Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-04-2015 04 Ran by Kasia at 2015-04-16 20:52:51 Run:3 Running from C:\Users\Kasia\Downloads Loaded Profiles: Kasia (Available profiles: Kasia) Boot Mode: Normal ============================================== Content of fixlist: ***************** Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\isearch.babylon.com" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DC727A8C-7582-483C-A1C2-2B885F099BB5} /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DC727A8C-7582-483C-A1C2-2B885F099BB5} /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF /f Reg: reg delete HKU\S-1-5-18\Software\AskPartnerNetwork /f CMD: del /q C:\Users\Kasia\Downloads\ibghrxzm.exe CMD: del /q C:\Windows\System32\drivers\iSafeKrnlBoot.sys RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\FRST\Quarantine RemoveDirectory: C:\Program Files\AdTrustMedia RemoveDirectory: C:\Program Files (x86)\Elex-tech RemoveDirectory: C:\Program Files (x86)\OpenOffice.org 3 RemoveDirectory: C:\Users\Kasia\Desktop\Stare dane programu Firefox RemoveDirectory: C:\Windows\System32\log ***************** ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\isearch.babylon.com" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DC727A8C-7582-483C-A1C2-2B885F099BB5} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DC727A8C-7582-483C-A1C2-2B885F099BB5} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKU\S-1-5-18\Software\AskPartnerNetwork /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= del /q C:\Users\Kasia\Downloads\ibghrxzm.exe ========= ========= End of CMD: ========= ========= del /q C:\Windows\System32\drivers\iSafeKrnlBoot.sys ========= ========= End of CMD: ========= Could not remove "C:\AdwCleaner" => Scheduled to remove on reboot. "C:\FRST\Quarantine" => Removed successfully. "C:\Program Files\AdTrustMedia" => Removed successfully. "C:\Program Files (x86)\Elex-tech" => Removed successfully. "C:\Program Files (x86)\OpenOffice.org 3" => Removed successfully. "C:\Users\Kasia\Desktop\Stare dane programu Firefox" => Removed successfully. "C:\Windows\System32\log" => Removed successfully. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-04-16 20:58:35)<= C:\AdwCleaner => Is removed successfully. ==== End of Fixlog 20:58:35 ====