Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-10-2014 Ran by zbyszek at 2014-10-17 22:22:34 Run:1 Running from C:\Users\zbyszek\Downloads Loaded Profiles: zbyszek & UpdatusUser (Available profiles: zbyszek & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-11] (Symantec Corporation) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-3979453871-354022052-2110772485-1000\...\MountPoints2: {e5db99f1-1d2f-11e4-86e8-9439e5a5e658} - F:\Startme.exe AppInit_DLLs-x32: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll => "c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll" File Not Found HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=156&d=pg HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://search.babylon.com/?affID=109220&tt=0313_5&babsrc=HP_ss&mntrId=902074ec000000000000a639e5a5e657 http://sony.msn.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://findgala.com/?&uid=9&q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://findgala.com/?&uid=9&q={searchTerms} SearchScopes: HKCU - {8AC42468-EFC7-4C13-AABA-BF7BFB1B0E5D} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=D7B92098-E643-4385-905A-9D9D8ADCFE14&apn_sauid=697E5BDA-E898-4453-ADBF-4F25A4E9F013 CHR HKLM-x32\...\Chrome\Extension: [aaaaojmikegpiepcfdkkjaplodkpfmlo] - C:\Users\zbyszek\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx [2012-10-17] CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\StartSearch plugin\vshareplg.crx [2012-07-26] Task: {028E0FEF-18C2-4514-9FDB-B6BD0F4C3379} - System32\Tasks\{C965709E-F7FC-4362-9803-9681AEDFD01E} => Chrome.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsMain Task: {55E3DBE9-E14F-4936-984B-D2F1E2FF0E34} - System32\Tasks\{E8EA96B3-2C28-486C-BCB9-00AF1472E7B6} => Chrome.exe http://ui.skype.com/ui/0/6.1.0.129.272/pl/abandoninstall?page=tsMain Task: {C5302F1A-4118-4439-A1B6-42E34C736FB1} - System32\Tasks\task565550 => C:\Users\zbyszek\AppData\Local\Temp\0.6928561684109467.exe <==== ATTENTION Task: {E7E981A5-50F1-44FE-AD5D-6EF89085AE93} - System32\Tasks\Norton Security Scan for zbyszek => C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\Nss.exe [2014-01-27] (Symantec Corporation) Task: C:\Windows\Tasks\Norton Security Scan for zbyszek.job => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched DeleteKey: HKCU\Software\Mozilla DeleteKey: HKCU\Software\MozillaPlugins DeleteKey: HKLM\SOFTWARE\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\mozilla.org DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\StartSearch plugin C:\ProgramData\McAfee C:\Users\zbyszek\AppData\Local\APN C:\Users\zbyszek\AppData\Roaming\Babylon C:\Users\zbyszek\AppData\Roaming\Mozilla C:\Users\zbyszek\AppData\Roaming\VshareComplete C:\Users\zbyszek\Downloads\SpyHunter-Installer.exe C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\zbyszek\AppData\Local CMD: dir /a C:\Users\zbyszek\AppData\LocalLow CMD: dir /a C:\Users\zbyszek\AppData\Roaming CMD: netsh advfirewall reset Hosts: EmptyTemp: ***************** Processes closed successfully. eeCtrl => Service not found. esgiguard => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. "HKU\S-1-5-21-3979453871-354022052-2110772485-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e5db99f1-1d2f-11e4-86e8-9439e5a5e658}" => Key deleted successfully. "HKCR\CLSID\{e5db99f1-1d2f-11e4-86e8-9439e5a5e658}" => Key not found. "c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll" => Value Data removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8AC42468-EFC7-4C13-AABA-BF7BFB1B0E5D}" => Key deleted successfully. "HKCR\CLSID\{8AC42468-EFC7-4C13-AABA-BF7BFB1B0E5D}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo" => Key deleted successfully. C:\Users\zbyszek\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj" => Key deleted successfully. "C:\Program Files (x86)\StartSearch plugin\vshareplg.crx" => File/Directory not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{028E0FEF-18C2-4514-9FDB-B6BD0F4C3379}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{028E0FEF-18C2-4514-9FDB-B6BD0F4C3379}" => Key deleted successfully. C:\Windows\System32\Tasks\{C965709E-F7FC-4362-9803-9681AEDFD01E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C965709E-F7FC-4362-9803-9681AEDFD01E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{55E3DBE9-E14F-4936-984B-D2F1E2FF0E34}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55E3DBE9-E14F-4936-984B-D2F1E2FF0E34}" => Key deleted successfully. C:\Windows\System32\Tasks\{E8EA96B3-2C28-486C-BCB9-00AF1472E7B6} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E8EA96B3-2C28-486C-BCB9-00AF1472E7B6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5302F1A-4118-4439-A1B6-42E34C736FB1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5302F1A-4118-4439-A1B6-42E34C736FB1}" => Key deleted successfully. C:\Windows\System32\Tasks\task565550 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\task565550" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E7E981A5-50F1-44FE-AD5D-6EF89085AE93}" => Key not found. C:\Windows\System32\Tasks\Norton Security Scan for zbyszek not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Security Scan for zbyszek" => Key not found. C:\Windows\Tasks\Norton Security Scan for zbyszek.job not found. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched => Key Deleted successfully. HKCU\Software\Mozilla => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\Mozilla => Key Deleted Successfully. HKCU\Software\MozillaPlugins => Failed to delete key at first attempt (Error: C0000121), see next line. HKCU\Software\MozillaPlugins => Key Deleted Successfully. HKLM\SOFTWARE\MozillaPlugins => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\MozillaPlugins => Key Deleted Successfully. HKLM\SOFTWARE\Wow6432Node\Mozilla => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\Mozilla => Key Deleted Successfully. HKLM\SOFTWARE\Wow6432Node\mozilla.org => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\mozilla.org => Key Deleted Successfully. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => Key Deleted Successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. "C:\Program Files (x86)\StartSearch plugin" => File/Directory not found. C:\ProgramData\McAfee => Moved successfully. C:\Users\zbyszek\AppData\Local\APN => Moved successfully. C:\Users\zbyszek\AppData\Roaming\Babylon => Moved successfully. C:\Users\zbyszek\AppData\Roaming\Mozilla => Moved successfully. "C:\Users\zbyszek\AppData\Roaming\VshareComplete" => File/Directory not found. C:\Users\zbyszek\Downloads\SpyHunter-Installer.exe => Moved successfully. C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP => Moved successfully. ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 9020-74EC Katalog: C:\Program Files 2014-10-17 22:20