Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:8-08-2014 Ran by Pawel at 2014-08-08 14:11:50 Run:1 Running from C:\Users\Pawel\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {290440F2-445A-47DC-8D6E-BE1C4D5E68F8} - System32\Tasks\BitGuard => Sc.exe start BitGuard Task: {4CBC9302-ADEA-41AD-B426-2FA59E8F193D} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Task: {72E243E0-10D8-4227-BAEA-D2ED41333A99} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files\AVG Secure Search\PostInstall\ROC.exe Task: {AB1F31B5-E0C2-46F2-BAA0-0E2E82799A52} - System32\Tasks\EPUpdater => C:\Users\PAWE~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: C:\windows\Tasks\ROC_JAN2013_TB_rmv.job => C:\Program Files\AVG Secure Search\PostInstall\ROC.exe Task: C:\windows\Tasks\schedule!3036567561.job => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe <==== ATTENTION C:\ProgramData\BetterSoft\OptimizerPro C:\Program Files\AVG Secure Search SCONFIG\startupreg: ROC_JAN2013_TB => "C:\Program Files\AVG Secure Search\ROC_JAN2013_TB.exe" /PROMPT /CMPID=JAN2013_TB MSCONFIG\startupreg: ROC_ROC_JULY_P1 => "C:\Program Files\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 MSCONFIG\startupreg: ROC_roc_ssl_v12 => "C:\Program Files\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 MSCONFIG\startupreg: vProt => "C:\Program Files\AVG SafeGuard toolbar\vprot.exe" C:\Program Files\AVG SafeGuard toolbar C:\Users\Pawel\AppData\Roaming\wyUpdate AU C:\Users\Pawel\AppData\Roaming\newnext.me HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol..._Dmntr&tsp=4972 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.sea...&cc=PL&unqvl=37 SearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.sea...&cc=PL&unqvl=37 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} BHO: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG SafeGuard toolbar\17.0.2.13\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) BHO: delta Helper Object -> {C1AF5FA5-852C-4C90-812E-A7F75E011D87} -> C:\Program Files\Delta\delta\1.8.22.0\bh\delta.dll (Delta-search.com) C:\Program Files\Delta Toolbar: HKLM - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\17.0.2.13\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.22.0\deltaTlbr.dll (Delta-search.com) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search) FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.0.2.13 CHR Extension: (AVG SafeGuard) - C:\Users\Pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\17.0.2.13\avg.crx R1 avgtp; C:\windows\system32\drivers\avgtpx86.sys [37664 2013-10-02] (AVG Technologies) C:\ProgramData\2308189059 C:\windows\Tasks\ROC_JAN2013_TB_rmv.job C:\ProgramData\SearchNewTab C:\ProgramData\DoowonloAd keeper :\ProgramData\7tbnwrjfr8z.bxx C:\ProgramData\7tbnwrjfr8z.fvv C:\Users\Mama\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp6dsbgf.dll C:\Users\Mama\AppData\Local\Temp\Foxit Updater.exe C:\Users\Mama\AppData\Local\Temp\i4jdel0.exe C:\Users\Pawel\AppData\Local\Temp\CmdLineExt02.dll C:\Users\Pawel\AppData\Local\Temp\DTLite4481-0347.exe C:\Users\Pawel\AppData\Local\Temp\Foxit Updater.exe C:\Users\Pawel\AppData\Local\Temp\ICReinstall_Light Image Resizer 4.5.4.0.exe C:\Users\Pawel\AppData\Local\Temp\KMP_3.7.0.113.exe C:\Users\Pawel\AppData\Local\Temp\optprosetup.exe C:\Users\Pawel\AppData\Local\Temp\SHSetup.exe C:\Users\Pawel\AppData\Local\Temp\SIntf16.dll C:\Users\Pawel\AppData\Local\Temp\SIntf32.dll C:\Users\Pawel\AppData\Local\Temp\SIntfNT.dll C:\Users\Samsung\AppData\Local\Temp\Foxit Updater.exe C:\Users\Samsung\AppData\Local\Temp\i4jdel0.exe Reboot: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{290440F2-445A-47DC-8D6E-BE1C4D5E68F8}" => Key not found. C:\Windows\System32\Tasks\BitGuard not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4CBC9302-ADEA-41AD-B426-2FA59E8F193D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CBC9302-ADEA-41AD-B426-2FA59E8F193D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Program aktualizacji online firmy Adobe." => Key deleted successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{72E243E0-10D8-4227-BAEA-D2ED41333A99}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72E243E0-10D8-4227-BAEA-D2ED41333A99}" => Key deleted successfully. C:\Windows\System32\Tasks\ROC_JAN2013_TB_rmv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ROC_JAN2013_TB_rmv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB1F31B5-E0C2-46F2-BAA0-0E2E82799A52}" => Key not found. C:\Windows\System32\Tasks\EPUpdater not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => Key not found. C:\windows\Tasks\ROC_JAN2013_TB_rmv.job => Moved successfully. C:\windows\Tasks\schedule!3036567561.job => Moved successfully. "C:\ProgramData\BetterSoft\OptimizerPro" => File/Directory not found. "C:\Program Files\AVG Secure Search" => File/Directory not found. SCONFIG\startupreg: ROC_JAN2013_TB => "C:\Program Files\AVG Secure Search\ROC_JAN2013_TB.exe" /PROMPT /CMPID=JAN2013_TB => Error: No automatic fix found for this entry. MSCONFIG\startupreg: ROC_ROC_JULY_P1 => "C:\Program Files\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 => Error: No automatic fix found for this entry. MSCONFIG\startupreg: ROC_roc_ssl_v12 => "C:\Program Files\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 => Error: No automatic fix found for this entry. MSCONFIG\startupreg: vProt => "C:\Program Files\AVG SafeGuard toolbar\vprot.exe" => Error: No automatic fix found for this entry. "C:\Program Files\AVG SafeGuard toolbar" => File/Directory not found. C:\Users\Pawel\AppData\Roaming\wyUpdate AU => Moved successfully. "C:\Users\Pawel\AppData\Roaming\newnext.me" => File/Directory not found. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key not found. "HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Value not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}" => Key not found. "HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}" => Key not found. "C:\Program Files\Delta" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} => Value not found. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value not found. "HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}" => Key not found. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => Key deleted successfully. "HKCR\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}" => Key deleted successfully. "HKCR\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => Key deleted successfully. "HKCR\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => Key deleted successfully. "HKCR\PROTOCOLS\Handler\viprotocol" => Key not found. "HKCR\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}" => Key not found. FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.0.2.13 => not found. CHR Extension: (AVG SafeGuard) - C:\Users\Pawel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof directory not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof" => Key not found. "CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\17.0.2.13\avg.crx" => File/Directory not found. avgtp => Service not found. "C:\ProgramData\2308189059" => File/Directory not found. "C:\windows\Tasks\ROC_JAN2013_TB_rmv.job" => File/Directory not found. C:\ProgramData\SearchNewTab => Moved successfully. "C:\ProgramData\DoowonloAd keeper" => File/Directory not found. :\ProgramData\7tbnwrjfr8z.bxx => Error: No automatic fix found for this entry. C:\ProgramData\7tbnwrjfr8z.fvv => Moved successfully. C:\Users\Mama\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp6dsbgf.dll => Moved successfully. C:\Users\Mama\AppData\Local\Temp\Foxit Updater.exe => Moved successfully. C:\Users\Mama\AppData\Local\Temp\i4jdel0.exe => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\CmdLineExt02.dll => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\DTLite4481-0347.exe => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\Foxit Updater.exe => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\ICReinstall_Light Image Resizer 4.5.4.0.exe => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\KMP_3.7.0.113.exe => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\optprosetup.exe => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\SHSetup.exe => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\SIntf16.dll => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\SIntf32.dll => Moved successfully. C:\Users\Pawel\AppData\Local\Temp\SIntfNT.dll => Moved successfully. C:\Users\Samsung\AppData\Local\Temp\Foxit Updater.exe => Moved successfully. C:\Users\Samsung\AppData\Local\Temp\i4jdel0.exe => Moved successfully. The system needed a reboot. ==== End of Fixlog ====