Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-02-2014 01 Ran by EWA at 2014-02-11 12:47:57 Run:1 Running from F:\Naprawa\instalki Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [ROC_ROC_NT] - "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT HKLM-x32\...\Run: [ROC_roc_ssl_v12] - "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=119357&tt=120613_ctrl&babsrc=HP_ss_din2g&mntrId=2AE3A639E5C3AB57 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = URLSearchHook: HKLM-x32 - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871} URLSearchHook: HKLM-x32 - Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\tbFree.dll (Conduit Ltd.) URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File URLSearchHook: HKCU - Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\tbFree.dll (Conduit Ltd.) SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1708250 SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1708250 SearchScopes: HKCU - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1708250 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=119357&tt=120613_ctrl&babsrc=SP_ss_din2g&mntrId=2AE3A639E5C3AB57 SearchScopes: HKCU - {5C0906BD-92B1-420D-A708-E7D20A530F3C} URL = http://websearch.ask.com/redirect?client=ie&tb=ASV5&o=101719&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AL&apn_dtid=^YYYYYY^YY^PL&apn_uid=A6578D52-DC93-4E78-A835-085815BD790F&apn_sauid=F07E5BC9-B6B4-427B-B0D2-83293E9E5392 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1708250 BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll No File BHO-x32: Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\tbFree.dll (Conduit Ltd.) BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File Toolbar: HKLM-x32 - Free Lunch Design Toolbar - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files (x86)\Free_Lunch_Design\tbFree.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} - No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml CHR HKLM-x32\...\Chrome\Extension: [hidjnkeodmholilgafgdlgmgggbhnigl] - C:\Users\EWA\AppData\Roaming\SimilarSites\similarsites.crx [2012-11-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [X] Task: {184E15F3-7970-495D-85D6-F70D082E508C} - System32\Tasks\{B9E467B4-F032-43AF-9319-5E85B8815343} => Firefox.exe http://ui.skype.com/ui/0/6.0.0.126/pl/abandoninstall?page=tsProgressBar Task: {405D0BF6-708A-402B-B087-DD8819170ABB} - System32\Tasks\{5B5C6A74-8526-43CC-A4A7-4A4F9D015BA5} => C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe Task: {8A9EE81D-8D15-43E9-928F-6CE722DAF1F0} - System32\Tasks\{67757B8B-257F-4E93-8906-E6C6ACD0CBB1} => Firefox.exe http://ui.skype.com/ui/0/5.8.0.158.259/pl/abandoninstall?source=lightinstaller&page=tsInstall Task: {D30E5FF0-E195-4B3E-8AE0-E10421E5869A} - System32\Tasks\QtraxPlayer => C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe [2013-09-13] (Microsoft Corporation) Task: {F3D90867-70DA-43AD-A380-05B4FE3C2B3A} - System32\Tasks\{48691BE6-0E3D-4A78-80AF-CE62B187BC03} => Chrome.exe http://ui.skype.com/ui/0/6.6.0.106/pl/abandoninstall?page=tsPlugin C:\Users\EWA\AppData\Roaming\BabSolution C:\Users\EWA\AppData\Roaming\Babylon C:\Users\EWA\AppData\Roaming\DVDVideoSoft C:\Users\EWA\AppData\Roaming\DVDVideoSoftIEHelpers C:\Users\EWA\AppData\Roaming\File Scout C:\Users\EWA\AppData\Roaming\OpenCandy C:\Users\EWA\AppData\Roaming\PerformerSoft Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: sc config "Multimedia mobilNET. RunOuc" start= demand ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ROC_ROC_NT => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ROC_roc_ssl_v12 => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5C0906BD-92B1-420D-A708-E7D20A530F3C} => Key deleted successfully. HKCR\CLSID\{5C0906BD-92B1-420D-A708-E7D20A530F3C} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKCR\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} => Value deleted successfully. HKCR\CLSID\{57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} => Key not found. C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl => Key deleted successfully. "C:\Users\EWA\AppData\Roaming\SimilarSites\similarsites.crx" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. ACDaemon => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{184E15F3-7970-495D-85D6-F70D082E508C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{184E15F3-7970-495D-85D6-F70D082E508C} => Key deleted successfully. C:\Windows\System32\Tasks\{B9E467B4-F032-43AF-9319-5E85B8815343} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B9E467B4-F032-43AF-9319-5E85B8815343} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{405D0BF6-708A-402B-B087-DD8819170ABB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{405D0BF6-708A-402B-B087-DD8819170ABB} => Key deleted successfully. C:\Windows\System32\Tasks\{5B5C6A74-8526-43CC-A4A7-4A4F9D015BA5} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5B5C6A74-8526-43CC-A4A7-4A4F9D015BA5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A9EE81D-8D15-43E9-928F-6CE722DAF1F0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9EE81D-8D15-43E9-928F-6CE722DAF1F0} => Key deleted successfully. C:\Windows\System32\Tasks\{67757B8B-257F-4E93-8906-E6C6ACD0CBB1} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{67757B8B-257F-4E93-8906-E6C6ACD0CBB1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D30E5FF0-E195-4B3E-8AE0-E10421E5869A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D30E5FF0-E195-4B3E-8AE0-E10421E5869A} => Key deleted successfully. C:\Windows\System32\Tasks\QtraxPlayer => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QtraxPlayer => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3D90867-70DA-43AD-A380-05B4FE3C2B3A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3D90867-70DA-43AD-A380-05B4FE3C2B3A} => Key deleted successfully. C:\Windows\System32\Tasks\{48691BE6-0E3D-4A78-80AF-CE62B187BC03} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{48691BE6-0E3D-4A78-80AF-CE62B187BC03} => Key deleted successfully. C:\Users\EWA\AppData\Roaming\BabSolution => Moved successfully. C:\Users\EWA\AppData\Roaming\Babylon => Moved successfully. C:\Users\EWA\AppData\Roaming\DVDVideoSoft => Moved successfully. C:\Users\EWA\AppData\Roaming\DVDVideoSoftIEHelpers => Moved successfully. C:\Users\EWA\AppData\Roaming\File Scout => Moved successfully. C:\Users\EWA\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\EWA\AppData\Roaming\PerformerSoft => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "Multimedia mobilNET. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ==== End of Fixlog ====