Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 18-02-2015 01 Ran by Patrycja at 2015-02-20 12:56:33 Run:2 Running from C:\Documents and Settings\Patrycja\Moje dokumenty Loaded Profiles: Patrycja (Available profiles: Patrycja) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 {3cee21b8-f45f-4b81-8601-1f2cae0a9621}t; C:\WINDOWS\System32\drivers\{3cee21b8-f45f-4b81-8601-1f2cae0a9621}t.sys [55832 2015-02-19] (StdLib) R1 {6d550375-e98e-48ce-8260-daa7e461d495}t; C:\WINDOWS\System32\drivers\{6d550375-e98e-48ce-8260-daa7e461d495}t.sys [55824 2014-10-02] (StdLib) R1 {dcd044e6-adb7-46c3-8ece-3d3a0a33bf3a}t; C:\WINDOWS\System32\drivers\{dcd044e6-adb7-46c3-8ece-3d3a0a33bf3a}t.sys [55832 2015-02-15] (StdLib) R1 {e4a6645a-3f85-4e1f-aa41-8367978844db}t; C:\WINDOWS\System32\drivers\{e4a6645a-3f85-4e1f-aa41-8367978844db}t.sys [55872 2014-10-16] (StdLib) R1 {e65048d8-bd76-44ed-ac28-c25d339ab590}t; C:\WINDOWS\System32\drivers\{e65048d8-bd76-44ed-ac28-c25d339ab590}t.sys [55832 2015-02-09] (StdLib) S1 iSafeKrnlMon; \??\C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [X] S2 MaintainerSvc2.65.3980626; "C:\Documents and Settings\All Users\Dane aplikacji\ee70f246-63a3-464e-a2ed-28bc4d8db631\maintainer.exe" [X] S1 rfqoveiv; \??\C:\WINDOWS\system32\drivers\rfqoveiv.sys [X] S2 Update Browser Good; "C:\Program Files\Browser Good\updateBrowserGood.exe" [X] S2 winzipersvc; C:\Program Files\WinZipper\winzipersvc.exe [X] <==== ATTENTION Task: C:\WINDOWS\Tasks\At1.job => C:\DOCUME~1\Patrycja\DANEAP~1\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\WINDOWS\Tasks\e01f31b0-ec5e-4b84-821b-062247fa9655-5.job => C:\Program Files\HD Cinema Pro 1.8cV16.02\e01f31b0-ec5e-4b84-821b-062247fa9655-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\RegClean Prosch.job => C:\Program Files\RCP\RegCleanPro.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files\RCP\RegCleanPro.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\RegClean Pro_UPDATES.job => C:\Program Files\RCP\RegCleanPro.exe <==== ATTENTION HKLM\...\Run: [upfst_pl_207.exe] => C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\fst_pl_207\upfst_pl_207.exe [3303928 2014-09-25] () HKU\S-1-5-21-790525478-861567501-682003330-1004\...\Run: [Akamai NetSession Interface] => "C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe" HKU\S-1-5-21-790525478-861567501-682003330-1004\...\Run: [Mobile Partner] => C:\Program Files\Wi-Fi Modem\Wi-Fi Modem AppInit_DLLs: c:\docume~1\alluse~1\daneap~1\bitguard\271832~1.68\{c16c1~1\bitguard.dll => c:\docume~1\alluse~1\daneap~1\bitguard\271832~1.68\{c16c1~1\bitguard.dll File Not Found AppInit_DLLs: c:\progra~1\suppor~1\suppor~1.dll => c:\progra~1\suppor~1\suppor~1.dll File Not Found Startup: C:\Documents and Settings\Patrycja\Menu Start\Programy\Autostart\superpc_soft_partner.lnk GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1424287421&from=brd&uid=HITACHIXHTS542512K9SA00_080407BB0202WBJW33EAX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1424287421&from=brd&uid=HITACHIXHTS542512K9SA00_080407BB0202WBJW33EAX&q={searchTerms} HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1418980592&from=wpm12173&uid=HITACHIXHTS542512K9SA00_080407BB0202WBJW33EAX&q={searchTerms} HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1418980592&from=wpm12173&uid=HITACHIXHTS542512K9SA00_080407BB0202WBJW33EAX&q={searchTerms} URLSearchHook: HKLM - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871} URLSearchHook: HKU\S-1-5-21-790525478-861567501-682003330-1004 - Default Value = {FE69C007-C452-4d3e-86D2-1730DF8BC871} BHO: BlockAndSurf -> {08DB7275-1643-E608-A596-F0D5D89AB9A0} -> C:\Program Files\ver4BlockAndSurf\179.dll No File BHO: browseandshop -> {44e61e69-2845-4e6c-b785-88e009eb6a78} -> C:\Documents and Settings\All Users\Dane aplikacji\browseandshop\Znrq1pVpJDoDIi.dll No File Toolbar: HKU\S-1-5-21-790525478-861567501-682003330-1004 -> No Name - {4F524A2D-5350-4500-76A7-7A786E7484D7} - No File FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\{b6a94784-0ffb-4121-88c6-435139067ee2}.xpi C:\Documents and Settings\All Users\Dane aplikacji\{649bc223-64bd-806a-649b-bc22364b088d} C:\Documents and Settings\All Users\Dane aplikacji\17484233891940776556 C:\Documents and Settings\All Users\Dane aplikacji\2b87154c00004f54 C:\Documents and Settings\All Users\Dane aplikacji\couponcheapchea C:\Documents and Settings\Patrycja\Dane aplikacji\istartsurf C:\Documents and Settings\Patrycja\Dane aplikacji\WinZipper C:\Documents and Settings\Patrycja\Moje dokumenty\*(*)-dp*.exe C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\nsx45.tmp C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\fst_pl_207 C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\Google C:\Program Files\Google C:\Program Files\WinZipper C:\WINDOWS\System32\drivers\{3cee21b8-f45f-4b81-8601-1f2cae0a9621}t.sys C:\WINDOWS\System32\drivers\{6d550375-e98e-48ce-8260-daa7e461d495}t.sys C:\WINDOWS\System32\drivers\{dcd044e6-adb7-46c3-8ece-3d3a0a33bf3a}t.sys C:\WINDOWS\System32\drivers\{e4a6645a-3f85-4e1f-aa41-8367978844db}t.sys C:\WINDOWS\System32\drivers\{e65048d8-bd76-44ed-ac28-c25d339ab590}t.sys C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension Reg: reg delete HKCU\Software\Google /f Reg: reg delete HKLM\SOFTWARE\Google /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. {3cee21b8-f45f-4b81-8601-1f2cae0a9621}t => Service not found. {6d550375-e98e-48ce-8260-daa7e461d495}t => Service not found. {dcd044e6-adb7-46c3-8ece-3d3a0a33bf3a}t => Service not found. {e4a6645a-3f85-4e1f-aa41-8367978844db}t => Service not found. {e65048d8-bd76-44ed-ac28-c25d339ab590}t => Service not found. iSafeKrnlMon => Service not found. MaintainerSvc2.65.3980626 => Service not found. rfqoveiv => Service not found. Update Browser Good => Service not found. winzipersvc => Service not found. C:\WINDOWS\Tasks\At1.job not found. C:\WINDOWS\Tasks\e01f31b0-ec5e-4b84-821b-062247fa9655-5.job not found. C:\WINDOWS\Tasks\RegClean Prosch.job not found. C:\WINDOWS\Tasks\RegClean Pro_DEFAULT.job not found. C:\WINDOWS\Tasks\RegClean Pro_UPDATES.job not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upfst_pl_207.exe => Value not found. HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => Value not found. HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Run\\Mobile Partner => Value not found. "c:\docume~1\alluse~1\daneap~1\bitguard\271832~1.68\{c16c1~1\bitguard.dll" => Value Data not found. "c:\progra~1\suppor~1\suppor~1.dll" => Value Data not found. C:\Documents and Settings\Patrycja\Menu Start\Programy\Autostart\superpc_soft_partner.lnk not found. "C:\WINDOWS\system32\GroupPolicy\Machine" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key not found. HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value not found. HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{08DB7275-1643-E608-A596-F0D5D89AB9A0} => Key not found. "HKCR\CLSID\{08DB7275-1643-E608-A596-F0D5D89AB9A0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44e61e69-2845-4e6c-b785-88e009eb6a78}" => Key deleted successfully. "HKCR\CLSID\{44e61e69-2845-4e6c-b785-88e009eb6a78}" => Key deleted successfully. HKU\S-1-5-21-790525478-861567501-682003330-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4F524A2D-5350-4500-76A7-7A786E7484D7} => value deleted successfully. HKCR\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7} => Key not found. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. C:\{b6a94784-0ffb-4121-88c6-435139067ee2}.xpi => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\{649bc223-64bd-806a-649b-bc22364b088d} => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\17484233891940776556 => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\2b87154c00004f54 => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\couponcheapchea => Moved successfully. C:\Documents and Settings\Patrycja\Dane aplikacji\istartsurf => Moved successfully. C:\Documents and Settings\Patrycja\Dane aplikacji\WinZipper => Moved successfully. C:\Documents and Settings\Patrycja\Moje dokumenty\*(*)-dp*.exe => Moved successfully. C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\nsx45.tmp => Moved successfully. C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\fst_pl_207 => Moved successfully. C:\Documents and Settings\Patrycja\Ustawienia lokalne\Dane aplikacji\Google => Moved successfully. C:\Program Files\Google => Moved successfully. C:\Program Files\WinZipper => Moved successfully. C:\WINDOWS\System32\drivers\{3cee21b8-f45f-4b81-8601-1f2cae0a9621}t.sys => Moved successfully. C:\WINDOWS\System32\drivers\{6d550375-e98e-48ce-8260-daa7e461d495}t.sys => Moved successfully. C:\WINDOWS\System32\drivers\{dcd044e6-adb7-46c3-8ece-3d3a0a33bf3a}t.sys => Moved successfully. C:\WINDOWS\System32\drivers\{e4a6645a-3f85-4e1f-aa41-8367978844db}t.sys => Moved successfully. C:\WINDOWS\System32\drivers\{e65048d8-bd76-44ed-ac28-c25d339ab590}t.sys => Moved successfully. C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. ========= reg delete HKCU\Software\Google /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= EmptyTemp: => Removed 714.2 MB temporary data. The system needed a reboot. ==== End of Fixlog 12:57:46 ====