Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-01-2015 02 Ran by KSIEGOWY at 2015-01-14 16:05:40 Run:2 Running from C:\Users\KSIEGOWY\Desktop\aaa Loaded Profile: KSIEGOWY (Available profiles: KSIEGOWY & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\...\Run: [YTVPack] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\KSIEGOWY\AppData\Local\Ektion\rvvbobqwdyjcc.dll HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\...\Run: [Ezztion] => regsvr32.exe C:\Users\KSIEGOWY\AppData\Local\Ezztion\plc4.dll <===== ATTENTION HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\...\Run: [BluetoothS] => rundll32.exe "%appdata%\BtvStack.dll",BTHF_Register URLSearchHook: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> 7B25F7A08463410AB1D6D9C86FEB050F URL = http://search.babylon.com/?q={searchTerms}&AF=100480&babsrc=SP_ss&mntrId=aa814c8600000000000064315023b703 SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {2AE70A0E-39B8-48D4-9229-9E2C0E150E4B} URL = http://www.search.ask.com/web?p2=^ADN^OSJ000^YY^PL&gct=&itbv=12.0.1.100&o=APN10616&tpid=ORJ-V7&apn_uid=43BDBA54-CA96-429E-8979-478EFC4398ED&apn_ptnrs=ADN&apn_dtid=^OSJ000^YY^PL&apn_dbr=ie_9.0.8112.16476&doi=2013-10-11&trgb=IE&q={searchTerms}&psv= SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMDTDF SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&appid=102&systemid=406&sr=0&q={searchTerms} SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = Toolbar: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> No Name - {4F524A2D-5637-006A-76A7-7A786E7484D7} - No File HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\35355970.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\57130876.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\35355970.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\57130876.sys => ""="Driver" C:\Users\Administrator\temp C:\Users\KSIEGOWY\AppData\Roaming\Babylon Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: dir /a C:\Users\KSIEGOWY\AppData\Local ***************** Processes closed successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Windows\CurrentVersion\Run\\YTVPack => value deleted successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Ezztion => value deleted successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Windows\CurrentVersion\Run\\BluetoothS => value deleted successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => value deleted successfully. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\7B25F7A08463410AB1D6D9C86FEB050F" => Key deleted successfully. HKCR\CLSID\7B25F7A08463410AB1D6D9C86FEB050F => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2AE70A0E-39B8-48D4-9229-9E2C0E150E4B}" => Key deleted successfully. HKCR\CLSID\{2AE70A0E-39B8-48D4-9229-9E2C0E150E4B} => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}" => Key deleted successfully. HKCR\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key not found. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4F524A2D-5637-006A-76A7-7A786E7484D7} => value deleted successfully. HKCR\CLSID\{4F524A2D-5637-006A-76A7-7A786E7484D7} => Key not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\35355970.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\57130876.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\35355970.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\57130876.sys" => Key deleted successfully. C:\Users\Administrator\temp => Moved successfully. C:\Users\KSIEGOWY\AppData\Roaming\Babylon => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a C:\Users\KSIEGOWY\AppData\Local ========= Wolumin w stacji C to OS Numer seryjny woluminu: AA81-4C86 Katalog: C:\Users\KSIEGOWY\AppData\Local 2015-01-12 14:27