Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 07-09-2014 Ran by Asia at 2014-09-11 20:03:37 Run:1 Running from C:\Documents and Settings\Asia\Moje dokumenty\Pobrane\do logów Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R2 Update sizlsearch; C:\Program Files\sizlsearch\updatesizlsearch.exe [323360 2014-09-08] () R2 Util sizlsearch; C:\Program Files\sizlsearch\bin\utilsizlsearch.exe [323360 2014-09-08] () R2 WindowsMangerProtect; C:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect\ProtectWindowsManager.exe [528896 2014-09-03] (Fuyu LIMITED) [File not signed] R1 {9d5747ee-0448-4681-8337-1555de75a3b6}Gt; C:\WINDOWS\System32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys [55104 2014-08-23] (StdLib) S3 adusbser; system32\DRIVERS\adusbser.sys [X] S1 eeCtrl; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [X] S3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [X] S3 HidNt; system32\DRIVERS\HIDNt.sys [X] S3 Mac606; system32\DRIVERS\Mac606.sys [X] HKLM\...\Run: [] => [X] HKLM\...\Run: [fst_pl_188] => [X] AppInit_DLLs: c:\progra~1\movies~1\datamngr\mgrldr.dll => c:\progra~1\movies~1\datamngr\mgrldr.dll File Not Found HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe Task: C:\WINDOWS\Tasks\APSnotifierPP1.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\APSnotifierPP2.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\APSnotifierPP3.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\EPUpdater.job => C:\DOCUME~1\Asia\DANEAP~1\BABSOL~1\Shared\BabMaint.exe Startup: C:\Documents and Settings\Asia\Menu Start\Programy\Autostart\ Canon IJ Status Monitor Canon MP230 series Printer.lnk HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1409764853&from=obw&uid=SAMSUNGXHD250HJ_S0URJ9DQ221815&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1409764853&from=obw&uid=SAMSUNGXHD250HJ_S0URJ9DQ221815&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.doko-search.com/?babsrc=HP_ss&mntrId=58DD001BFCD00BC7&affID=125839&tl=gpn65235&tsp=5039 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1409764853&from=obw&uid=SAMSUNGXHD250HJ_S0URJ9DQ221815&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1409764853&from=obw&uid=SAMSUNGXHD250HJ_S0URJ9DQ221815&q={searchTerms} URLSearchHook: HKCU - UsProvider Class - {539F76FD-084E-4858-86D5-62F02F54AE86} - C:\Program Files\Minibar\Minibar.dll (KangoExtensions) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1409764853&from=obw&uid=SAMSUNGXHD250HJ_S0URJ9DQ221815 SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=495&systemid=406&v=a9396-116&apn_uid=5044781299234525&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={44DB1399-D6E7-4B27-863D-B1A7B726FEFC} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.doko-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=58DD001BFCD00BC7&affID=125839&tl=gpn65235&tsp=5039 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=495&systemid=406&apn_uid=5044781299234525&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={44DB1399-D6E7-4B27-863D-B1A7B726FEFC} BHO: sizlsearch -> {36d96925-abfa-4eb8-b630-305e905a930d} -> C:\Program Files\sizlsearch\sizlsearchbho.dll (sizlsearch) BHO: MinibarBHO -> {AA74D58F-ACD0-450D-A85E-6C04B171C044} -> C:\Program Files\Minibar\Minibar.dll (KangoExtensions) Toolbar: HKLM - No Name - {377e5d4d-77e5-476a-8716-7e70a9272da0} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll No File FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll No File FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKLM\...\Firefox\Extensions: [{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}] - C:\Documents and Settings\All Users\Dane aplikacji\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.8.0.5\coFFFw FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-10-18] CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2012-11-26] CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx [2012-11-26] CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\DOCUME~1\Asia\USTAWI~1\DANEAP~1\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-21] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION GroupPolicy: Group Policy on Chrome detected <======= ATTENTION C:\Documents and Settings\All Users\Dane aplikacji\Babylon C:\Documents and Settings\All Users\Dane aplikacji\BitGuard C:\Documents and Settings\All Users\Dane aplikacji\Norton C:\Documents and Settings\All Users\Dane aplikacji\Tarma Installer C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\Asia\Dane aplikacji\ap_logs C:\Documents and Settings\Asia\Dane aplikacji\aps.uninstall.scan.results C:\Documents and Settings\Asia\Dane aplikacji\BabSolution C:\Documents and Settings\Asia\Dane aplikacji\Babylon C:\Documents and Settings\Asia\Dane aplikacji\Minibar C:\Documents and Settings\Asia\Dane aplikacji\onlysearch C:\Documents and Settings\Asia\Dane aplikacji\OpenCandy C:\Documents and Settings\Asia\Dane aplikacji\Radmin C:\Documents and Settings\Asia\Dane aplikacji\webssearches C:\Documents and Settings\Asia\Pulpit\Continue Live Installation.lnk C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\*.tmp C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847} C:\Program Files\Minibar C:\Program Files\predm C:\WINDOWS\jumpshot. com C:\WINDOWS\system32\Drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetIM" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f CMD: netsh firewall reset CMD: sc config "PLAY ONLINE. RunOuc" start= demand ***************** Processes closed successfully. Update sizlsearch => Service stopped successfully. Update sizlsearch => Service deleted successfully. Util sizlsearch => Service deleted successfully. WindowsMangerProtect => Service deleted successfully. {9d5747ee-0448-4681-8337-1555de75a3b6}Gt => Unable to stop service {9d5747ee-0448-4681-8337-1555de75a3b6}Gt => Service deleted successfully. adusbser => Service deleted successfully. eeCtrl => Service deleted successfully. EraserUtilRebootDrv => Service deleted successfully. HidNt => Service deleted successfully. Mac606 => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\fst_pl_188 => value deleted successfully. "c:\progra~1\movies~1\datamngr\mgrldr.dll" => Value Data removed successfully. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => value deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => Key deleted successfully. C:\WINDOWS\Tasks\APSnotifierPP1.job => Moved successfully. C:\WINDOWS\Tasks\APSnotifierPP2.job => Moved successfully. C:\WINDOWS\Tasks\APSnotifierPP3.job => Moved successfully. C:\WINDOWS\Tasks\EPUpdater.job => Moved successfully. Startup: C:\Documents and Settings\Asia\Menu Start\Programy\Autostart\ not found. Canon => Error: No automatic fix found for this entry. IJ Status Monitor Canon MP230 series Printer.lnk => Error: No automatic fix found for this entry. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{539F76FD-084E-4858-86D5-62F02F54AE86} => value deleted successfully. "HKCR\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully. "HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key deleted successfully. "HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully. "HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. "HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully. "HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key deleted successfully. "HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36d96925-abfa-4eb8-b630-305e905a930d}" => Key deleted successfully. "HKCR\CLSID\{36d96925-abfa-4eb8-b630-305e905a930d}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}" => Key deleted successfully. "HKCR\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{377e5d4d-77e5-476a-8716-7e70a9272da0} => value deleted successfully. "HKCR\CLSID\{377e5d4d-77e5-476a-8716-7e70a9272da0}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => value deleted successfully.