Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-10-2014 Ran by Wojtek at 2014-10-20 12:56:49 Run:2 Running from C:\htw Loaded Profile: Wojtek (Available profiles: Wojtek) Boot Mode: Safe Mode (minimal) ============================================== Content of fixlist: ***************** R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2014-09-24] (Elex do Brasil Participaçoes Ltda) R2 WebUpdate4; C:\Windows\SysWOW64\WebUpdateSvc4.exe [278800 2010-08-18] (Data Perceptions / PowerProgrammer) R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [248488 2014-09-24] (Elex do Brasil Participaçoes Ltda) R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [99496 2014-09-24] (Elex do Brasil Participaçoes Ltda) R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [65704 2014-09-24] (Elex do Brasil Participaçoes Ltda) R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [49320 2014-09-22] (Elex do Brasil Participaçoes Ltda) S1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [95712 2013-01-09] (Panda Security, S.L.) R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [33320 2012-10-22] (Panda Security, S.L.) S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X] Task: {448F89C6-AADB-44B0-9313-D639F0F2A7C0} - System32\Tasks\LCANJ => C:\Users\Wojtek\AppData\Roaming\LCANJ.exe <==== ATTENTION Task: {66E8C573-A9A3-4689-8B77-EF1E67062D76} - \RealUpgradeScheduledTaskS-1-5-21-4094745809-975373488-2947739042-1000 No Task File <==== ATTENTION Task: {81D05BD1-2B23-46FF-89D1-E03B949CEF9A} - System32\Tasks\DTTYN => C:\Users\Wojtek\AppData\Roaming\DTTYN.exe <==== ATTENTION Task: {8CD51B56-470A-4FFC-A653-315144A1C7A3} - \{B262C4AE-99FB-4D14-8E37-7231A36355C4} No Task File <==== ATTENTION Task: {C2DA9667-76A9-4B99-B53C-3961B093CC9D} - System32\Tasks\WPOLXBFS => C:\Users\Wojtek\AppData\Roaming\WPOLXBFS.exe <==== ATTENTION Task: {C3F47F27-012F-4029-B5DF-43D9557B8604} - System32\Tasks\GCWKSGNG => C:\Users\Wojtek\AppData\Roaming\GCWKSGNG.exe <==== ATTENTION Task: {D45B0623-7D1F-4CB2-8C7B-C5B06526EDD3} - System32\Tasks\{954586E7-E94F-4401-9F00-05481696402A} => Firefox.exe http://ui.skype.com/ui/0/6.5.0.158/pl/go/help.faq.installer?LastError=1618 Task: {D60F456A-20E5-412C-8993-60C2F1321361} - \RealUpgradeLogonTaskS-1-5-21-4094745809-975373488-2947739042-1000 No Task File <==== ATTENTION Task: {EC069260-24BC-4CBC-9FBB-63C81E45323B} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-WOJTEK_FISHPOIN => C:\Windows\ehome\McxTask.exe Task: C:\Windows\Tasks\DTTYN.job => C:\Users\Wojtek\AppData\Roaming\DTTYN.exe <==== ATTENTION Task: C:\Windows\Tasks\GCWKSGNG.job => C:\Users\Wojtek\AppData\Roaming\GCWKSGNG.exe <==== ATTENTION Task: C:\Windows\Tasks\LCANJ.job => C:\Users\Wojtek\AppData\Roaming\LCANJ.exe <==== ATTENTION Task: C:\Windows\Tasks\WPOLXBFS.job => C:\Users\Wojtek\AppData\Roaming\WPOLXBFS.exe <==== ATTENTION HKU\S-1-5-21-4094745809-975373488-2947739042-1000\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\Wojtek\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=60285c23d09047d3b4957d3bcffc2508-78e38c0f48d7f088e41a422eb830071f395ca4ef /CMPID=1213b BootExecute: PDBoot.exeautocheck autochk * sdnclean64.exe SearchScopes: HKCU - {98A9AA01-09BA-495C-B969-989F60A13EC1} URL = https://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms} BHO-x32: No Name -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> No File C:\Program Files\Opera x64 C:\Program Files (x86)\Elex-tech C:\Program Files (x86)\Mozilla Maintenance Service C:\Program Files (x86)\Opera x64 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC C:\ProgramData\Mozilla C:\Users\Wojtek\AppData\Local\Google\Chrome C:\Users\Wojtek\AppData\Local\Mozilla C:\Users\Wojtek\AppData\Local\Opera C:\Users\Wojtek\AppData\Roaming\ArcaVirMicroScan C:\Users\Wojtek\AppData\Roaming\eCyber C:\Users\Wojtek\AppData\Roaming\Elex-tech C:\Users\Wojtek\AppData\Roaming\Mozilla C:\Users\Wojtek\AppData\Roaming\Opera C:\Windows\System32\DRIVERS\iSafeNetFilter.sys C:\Windows\System32\DRIVERS\NNSHttps.sys C:\Windows\System32\DRIVERS\NNSNAHSL.sys C:\Windows\SysWOW64\WebUpdateSvc4.exe Reg: reg delete HKCU\Software\Google\Chrome /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Opera 12.16.1860" /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Wojtek\AppData\Local CMD: dir /a C:\Users\Wojtek\AppData\LocalLow CMD: dir /a C:\Users\Wojtek\AppData\Roaming CMD: netsh advfirewall reset Reboot: ***************** iSafeService => Service deleted successfully. WebUpdate4 => Service deleted successfully. iSafeKrnl => Service deleted successfully. iSafeKrnlKit => Service stopped successfully. iSafeKrnlKit => Service deleted successfully. iSafeKrnlR3 => Service deleted successfully. iSafeNetFilter => Service deleted successfully. NNSHTTPS => Service deleted successfully. NNSNAHSL => Service deleted successfully. iSafeKrnlBoot => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{448F89C6-AADB-44B0-9313-D639F0F2A7C0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{448F89C6-AADB-44B0-9313-D639F0F2A7C0}" => Key deleted successfully. C:\Windows\System32\Tasks\LCANJ => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LCANJ" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{66E8C573-A9A3-4689-8B77-EF1E67062D76}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66E8C573-A9A3-4689-8B77-EF1E67062D76}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealUpgradeScheduledTaskS-1-5-21-4094745809-975373488-2947739042-1000" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{81D05BD1-2B23-46FF-89D1-E03B949CEF9A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81D05BD1-2B23-46FF-89D1-E03B949CEF9A}" => Key deleted successfully. C:\Windows\System32\Tasks\DTTYN => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DTTYN" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8CD51B56-470A-4FFC-A653-315144A1C7A3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CD51B56-470A-4FFC-A653-315144A1C7A3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B262C4AE-99FB-4D14-8E37-7231A36355C4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2DA9667-76A9-4B99-B53C-3961B093CC9D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2DA9667-76A9-4B99-B53C-3961B093CC9D}" => Key deleted successfully. C:\Windows\System32\Tasks\WPOLXBFS => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPOLXBFS" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C3F47F27-012F-4029-B5DF-43D9557B8604}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3F47F27-012F-4029-B5DF-43D9557B8604}" => Key deleted successfully. C:\Windows\System32\Tasks\GCWKSGNG => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GCWKSGNG" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D45B0623-7D1F-4CB2-8C7B-C5B06526EDD3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D45B0623-7D1F-4CB2-8C7B-C5B06526EDD3}" => Key deleted successfully. C:\Windows\System32\Tasks\{954586E7-E94F-4401-9F00-05481696402A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{954586E7-E94F-4401-9F00-05481696402A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D60F456A-20E5-412C-8993-60C2F1321361}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D60F456A-20E5-412C-8993-60C2F1321361}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealUpgradeLogonTaskS-1-5-21-4094745809-975373488-2947739042-1000" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EC069260-24BC-4CBC-9FBB-63C81E45323B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC069260-24BC-4CBC-9FBB-63C81E45323B}" => Key deleted successfully. C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-WOJTEK_FISHPOIN => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-WOJTEK_FISHPOIN" => Key deleted successfully. C:\Windows\Tasks\DTTYN.job => Moved successfully. C:\Windows\Tasks\GCWKSGNG.job => Moved successfully. C:\Windows\Tasks\LCANJ.job => Moved successfully. C:\Windows\Tasks\WPOLXBFS.job => Moved successfully. HKU\S-1-5-21-4094745809-975373488-2947739042-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_1213b => value deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{98A9AA01-09BA-495C-B969-989F60A13EC1}" => Key deleted successfully. "HKCR\CLSID\{98A9AA01-09BA-495C-B969-989F60A13EC1}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}" => Key not found. C:\Program Files\Opera x64 => Moved successfully. C:\Program Files (x86)\Elex-tech => Moved successfully. C:\Program Files (x86)\Mozilla Maintenance Service => Moved successfully. C:\Program Files (x86)\Opera x64 => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC => Moved successfully. C:\ProgramData\Mozilla => Moved successfully. C:\Users\Wojtek\AppData\Local\Google\Chrome => Moved successfully. C:\Users\Wojtek\AppData\Local\Mozilla => Moved successfully. C:\Users\Wojtek\AppData\Local\Opera => Moved successfully. C:\Users\Wojtek\AppData\Roaming\ArcaVirMicroScan => Moved successfully. C:\Users\Wojtek\AppData\Roaming\eCyber => Moved successfully. C:\Users\Wojtek\AppData\Roaming\Elex-tech => Moved successfully. C:\Users\Wojtek\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Wojtek\AppData\Roaming\Opera => Moved successfully. C:\Windows\System32\DRIVERS\iSafeNetFilter.sys => Moved successfully. C:\Windows\System32\DRIVERS\NNSHttps.sys => Moved successfully. C:\Windows\System32\DRIVERS\NNSNAHSL.sys => Moved successfully. C:\Windows\SysWOW64\WebUpdateSvc4.exe => Moved successfully. ========= reg delete HKCU\Software\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Opera 12.16.1860" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 5896-14AA Katalog: C:\Program Files 2014-10-20 12:56