Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-02-2014 01 Ran by PAWEL at 2014-02-15 15:09:41 Run:1 Running from C:\Users\PAWEL\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** URLSearchHook: HKLM - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} URLSearchHook: HKLM - Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) URLSearchHook: HKLM - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) URLSearchHook: HKLM - SiteFinder - {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files\SiteFinder\SiteFinder.dll (Site Finder) URLSearchHook: HKCU - Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) URLSearchHook: HKCU - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033 SearchScopes: HKCU - {69EBE55B-9D7F-4CDF-BA9D-4DDF524A2C54} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=7CDF101D-9FB3-4AF4-8297-CB4322A235B7&apn_sauid=77D05FE8-29E5-468A-9BCA-B7AF22D52015 SearchScopes: HKCU - {A57A5B3D-D23E-4589-A8BA-38D209ADD858} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468 BHO: Winamp Toolbar Loader - {4accc990-3dc7-4456-a734-5cb4b610a7f5} - C:\Program Files\Winamp Toolbar\winamppltb.dll (AOL Inc.) BHO: uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) BHO: Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) Toolbar: HKLM - Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) Toolbar: HKLM - Winamp Toolbar - {a0b1221c-a3ff-4f7c-a393-dc63af5301e9} - C:\Program Files\Winamp Toolbar\winamppltb.dll (AOL Inc.) Toolbar: HKLM - uTorrentControl_v2 Toolbar - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) Toolbar: HKLM - SiteFinder - {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files\SiteFinder\SiteFinder.dll (Site Finder) Toolbar: HKCU - Winamp Toolbar - {A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} - C:\Program Files\Winamp Toolbar\winamppltb.dll (AOL Inc.) Toolbar: HKCU - uTorrentControl_v2 Toolbar - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.) Toolbar: HKCU - Ashampoo PO Toolbar - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) CHR HKLM\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\PAWEL\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-08-26] CHR HKCU\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\PAWEL\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-08-26] FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml HKU\S-1-5-21-601188784-2125393631-3366121521-1001\...\Run: [Akamai NetSession Interface] - C:\Users\PAWEL\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKU\S-1-5-21-601188784-2125393631-3366121521-1004\...\Run: [AVG-Secure-Search-Update_JUNE2013_TB] - "C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_TB.exe" /PROMPT /CMPID=JUNE2013_TB HKU\S-1-5-21-601188784-2125393631-3366121521-1004\...\Run: [AVG-Secure-Search-Update_JUNE2013_HP] - "C:\Program Files\AVG Secure Search\AVG-Secure-Search-Update_JUNE2013_HP.exe" /PROMPT /CMPID=JUNE2013_HP AppInit_DLLs: C:\Windows\System32\guard32.dll => File Not Found S3 catchme; \??\C:\Users\PAWEL\AppData\Local\Temp\catchme.sys [X] S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X] C:\Program Files\AVG Secure Search C:\Program Files\SimilarSites C:\Program Files\Comodo C:\ProgramData\Comodo C:\Users\PAWEL\AppData\Local\CRE C:\Users\PAWEL\AppData\Roaming\SimilarSites C:\Users\PAWEL\Downloads\avast-Free-Antivirus(13266).exe C:\Users\PAWEL\Downloads\Spybot - Search & Destroy 1.6.2_isdmgr.exe C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup C:\Windows\system32\Drivers\sfi.dat C:\Windows\system32\Drivers\etc\hosts.*.backup Task: {0EB3E696-F8C6-4096-B8FE-081523D12DD6} - System32\Tasks\{6F691EE1-9A03-4072-BCD8-CDB9D7EDD715} => D:\1\Acrobat 5 CE\Setup.exe Task: {5981B041-37D8-42B1-966B-0F2CA135C008} - System32\Tasks\{469CFDB8-7E32-4596-B49E-24FAB0ABB6D8} => D:\1\Acrobat 5 CE\Setup.exe Task: {70F3F3E5-E230-416B-88DD-D39DD0D038A0} - System32\Tasks\{E7CE41F9-B335-4AC6-96E6-312CDEF091B7} => D:\SETUP.EXE Task: {DD0F369A-A6C3-4922-882E-BA229022EE60} - System32\Tasks\{12D50971-FFE8-4123-8F1E-C2B85C80B81F} => D:\SETUP.EXE Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt" /f ***************** HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully. HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Unable to delete value HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Unable to delete value HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\{CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} => Value deleted successfully. HKCR\CLSID\{CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Unable to delete value HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Unable to delete value HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{69EBE55B-9D7F-4CDF-BA9D-4DDF524A2C54} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{69EBE55B-9D7F-4CDF-BA9D-4DDF524A2C54} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A57A5B3D-D23E-4589-A8BA-38D209ADD858} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{A57A5B3D-D23E-4589-A8BA-38D209ADD858} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4accc990-3dc7-4456-a734-5cb4b610a7f5} => Key deleted successfully. HKCR\CLSID\{4accc990-3dc7-4456-a734-5cb4b610a7f5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key not found. HKCR\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Key not found. HKCR\CLSID\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Unable to delete value HKCR\CLSID\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{a0b1221c-a3ff-4f7c-a393-dc63af5301e9} => Value deleted successfully. HKCR\CLSID\{a0b1221c-a3ff-4f7c-a393-dc63af5301e9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Unable to delete value HKCR\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} => Value deleted successfully. HKCR\CLSID\{CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} => Value deleted successfully. HKCR\CLSID\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Unable to delete value HKCR\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Unable to delete value HKCR\CLSID\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Key not found. HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda => Key deleted successfully. C:\Users\PAWEL\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx => Moved successfully. HKCU\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda => Key deleted successfully. "C:\Users\PAWEL\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx" => File/Directory not found. C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml => Moved successfully. HKU\S-1-5-21-601188784-2125393631-3366121521-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => Unable to delete value HKU\S-1-5-21-601188784-2125393631-3366121521-1004\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_JUNE2013_TB => Value deleted successfully. HKU\S-1-5-21-601188784-2125393631-3366121521-1004\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_JUNE2013_HP => Value deleted successfully. "C:\\Windows\\System32\\guard32.dll" => Value Data removed successfully. catchme => Service deleted successfully. pccsmcfd => Service deleted successfully. C:\Program Files\AVG Secure Search => Moved successfully. C:\Program Files\SimilarSites => Moved successfully. C:\Program Files\Comodo => Moved successfully. C:\ProgramData\Comodo => Moved successfully. C:\Users\PAWEL\AppData\Local\CRE => Moved successfully. C:\Users\PAWEL\AppData\Roaming\SimilarSites => Moved successfully. C:\Users\PAWEL\Downloads\avast-Free-Antivirus(13266).exe => Moved successfully. C:\Users\PAWEL\Downloads\Spybot - Search & Destroy 1.6.2_isdmgr.exe => Moved successfully. C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup => Moved successfully. C:\Windows\system32\Drivers\sfi.dat => Moved successfully. C:\Windows\system32\Drivers\etc\hosts.*.backup => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0EB3E696-F8C6-4096-B8FE-081523D12DD6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0EB3E696-F8C6-4096-B8FE-081523D12DD6} => Key deleted successfully. C:\Windows\System32\Tasks\{6F691EE1-9A03-4072-BCD8-CDB9D7EDD715} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6F691EE1-9A03-4072-BCD8-CDB9D7EDD715} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5981B041-37D8-42B1-966B-0F2CA135C008} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5981B041-37D8-42B1-966B-0F2CA135C008} => Key deleted successfully. C:\Windows\System32\Tasks\{469CFDB8-7E32-4596-B49E-24FAB0ABB6D8} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{469CFDB8-7E32-4596-B49E-24FAB0ABB6D8} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70F3F3E5-E230-416B-88DD-D39DD0D038A0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70F3F3E5-E230-416B-88DD-D39DD0D038A0} => Key deleted successfully. C:\Windows\System32\Tasks\{E7CE41F9-B335-4AC6-96E6-312CDEF091B7} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E7CE41F9-B335-4AC6-96E6-312CDEF091B7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DD0F369A-A6C3-4922-882E-BA229022EE60} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD0F369A-A6C3-4922-882E-BA229022EE60} => Key deleted successfully. C:\Windows\System32\Tasks\{12D50971-FFE8-4123-8F1E-C2B85C80B81F} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{12D50971-FFE8-4123-8F1E-C2B85C80B81F} => Key deleted successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====