Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01 Ran by 1 at 2014-04-04 20:20:25 Run:1 Running from C:\Documents and Settings\1\Pulpit\naprawa kompa Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: C:\WINDOWS\Tasks\EPUpdater.job => C:\DOCUME~1\1\DANEAP~1\BABSOL~1\Shared\BabMaint.exe SearchScopes: HKCU - DefaultScope {2FDEF81B-9DC2-48ED-B20E-BC49FFFF40FE} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID=119357&tt=gc_&babsrc=SP_ss&mntrId=DC4F00158315A310 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=67738826-0645-4C83-9F62-B54AE0382F2A&apn_sauid=380B81D3-B00E-4E71-9CC5-5AD418A9C5CD SearchScopes: HKCU - {2FDEF81B-9DC2-48ED-B20E-BC49FFFF40FE} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear BHO: Lyrmix - {A8E06666-F1AE-4436-80C1-A1A1A865F236} - C:\Program Files\Lyrmix\lyrmix.dll No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [lyrmix@lyrmix.net] - C:\Program Files\Lyrmix\FF\ CHR HKLM\...\Chrome\Extension: [jofdlbdmefjogcipddjnblinigmpagoj] - C:\Program Files\Lyrmix\Chrome.crx [2013-08-23] HKLM\...\Run: [VDownloader] - C:\Program Files\VDownloader\VDownloader.exe /silent S2 Apple Mobile Device; "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [X] S3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [35088 2013-04-30] (The OpenVPN Project) S3 amsint32; \??\C:\WINDOWS\system32\drivers\ohgnt.sys [X] S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [X] S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [X] C:\Documents and Settings\1\ciedeih.exe C:\Documents and Settings\1\Dane aplikacji\Babylon C:\Documents and Settings\1\Dane aplikacji\DealPly C:\Documents and Settings\All Users\Dane aplikacji\Ask C:\Documents and Settings\All Users\Dane aplikacji\Babylon C:\Program Files\Mozilla Firefox\extensions C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\WINDOWS\System32\DRIVERS\tap0901.sys D:\autorun.inf Reg: reg add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot /v AlternateShell /t REG_SZ /d cmd.exe /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System /v EnableLUA /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\lyrmix@lyrmix.net /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: sc config "PLAY ONLINE. RunOuc" start= demand CMD: netsh firewall reset ***************** C:\WINDOWS\Tasks\EPUpdater.job => Moved successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FDEF81B-9DC2-48ED-B20E-BC49FFFF40FE} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{2FDEF81B-9DC2-48ED-B20E-BC49FFFF40FE} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8E06666-F1AE-4436-80C1-A1A1A865F236} => Key deleted successfully. HKCR\CLSID\{A8E06666-F1AE-4436-80C1-A1A1A865F236} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => Value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\smartwebprinting@hp.com => Value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\smartwebprinting@hp.com => Value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\lyrmix@lyrmix.net => Value deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\jofdlbdmefjogcipddjnblinigmpagoj => Key deleted successfully. "C:\Program Files\Lyrmix\Chrome.crx" => File/Directory not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\VDownloader => Value deleted successfully. Apple Mobile Device => Service deleted successfully. tap0901 => Service deleted successfully. amsint32 => Service deleted successfully. EagleNT => Service deleted successfully. EagleXNt => Service deleted successfully. C:\Documents and Settings\1\ciedeih.exe => Moved successfully. C:\Documents and Settings\1\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\1\Dane aplikacji\DealPly => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Ask => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Babylon => Moved successfully. C:\Program Files\Mozilla Firefox\extensions => Moved successfully. C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\WINDOWS\System32\DRIVERS\tap0901.sys => Moved successfully. D:\autorun.inf => Moved successfully. ========= reg add HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot /v AlternateShell /t REG_SZ /d cmd.exe /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System /v EnableLUA /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\lyrmix@lyrmix.net /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= sc config "PLAY ONLINE. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUCCESS ========= End of CMD: ========= ========= netsh firewall reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====