Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 16-09-2013 03 Ran by Barbara Postek at 2013-09-17 13:50:15 Run:1 Running from C:\Documents and Settings\Barbara Postek\Moje dokumenty\Pobieranie Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\WINDOWS\system32\ACF7EF C:\Documents and Settings\All Users\Dane aplikacji\Babylon C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\Barbara Postek\Dane aplikacji\Babylon C:\Documents and Settings\Barbara Postek\Dane aplikacji\File Scout C:\Documents and Settings\Barbara Postek\Dane aplikacji\PerformerSoft C:\Documents and Settings\Barbara Postek\Dane aplikacji\PriceGong C:\Documents and Settings\Barbara Postek\Ustawienia lokalne\Dane aplikacji\Conduit C:\Documents and Settings\Patryk\Menu Start\Programy\Autostart\74BE16.lnk C:\Program Files\McAfee Security Scan MountPoints2: {452060c8-6b9b-11dc-95fc-001b770f419d} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe MountPoints2: {452060c9-6b9b-11dc-95fc-001b770f419d} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe MountPoints2: {4c2271c6-847e-11dc-9620-001b770f419d} - G:\2u.com MountPoints2: {5e1a865e-cb6b-11dd-983d-0017a4e1e168} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe MountPoints2: {66910f0d-03a6-11df-99b8-0017a4e1e168} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe MountPoints2: {6a1e24a0-b2a2-11de-9957-0017a4e1e168} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe MountPoints2: {943d1a60-4191-11df-9a15-0017a4e1e168} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe MountPoints2: {943d1a62-4191-11df-9a15-0017a4e1e168} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe MountPoints2: {ef30e5f4-4322-11df-9a18-0017a4e1e168} - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycle.exe HKU\Administrator\...\Run: [wsctf.exe] - wsctf.exe HKU\Administrator\...\Run: [EXPLORER.EXE] - EXPLORER.EXE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=119961&babsrc=HP_ss&mntrId=097C0017A4E1E168 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&affID=119961&babsrc=SP_ss&mntrId=097C0017A4E1E168 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 FF HKLM\...\Firefox\Extensions: [speedanalysis@SpeedAnalysis.com] - C:\Documents and Settings\Barbara Postek\Dane aplikacji\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com FF HKCU\...\Firefox\Extensions: [speedanalysis@SpeedAnalysis.com] - C:\Documents and Settings\Barbara Postek\Dane aplikacji\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com FF Extension: SpeedAnalysis.com - C:\Documents and Settings\Barbara Postek\Dane aplikacji\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} http://megapanel.gem.pl/WebInstaller.dll Unlock: HKLM\SYSTEM\CurrentControlSet\Services\sptd S3 ASFWHide; \??\C:\DOCUME~1\BARBAR~1\USTAWI~1\Temp\ASFWHide [x] S4 sptd; System32\Drivers\sptd.sys [x] ***************** C:\WINDOWS\system32\ACF7EF => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. C:\Documents and Settings\Barbara Postek\Dane aplikacji\Babylon => Moved successfully. C:\Documents and Settings\Barbara Postek\Dane aplikacji\File Scout => Moved successfully. C:\Documents and Settings\Barbara Postek\Dane aplikacji\PerformerSoft => Moved successfully. C:\Documents and Settings\Barbara Postek\Dane aplikacji\PriceGong => Moved successfully. C:\Documents and Settings\Barbara Postek\Ustawienia lokalne\Dane aplikacji\Conduit => Moved successfully. C:\Documents and Settings\Patryk\Menu Start\Programy\Autostart\74BE16.lnk => Moved successfully. C:\Program Files\McAfee Security Scan => Moved successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{452060c8-6b9b-11dc-95fc-001b770f419d} => Key deleted successfully. HKCR\CLSID\{452060c8-6b9b-11dc-95fc-001b770f419d} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{452060c9-6b9b-11dc-95fc-001b770f419d} => Key deleted successfully. HKCR\CLSID\{452060c9-6b9b-11dc-95fc-001b770f419d} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c2271c6-847e-11dc-9620-001b770f419d} => Key deleted successfully. HKCR\CLSID\{4c2271c6-847e-11dc-9620-001b770f419d} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5e1a865e-cb6b-11dd-983d-0017a4e1e168} => Key deleted successfully. HKCR\CLSID\{5e1a865e-cb6b-11dd-983d-0017a4e1e168} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{66910f0d-03a6-11df-99b8-0017a4e1e168} => Key deleted successfully. HKCR\CLSID\{66910f0d-03a6-11df-99b8-0017a4e1e168} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6a1e24a0-b2a2-11de-9957-0017a4e1e168} => Key deleted successfully. HKCR\CLSID\{6a1e24a0-b2a2-11de-9957-0017a4e1e168} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{943d1a60-4191-11df-9a15-0017a4e1e168} => Key deleted successfully. HKCR\CLSID\{943d1a60-4191-11df-9a15-0017a4e1e168} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{943d1a62-4191-11df-9a15-0017a4e1e168} => Key deleted successfully. HKCR\CLSID\{943d1a62-4191-11df-9a15-0017a4e1e168} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ef30e5f4-4322-11df-9a18-0017a4e1e168} => Key deleted successfully. HKCR\CLSID\{ef30e5f4-4322-11df-9a18-0017a4e1e168} => Key not found. HKU\Administrator\Software\Microsoft\Windows\CurrentVersion\Run\\wsctf.exe => Value deleted successfully. HKU\Administrator\Software\Microsoft\Windows\CurrentVersion\Run\\EXPLORER.EXE => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKLM\Software\Mozilla\Firefox\Extensions\\speedanalysis@SpeedAnalysis.com => Value deleted successfully. HKCU\Software\Mozilla\Firefox\Extensions\\speedanalysis@SpeedAnalysis.com => Value deleted successfully. C:\Documents and Settings\Barbara Postek\Dane aplikacji\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\babylon.xml => Moved successfully. HKCR\CLSID\{65D72393-E210-4A2A-B8E0-10AC45986770} => Key deleted successfully. "HKLM\SYSTEM\CurrentControlSet\Services\sptd" => Key unlocked successfully. ASFWHide => Service deleted successfully. sptd => Service deleted successfully. ==== End of Fixlog ====