Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-02-2014 01 Ran by gr3nade at 2014-02-15 14:33:34 Run:1 Running from G:\#Pierdolcoki\fixitpc Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [] - [X] HKU\S-1-5-21-1066508603-529841488-691085831-1000\...\Run: [AdobeBridge] - [X] HKU\S-1-5-21-1066508603-529841488-691085831-1000\...\Run: [] - D:\#Programy\Kies\External\FirmwareUpdate\KiesPDLR.exe HKU\S-1-5-21-1066508603-529841488-691085831-1000\...\Run: [BackgroundContainer] - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\gr3nade\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun <===== ATTENTION HKU\S-1-5-21-1066508603-529841488-691085831-500\...\Run: [SearchProtect] - C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&CUI=UN25336955242354018&UM=2&ctid=CT3288691 URLSearchHook: HKLM-x32 - DivX Browser Bar Toolbar - {77e8143b-6759-416e-b521-82cfed75150b} - C:\Program Files (x86)\DivX_Browser_Bar\prxtbDiv0.dll (Conduit Ltd.) URLSearchHook: HKCU - DivX Browser Bar Toolbar - {77e8143b-6759-416e-b521-82cfed75150b} - C:\Program Files (x86)\DivX_Browser_Bar\prxtbDiv0.dll (Conduit Ltd.) SearchScopes: HKLM-x32 - DefaultScope {597295D3-05A4-4105-97F2-D5A333AD0034} URL = SearchScopes: HKCU - DefaultScope {597295D3-05A4-4105-97F2-D5A333AD0034} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3288691&CUI=UN25336955242354018&UM=2 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {597295D3-05A4-4105-97F2-D5A333AD0034} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3288691&CUI=UN25336955242354018&UM=2 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={D25D462F-08D1-4D39-8E66-850486404A71}&mid=ecfe5e2052eb47d0acedd16b5364681f-3b6c02514aa2cf405cf9c7e757ed61d5f60a51a0&lang=en&ds=ft011&pr=sa&d=2013-01-12 17:54:38&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKCU - No Name - {77E8143B-6759-416E-B521-82CFED75150B} - No File CHR HKCU\...\Chrome\Extension: [pkmpcdbgnfjfeelcpebpkflcmbkclfho] - C:\Users\gr3nade\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx [2013-06-05] CHR HKLM-x32\...\Chrome\Extension: [pkmpcdbgnfjfeelcpebpkflcmbkclfho] - C:\Users\gr3nade\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx [2013-06-05] Task: {6D9CCE66-B8F4-4B40-B35F-A69F957810E0} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{4FED9368-AA1A-4949-B8CF-7685D625383C}.exe Task: {906AA4E4-712D-4852-B3E7-60189FB8A96E} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\gr3nade\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{4FED9368-AA1A-4949-B8CF-7685D625383C}.exe AlternateDataStreams: C:\Program Files\Common Files\System:5lnbCusodGEtHQhbHDI611 AlternateDataStreams: C:\ProgramData\Microsoft:iMFymG0TXpUaIaLILIeVb2 AlternateDataStreams: C:\ProgramData\Microsoft:RgS5D9jS95niBxbAR2YPaFgE AlternateDataStreams: C:\Users\gr3nade\AppData\Local\Temp:r7tP9FM48biVAfgiJfDFziUU C:\Users\gr3nade\AppData\Local\Conduit C:\Users\gr3nade\AppData\Local\CRE C:\Users\gr3nade\AppData\Roaming\3909 C:\Users\Administrator\AppData\Roaming\SearchProtect ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKU\S-1-5-21-1066508603-529841488-691085831-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. HKU\S-1-5-21-1066508603-529841488-691085831-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKU\S-1-5-21-1066508603-529841488-691085831-1000\Software\Microsoft\Windows\CurrentVersion\Run\\BackgroundContainer => Value deleted successfully. HKU\S-1-5-21-1066508603-529841488-691085831-500\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect => Value not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{77e8143b-6759-416e-b521-82cfed75150b} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{77e8143b-6759-416e-b521-82cfed75150b} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{77e8143b-6759-416e-b521-82cfed75150b} => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{597295D3-05A4-4105-97F2-D5A333AD0034} => Key deleted successfully. HKCR\CLSID\{597295D3-05A4-4105-97F2-D5A333AD0034} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{77E8143B-6759-416E-B521-82CFED75150B} => Value deleted successfully. HKCR\CLSID\{77E8143B-6759-416E-B521-82CFED75150B} => Key not found. HKCU\SOFTWARE\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho => Key deleted successfully. C:\Users\gr3nade\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho => Key deleted successfully. "C:\Users\gr3nade\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6D9CCE66-B8F4-4B40-B35F-A69F957810E0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D9CCE66-B8F4-4B40-B35F-A69F957810E0} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{906AA4E4-712D-4852-B3E7-60189FB8A96E} => Key not found. C:\Windows\System32\Tasks\BackgroundContainer Startup Task => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Program Files\Common Files\System => ":5lnbCusodGEtHQhbHDI611" ADS removed successfully. C:\ProgramData\Microsoft => ":iMFymG0TXpUaIaLILIeVb2" ADS removed successfully. C:\ProgramData\Microsoft => ":RgS5D9jS95niBxbAR2YPaFgE" ADS removed successfully. C:\Users\gr3nade\AppData\Local\Temp => ":r7tP9FM48biVAfgiJfDFziUU" ADS removed successfully. C:\Users\gr3nade\AppData\Local\Conduit => Moved successfully. C:\Users\gr3nade\AppData\Local\CRE => Moved successfully. C:\Users\gr3nade\AppData\Roaming\3909 => Moved successfully. C:\Users\Administrator\AppData\Roaming\SearchProtect => Moved successfully. ==== End of Fixlog ====