Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 05-02-2014 Ran by user at 2014-02-06 10:31:53 Run:1 Running from C:\Documents and Settings\user\Pulpit\Diagnostyka Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\fst_pl_41\upfst_pl_41.exe HKLM\...\Run: [Regedit32] - C:\WINDOWS\system32\regedit.exe HKLM\...\Run: [] - [X] HKLM\...\Run: [fst_pl_41] - [X] HKLM\...\Run: [upfst_pl_41.exe] - C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\fst_pl_41\upfst_pl_41.exe [3154416 2014-01-27] () HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\RunOnce: [Discount Dragon-repairJob] - wscript.exe "C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Discount Dragon\repair.js" "Discount Dragon-repairJob" [1846 2013-12-18] () HKU\S-1-5-21-1659004503-1417001333-1801674531-1004\...\Run: [Tiny download manager] - "C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DM\TinyDM.exe" /M HKU\S-1-5-21-1659004503-1417001333-1801674531-1004\...\Run: [NextLive] - C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\user\Dane aplikacji\newnext.me\nengine.dll",EntryPoint -m l Task: C:\WINDOWS\Tasks\bench-S-1-5-21-1659004503-1417001333-1801674531-1004.job => C:\Program Files\Bench\Updater\updater.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\bench-sys.job => C:\Program Files\Bench\Updater\updater.exe <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1391433867&from=slbnew&uid=HitachiXHDS721616PLA380_PVG904Z23NZS0V3NZS0VX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1391433867&from=slbnew&uid=HitachiXHDS721616PLA380_PVG904Z23NZS0V3NZS0VX&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1391433867&from=slbnew&uid=HitachiXHDS721616PLA380_PVG904Z23NZS0V3NZS0VX&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1391433867&from=slbnew&uid=HitachiXHDS721616PLA380_PVG904Z23NZS0V3NZS0VX&q={searchTerms} SearchScopes: HKCU - {28E271C9-9EE6-463F-8204-872054D9D679} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} BHO: Discount Dragon BHO - {EA34C851-D481-49F5-A356-3A8B0A8F3B7E} - C:\Program Files\Discount Dragon\FrameworkBHO.dll () Hosts: 54.204.28.26 nikdaiaidiiiogaidkkekcmokcgcdeac S0 b9b0c9bf14119a19; \SystemRoot\System32\Drivers\b9b0c9bf14119a19.sys [X] S3 catchme; \??\C:\DOCUME~1\user\USTAWI~1\Temp\catchme.sys [X] S1 iSafeNetFilter; \??\C:\Program Files\iSafe\iSafeNetFilter.sys [X] C:\Documents and Settings\All Users\Dane aplikacji\IePluginService C:\Documents and Settings\All Users\Dane aplikacji\WPM C:\Documents and Settings\user\.android C:\Documents and Settings\user\daemonprocess.txt C:\Documents and Settings\user\Dane aplikacji\iSafe C:\Documents and Settings\user\Dane aplikacji\nationzoom C:\Documents and Settings\user\Dane aplikacji\newnext.me C:\Documents and Settings\user\Dane aplikacji\SwvUpdater C:\Documents and Settings\user\Moje dokumenty\Mobogenie C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\BenchUpdater C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\freeSOFTtoday C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\fst_pl_41 C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Lollipop C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Documents and Settings\user\Dane aplikacji\systweak C:\Program Files\Bench C:\Program Files\MyPC Backup C:\Program Files\predm C:\Program Files\SupTab C:\WINDOWS\System32\dmwu.exe C:\WINDOWS\system32\epe2000.dll C:\WINDOWS\System32\ImHttpComm.dll C:\WINDOWS\system32\roboot.exe Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search the Web" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\MenuExt\Search the Web" /f ***************** [3016] C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\fst_pl_41\upfst_pl_41.exe => Process closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Regedit32 => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\fst_pl_41 => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upfst_pl_41.exe => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Discount Dragon-repairJob => Value deleted successfully. HKU\S-1-5-21-1659004503-1417001333-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Run\\Tiny download manager => Value deleted successfully. HKU\S-1-5-21-1659004503-1417001333-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. C:\WINDOWS\Tasks\bench-S-1-5-21-1659004503-1417001333-1801674531-1004.job => Moved successfully. C:\WINDOWS\Tasks\bench-sys.job => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{28E271C9-9EE6-463F-8204-872054D9D679} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{28E271C9-9EE6-463F-8204-872054D9D679} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} => Key deleted successfully. HKCR\CLSID\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} => Key deleted successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. b9b0c9bf14119a19 => Service deleted successfully. catchme => Service deleted successfully. iSafeNetFilter => Service deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\IePluginService => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\WPM => Moved successfully. C:\Documents and Settings\user\.android => Moved successfully. C:\Documents and Settings\user\daemonprocess.txt => Moved successfully. C:\Documents and Settings\user\Dane aplikacji\iSafe => Moved successfully. C:\Documents and Settings\user\Dane aplikacji\nationzoom => Moved successfully. C:\Documents and Settings\user\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\user\Dane aplikacji\SwvUpdater => Moved successfully. C:\Documents and Settings\user\Moje dokumenty\Mobogenie => Moved successfully. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\BenchUpdater => Moved successfully. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\freeSOFTtoday => Moved successfully. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\fst_pl_41 => Moved successfully. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Lollipop => Moved successfully. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. C:\Documents and Settings\user\Dane aplikacji\systweak => Moved successfully. C:\Program Files\Bench => Moved successfully. C:\Program Files\MyPC Backup => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\SupTab => Moved successfully. C:\WINDOWS\System32\dmwu.exe => Moved successfully. C:\WINDOWS\system32\epe2000.dll => Moved successfully. C:\WINDOWS\System32\ImHttpComm.dll => Moved successfully. C:\WINDOWS\system32\roboot.exe => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search the Web" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\MenuExt\Search the Web" /f ========= Błąd: system nie może odnaleźć określonego klucza rejestru lub wartości. ========= End of Reg: ========= ==== End of Fixlog ====