Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-12-2014 02
Ran by Andrrzej Szachta at 2014-12-07 18:11:29 Run:2
Running from C:\Users\Andrrzej Szachta\Documents\Skany i Logi,Naprawa,Fixit.pl
Loaded Profile: Andrrzej Szachta (Available profiles: Andrrzej Szachta)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
CloseProcesses:
HKLM-x32\...\Run: [mbot_de_241] => [X]
HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC7A,,&q={searchTerms}
HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC7A,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2101704784-470427644-3715861599-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC7A,,&q={searchTerms}
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
C:\Program Files (x86)\57ab390e-e982-4bd7-86fa-9a065fb4dbbe
C:\ProgramData\AVG Security Toolbar
C:\Program Files (x86)\CinPlus-2.4cV19.11
C:\Program Files (x86)\LPT
C:\Program Files (x86)\predm
C:\Program Files (x86)\Temp
C:\Program Files (x86)\ver7VeriBrowse
C:\Users\Andrrzej Szachta\AppData\Local\LPT
C:\Users\Andrrzej Szachta\AppData\Local\Smartbar
C:\Users\Andrrzej Szachta\AppData\Roaming\trustedshopper
CMD: dir /a "C:\Program Files"
CMD: dir /a "C:\Program Files (x86)"
CMD: dir /a C:\ProgramData
CMD: dir /a "C:\Users\Andrrzej Szachta\AppData\Local"
CMD: dir /a "C:\Users\Andrrzej Szachta\AppData\LocalLow"
CMD: dir /a "C:\Users\Andrrzej Szachta\AppData\Roaming"
EmptyTemp:
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mbot_de_241 => value deleted successfully.
HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
"HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully.
"HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully.
"HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found.
C:\Program Files (x86)\57ab390e-e982-4bd7-86fa-9a065fb4dbbe => Moved successfully.
C:\ProgramData\AVG Security Toolbar => Moved successfully.
C:\Program Files (x86)\CinPlus-2.4cV19.11 => Moved successfully.
C:\Program Files (x86)\LPT => Moved successfully.
C:\Program Files (x86)\predm => Moved successfully.
C:\Program Files (x86)\Temp => Moved successfully.
C:\Program Files (x86)\ver7VeriBrowse => Moved successfully.
C:\Users\Andrrzej Szachta\AppData\Local\LPT => Moved successfully.
C:\Users\Andrrzej Szachta\AppData\Local\Smartbar => Moved successfully.
C:\Users\Andrrzej Szachta\AppData\Roaming\trustedshopper => Moved successfully.
========= dir /a "C:\Program Files" =========
Volume in drive C is Acer
Volume Serial Number is ACD0-91AD
Directory of C:\Program Files
2014-12-06 16:49
.
2014-12-06 16:49 ..
2013-12-21 05:17 Accessory Store
2013-11-12 07:16 Acer
2013-11-12 06:55 Broadcom
2014-01-10 19:13 CCleaner
2013-08-22 16:36 Common Files
2013-08-22 16:35 174 desktop.ini
2014-04-12 09:27 Elantech
2013-11-12 06:52 Intel
2014-11-23 15:58 Internet Explorer
2014-03-14 09:42 Microsoft Office
2014-08-11 14:07 Microsoft Silverlight
2014-04-12 10:20 MSBuild
2014-04-12 09:28 Realtek
2014-04-12 10:20 Reference Assemblies
2012-07-26 08:22 Uninstall Information
2014-06-20 20:54 VideoLAN
2014-11-23 15:58 Windows Defender
2014-09-19 19:19 Windows Journal
2014-04-12 09:38 Windows Mail
2014-04-12 09:38 Windows Media Player
2014-03-18 11:09 Windows Multimedia Platform
2014-04-12 09:50 Windows NT
2014-04-12 09:38 Windows Photo Viewer
2014-03-18 11:09 Windows Portable Devices
2014-04-12 09:38 Windows Sidebar
2014-12-06 16:39 WindowsApps
2013-08-22 16:36 WindowsPowerShell
1 File(s) 174 bytes
28 Dir(s) 171ÿ885ÿ211ÿ648 bytes free
========= End of CMD: =========
========= dir /a "C:\Program Files (x86)" =========
Volume in drive C is Acer
Volume Serial Number is ACD0-91AD
Directory of C:\Program Files (x86)
2014-12-07 18:11 .
2014-12-07 18:11 ..
2013-11-12 07:22 Acer
2014-11-23 15:35 AVG
2014-08-30 21:30 Becker
2014-11-23 15:35 Browsers Apps
2014-12-06 16:49 Common Files
2013-08-22 16:34 174 desktop.ini
2014-07-21 11:57 Google
2014-08-13 21:46 Greener Web
2014-10-12 12:50 HP
2013-11-12 07:18 InstallShield Installation Information
2014-04-12 09:38 Intel
2014-11-23 15:58 Internet Explorer
2014-03-14 09:45 Microsoft Office
2014-08-11 14:07 Microsoft Silverlight
2014-06-21 21:51 Microsoft Works
2014-04-12 09:38 Microsoft.NET
2014-04-12 10:20 MSBuild
2013-06-04 05:32 Nero
2013-11-12 07:04 Qualcomm Atheros
2013-11-12 06:57 Realtek
2014-04-12 10:20 Reference Assemblies
2013-11-12 07:08 Spotify
2014-07-21 12:22 SupTab
2014-06-21 07:11 WildTangent Games
2014-11-23 15:35 Windows Defender
2014-04-12 09:38 Windows Mail
2014-04-12 09:38 Windows Media Player
2014-03-18 11:09 Windows Multimedia Platform
2013-08-22 16:36 Windows NT
2014-04-12 09:38 Windows Photo Viewer
2014-03-18 11:09 Windows Portable Devices
2014-04-12 09:38 Windows Sidebar
2013-08-22 16:36 WindowsPowerShell
2014-01-12 19:50 XSManager
1 File(s) 174 bytes
35 Dir(s) 171ÿ885ÿ211ÿ648 bytes free
========= End of CMD: =========
========= dir /a C:\ProgramData =========
Volume in drive C is Acer
Volume Serial Number is ACD0-91AD
Directory of C:\ProgramData
2014-12-07 18:11 .
2014-12-07 18:11 ..
2013-11-12 07:20 Acer
2013-08-22 15:45 Application Data [C:\ProgramData]
2014-01-11 22:34 Atheros
2014-08-19 19:16 AVAST Software
2014-08-13 21:39 AVG
2014-11-20 20:41 AVG2014
2014-08-30 19:05 Avg_Update_0814avt
2014-08-13 22:10 boost_interprocess
2013-11-12 07:18 CLSK
2014-09-02 15:46 Common Files
2013-11-12 07:18 CyberLink
2014-04-12 09:50 Dane aplikacji [C:\ProgramData]
2014-06-21 07:10 DatacardService
2013-08-22 15:45 Desktop [C:\Users\Public\Desktop]
2013-08-22 15:45 Documents [C:\Users\Public\Documents]
2014-04-12 09:50 Dokumenty [C:\Users\Public\Documents]
2014-11-23 13:29 HP
2014-10-12 12:50 HP Product Assistant
2014-10-12 12:58 1ÿ255 hpzinstall.log
2013-11-12 07:18 install_clap
2013-11-12 06:52 Intel
2014-05-04 14:43 McAfee
2014-04-12 09:50 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu]
2014-12-07 17:16 MFAData
2014-06-21 19:03 Microsoft
2014-11-14 19:12 Microsoft Help
2013-12-21 05:36 Mobile Partner
2014-01-12 09:43 Mozilla
2013-06-04 05:32 Nero
2014-01-06 10:45 Norton
2014-08-13 22:10 NortonInstaller
2013-11-12 07:11 OEM
2013-12-21 05:17 OEM_YAHOO
2013-12-21 05:19 Pokki
2014-04-12 09:38 PRICache
2014-04-12 09:50 Pulpit [C:\Users\Public\Desktop]
2013-11-12 07:01 Qualcomm Atheros
2014-04-12 09:42 regid.1991-06.com.microsoft
2013-08-22 15:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
2014-04-12 09:50 Szablony [C:\ProgramData\Microsoft\Windows\Templates]
2013-11-12 07:18 Temp
2013-08-22 15:45 Templates [C:\ProgramData\Microsoft\Windows\Templates]
2014-10-12 13:00 WEBREG
2014-06-21 07:11 WildTangent
2014-10-05 08:30 WindowsProtectManger
2014-08-13 21:56 {01BD4FC9-2F86-4706-A62E-774BB7E9D308}
1 File(s) 1ÿ255 bytes
47 Dir(s) 171ÿ885ÿ207ÿ552 bytes free
========= End of CMD: =========
========= dir /a "C:\Users\Andrrzej Szachta\AppData\Local" =========
Volume in drive C is Acer
Volume Serial Number is ACD0-91AD
Directory of C:\Users\Andrrzej Szachta\AppData\Local
2014-12-07 18:11 .
2014-12-07 18:11 ..
2014-03-14 09:48 Apps
2014-04-16 21:12 assembly
2014-11-18 20:12 AVG
2014-11-18 20:45 Avg2014
2014-01-11 22:34 BMExplorer
2014-03-14 23:35 clear.fi
2014-03-19 23:24 CrashDumps
2014-04-12 09:35 Dane aplikacji [C:\Users\Andrrzej Szachta\AppData\Local]
2014-11-23 11:39 Deployment
2014-10-09 20:19 Diagnostics
2014-12-07 18:01 ElevatedDiagnostics
2014-11-19 20:44 EmieBrowserModeList
2014-08-15 20:22 EmieSiteList
2014-08-15 20:22 EmieUserList
2014-06-03 20:18 81ÿ512 GDIPFONTCACHEV1.DAT
2014-07-21 11:59 Google
2014-04-12 09:35 Historia [C:\Users\Andrrzej Szachta\AppData\Local\Microsoft\Windows\History]
2014-10-12 13:00 HP
2014-12-06 16:26 12ÿ256 IconCache.db
2014-06-30 08:00 Intel_Corporation
2014-01-12 10:06 Macromedia
2014-03-06 19:21 MFAData
2014-04-12 10:32 Microsoft
2014-03-14 09:41 Microsoft Help
2014-01-12 09:43 Mozilla
2014-10-12 12:23 Packages
2014-07-21 12:21 Pokki
2014-06-20 20:53 Programs
2014-01-12 09:41 Spotify
2014-12-07 18:11 Temp
2014-04-12 09:35 Temporary Internet Files [C:\Users\Andrrzej Szachta\AppData\Local\Microsoft\Windows\INetCache]
2014-07-21 12:23 Unity
2014-04-11 21:02 VirtualStore
2 File(s) 93ÿ768 bytes
33 Dir(s) 171ÿ885ÿ203ÿ456 bytes free
========= End of CMD: =========
========= dir /a "C:\Users\Andrrzej Szachta\AppData\LocalLow" =========
Volume in drive C is Acer
Volume Serial Number is ACD0-91AD
Directory of C:\Users\Andrrzej Szachta\AppData\LocalLow
2014-12-06 16:48 .
2014-12-06 16:48 ..
2014-11-29 09:54 EmieBrowserModeList
2014-08-15 20:22 EmieSiteList
2014-08-15 20:22 EmieUserList
2014-06-21 19:03 Microsoft
2014-11-22 11:59 Smartbar
2014-11-19 20:41 Sun
2014-04-16 22:02 Temp
2014-11-19 20:39 trustedshopper
2014-07-21 12:23 Unity
0 File(s) 0 bytes
11 Dir(s) 171ÿ885ÿ203ÿ456 bytes free
========= End of CMD: =========
========= dir /a "C:\Users\Andrrzej Szachta\AppData\Roaming" =========
Volume in drive C is Acer
Volume Serial Number is ACD0-91AD
Directory of C:\Users\Andrrzej Szachta\AppData\Roaming
2014-12-07 18:11 .
2014-12-07 18:11 ..
2013-12-21 05:16 Adobe
2014-11-19 20:39 Apple Computer
2013-12-21 05:17 Atheros
2014-08-13 21:38 AVG
2014-03-06 19:25 AVG2014
2014-08-30 21:31 becker
2014-08-09 09:23 BRT
2014-10-12 13:00 HP
2014-10-19 15:58 HpUpdate
2014-04-12 10:32 Identities
2014-01-05 12:54 Macromedia
2014-11-23 15:35 Microsoft
2014-09-01 09:18 1ÿ248 QEDYQJMM
2014-01-12 09:41 Spotify
2014-03-06 19:24 TuneUp Software
2014-04-13 13:24 Unity
2014-09-01 09:18 2ÿ086 VKZRD
2014-11-28 11:00 vlc
2014-01-12 19:52 XSManager
2 File(s) 3ÿ334 bytes
19 Dir(s) 171ÿ885ÿ203ÿ456 bytes free
========= End of CMD: =========
EmptyTemp: => Removed 304.5 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====