Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 14-11-2013 Ran by Kamila at 2013-11-15 23:00:33 Run:1 Running from C:\Users\Kamila\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [facemoods] - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe [362200 2011-09-05] (facemoods.com) HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?u...6&ts=1355685030 SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = http://start.facemoo...earchTerms}&f=4 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylo...00006265efddb16 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com...6&ts=1355685031 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={DDA9A96A-BDBA-4CD9-830D-D78C70A733E0}&mid=a1840ec1b194d4f3128f37df7249ad6c-26daff4126c9cab5a9b43985ef4aefecb91d645f&lang=pl&ds=AVG&coid=avgtbavg&pr=pr&d=2013-10-02 18:31:54&v=17.0.0.12&pid=avg&sg=0&sap=dsp&q={searchTerms} BHO: No Name - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO) BHO: DealPly - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) Toolbar: HKLM - facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File CHR HKLM\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Users\Kamila\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx CHR HKLM\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files\DealPly\DealPly.crx CHR HKLM\...\Chrome\Extension: [ihflimipbcaljfnojhhknppphnnciiif] - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoods.crx S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] 2013-11-07 18:12 - 2012-03-12 17:18 - 00000000 ____D C:\Program Files\DealPly 2013-11-07 18:12 - 2012-02-01 12:09 - 00000000 ____D C:\Program Files\facemoods.com 2013-11-07 18:56 - 2010-03-03 21:39 - 00000000 ____D C:\ProgramData\avg9 C:\Users\Kamila\AppData\Local\Temp\AMPing.exe C:\Users\Kamila\AppData\Local\Temp\avgnt.exe C:\Users\Kamila\AppData\Local\Temp\avguidx.dll C:\Users\Kamila\AppData\Local\Temp\CommonInstaller.exe C:\Users\Kamila\AppData\Local\Temp\gg10.upgr.exe C:\Users\Kamila\AppData\Local\Temp\gg10_upgr_to_11790_from_11119.exe C:\Users\Kamila\AppData\Local\Temp\gg10_upgr_to_11999_from_11790.exe C:\Users\Kamila\AppData\Local\Temp\gg10_upgr_to_12096_from_11790.exe C:\Users\Kamila\AppData\Local\Temp\GLF1F6A.EXE C:\Users\Kamila\AppData\Local\Temp\GLF4245.EXE C:\Users\Kamila\AppData\Local\Temp\GLF6C4D.EXE C:\Users\Kamila\AppData\Local\Temp\GLF8B16.EXE C:\Users\Kamila\AppData\Local\Temp\GLF95B2.EXE C:\Users\Kamila\AppData\Local\Temp\GLFA09A.EXE C:\Users\Kamila\AppData\Local\Temp\GLFA0D5.EXE C:\Users\Kamila\AppData\Local\Temp\GLFA97F.EXE C:\Users\Kamila\AppData\Local\Temp\GLFE69.EXE C:\Users\Kamila\AppData\Local\Temp\GLFE96A.EXE C:\Users\Kamila\AppData\Local\Temp\GLFEE1B.EXE C:\Users\Kamila\AppData\Local\Temp\GLFFE7E.EXE C:\Users\Kamila\AppData\Local\Temp\GUR3800.exe C:\Users\Kamila\AppData\Local\Temp\GUR382F.exe C:\Users\Kamila\AppData\Local\Temp\GUR3E28.exe C:\Users\Kamila\AppData\Local\Temp\GUR43D2.exe C:\Users\Kamila\AppData\Local\Temp\GUR648.exe C:\Users\Kamila\AppData\Local\Temp\GUR672A.exe C:\Users\Kamila\AppData\Local\Temp\HomePageV9.exe C:\Users\Kamila\AppData\Local\Temp\IadHide5.dll C:\Users\Kamila\AppData\Local\Temp\iGearedHelper.dll C:\Users\Kamila\AppData\Local\Temp\InstallManager_BAB_BAB.exe C:\Users\Kamila\AppData\Local\Temp\jre-1.6.0_20-windows-i586-iftw.exe_90744722.exe C:\Users\Kamila\AppData\Local\Temp\jre-6u20-windows-i586-jinstall_uac.exe C:\Users\Kamila\AppData\Local\Temp\MachineIdCreator.exe C:\Users\Kamila\AppData\Local\Temp\Mario_Forever.exe C:\Users\Kamila\AppData\Local\Temp\oi_{0C43E2D4-102F-45A5-A2EC-EA264174B0B9}.exe C:\Users\Kamila\AppData\Local\Temp\oi_{9D13E41E-4AEC-4EB3-8F3D-EEBF16A5647F}.exe C:\Users\Kamila\AppData\Local\Temp\SkypeSetup.exe C:\Users\Kamila\AppData\Local\Temp\Super_Bros_3_Mario_Forever.exe C:\Users\Kamila\AppData\Local\Temp\ToolbarInstaller.exe C:\Users\Kamila\AppData\Local\Temp\v9formalavida.exe C:\ProgramData\PKP_DLbx.DAT ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\facemoods => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} => Key deleted successfully. HKCR\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC} => Key deleted successfully. HKCR\CLSID\{64182481-4F71-486b-A045-B233BD0DA8FC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} => Key deleted successfully. HKCR\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} => Value deleted successfully. HKCR\CLSID\{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb => Key deleted successfully. "C:\Users\Kamila\AppData\Roaming\BabylonToolbar\CR\BabylonChrome1.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje => Key deleted successfully. "C:\Program Files\DealPly\DealPly.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif => Key deleted successfully. "C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoods.crx" => File/Directory not found. Synth3dVsc => Service deleted successfully. tsusbhub => Service deleted successfully. C:\Program Files\DealPly => Moved successfully. C:\Program Files\facemoods.com => Moved successfully. C:\ProgramData\avg9 => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\AMPing.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\avgnt.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\avguidx.dll => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\CommonInstaller.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\gg10.upgr.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\gg10_upgr_to_11790_from_11119.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\gg10_upgr_to_11999_from_11790.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\gg10_upgr_to_12096_from_11790.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLF1F6A.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLF4245.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLF6C4D.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLF8B16.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLF95B2.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLFA09A.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLFA0D5.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLFA97F.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLFE69.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLFE96A.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLFEE1B.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GLFFE7E.EXE => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GUR3800.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GUR382F.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GUR3E28.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GUR43D2.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GUR648.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\GUR672A.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\HomePageV9.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\IadHide5.dll => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\iGearedHelper.dll => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\InstallManager_BAB_BAB.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\jre-1.6.0_20-windows-i586-iftw.exe_90744722.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\jre-6u20-windows-i586-jinstall_uac.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\MachineIdCreator.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\Mario_Forever.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\oi_{0C43E2D4-102F-45A5-A2EC-EA264174B0B9}.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\oi_{9D13E41E-4AEC-4EB3-8F3D-EEBF16A5647F}.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\SkypeSetup.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\Super_Bros_3_Mario_Forever.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\ToolbarInstaller.exe => Moved successfully. C:\Users\Kamila\AppData\Local\Temp\v9formalavida.exe => Moved successfully. C:\ProgramData\PKP_DLbx.DAT => Moved successfully. ==== End of Fixlog ====