Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:24-08-2014 02 Ran by Kuba at 2014-08-24 17:21:46 Run:1 Running from C:\Documents and Settings\Kuba\Moje dokumenty\Pobrane Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Documents and Settings\Kuba\buaage.exe HKU\S-1-5-21-2025429265-261478967-682003330-1003\...\Run: [buaage] => C:\Documents and Settings\Kuba\buaage.exe [138240 2014-05-22] () NETSVC: hsrxlhdnv -> No Registry Path. S3 AndNetDiag; system32\DRIVERS\lgandnetdiag.sys [X] S3 ANDNetModem; system32\DRIVERS\lgandnetmodem.sys [X] S3 andnetndis; system32\DRIVERS\lgandnetndis.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 ryaatjfr; \??\C:\WINDOWS\system32\01.tmp [X] U2 wuaserv; S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] Task: C:\WINDOWS\Tasks\At1.job => C:\DOCUME~1\Kuba\DANEAP~1\FoxTab\UPDATE~1\UPDATE~1.EXE Task: C:\WINDOWS\Tasks\Express FilesUpdate.job => C:\Program Files\ExpressFiles\EFUpdater.exe Task: C:\WINDOWS\Tasks\Registry Optimizer_DEFAULT.job => C:\Program Files\WinZip Registry Optimizer\Winzipro.exe Task: C:\WINDOWS\Tasks\Registry Optimizer_UPDATES.job => C:\Program Files\WinZip Registry Optimizer\Winzipro.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=21.2.0.38 URLSearchHook: HKLM - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File C:\Documents and Settings\Kuba\*.bat C:\Documents and Settings\Kuba\*.exe C:\Documents and Settings\Kuba\*.lnk C:\Documents and Settings\Kuba\*.scr C:\Documents and Settings\All Users\Dane aplikacji\eSafe C:\Documents and Settings\All Users\Dane aplikacji\Norton C:\Documents and Settings\Kuba\Dane aplikacji\DRPSu C:\Documents and Settings\Kuba\Dane aplikacji\ExpressFiles C:\Documents and Settings\Kuba\Dane aplikacji\FoxTab C:\Documents and Settings\Kuba\Dane aplikacji\newnext.me C:\Documents and Settings\Kuba\Dane aplikacji\SimilarSites C:\Documents and Settings\Kuba\Dane aplikacji\SwvUpdater C:\Documents and Settings\Kuba\Dane aplikacji\Thinstall RemoveDirectory: C:\found.001 Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Hosts: EmptyTemp: ***************** C:\Documents and Settings\Kuba\buaage.exe => No running process found HKU\S-1-5-21-2025429265-261478967-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run\\buaage => value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs hsrxlhdnv => Value deleted successfully. AndNetDiag => Service deleted successfully. ANDNetModem => Service deleted successfully. andnetndis => Service deleted successfully. massfilter => Service deleted successfully. ryaatjfr => Service deleted successfully. wuaserv => Service deleted successfully. ZTEusbnet => Service deleted successfully. ZTEusbnmea => Service deleted successfully. ZTEusbser6k => Service deleted successfully. C:\WINDOWS\Tasks\At1.job => Moved successfully. C:\WINDOWS\Tasks\Express FilesUpdate.job => Moved successfully. C:\WINDOWS\Tasks\Registry Optimizer_DEFAULT.job => Moved successfully. C:\WINDOWS\Tasks\Registry Optimizer_UPDATES.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value deleted successfully. "HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => Key deleted successfully. C:\Documents and Settings\Kuba\*.bat => Moved successfully. C:\Documents and Settings\Kuba\*.exe => Moved successfully. C:\Documents and Settings\Kuba\*.lnk => Moved successfully. C:\Documents and Settings\Kuba\*.scr => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\eSafe => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Norton => Moved successfully. C:\Documents and Settings\Kuba\Dane aplikacji\DRPSu => Moved successfully. C:\Documents and Settings\Kuba\Dane aplikacji\ExpressFiles => Moved successfully. C:\Documents and Settings\Kuba\Dane aplikacji\FoxTab => Moved successfully. C:\Documents and Settings\Kuba\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\Kuba\Dane aplikacji\SimilarSites => Moved successfully. C:\Documents and Settings\Kuba\Dane aplikacji\SwvUpdater => Moved successfully. C:\Documents and Settings\Kuba\Dane aplikacji\Thinstall => Moved successfully. "C:\found.001" => removed successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 299.9 MB temporary data. The system needed a reboot. ==== End of Fixlog ====