and Settings\kUlka\Dane aplikacji\CamLayout.ini C:\Documents and Settings\kUlka\Dane aplikacji\CamShapes.ini C:\Documents and Settings\All Users\nvwiz.exe C:\Documents and Settings\Default User\ytb.exe C:\Documents and Settings\kUlka\ytb.exe ***************** C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => Moved successfully. C:\WINDOWS\Tasks\YourFile DownloaderUpdate.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\241433449C2C40FBAB5CC8929A5B3533 => Key deleted successfully. HKCR\Wow6432Node\CLSID\241433449C2C40FBAB5CC8929A5B3533 => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3DFAB2B5-06E7-44C1-98D8-137B4EEBA75B} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{3DFAB2B5-06E7-44C1-98D8-137B4EEBA75B} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{42168F92-DA71-42E6-BC7F-132EAC1F1899} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{42168F92-DA71-42E6-BC7F-132EAC1F1899} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99} => Key deleted successfully. HKCR\CLSID\{71e129ff-6c2a-4984-818c-7e2c998b8d99} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{8660E5B3-6C41-44DE-8503-98D99BBECD41} => Value deleted successfully. HKCR\CLSID\{8660E5B3-6C41-44DE-8503-98D99BBECD41} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8660E5B3-6C41-44DE-8503-98D99BBECD41} => Value deleted successfully. HKCR\CLSID\{8660E5B3-6C41-44DE-8503-98D99BBECD41} => Key not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc => Key deleted successfully. "C:\DOCUME~1\kUlka\USTAWI~1\Temp\ccex.crx" => File/Directory not found. CiSvc => Service deleted successfully. ERSvc => Service deleted successfully. ewusbnet => Service deleted successfully. huawei_enumerator => Service deleted successfully. hwdatacard => Service deleted successfully. iSafeNetFilter => Service deleted successfully. sptd => Service deleted successfully. uxddqpog => Service not found. C:\Documents and Settings\kUlka\Dane aplikacji\Toolbar4 => Moved successfully. "C:\WINDOWS\Tasks\YourFile DownloaderUpdate.job" => File/Directory not found. "C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job" => File/Directory not found. C:\Documents and Settings\kUlka\Dane aplikacji\CamLayout.ini => Moved successfully. C:\Documents and Settings\kUlka\Dane aplikacji\CamShapes.ini => Moved successfully. C:\Documents and Settings\All Users\nvwiz.exe => Moved successfully. C:\Documents and Settings\Default User\ytb.exe => Moved successfully. C:\Documents and Settings\kUlka\ytb.exe => Moved successfully. ==== End of Fixlog ====