Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:03-07-2014 Ran by Administrator at 2014-07-04 17:19:55 Run:1 Running from E:\!!Archiwum\!!!Diagnostyka systemu Boot Mode: Normal ============================================== Content of fixlist: ***************** (APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (APN LLC.) C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe HKLM\...\Run: [ApnTBMon] => C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1956760 2014-06-24] (APN) ShortcutWithArgument: C:\Documents and Settings\Administrator\Menu Start\Programy\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570 ShortcutWithArgument: C:\Documents and Settings\Administrator\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Internet Explorer (bez dodatków).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570 ShortcutWithArgument: C:\Documents and Settings\Administrator\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570 ShortcutWithArgument: C:\Documents and Settings\Administrator\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Uruchom przeglądarkę Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570 ShortcutWithArgument: C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570 ShortcutWithArgument: C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=sc&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gwww.google.pl HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=3C8D0016E642E11B&affID=119357&tt=240913_246&tsp=5020 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dosearches.com/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=hp&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570 URLSearchHook: HKCU - SearchHook Class - {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\Program Files\AskPartnerNetwork\Toolbar\searchhook.dll (APN LLC.) SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570&type=default&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=3C8D0016E642E11B&affID=119357&tt=240913_246&tsp=5020 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=WDCXWD800JB-00JJC0_WD-WCAM9F80673906739&ts=1384246570&type=default&q={searchTerms} BHO: Ask Toolbar - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll (APN LLC.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll No File Toolbar: HKLM - Ask Toolbar - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll (APN LLC.) CHR Extension: (uTorrentControl_v6) - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp [2014-04-16] CHR Extension: (Web Cake) - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh [2014-04-16] CHR HKLM\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-03-26] CHR HKLM\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files\Betcat\WebCakeLayers.crx [2013-08-13] CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-11-12] CHR HKLM\...\Chrome\Extension: [lpadbdkobbgjgonnfnipfngifldcdfin] - C:\Documents and Settings\All Users\Dane aplikacji\AskPartnerNetwork\Toolbar\ORJ-V7-SAT\CRX\ToolbarCR.crx [2014-06-25] CHR HKLM\...\Chrome\Extension: [pljcgbedjplidkdjahbaalanadmjfgop] - C:\Documents and Settings\All Users\Dane aplikacji\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx [2014-06-25] CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-03-26] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [165784 2014-06-24] (APN LLC.) S3 catchme; \??\C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\catchme.sys [X] S2 zumbus; system32\DRIVERS\zumbus.sys [X] C:\Documents and Settings\Administrator\Dane aplikacji\Babylon C:\Documents and Settings\Administrator\Dane aplikacji\Betcat C:\Documents and Settings\Administrator\Dane aplikacji\File Scout C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla C:\Documents and Settings\Administrator\Dane aplikacji\OpenCandy C:\Documents and Settings\Administrator\Dane aplikacji\PerformerSoft C:\Documents and Settings\Administrator\Dane aplikacji\systweak C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\CRE C:\Documents and Settings\All Users\Dane aplikacji\Babylon C:\Documents and Settings\All Users\Dane aplikacji\BitGuard C:\Documents and Settings\All Users\Dane aplikacji\eSafe C:\Documents and Settings\All Users\Dane aplikacji\Logs C:\Documents and Settings\All Users\Dane aplikacji\SafetyNut C:\Program Files\Mozilla Firefox C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnTBMon" /f Reboot: ***************** C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe => No running process found C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe => No running process found C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\AskPartnerNetwork\Toolbar\Updater\IDC\IdcLdr.exe => No running process found HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ApnTBMon => Value not found. C:\Documents and Settings\Administrator\Menu Start\Programy\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Documents and Settings\Administrator\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Internet Explorer (bez dodatków).lnk => Unable to remove or repair shortcut agument. The shortcut could be damaged. C:\Documents and Settings\Administrator\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Uruchom przeglądarkę Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => value deleted successfully. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4F524A2D-5637-4300-76A7-7A786E7484D7}'=> Key not found. 'HKCR\CLSID\{4F524A2D-5637-4300-76A7-7A786E7484D7}'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}' => Key deleted successfully. 'HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}' => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{4F524A2D-5637-4300-76A7-7A786E7484D7} => Value not found. 'HKCR\CLSID\{4F524A2D-5637-4300-76A7-7A786E7484D7}'=> Key not found. C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\cflheckfmhopnialghigdlggahiomebp => Moved successfully. C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh => Moved successfully. 'HKLM\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp' => Key deleted successfully. C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\CRE\cflheckfmhopnialghigdlggahiomebp.crx => Moved successfully. 'HKLM\SOFTWARE\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh' => Key deleted successfully. C:\Program Files\Betcat\WebCakeLayers.crx => Moved successfully. CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-11-12] ==> The Chrome "Settings" can be used to fix the entry. 'HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo'=> Key not found. "C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx" => File/Directory not found. 'HKLM\SOFTWARE\Google\Chrome\Extensions\lpadbdkobbgjgonnfnipfngifldcdfin'=> Key not found. "C:\Documents and Settings\All Users\Dane aplikacji\AskPartnerNetwork\Toolbar\ORJ-V7-SAT\CRX\ToolbarCR.crx" => File/Directory not found. 'HKLM\SOFTWARE\Google\Chrome\Extensions\pljcgbedjplidkdjahbaalanadmjfgop'=> Key not found. "C:\Documents and Settings\All Users\Dane aplikacji\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx" => File/Directory not found. 'HKCU\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp' => Key deleted successfully. "C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\CRE\cflheckfmhopnialghigdlggahiomebp.crx" => File/Directory not found. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. APNMCP => Service deleted successfully. catchme => Service deleted successfully. zumbus => Service deleted successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Betcat => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\File Scout => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\OpenCandy => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\PerformerSoft => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\systweak => Moved successfully. C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\CRE => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\BitGuard => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\eSafe => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Logs => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\SafetyNut => Moved successfully. C:\Program Files\Mozilla Firefox => Moved successfully. C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnTBMon" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====