Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 28-08-2013 Ran by Admin at 2013-08-30 08:35:05 Run:1 Running from C:\Documents and Settings\Admin\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=ST3808110AS_5LS23XBM____5LS23XBM&ts=1357050581 URLSearchHook: (No Name) - {83821C2B-32A8-4DD7-B6D4-44309A78E668} - No File SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2417} URL = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=417&sr=0&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2417} URL = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=417&sr=0&q={searchTerms} SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={E6AC97AF-400F-4CEC-B534-08E952C9C5FF} SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = http://start.funmoods.com/?a=nv1&s={searchTerms}&f=4 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=112555&tt=100512_4_&babsrc=SP_ss&mntrId=70dc199a000000000000001485cdbb26 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://www.bigseekpro.com/search/browser/cheatengine/{3AA81E45-291C-4F60-B1D6-76074C19EAFB}?q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2417} URL = http://dts.search-results.com/sr?src=ieb&appid=0&systemid=417&sr=0&q={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468 SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb139/?search={searchTerms}&loc=IB_DS&a=6OysRQdGOP&i=26 SearchScopes: HKCU - {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={E6AC97AF-400F-4CEC-B534-08E952C9C5FF} BHO: Plugin for Media Finder - {AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} - No File BHO: IEPluginBHO Class - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No File Toolbar: HKCU -No Name - {09900DE8-1DCA-443F-9243-26FF581438AF} - No File Toolbar: HKCU -No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU -No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File FF Plugin: @nexon.net/NxGame - \NGM\npNxGameUS.dll No File FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mailru.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\v9.xml FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} FF HKLM\...\Firefox\Extensions: [fbphotozoom@installdaddy.com] C:\Program Files\fbphotozoom\fbphotozoom13.xpi FF Extension: No Name - C:\Program Files\fbphotozoom\fbphotozoom13.xpi FF HKLM\...\Firefox\Extensions: [4faaf285f03f9@4faaf285f03fa.info] C:\Documents and Settings\Admin\Dane aplikacji\Mozilla\Firefox\Profiles\w9yazsoh.default\extensions\4faaf285f03f9@4faaf285f03fa.info FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox FF HKLM\...\Firefox\Extensions: [4faaf22b91f4c@4faaf22b91f4d.info] C:\Documents and Settings\Admin\Dane aplikacji\Mozilla\Firefox\Profiles\w9yazsoh.default\extensions\4faaf22b91f4c@4faaf22b91f4d.info HKU\Gość\...\Run: [Gadu-Gadu] - "D:\Gadu-Gadu\gg.exe" /tray [x] HKU\Gość\...\Run: [ares] - "C:\Program Files\Ares\Ares.exe" -h [x] HKU\Gość\...\Run: [Rubin] - C:\Documents and Settings\Gość\Ustawienia lokalne\Dane aplikacji\Rubin\rubin.exe [ 2010-09-03] () HKU\Gość\...\Run: [TQO Start] - C:\WINDOWS\system32\HTXDPJ\TQO.exe [x] Winlogon\Notify\AtiExtEvent: Unlock: HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg Unlock: HKLM\SYSTEM\CurrentControlSet\Services\sptd S0 bkeekeyn; System32\drivers\ltipk.sys [x] S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [x] S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x] S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x] S0 rseb; No ImagePath S0 sfsync02; System32\drivers\sfsync02.sys [x] S4 sptd; System32\Drivers\sptd.sys [x] S3 Video3D; System32\Drivers\Video3D32.sys [x] C:\Program Files\TornTV.com C:\Documents and Settings\Admin\pxdl.exe C:\Documents and Settings\Admin\Dane aplikacji\25Assist C:\Documents and Settings\Admin\Dane aplikacji\Media Finder C:\Documents and Settings\All Users\Dane aplikacji\9lojea9.dat C:\Documents and Settings\All Users\Dane aplikacji\100 C:\Documents and Settings\All Users\Dane aplikacji\ADDICT-THING C:\Documents and Settings\All Users\Dane aplikacji\Babylon C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess C:\Documents and Settings\All Users\Dane aplikacji\Common Files C:\Documents and Settings\All Users\Dane aplikacji\InstallMate C:\Documents and Settings\All Users\Dane aplikacji\Premium C:\Documents and Settings\Gość\Dane aplikacji\Incredibar.com C:\Documents and Settings\Gość\Dane aplikacji\searchqutoolbar C:\Documents and Settings\Tadek\Dane aplikacji\BabylonToolbar C:\Documents and Settings\Tadek\Dane aplikacji\Incredibar.com C:\Documents and Settings\Tadek\Dane aplikacji\searchquband C:\Documents and Settings\Tadek\Dane aplikacji\searchqutoolbar C:\Documents and Settings\Tadek\Dane aplikacji\Toolbar4 C:\Documents and Settings\Gość\Ustawienia lokalne\Dane aplikacji\Rubin\rubin.exe C:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome /f CMD: netsh firewall reset ***************** HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{83821C2B-32A8-4DD7-B6D4-44309A78E668} => Value deleted successfully. HKCR\CLSID\{83821C2B-32A8-4DD7-B6D4-44309A78E668} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\ToolbarSearchProviderProgress => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{E88E0043-C9D4-4e33-8555-FEE4F5B63060} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} => Key deleted successfully. HKCR\CLSID\{AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} => Key deleted successfully. HKCR\CLSID\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{09900DE8-1DCA-443F-9243-26FF581438AF} => Value deleted successfully. HKCR\CLSID\{09900DE8-1DCA-443F-9243-26FF581438AF} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => Value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. HKLM\Software\MozillaPlugins\FF Plugin: @nexon.net/NxGame - \NGM\npNxGameUS.dll No File => Key not found. FF Plugin: @nexon.net/NxGame - \NGM\npNxGameUS.dll No File not found. HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3 => Key deleted successfully. C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll not found. HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9 => Key deleted successfully. C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll not found. C:\Program Files\mozilla firefox\searchplugins\babylon.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\mailru.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\v9.xml => Moved successfully. C:\Program Files\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} => Moved successfully. HKLM\Software\Mozilla\Firefox\Extensions\\fbphotozoom@installdaddy.com => Value deleted successfully. C:\Program Files\fbphotozoom\fbphotozoom13.xpi => Moved successfully. HKLM\Software\Mozilla\Firefox\Extensions\\4faaf285f03f9@4faaf285f03fa.info => Value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} => Value deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\4faaf22b91f4c@4faaf22b91f4d.info => Value deleted successfully. HKU\Gość\Software\Microsoft\Windows\CurrentVersion\Run\\Gadu-Gadu => Value deleted successfully. HKU\Gość\Software\Microsoft\Windows\CurrentVersion\Run\\ares => Value deleted successfully. HKU\Gość\Software\Microsoft\Windows\CurrentVersion\Run\\Rubin => Value deleted successfully. HKU\Gość\Software\Microsoft\Windows\CurrentVersion\Run\\TQO Start => Value deleted successfully. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Winlogon\Notify\AtiExtEvent: => Key not found. "HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg" => Key unlocked successfully. "HKLM\SYSTEM\CurrentControlSet\Services\sptd" => Key unlocked successfully. bkeekeyn => Service deleted successfully. BootDefragDriver => Service deleted successfully. EagleNT => Service deleted successfully. EagleXNt => Service deleted successfully. rseb => Service deleted successfully. sfsync02 => Service deleted successfully. sptd => Service deleted successfully. Video3D => Service deleted successfully. C:\Program Files\TornTV.com => Moved successfully. C:\Documents and Settings\Admin\pxdl.exe => Moved successfully. C:\Documents and Settings\Admin\Dane aplikacji\25Assist => Moved successfully. C:\Documents and Settings\Admin\Dane aplikacji\Media Finder => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\9lojea9.dat => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\100 => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\ADDICT-THING => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Common Files => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\InstallMate => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Premium => Moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\Incredibar.com => Moved successfully. C:\Documents and Settings\Gość\Dane aplikacji\searchqutoolbar => Moved successfully. C:\Documents and Settings\Tadek\Dane aplikacji\BabylonToolbar => Moved successfully. C:\Documents and Settings\Tadek\Dane aplikacji\Incredibar.com => Moved successfully. C:\Documents and Settings\Tadek\Dane aplikacji\searchquband => Moved successfully. C:\Documents and Settings\Tadek\Dane aplikacji\searchqutoolbar => Moved successfully. C:\Documents and Settings\Tadek\Dane aplikacji\Toolbar4 => Moved successfully. C:\Documents and Settings\Gość\Ustawienia lokalne\Dane aplikacji\Rubin\rubin.exe => Moved successfully. C:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\Google\Chrome => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= netsh firewall reset ========= Ok. ========= End of CMD: ========= ==== End of Fixlog ====