Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-02-2014 Ran by xxx at 2014-02-05 14:24:36 Run:1 Running from F:\ Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-1644491937-2147091713-839522115-1004\...\Run: [ctfmon.exe] - C:\DOCUME~1\ALLUSE~1\DANEAP~1\rundll32.exe c:\docume~1\alluse~1\daneap~1\lwigto.dat,FG00 <===== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?l=dis&o=APN10260&gct=hp&apn_ptnrs=^AGR&apn_dtid=^YYYYYY^YY^PL&p2=^AGR^YYYYYY^YY^PL&tpid=ARS3&apn_dbr=ff_20.0&apn_uid=E0C4FB24-43BA-4CD7-ABEB-E96A0F0934A0&itbv=11.8.1.222&doi=2013-04-06 URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: HKCU - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.) URLSearchHook: HKCU - ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\prxtbTog0.dll (Conduit Ltd.) SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://asksearch.ask.com/redirect?client=ie&src=crm&tb=ARS3&itbv=11.8.1.222&o=APN10260&locale=en_US&apn_uid=E0C4FB24-43BA-4CD7-ABEB-E96A0F0934A0&apn_ptnrs=^AGR&apn_dtid=^YYYYYY^YY^PL&apn_dbr=ff_20.0&doi=2013-04-06&q={searchTerms}& SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://asksearch.ask.com/redirect?client=ie&src=crm&tb=ARS3&itbv=11.8.1.222&o=APN10260&locale=en_US&apn_uid=E0C4FB24-43BA-4CD7-ABEB-E96A0F0934A0&apn_ptnrs=^AGR&apn_dtid=^YYYYYY^YY^PL&apn_dbr=ff_20.0&doi=2013-04-06&q={searchTerms}& SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1708250 BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\prxtbTog0.dll (Conduit Ltd.) BHO: Ask Toolbar - {41525333-0076-A76A-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ARS3\Passport.dll (APN LLC.) Toolbar: HKLM - ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\prxtbTog0.dll (Conduit Ltd.) Toolbar: HKLM - Ask Toolbar - {41525333-0076-A76A-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ARS3\Passport.dll (APN LLC.) Toolbar: HKCU - Winamp Toolbar - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC) Toolbar: HKCU - ToggleEN Toolbar - {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - C:\Program Files\ToggleEN\prxtbTog0.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - Ask Toolbar - {41525333-0076-A76A-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ARS3\Passport.dll (APN LLC.) FF SearchPlugin: C:\Documents and Settings\xxx\Dane aplikacji\Mozilla\Firefox\Profiles\1ltcdqd0.default\searchplugins\conduit.xml S1 sfvpxojw; \??\C:\WINDOWS\system32\drivers\sfvpxojw.sys [X] C:\Documents and Settings\xxx\Dane aplikacji\PriceGong C:\Documents and Settings\xxx\duedue.exe CMD: netsh winsock reset CMD: netsh firewall reset ***************** HKU\S-1-5-21-1644491937-2147091713-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Run\\ctfmon.exe => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. Default URLSearchHook was restored successfully . HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{038cb5c7-48ea-4af9-94e0-a1646542e62b} => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b} => Key not found. HKCR\CLSID\{038cb5c7-48ea-4af9-94e0-a1646542e62b} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41525333-0076-A76A-76A7-7A786E7484D7} => Key not found. HKCR\CLSID\{41525333-0076-A76A-76A7-7A786E7484D7} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{038cb5c7-48ea-4af9-94e0-a1646542e62b} => Value not found. HKCR\CLSID\{038cb5c7-48ea-4af9-94e0-a1646542e62b} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{41525333-0076-A76A-76A7-7A786E7484D7} => Value not found. HKCR\CLSID\{41525333-0076-A76A-76A7-7A786E7484D7} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} => Value not found. HKCR\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{038CB5C7-48EA-4AF9-94E0-A1646542E62B} => Value not found. HKCR\CLSID\{038CB5C7-48EA-4AF9-94E0-A1646542E62B} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41525333-0076-A76A-76A7-7A786E7484D7} => Value deleted successfully. HKCR\CLSID\{41525333-0076-A76A-76A7-7A786E7484D7} => Key not found. C:\Documents and Settings\xxx\Dane aplikacji\Mozilla\Firefox\Profiles\1ltcdqd0.default\searchplugins\conduit.xml => Moved successfully. sfvpxojw => Service deleted successfully. C:\Documents and Settings\xxx\Dane aplikacji\PriceGong => Moved successfully. C:\Documents and Settings\xxx\duedue.exe => Moved successfully. ========= netsh winsock reset ========= OSTRZE½ENIE: Nie mo¾na uzyska† informacji o ho˜cie z komputera: [MS-D]. Niekt¢re polecenia mog¥ by† niedost©pne. Nie mo¾na uruchomi† okre˜lonej usˆugi, poniewa¾ jest ona wyˆ¥czona lub poniewa¾ nie s¥ wˆ¥czone skojarzone z ni¥ urz¥dzenia. Pomy˜lnie zresetowano Winsock Catalog. Musisz ponownie uruchomi† komputer, aby ukoäczy† resetowanie. ========= End of CMD: ========= ========= netsh firewall reset ========= OSTRZE½ENIE: Nie mo¾na uzyska† informacji o ho˜cie z komputera: [MS-D]. Niekt¢re polecenia mog¥ by† niedost©pne. Nie mo¾na uruchomi† okre˜lonej usˆugi, poniewa¾ jest ona wyˆ¥czona lub poniewa¾ nie s¥ wˆ¥czone skojarzone z ni¥ urz¥dzenia. Ok. ========= End of CMD: ========= ==== End of Fixlog ====