Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013 Ran by Ola Koszyk at 2013-10-14 18:16:15 Run:1 Running from C:\Users\Ola Koszyk\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1561768 2012-05-04] (Ask) HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2404376 2013-09-28] () HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\Ola Koszyk\AppData\Local\Smartbar\Application\Linkury.exe startup HKCU\...\Run: [efcccddacdfbc] - C:\ProgramData\efcccddacdfbc.exe [280064 2013-09-30] () HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=opc&from=opc&uid=3219913727_1789_8C4BC7E8&ts=1351455557 SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=TJ&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111585&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=a02e7f38-2a50-4cf7-8e7d-0b4d2d857bd3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {126B987E-8312-4401-94BE-70C4BA41A653} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {6E4DA852-611D-4F39-8807-74AA3ED227C8} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033 SearchScopes: HKCU - {7B020A0A-CE1F-4606-A503-20E27849BD2E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=2A8C200A-76DD-4F24-B7A2-74C7A1B48C13&apn_sauid=25EA7E61-90B6-4FD2-A0D7-AE382E2E1364 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={4FBD8DC0-3FA5-43AB-B52D-5E9A1F1F5EA5}&mid=4e5619e61b5f42b99db9d1ef10b2cad1-27228bf1ea501aad254aeb86831eaabdb660ef9f&lang=en&ds=hk011&pr=&d=2012-11-23 22:02:25&v=15.4.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} BHO: Linkury SmartbarEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.0.0.9\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) BHO: Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) Toolbar: HKLM - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) Toolbar: HKLM - Ashampoo PO Toolbar - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM - Linkury Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.0.0.9\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKCU -DVDVideoSoftTB Toolbar - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.) Toolbar: HKCU -Ashampoo PO Toolbar - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - C:\Program Files\Ashampoo_PO\prxtbAsha.dll (Conduit Ltd.) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.1\ViProtocol.dll (AVG Secure Search) Task: {5DBDE1CB-173D-4D45-8D77-8981A142B49C} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe [2012-05-04] () Task: {AA988155-6932-4626-AA86-8B8022CDA629} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{C4ED5A01-C77C-422B-93DD-DD906F97DBFA}.exe Task: {DF677ED1-CBA3-4230-B9CC-54CF54AC2725} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{C0262C7A-B8CE-4E83-A4D1-10EAAC0987BA}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{C4ED5A01-C77C-422B-93DD-DD906F97DBFA}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{C0262C7A-B8CE-4E83-A4D1-10EAAC0987BA}.exe R2 vToolbarUpdater17.0.1; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\ToolbarUpdater.exe [1734680 2013-09-28] (AVG Secure Search) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-09-28] (AVG Technologies) S3 ASUSProcObsrv; \??\F:\I386\AsProcOb.sys [x] C:\ProgramData\DPtPnrWzWVi C:\ProgramData\OxTYAhuzWHz C:\ProgramData\qmbtpijbrjqdrqn C:\ProgramData\buxosexehnsqmrc C:\ProgramData\bwsvprcqvxiiyca C:\ProgramData\efcccddacdfbc.cfg C:\ProgramData\efcccddacdfbc.exe C:\ProgramData\libnspr4.dll C:\Users\Ola Koszyk\microsoft.dat C:\Users\Ola Koszyk\AppData\Local\7mTfwxXJwgy C:\Users\Ola Koszyk\AppData\Local\kYNIzaV8dsO C:\Users\Ola Koszyk\AppData\Roaming\iESionWMyuc C:\Users\Ola Koszyk\AppData\Roaming\LZIf8Jl9V C:\Users\Ola Koszyk\AppData\Roaming\OpenCandy Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks" /v {872b5b88-9db5-4310-bdd0-ac189557e5f5} /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks" /v {d43723ae-1ae1-4a25-a6a4-bf0929273cab} /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\vProt => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Browser Infrastructure Helper => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\efcccddacdfbc => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{126B987E-8312-4401-94BE-70C4BA41A653} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{126B987E-8312-4401-94BE-70C4BA41A653} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6E4DA852-611D-4F39-8807-74AA3ED227C8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6E4DA852-611D-4F39-8807-74AA3ED227C8} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7B020A0A-CE1F-4606-A503-20E27849BD2E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7B020A0A-CE1F-4606-A503-20E27849BD2E} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0} => Key deleted successfully. HKCR\CLSID\{31ad400d-1b06-4e33-a59a-90c2c140cba0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => Key deleted successfully. HKCR\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Key deleted successfully. HKCR\CLSID\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => Value deleted successfully. HKCR\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Value deleted successfully. HKCR\CLSID\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully. HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} => Value deleted successfully. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} => Value deleted successfully. HKCR\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Value deleted successfully. HKCR\CLSID\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Key not found. HKCR\PROTOCOLS\Handler\viprotocol => Key deleted successfully. HKCR\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5DBDE1CB-173D-4D45-8D77-8981A142B49C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5DBDE1CB-173D-4D45-8D77-8981A142B49C} => Key deleted successfully. C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AA988155-6932-4626-AA86-8B8022CDA629} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA988155-6932-4626-AA86-8B8022CDA629} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DF677ED1-CBA3-4230-B9CC-54CF54AC2725} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF677ED1-CBA3-4230-B9CC-54CF54AC2725} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. vToolbarUpdater17.0.1 => Service deleted successfully. avgtp => Service deleted successfully. ASUSProcObsrv => Service deleted successfully. C:\ProgramData\DPtPnrWzWVi => Moved successfully. C:\ProgramData\OxTYAhuzWHz => Moved successfully. C:\ProgramData\qmbtpijbrjqdrqn => Moved successfully. C:\ProgramData\buxosexehnsqmrc => Moved successfully. C:\ProgramData\bwsvprcqvxiiyca => Moved successfully. C:\ProgramData\efcccddacdfbc.cfg => Moved successfully. C:\ProgramData\efcccddacdfbc.exe => Moved successfully. C:\ProgramData\libnspr4.dll => Moved successfully. C:\Users\Ola Koszyk\microsoft.dat => Moved successfully. C:\Users\Ola Koszyk\AppData\Local\7mTfwxXJwgy => Moved successfully. C:\Users\Ola Koszyk\AppData\Local\kYNIzaV8dsO => Moved successfully. C:\Users\Ola Koszyk\AppData\Roaming\iESionWMyuc => Moved successfully. C:\Users\Ola Koszyk\AppData\Roaming\LZIf8Jl9V => Moved successfully. C:\Users\Ola Koszyk\AppData\Roaming\OpenCandy => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks" /v {872b5b88-9db5-4310-bdd0-ac189557e5f5} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks" /v {d43723ae-1ae1-4a25-a6a4-bf0929273cab} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needs a manual reboot. ==== End of Fixlog ====