Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:21-05-2014 Ran by ja sam at 2014-05-23 12:42:44 Run:1 Running from C:\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\IePluginService\PluginService.exe () C:\Program Files\004\rqpbhevlkc32.exe () C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\t4pc_en_3\upt4pc_en_3.exe R2 IePluginService; C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\IePluginService\PluginService.exe [705136 2014-04-11] (Cherished Technololgy LIMITED) R2 rqpbhevlkc32; C:\Program Files\004\rqpbhevlkc32.exe [543232 2014-05-05] () S2 Update webget; "C:\Program Files\webget\updatewebget.exe" [X] HKLM\...\Run: [mobilegeni daemon] => C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Run: [fst_pl_117] => [X] HKLM\...\Run: [t4pc_en_3] => [X] HKLM\...\Run: [upt4pc_en_3.exe] => C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\t4pc_en_3\upt4pc_en_3.exe [3268080 2014-05-14] () HKU\S-1-5-21-299502267-1993962763-1417001333-1004\...\Run: [SpeedUpMyComputer] => C:\Program Files\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe HKLM\...\AppCertDlls: [x64] -> c:\program files\settings manager\systemk\x64\sysapcrt.dll Task: C:\WINDOWS\Tasks\APSnotifierPP1.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\APSnotifierPP2.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\APSnotifierPP3.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\bench-sys.job => C:\Program Files\Bench\Updater\updater.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.default-search.net?sid=492&aid=109&itype=a&ver=12692&tm=354&src=hmp HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1396980688&from=smt&uid=ST980811AS_5LY7743GXXXX5LY7743G&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1396980688&from=smt&uid=ST980811AS_5LY7743GXXXX5LY7743G&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1396980688&from=smt&uid=ST980811AS_5LY7743GXXXX5LY7743G SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396980688&from=smt&uid=ST980811AS_5LY7743GXXXX5LY7743G&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396980688&from=smt&uid=ST980811AS_5LY7743GXXXX5LY7743G&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=109&itype=a&ver=12692&tm=354&src=ds&p={searchTerms} SearchScopes: HKCU - DefaultScope {D9DC290A-C648-4059-8596-A905DF4F5037} URL = http://search.findwide.com/serp?guid={D2B77A2A-623F-4294-9EF8-EE59945FE51C}&action=default_search&serpv=22&k={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid=109&itype=a&ver=12692&tm=354&src=ds&p={searchTerms} SearchScopes: HKCU - {C72DDC0F-5BF4-4DA8-9F70-9A50C53E669C} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10809 SearchScopes: HKCU - {D9DC290A-C648-4059-8596-A905DF4F5037} URL = http://search.findwide.com/serp?guid={D2B77A2A-623F-4294-9EF8-EE59945FE51C}&action=default_search&serpv=22&k={searchTerms} BHO: BlockAndSurf - {8E9C1CC8-FCEC-F858-9CEC-A4143CA5EE64} - C:\Program Files\BlockAndSurf-soft\170.dll () BHO: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File BHO: BlockAndSurf - {DF521630-EB03-9984-BAFD-0E502341A6FD} - C:\Program Files\BlockAndSurf-soft\170.dll () Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Toolbar: HKCU - No Name - {8235B9EF-7F8E-4FFE-9261-CDABFB7345FA} - No File C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\IePluginService C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\WPM C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Dane aplikacji\aps.uninstall.scan.results C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Dane aplikacji\Settings Manager C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Dane aplikacji\SwvUpdater C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Moje dokumenty\Optimizer Pro C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Pulpit\Free Games.lnk C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\AnyProtectScannerSetup.exe C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\t4pc_en_3 C:\Program Files\004 C:\Program Files\Bench C:\Program Files\BlockAndSurf-soft C:\Program Files\Free Games 111 C:\Program Files\fst_pl_117 C:\Program Files\Mobogenie C:\Program Files\MyPC Backup C:\Program Files\predm C:\WINDOWS\system32\roboot.exe C:\AVScanner.ini C:\install.exe C:\winrarfree.exe Reboot: ***************** C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\IePluginService\PluginService.exe => No running process found C:\Program Files\004\rqpbhevlkc32.exe => No running process found C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\t4pc_en_3\upt4pc_en_3.exe => No running process found IePluginService => Service stopped successfully. IePluginService => Service deleted successfully. rqpbhevlkc32 => Service stopped successfully. rqpbhevlkc32 => Service deleted successfully. Update webget => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\fst_pl_117 => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\t4pc_en_3 => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upt4pc_en_3.exe => Value deleted successfully. HKU\S-1-5-21-299502267-1993962763-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Run\\SpeedUpMyComputer => Value deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe => Key deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => Value deleted successfully. C:\WINDOWS\Tasks\APSnotifierPP1.job => Moved successfully. C:\WINDOWS\Tasks\APSnotifierPP2.job => Moved successfully. C:\WINDOWS\Tasks\APSnotifierPP3.job => Moved successfully. C:\WINDOWS\Tasks\bench-sys.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C72DDC0F-5BF4-4DA8-9F70-9A50C53E669C} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{C72DDC0F-5BF4-4DA8-9F70-9A50C53E669C} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D9DC290A-C648-4059-8596-A905DF4F5037} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{D9DC290A-C648-4059-8596-A905DF4F5037} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E9C1CC8-FCEC-F858-9CEC-A4143CA5EE64} => Key deleted successfully. HKCR\CLSID\{8E9C1CC8-FCEC-F858-9CEC-A4143CA5EE64} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF521630-EB03-9984-BAFD-0E502341A6FD} => Key deleted successfully. HKCR\CLSID\{DF521630-EB03-9984-BAFD-0E502341A6FD} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8235B9EF-7F8E-4FFE-9261-CDABFB7345FA} => Value deleted successfully. HKCR\CLSID\{8235B9EF-7F8E-4FFE-9261-CDABFB7345FA} => Key not found. C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\IePluginService => Moved successfully. C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\WPM => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Dane aplikacji\aps.uninstall.scan.results => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Dane aplikacji\Settings Manager => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Dane aplikacji\SwvUpdater => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Moje dokumenty\Optimizer Pro => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Pulpit\Free Games.lnk => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\AnyProtectScannerSetup.exe => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\ja sam.ANONIM-E21ED28F\Ustawienia lokalne\Dane aplikacji\t4pc_en_3 => Moved successfully. C:\Program Files\004 => Moved successfully. C:\Program Files\Bench => Moved successfully. C:\Program Files\BlockAndSurf-soft => Moved successfully. C:\Program Files\Free Games 111 => Moved successfully. C:\Program Files\fst_pl_117 => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Program Files\MyPC Backup => Moved successfully. C:\Program Files\predm => Moved successfully. C:\WINDOWS\system32\roboot.exe => Moved successfully. C:\AVScanner.ini => Moved successfully. C:\install.exe => Moved successfully. C:\winrarfree.exe => Moved successfully. The system needed a reboot. ==== End of Fixlog ====