Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:25-05-2014 Ran by eo07 at 2014-05-25 08:06:15 Run:1 Running from C:\Documents and Settings\eo07\Moje dokumenty\Pobieranie Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices\PluginService.exe R2 IePluginServices; C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) S2 mi-raysat_3dsmax2012_32; "C:\Program Files\Autodesk\3ds Max Design 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe" [X] S3 NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [X] S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X] S2 Update webget; "C:\Program Files\webget\updatewebget.exe" [X] S2 Util webget; "C:\Program Files\webget\bin\utilwebget.exe" [X] S3 dmyymtgf; No ImagePath S4 IntelIde; No ImagePath S3 ZDCndis5; \??\C:\WINDOWS\system32\ZDCndis5.SYS [X] S3 ZDPSp50; System32\Drivers\ZDPSp50.sys [X] NETSVC: SSHNAS -> No Registry Path. HKLM\...\Run: [] => [X] HKU\S-1-5-21-602162358-1409082233-1417001333-1008\...\Run: [ABBYY Screenshot Reader Bonus] => [X] AppInit_DLLs: C:\PROGRA~1\SupTab\SEARCH~1.DLL => C:\PROGRA~1\SupTab\SEARCH~1.DLL File Not Found Startup: C:\Documents and Settings\WIN\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.0.2.lnk Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.sweet-page.com/?type=scpp&ts=1400516250&from=cor&uid=SAMSUNGXHD502HI_S1VZJ9CS708421 ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox 3.6 Beta 5\Mozilla Firefox 3.6 Beta 5 (Tryb awaryjny).lnk -> C:\Program Files\Mozilla Firefox 3.6 Beta 5\firefox.exe (Mozilla Corporation) -> hxxp://www.sweet-page.com/?type=scpp&ts=1400516250&from=cor&uid=SAMSUNGXHD502HI_S1VZJ9CS708421 ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox 3.6 Beta 5\Mozilla Firefox 3.6 Beta 5.lnk -> C:\Program Files\Mozilla Firefox 3.6 Beta 5\firefox.exe (Mozilla Corporation) -> hxxp://www.sweet-page.com/?type=scpp&ts=1400516250&from=cor&uid=SAMSUNGXHD502HI_S1VZJ9CS708421 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1400516197&from=cor&uid=SAMSUNGXHD502HI_S1VZJ9CS708421&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1400516197&from=cor&uid=SAMSUNGXHD502HI_S1VZJ9CS708421&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=scpp&ts=1400516250&from=cor&uid=SAMSUNGXHD502HI_S1VZJ9CS708421 SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = http://pl.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo BHO: No Name - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File Toolbar: HKLM - No Name - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess C:\Documents and Settings\All Users\Dane aplikacji\BurrowsEE2siave C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices C:\Documents and Settings\All Users\Dane aplikacji\InstallMate C:\Documents and Settings\All Users\Dane aplikacji\WPM C:\Documents and Settings\eo07\Dane aplikacji\facemoods.com C:\Documents and Settings\eo07\Dane aplikacji\NCdownloader C:\Documents and Settings\eo07\Dane aplikacji\OpenCandy C:\Documents and Settings\eo07\Dane aplikacji\sweet-page C:\Documents and Settings\eo07\Ustawienia lokalne\Dane aplikacji\Google C:\Documents and Settings\systemowe\Dane aplikacji\facemoods.com C:\Documents and Settings\systemowe\Dane aplikacji\PriceGong C:\Program Files\mozilla firefox\plugins C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension Reg: reg delete HKCU\Software\Google /f Reg: reg delete HKLM\SOFTWARE\Google /f Reboot: ***************** C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices\PluginService.exe => No running process found IePluginServices => Service stopped successfully. IePluginServices => Service deleted successfully. mi-raysat_3dsmax2012_32 => Service deleted successfully. NBService => Service deleted successfully. NMIndexingService => Service deleted successfully. Update webget => Service deleted successfully. Util webget => Service deleted successfully. dmyymtgf => Service deleted successfully. IntelIde => Service deleted successfully. ZDCndis5 => Service deleted successfully. ZDPSp50 => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs SSHNAS => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKU\S-1-5-21-602162358-1409082233-1417001333-1008\Software\Microsoft\Windows\CurrentVersion\Run\\ABBYY Screenshot Reader Bonus => Value deleted successfully. "C:\PROGRA~1\SupTab\SEARCH~1.DLL" => Value Data not found. C:\Documents and Settings\WIN\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.0.2.lnk => Moved successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}\\SystemComponent => Value deleted successfully. C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox 3.6 Beta 5\Mozilla Firefox 3.6 Beta 5 (Tryb awaryjny).lnk => Shortcut argument was removed successfully. C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox 3.6 Beta 5\Mozilla Firefox 3.6 Beta 5.lnk => Shortcut argument was removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} => Key deleted successfully. HKCR\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} => Value deleted successfully. HKCR\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} => Key not found. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => Value deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\BurrowsEE2siave => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\InstallMate => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\WPM => Moved successfully. C:\Documents and Settings\eo07\Dane aplikacji\facemoods.com => Moved successfully. C:\Documents and Settings\eo07\Dane aplikacji\NCdownloader => Moved successfully. C:\Documents and Settings\eo07\Dane aplikacji\OpenCandy => Moved successfully. C:\Documents and Settings\eo07\Dane aplikacji\sweet-page => Moved successfully. C:\Documents and Settings\eo07\Ustawienia lokalne\Dane aplikacji\Google => Moved successfully. C:\Documents and Settings\systemowe\Dane aplikacji\facemoods.com => Moved successfully. C:\Documents and Settings\systemowe\Dane aplikacji\PriceGong => Moved successfully. C:\Program Files\mozilla firefox\plugins => Moved successfully. C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. ========= reg delete HKCU\Software\Google /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====