Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-10-2014 02 Ran by Admin at 2014-10-13 19:51:24 Run:1 Running from C:\Users\Admin\Desktop\frst64 Loaded Profile: Admin (Available profiles: Admin) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-10-09] (globalUpdate) [File not signed] S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-10-09] (globalUpdate) [File not signed] R2 Update RightSurf; C:\Program Files (x86)\RightSurf\updateRightSurf.exe [522528 2014-10-12] () R2 Util RightSurf; C:\Program Files (x86)\RightSurf\bin\utilRightSurf.exe [522528 2014-10-12] () ) R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61112 2014-04-18] (StdLib) R1 {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64; C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys [61112 2014-04-24] (StdLib) Task: {6D4B5E92-518E-4251-8C4D-DD5C0D2ADAB9} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-09] (globalUpdate) <==== ATTENTION Task: {6F88297E-477E-4B15-AF42-DA5EDFEBE233} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-09] (globalUpdate) <==== ATTENTION Task: {C7A3732A-C63E-443F-B8CA-6F05C3B2D2BC} - System32\Tasks\YWDGNH => C:\Users\Admin\AppData\Roaming\YWDGNH.exe [2014-10-09] (Object Browser) <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\YWDGNH.job => C:\Users\Admin\AppData\Roaming\YWDGNH.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.dalesearch.com/?babsrc=HP_ss&mntrId=4E4F001B9EEBA14D&affID=119357&tt=021013_dle&tsp=5023 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.dalesearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=4E4F001B9EEBA14D&affID=119357&tt=021013_dle&tsp=5023 SearchScopes: HKCU - {EE36B910-E61C-46E5-8375-0A788BA8502E} URL = http://rts.dsrlte.com/?q={searchTerms}&r=316 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\Mobogenie3 C:\Program Files (x86)\RightSurf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppsHat C:\ProgramData\TEMP C:\ProgramData\Thunder Network C:\ProgramData\Xunlei C:\Users\Admin\AppData\Local\CrashRpt C:\Users\Admin\AppData\Local\globalUpdate C:\Users\Admin\AppData\Local\Lollipop C:\Users\Admin\AppData\Local\Mobogenie C:\Users\Admin\AppData\Roaming\*.exe C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} C:\Users\Admin\AppData\Roaming\newnext.me C:\Users\Admin\Downloads\*downloader*.exe C:\Users\Admin\Downloads\*patch*.exe C:\Users\Admin\Documents\Mobogenie C:\Users\Public\Documents\GOOBZO C:\Users\Public\Documents\YTAHelper C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys C:\Windows\System32\drivers\wStLibG64.sys C:\Windows\SysWOW64\GroupPolicy\GPT.INI RemoveDirectory: C:\Users\Admin\Desktop\Stare dane programu Firefox DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Skype Packages DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Admin\AppData\Local CMD: dir /a C:\Users\Admin\AppData\LocalLow CMD: dir /a C:\Users\Admin\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. globalUpdate => Service not found. globalUpdatem => Service not found. Update RightSurf => Service deleted successfully. Util RightSurf => Service deleted successfully. wStLibG64 => Service stopped successfully. wStLibG64 => Service deleted successfully. {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64 => Service stopped successfully. {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D4B5E92-518E-4251-8C4D-DD5C0D2ADAB9}" => Key not found. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F88297E-477E-4B15-AF42-DA5EDFEBE233}" => Key not found. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7A3732A-C63E-443F-B8CA-6F05C3B2D2BC}" => Key not found. C:\Windows\System32\Tasks\YWDGNH not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YWDGNH" => Key not found. C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found. C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job not found. C:\Windows\Tasks\YWDGNH.job not found. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. "HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EE36B910-E61C-46E5-8375-0A788BA8502E}" => Key deleted successfully. "HKCR\CLSID\{EE36B910-E61C-46E5-8375-0A788BA8502E}" => Key not found. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => Key not found. C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => Key not found. C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll not found. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Program Files (x86)\Mobogenie3 => Moved successfully. C:\Program Files (x86)\RightSurf => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppsHat => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\Thunder Network => Moved successfully. C:\ProgramData\Xunlei => Moved successfully. C:\Users\Admin\AppData\Local\CrashRpt => Moved successfully. C:\Users\Admin\AppData\Local\globalUpdate => Moved successfully. C:\Users\Admin\AppData\Local\Lollipop => Moved successfully. C:\Users\Admin\AppData\Local\Mobogenie => Moved successfully. C:\Users\Admin\AppData\Roaming\*.exe => Moved successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard => Moved successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully. C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} => Moved successfully. C:\Users\Admin\AppData\Roaming\newnext.me => Moved successfully. "C:\Users\Admin\Downloads\*downloader*.exe" => File/Directory not found. C:\Users\Admin\Downloads\*patch*.exe => Moved successfully. C:\Users\Admin\Documents\Mobogenie => Moved successfully. C:\Users\Public\Documents\GOOBZO => Moved successfully. C:\Users\Public\Documents\YTAHelper => Moved successfully. C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys => Moved successfully. C:\Windows\System32\drivers\wStLibG64.sys => Moved successfully. "C:\Windows\SysWOW64\GroupPolicy\GPT.INI" => File/Directory not found. "C:\Users\Admin\Desktop\Stare dane programu Firefox" => removed successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Skype Packages => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive => Key Deleted successfully. ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 4E4F-F12E Katalog: C:\Program Files 2014-10-02 16:01