Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-10-2014 01 Ran by Kamil at 2014-10-28 16:36:28 Run:1 Running from C:\Users\Kamil\Downloads Loaded Profile: Kamil (Available profiles: Kamil) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R1 {972b8ad0-9d6f-4688-9227-759df6914df4}w64; C:\Windows\System32\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}w64.sys [48776 2014-10-24] (StdLib) R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [705416 2014-09-24] (Cherished Technololgy LIMITED) R2 YouTubeAcceleratorService; C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe [1510248 2014-10-24] (GOOBZO) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1413460407&from=cor&uid=ST3500418AS_6VMGGVAGXXXX6VMGGVAG&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1413460407&from=cor&uid=ST3500418AS_6VMGGVAGXXXX6VMGGVAG&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1413460407&from=cor&uid=ST3500418AS_6VMGGVAGXXXX6VMGGVAG&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1413460407&from=cor&uid=ST3500418AS_6VMGGVAGXXXX6VMGGVAG&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1413460407&from=cor&uid=ST3500418AS_6VMGGVAGXXXX6VMGGVAG Startup: C:\Users\Kamil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Menedżer Realtek HD Audio.lnk Task: C:\WINDOWS\Tasks\Opera N.job => C:\Program Files (x86)\Opera\launcher.exe C:\Program Files (x86)\Apps Hat C:\Program Files (x86)\globalUpdate C:\Program Files (x86)\Opera C:\Program Files (x86)\Temp C:\Program Files (x86)\YTAHelper C:\ProgramData\374311380 C:\ProgramData\IePluginServices C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator C:\ProgramData\TEMP C:\ProgramData\WindowsMangerProtect C:\ProgramData\YTAHelper C:\Users\Kamil\AppData\Local\globalUpdate C:\Users\Kamil\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Kamil\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences C:\Users\Kamil\AppData\Local\Opera Software C:\Users\Kamil\AppData\Roaming\Opera Software C:\Users\Kamil\AppData\Roaming\Systweak C:\Users\Kamil\Downloads\*_downloader*.exe C:\Users\Public\Documents\GOOBZO C:\Users\Public\Documents\ShopperPro C:\Users\Public\Documents\YTAHelper C:\WINDOWS\system32\netcfg-*.txt C:\WINDOWS\system32\roboot64.exe C:\Windows\System32\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}w64.sys CMD: netsh winsock reset CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Kamil\AppData\Local CMD: dir /a C:\Users\Kamil\AppData\LocalLow CMD: dir /a C:\Users\Kamil\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. {972b8ad0-9d6f-4688-9227-759df6914df4}w64 => Unable to stop service {972b8ad0-9d6f-4688-9227-759df6914df4}w64 => Service deleted successfully. IePluginServices => Service deleted successfully. YouTubeAcceleratorService => Service deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => Key deleted successfully. C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll => Moved successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => Key deleted successfully. C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. C:\Users\Kamil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Menedżer Realtek HD Audio.lnk => Moved successfully. C:\WINDOWS\Tasks\Opera N.job => Moved successfully. C:\Program Files (x86)\Apps Hat => Moved successfully. C:\Program Files (x86)\globalUpdate => Moved successfully. C:\Program Files (x86)\Opera => Moved successfully. C:\Program Files (x86)\Temp => Moved successfully. C:\Program Files (x86)\YTAHelper => Moved successfully. C:\ProgramData\374311380 => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\ProgramData\YTAHelper => Moved successfully. C:\Users\Kamil\AppData\Local\globalUpdate => Moved successfully. C:\Users\Kamil\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Kamil\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences => Moved successfully. C:\Users\Kamil\AppData\Local\Opera Software => Moved successfully. C:\Users\Kamil\AppData\Roaming\Opera Software => Moved successfully. C:\Users\Kamil\AppData\Roaming\Systweak => Moved successfully. C:\Users\Kamil\Downloads\*_downloader*.exe => Moved successfully. C:\Users\Public\Documents\GOOBZO => Moved successfully. C:\Users\Public\Documents\ShopperPro => Moved successfully. C:\Users\Public\Documents\YTAHelper => Moved successfully. C:\WINDOWS\system32\netcfg-*.txt => Moved successfully. C:\WINDOWS\system32\roboot64.exe => Moved successfully. C:\Windows\System32\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}w64.sys => Moved successfully. ========= netsh winsock reset ========= Sucessfully reset the Winsock Catalog. You must restart the computer in order to complete the reset. ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is 4826-7A4E Directory of C:\Program Files 2014-10-23 16:19