Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-11-2014 03 Ran by justyna i darek at 2014-11-17 09:54:47 Run:1 Running from C:\Users\justyna i darek\Desktop Loaded Profile: justyna i darek (Available profiles: justyna i darek & Justyna) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [dndmwdd.exe] => "C:\Users\justyna i darek\AppData\Roaming\dndmwdd.exe" HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [M0JCOTNCMkY3NDQzMDNDRj] => C:\ProgramData\aqlgbtmh.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [RDUwMzMzMzE2QTU5ODNBNT] => C:\ProgramData\bryxirhy.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [84639553] => C:\ProgramData\wnvlsizt.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [MzY1QjcxRTE5NUNGM0VFRk] => C:\ProgramData\ichafcgt.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [KB7J65QX52UA] => C:\Users\justyna i darek\AppData\Roaming\OZDTD0GD.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [Ogu3FMdasw3tbhy6] => "C:\Users\justyna i darek\AppData\Roaming\dndmwdd.exe" HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [firefox] => C:\Users\justyna i darek\AppData\Roaming\Microsoft\00010ccc.tmp HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [sys] => C:\Users\justyna i darek\AppData\Roaming\7SHBPQBYL5.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [SYSTEM Tools] => C:\Users\justyna i darek\AppData\Roaming\pixels\admin523e2cdb4a0a46e78ba1e2037bb534de.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [Java Applet Launcher] => C:\Users\JUSTYN~1\AppData\Local\Temp\jd2launcher.exe <===== ATTENTION HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [windows] => C:\Users\justyna i darek\AppData\Roaming\winupdatex7.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [] => C:\ [0 ] () HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [udpqt] => C:\Users\justyna i darek\AppData\Roaming\Microsoft\jigtPFhx.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [Windows Update] => C:\Users\justyna i darek\AppData\Roaming\System\Windows Update.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [msnmsgr] => C:\Users\justyna i darek\AppData\Roaming\microsoft\StartUp.exe [55632 2009-06-10] (Microsoft Corporation) HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [VC7T408C46XT] => C:\Users\justyna i darek\AppData\Roaming\FLASH34.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [REU0OTQzRkMzNEI3RDkzOT] => C:\ProgramData\wajyvwcl.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [MSE] => C:\Users\justyna i darek\AppData\Local\Temp\javaw.exe <===== ATTENTION HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [bfbnlkcuf] => C:\Users\justyna i darek\AppData\Local\Temp\bmghmmg.exe <===== ATTENTION HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [Hylqlx] => C:\Users\justyna i darek\AppData\Roaming\Hylqlx.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Run: [06a04cf] => C:\Users\justyna i darek\AppData\Roaming\Microsoft\06a04cf.exe HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\...\Policies\system: [WallpaperStyle] 2 HKU\S-1-5-18\...\Policies\system: [WallpaperStyle] 2 ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie URLSearchHook: HKLM-x32 - (No Name) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No File URLSearchHook: HKCU - (No Name) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No File BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO-x32: AOL Toolbar BHO -> {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -> C:\Program Files (x86)\AOL\Pasek narzędzi AOL 5.0\aoltb.dll No File BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File BHO-x32: IEPluginBHO Class -> {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} -> C:\ProgramData\Gadu-Gadu 10\_userdata\ggbho.2.dll No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKLM-x32 - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\Pasek narzędzi AOL 5.0\aoltb.dll No File Toolbar: HKU\S-1-5-21-2497160206-2615029055-3091190810-1000 -> No Name - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File Toolbar: HKU\S-1-5-21-2497160206-2615029055-3091190810-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Task: {16539DC8-8710-41C8-973D-B0CE70934AD7} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{5DCA02B1-0B4F-444E-9654-39FDFE87EB72}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{5DCA02B1-0B4F-444E-9654-39FDFE87EB72}.exe DisableService: sptd S3 vzcmwezd; No ImagePath S3 ALSysIO; \??\C:\Users\JUSTYN~1\AppData\Local\Temp\ALSysIO64.sys [X] AlternateDataStreams: C:\Windows\Temp:temp AlternateDataStreams: C:\Users\justyna i darek\Local Settings:init C:\Program Files\AVAST Software C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 C:\ProgramData\Doctor Web C:\ProgramData\Norton C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader C:\Users\justyna i darek\Doctor Web C:\Users\justyna i darek\AppData\Local\Google\Chrome C:\Users\justyna i darek\AppData\Local\NPE C:\Users\justyna i darek\AppData\Roaming\microsoft\*.exe C:\Users\justyna i darek\AppData\Roaming\Mozilla C:\Users\justyna i darek\Nokia PC Suite 7\bkmrksync Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Wyszukiwarka na pasku narzędzi AOL" /f Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MenuExt\&Wyszukiwarka na pasku narzędzi AOL" /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7} /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f CMD: netsh advfirewall reset CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a "C:\Users\justyna i darek\AppData\Local" CMD: dir /a "C:\Users\justyna i darek\AppData\LocalLow" CMD: dir /a "C:\Users\justyna i darek\AppData\Roaming" CMD: dir /a "C:\Users\justyna i darek\AppData\Roaming\Microsoft" EmptyTemp: ***************** Processes closed successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\dndmwdd.exe => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\M0JCOTNCMkY3NDQzMDNDRj => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\RDUwMzMzMzE2QTU5ODNBNT => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\84639553 => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MzY1QjcxRTE5NUNGM0VFRk => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\KB7J65QX52UA => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Ogu3FMdasw3tbhy6 => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\firefox => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\sys => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SYSTEM Tools => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Java Applet Launcher => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\windows => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\udpqt => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Update => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\VC7T408C46XT => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\REU0OTQzRkMzNEI3RDkzOT => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MSE => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\bfbnlkcuf => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Hylqlx => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Run\\06a04cf => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\WallpaperStyle => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\WallpaperStyle => value deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. "HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key not found. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. "HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{DE9C389F-3316-41A7-809B-AA305ED9D922} => value deleted successfully. "HKCR\Wow6432Node\CLSID\{DE9C389F-3316-41A7-809B-AA305ED9D922}" => Key deleted successfully. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DE9C389F-3316-41A7-809B-AA305ED9D922} => value deleted successfully. "HKCR\CLSID\{DE9C389F-3316-41A7-809B-AA305ED9D922}" => Key not found. HKU\S-1-5-21-2497160206-2615029055-3091190810-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. "HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{16539DC8-8710-41C8-973D-B0CE70934AD7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{16539DC8-8710-41C8-973D-B0CE70934AD7}" => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv" => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. sptd service was disabled vzcmwezd => Service deleted successfully. ALSysIO => Service deleted successfully. C:\Windows\Temp => ":temp" ADS removed successfully. C:\Users\justyna i darek\Local Settings => ":init" ADS removed successfully. C:\Program Files\AVAST Software => Moved successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt => Moved successfully. C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 => Moved successfully. C:\ProgramData\Doctor Web => Moved successfully. C:\ProgramData\Norton => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader => Moved successfully. C:\Users\justyna i darek\Doctor Web => Moved successfully. C:\Users\justyna i darek\AppData\Local\Google\Chrome => Moved successfully. C:\Users\justyna i darek\AppData\Local\NPE => Moved successfully. C:\Users\justyna i darek\AppData\Roaming\microsoft\*.exe => Moved successfully. C:\Users\justyna i darek\AppData\Roaming\Mozilla => Moved successfully. C:\Users\justyna i darek\Nokia PC Suite 7\bkmrksync => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Wyszukiwarka na pasku narzędzi AOL" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MenuExt\&Wyszukiwarka na pasku narzędzi AOL" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 2AF5-CC4F Katalog: C:\Program Files 2014-11-17 09:55