Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-02-2014 Ran by media at 2014-02-21 20:27:27 Run:1 Running from C:\Users\media\Desktop\Nowy folder Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {85C61AEA-9B49-4642-9ECF-306737E68544} - System32\Tasks\MetaCrawler => C:\Users\media\AppData\Roaming\METACR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\windows\Tasks\MetaCrawler.job => C:\Users\media\AppData\Roaming\METACR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe /svc [X] S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe /medsvc [X] R4 ehdrv; system32\DRIVERS\ehdrv.sys [X] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" HKLM-x32\...\Run: [tuto4pc_pl_17] - [X] HKLM-x32\...\Run: [ConvertAd] - C:\Users\media\AppData\Local\ConvertAd\ConvertAd.exe HKLM-x32\...\Run: [AnyProtect Tray] - C:\Program Files (x86)\AnyProtectEx\AnyProtectTray.exe /scanner HKLM-x32\...\Run: [AnyProtect] - C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird C:\Users\media\AppData\Local\AnyProtectScannerSetup.exe C:\Users\media\AppData\Local\Google C:\Users\media\AppData\Local\Temp\InstHelper.exe C:\Users\media\AppData\Roaming\SimilarSites ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{85C61AEA-9B49-4642-9ECF-306737E68544} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85C61AEA-9B49-4642-9ECF-306737E68544} => Key deleted successfully. C:\Windows\System32\Tasks\MetaCrawler => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MetaCrawler => Key deleted successfully. C:\windows\Tasks\MetaCrawler.job => Moved successfully. bonanzadealslive => Service deleted successfully. bonanzadealslivem => Service deleted successfully. ehdrv => Service not found. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MCODS => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MpfService => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\tuto4pc_pl_17 => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ConvertAd => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AnyProtect Tray => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AnyProtect => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key deleted successfully. HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKLM\Software\Mozilla\Thunderbird\Extensions\\eplgTb@eset.com => Value deleted successfully. C:\Users\media\AppData\Local\AnyProtectScannerSetup.exe => Moved successfully. C:\Users\media\AppData\Local\Google => Moved successfully. C:\Users\media\AppData\Local\Temp\InstHelper.exe => Moved successfully. C:\Users\media\AppData\Roaming\SimilarSites => Moved successfully. ==== End of Fixlog ====