Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-05-2014 Ran by TEST at 2014-05-25 12:41:37 Run:1 Running from C:\Users\TEST\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32 \ ... \ Run: [] => [X] CHR HKLM \ Software \ Policies \ Google: ograniczenie Polityka <======= UWAGA FF SearchEngineOrder.1: Ask.com Szukaj FF NetworkProxy: " typ ", 0 FF SearchPlugin: C: \ Users \ Test \ AppData \ Roaming \ Mozilla \ Firefox \ Profiles \ kp38ngeg.default \ searchplugins \ askcom.xml FF SearchPlugin: HKLM \ ... \ Firefox \ Extensions: [{C1CA7765-44E4-452e-9D00-A04F3D434281}] - FF HKLM-x32 \ ... \ Firefox \ Extensions: [{C1CA7765-44E4-452e-9D00-A04F3D434281}] - FF HKLM-x32 \ ... \ Firefox \ Extensions: [ff-bmboc@bytemobile.com] - C: \ Program Files \ T-Mobile \ InternetManager_H \ OCx64 \ addon StartMenuInternet: IEXPLORE.EXE - C: \ Program Files (x86) \ Internet Explorer \ iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {887563D7-8775-4D42-87BD-ABB96E35BA3D} URL = HKCU - {D66EE8CE-80A5-4A2F-B5CC-7A89B495D91E} URL = DPF: HKLM-x32 {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab S3 BlueletAudio ; system32 \ drivers \ blueletaudio.sys [X] S3 BlueletSCOAudio; system32 \ drivers \ BlueletSCOAudio.sys [X] S3 BT; system32 \ drivers \ btnetdrv.sys [X] S3 BTHidEnum; system32 \ drivers \ vbtenum.sys [X] S4 BTHidMgr; System32 \ Drivers \ BTHidMgr.sys [X] S3 catchme; ? \ \ C: \ ComboFix \ catchme.sys [X] S3 VComm; system32 \ drivers \ VComm.sys [X] S3 VcommMgr; System32 \ Drivers \ VcommMgr.sys [X] CMD: sc config ". Mobilny Internet RunOuc" start = popytu ***************** Firefox SearchEngineOrder.1 deleted successfully. Firefox Proxy settings were reset. "C: \ Users \ Test \ AppData \ Roaming \ Mozilla \ Firefox \ Profiles \ kp38ngeg.default \ searchplugins \ askcom.xml" => not found. "FF SearchPlugin:" => not found. HKLM\Software\Wow6432Node\Mozilla\FF HKLM-x32 \ ... \ Firefox \ Extensions: [{C1CA7765-44E4-452e-9D00-A04F3D434281}] -\\FF HKLM-x32 \ ... \ Firefox \ Extensions: [{C1CA7765-44E4-452e-9D00-A04F3D434281}] - => Value not found. HKLM\Software\Wow6432Node\Mozilla\FF HKLM-x32 \ ... \ Firefox \ Extensions: [ff-bmboc@bytemobile.com] - C: \ Program Files \ T-Mobile \ InternetManager_H \ OCx64 \ addon\\FF HKLM-x32 \ ... \ Firefox \ Extensions: [ff-bmboc@bytemobile.com] - C: \ Program Files \ T-Mobile \ InternetManager_H \ OCx64 \ addon => Value not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{887563D7-8775-4D42-87BD-ABB96E35BA3D} => Key deleted successfully. HKCR\CLSID\{887563D7-8775-4D42-87BD-ABB96E35BA3D} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. BlueletAudio => Service not found. BlueletSCOAudio => Service deleted successfully. BT => Service deleted successfully. BTHidEnum => Service deleted successfully. BTHidMgr => Service deleted successfully. catchme => Service deleted successfully. VComm => Service deleted successfully. VcommMgr => Service deleted successfully. ========= sc config ". Mobilny Internet RunOuc" start = popytu ========= OPIS: Modyfikuje wpis usˆugi w rejestrze i w bazie danych usˆug. SPOSàB U½YCIA: sc config [nazwa_usˆugi] ... OPCJE: UWAGA: Nazwa opcji zawiera znak r¢wno˜ci. Pomi©dzy znakiem r¢wno˜ci a warto˜ci¥ wymagany jest odst©p. type= start= error= binPath= group= tag= depend= obj= DisplayName= password= ========= End of CMD: ========= ==== End of Fixlog ====