Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-10-2014 02 Ran by Admin at 2014-10-13 19:51:24 Run:1 Running from C:\Users\Admin\Desktop\frst64 Loaded Profile: Admin (Available profiles: Admin) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-10-09] (globalUpdate) [File not signed] S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-10-09] (globalUpdate) [File not signed] R2 Update RightSurf; C:\Program Files (x86)\RightSurf\updateRightSurf.exe [522528 2014-10-12] () R2 Util RightSurf; C:\Program Files (x86)\RightSurf\bin\utilRightSurf.exe [522528 2014-10-12] () ) R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61112 2014-04-18] (StdLib) R1 {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64; C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys [61112 2014-04-24] (StdLib) Task: {6D4B5E92-518E-4251-8C4D-DD5C0D2ADAB9} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-09] (globalUpdate) <==== ATTENTION Task: {6F88297E-477E-4B15-AF42-DA5EDFEBE233} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-09] (globalUpdate) <==== ATTENTION Task: {C7A3732A-C63E-443F-B8CA-6F05C3B2D2BC} - System32\Tasks\YWDGNH => C:\Users\Admin\AppData\Roaming\YWDGNH.exe [2014-10-09] (Object Browser) <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\YWDGNH.job => C:\Users\Admin\AppData\Roaming\YWDGNH.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.dalesearch.com/?babsrc=HP_ss&mntrId=4E4F001B9EEBA14D&affID=119357&tt=021013_dle&tsp=5023 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1412872737&from=smt&uid=TOSHIBAXMK2046GSX_48MMCCD6TXX48MMCCD6T SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.dalesearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=4E4F001B9EEBA14D&affID=119357&tt=021013_dle&tsp=5023 SearchScopes: HKCU - {EE36B910-E61C-46E5-8375-0A788BA8502E} URL = http://rts.dsrlte.com/?q={searchTerms}&r=316 GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\Mobogenie3 C:\Program Files (x86)\RightSurf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppsHat C:\ProgramData\TEMP C:\ProgramData\Thunder Network C:\ProgramData\Xunlei C:\Users\Admin\AppData\Local\CrashRpt C:\Users\Admin\AppData\Local\globalUpdate C:\Users\Admin\AppData\Local\Lollipop C:\Users\Admin\AppData\Local\Mobogenie C:\Users\Admin\AppData\Roaming\*.exe C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} C:\Users\Admin\AppData\Roaming\newnext.me C:\Users\Admin\Downloads\*downloader*.exe C:\Users\Admin\Downloads\*patch*.exe C:\Users\Admin\Documents\Mobogenie C:\Users\Public\Documents\GOOBZO C:\Users\Public\Documents\YTAHelper C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys C:\Windows\System32\drivers\wStLibG64.sys C:\Windows\SysWOW64\GroupPolicy\GPT.INI RemoveDirectory: C:\Users\Admin\Desktop\Stare dane programu Firefox DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Skype Packages DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Admin\AppData\Local CMD: dir /a C:\Users\Admin\AppData\LocalLow CMD: dir /a C:\Users\Admin\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. globalUpdate => Service not found. globalUpdatem => Service not found. Update RightSurf => Service deleted successfully. Util RightSurf => Service deleted successfully. wStLibG64 => Service stopped successfully. wStLibG64 => Service deleted successfully. {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64 => Service stopped successfully. {b9a19c25-a741-47e5-91a2-0b62bef307ff}w64 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D4B5E92-518E-4251-8C4D-DD5C0D2ADAB9}" => Key not found. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F88297E-477E-4B15-AF42-DA5EDFEBE233}" => Key not found. C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7A3732A-C63E-443F-B8CA-6F05C3B2D2BC}" => Key not found. C:\Windows\System32\Tasks\YWDGNH not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YWDGNH" => Key not found. C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found. C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job not found. C:\Windows\Tasks\YWDGNH.job not found. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. "HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EE36B910-E61C-46E5-8375-0A788BA8502E}" => Key deleted successfully. "HKCR\CLSID\{EE36B910-E61C-46E5-8375-0A788BA8502E}" => Key not found. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => Key not found. C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => Key not found. C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll not found. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Program Files (x86)\Mobogenie3 => Moved successfully. C:\Program Files (x86)\RightSurf => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppsHat => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\Thunder Network => Moved successfully. C:\ProgramData\Xunlei => Moved successfully. C:\Users\Admin\AppData\Local\CrashRpt => Moved successfully. C:\Users\Admin\AppData\Local\globalUpdate => Moved successfully. C:\Users\Admin\AppData\Local\Lollipop => Moved successfully. C:\Users\Admin\AppData\Local\Mobogenie => Moved successfully. C:\Users\Admin\AppData\Roaming\*.exe => Moved successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard => Moved successfully. C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully. C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} => Moved successfully. C:\Users\Admin\AppData\Roaming\newnext.me => Moved successfully. "C:\Users\Admin\Downloads\*downloader*.exe" => File/Directory not found. C:\Users\Admin\Downloads\*patch*.exe => Moved successfully. C:\Users\Admin\Documents\Mobogenie => Moved successfully. C:\Users\Public\Documents\GOOBZO => Moved successfully. C:\Users\Public\Documents\YTAHelper => Moved successfully. C:\Windows\System32\drivers\{b9a19c25-a741-47e5-91a2-0b62bef307ff}w64.sys => Moved successfully. C:\Windows\System32\drivers\wStLibG64.sys => Moved successfully. "C:\Windows\SysWOW64\GroupPolicy\GPT.INI" => File/Directory not found. "C:\Users\Admin\Desktop\Stare dane programu Firefox" => removed successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Skype Packages => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive => Key Deleted successfully. ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 4E4F-F12E Katalog: C:\Program Files 2014-10-02 16:01 . 2014-10-02 16:01 .. 2014-10-02 16:02 CCleaner 2014-01-28 12:33 CDBurnerXP 2014-01-23 12:25 Common Files 2009-07-14 06:54 174 desktop.ini 2013-07-28 15:32 DVD Maker 2014-10-05 09:50 Internet Explorer 2009-07-14 20:09 Microsoft Games 2014-01-23 12:38 Microsoft Office 2009-07-14 07:32 MSBuild 2009-07-14 07:32 Reference Assemblies 2009-07-14 07:09 Uninstall Information 2013-07-29 10:30 Windows Defender 2014-07-12 16:03 Windows Journal 2013-07-28 15:32 Windows Mail 2013-07-28 15:32 Windows Media Player 2013-07-11 08:56 Windows NT 2013-07-28 15:32 Windows Photo Viewer 2013-07-28 15:32 Windows Portable Devices 2013-07-28 15:32 Windows Sidebar 1 plik(¢w) 174 bajt¢w 20 katalog(¢w) 31ÿ678ÿ889ÿ984 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 4E4F-F12E Katalog: C:\Program Files (x86) 2014-10-13 19:52 . 2014-10-13 19:52 .. 2013-07-29 00:08 Adobe 2014-10-02 15:36 Citrix 2014-10-13 00:42 Common Files 2014-01-23 06:30 DAEMON Tools Lite 2009-07-14 06:54 174 desktop.ini 2013-09-12 09:36 Google 2013-07-12 17:41 Intel 2014-10-05 09:50 Internet Explorer 2014-01-23 12:45 Microsoft Office 2014-01-23 12:44 Microsoft Visual Studio 2014-01-23 12:38 Microsoft Visual Studio 8 2014-01-26 21:48 Microsoft Works 2014-01-23 12:43 Microsoft.NET 2014-10-09 18:40 Mozilla Firefox 2014-01-23 12:45 MSBuild 2009-07-14 07:32 Reference Assemblies 2014-06-09 00:00 Skype 2014-10-10 15:27 TeamSpeak 3 Client 2009-07-14 06:57 Uninstall Information 2013-07-29 10:30 Windows Defender 2013-07-28 15:32 Windows Mail 2013-07-28 15:32 Windows Media Player 2009-07-14 07:32 Windows NT 2013-07-28 15:32 Windows Photo Viewer 2013-07-28 15:32 Windows Portable Devices 2013-07-28 15:32 Windows Sidebar 2013-10-01 10:03 WinRAR 1 plik(¢w) 174 bajt¢w 28 katalog(¢w) 31ÿ678ÿ885ÿ888 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 4E4F-F12E Katalog: C:\ProgramData 2014-10-13 19:52 . 2014-10-13 19:52 .. 2013-07-29 09:37 Adobe 2009-07-14 07:08 Application Data [C:\ProgramData] 2013-07-21 20:24 Babylon 2013-10-06 10:01 BitGuard 2013-07-21 20:27 Canneverbe Limited 2014-01-23 06:29 DAEMON Tools Lite 2013-07-11 08:56 Dane aplikacji [C:\ProgramData] 2009-07-14 07:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 07:08 Documents [C:\Users\Public\Documents] 2013-07-11 08:56 Dokumenty [C:\Users\Public\Documents] 2009-07-14 07:08 Favorites [C:\Users\Public\Favorites] 2013-07-22 20:48 McAfee 2013-07-11 08:56 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-09-26 17:21 Microsoft 2014-10-05 09:48 Microsoft Help 2013-07-12 17:47 Mozilla 2014-10-05 09:51 266 ntuser.pol 2013-07-11 08:56 Pulpit [C:\Users\Public\Desktop] 2014-08-10 10:33 Skype 2009-07-14 07:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2013-09-02 15:48 Sun 2013-07-11 08:56 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2009-07-14 07:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2013-07-11 08:56 Ulubione [C:\Users\Public\Favorites] 1 plik(¢w) 266 bajt¢w 25 katalog(¢w) 31ÿ678ÿ885ÿ888 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Admin\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 4E4F-F12E Katalog: C:\Users\Admin\AppData\Local 2014-10-13 19:52 . 2014-10-13 19:52 .. 2013-07-29 09:35 Adobe 2013-10-02 20:26 avgchrome 2014-01-27 14:26 cache 2014-10-02 15:13 Citrix 2013-07-11 08:56 Dane aplikacji [C:\Users\Admin\AppData\Local] 2014-06-24 22:09 15ÿ360 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-09-30 16:28 Diagnostics 2014-10-09 19:02 EmieSiteList 2014-10-09 19:02 EmieUserList 2014-01-23 17:47 108ÿ840 GDIPFONTCACHEV1.DAT 2014-01-23 11:41 genienext 2013-09-12 09:37 Google 2013-07-11 08:56 Historia [C:\Users\Admin\AppData\Local\Microsoft\Windows\History] 2014-10-13 16:54 3ÿ824ÿ350 IconCache.db 2014-10-09 18:40 Installer 2013-07-22 20:49 Macromedia 2014-09-26 14:53 Microsoft 2013-10-01 10:15 Microsoft Help 2014-01-23 02:06 Microsoft Toolkit 2013-10-23 08:55 Mozilla 2014-01-27 16:05 Programs 2014-03-04 18:39 Skype 2014-10-13 19:51 Temp 2013-07-11 08:56 Temporary Internet Files [C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2013-07-11 08:56 VirtualStore 3 plik(¢w) 3ÿ948ÿ550 bajt¢w 24 katalog(¢w) 31ÿ678ÿ881ÿ792 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Admin\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 4E4F-F12E Katalog: C:\Users\Admin\AppData\LocalLow 2014-10-09 19:02 . 2014-10-09 19:02 .. 2013-07-29 09:35 Adobe 2013-07-27 16:55 Delta 2014-10-09 19:02 EmieSiteList 2014-10-09 19:02 EmieUserList 2013-08-10 21:19 Microsoft 2013-09-02 14:45 Sun 0 plik(¢w) 0 bajt¢w 8 katalog(¢w) 31ÿ678ÿ881ÿ792 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Admin\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 4E4F-F12E Katalog: C:\Users\Admin\AppData\Roaming 2014-10-13 19:52 . 2014-10-13 19:52 .. 2013-10-02 21:01 0F1F1C2Y1H1P1C0I0T 2013-07-29 09:35 Adobe 2013-07-21 20:24 Babylon 2013-07-12 17:46 BESTplayer 2013-07-21 20:27 Canneverbe Limited 2014-01-23 06:32 DAEMON Tools Lite 2013-07-11 08:56 Identities 2013-07-22 20:49 Macromedia 2009-07-14 20:09 Media Center Programs 2013-08-27 13:40 Media Player Classic 2014-10-02 15:13 Microsoft 2014-07-20 21:06 Mobogenie 2013-07-12 18:09 Mozilla 2014-10-02 16:39 Skype 2014-01-27 16:06 Softland 2014-10-12 22:59 TS3Client 2013-07-12 17:39 WinBatch 2013-10-01 10:03 WinRAR 0 plik(¢w) 0 bajt¢w 20 katalog(¢w) 31ÿ678ÿ881ÿ792 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 808.7 MB temporary data. The system needed a reboot. ==== End of Fixlog ====