Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 25-11-2013 01 Ran by Robert at 2013-11-26 18:05:53 Run:1 Running from C:\Documents and Settings\Robert\Moje dokumenty\Pobieranie Boot Mode: Normal ============================================== Content of fixlist: ***************** BHO: extrafind - {249d1086-0670-c91e-32d0-7cc1a90cfc20} - C:\WINDOWS\system32\d24e741a.dll No File Toolbar: HKLM - No Name - {37B85A29-692B-4205-9CAD-2626E4993404} - No File Toolbar: HKCU - No Name - {C4069E3A-68F1-403E-B40E-20066696354B} - No File Toolbar: HKCU - No Name - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No File Toolbar: HKCU - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/...01-001641ca4d89 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/...01-001641ca4d89 URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) SearchScopes: HKLM - {91E0E636-F054-45FC-B343-EF4D3ACFD0AB} URL = http://startsear.ch/...q={searchTerms} FF user.js: detected! => C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\user.js FF DefaultSearchEngine: Search the web FF SearchEngineOrder.1: Search the web FF SelectedSearchEngine: Search the web FF Homepage: hxxp://startsear.ch/?aff=1&cf=af368b60-7044-11e1-bd01-001641ca4d89 FF Keyword.URL: hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q= FF SearchPlugin: C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\searchplugins\web-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Search the web.src FF Extension: Ask Toolbar - C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\Extensions\toolbar@ask.com FF Extension: vShare - C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\Extensions\vshare@toolbar S2 aswFsBlk; system32\DRIVERS\aswFsBlk.sys [x] S1 aswSP; No ImagePath S3 catchme; \??\C:\DOCUME~1\Robert\USTAWI~1\Temp\catchme.sys [x] S3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] 2013-11-25 21:43 - 2010-11-07 18:20 - 00208896 _____ C:\WINDOWS\MBR.exe 2013-11-25 21:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe 2013-11-25 21:42 - 2011-06-26 07:45 - 00256000 _____ C:\WINDOWS\PEV.exe 2013-11-25 21:42 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe 2013-11-25 21:42 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe 2013-11-25 21:42 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe 2013-11-25 21:42 - 2000-08-31 01:00 - 00098816 _____ C:\WINDOWS\sed.exe 2013-11-25 21:42 - 2000-08-31 01:00 - 00080412 _____ C:\WINDOWS\grep.exe 2013-11-25 21:42 - 2000-08-31 01:00 - 00068096 _____ C:\WINDOWS\zip.exe 2013-11-25 21:31 - 2013-11-25 22:50 - 00000000 ____D C:\Qoobox C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job 2013-11-25 22:50 - 2013-11-25 21:31 - 00000000 ____D C:\Qoobox ***************** HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{249d1086-0670-c91e-32d0-7cc1a90cfc20} => Key deleted successfully. HKCR\CLSID\{249d1086-0670-c91e-32d0-7cc1a90cfc20} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{37B85A29-692B-4205-9CAD-2626E4993404} => Value deleted successfully. HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} => Value deleted successfully. HKCR\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} => Value deleted successfully. HKCR\CLSID\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE5D279F-081B-4404-994D-C6B60AAEBA6D} => Value deleted successfully. HKCR\CLSID\{EE5D279F-081B-4404-994D-C6B60AAEBA6D} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} => Value deleted successfully. HKCR\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{91E0E636-F054-45FC-B343-EF4D3ACFD0AB} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{91E0E636-F054-45FC-B343-EF4D3ACFD0AB} => Key not found. C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\user.js => Moved successfully. Firefox DefaultSearchEngine deleted successfully. Firefox SearchEngineOrder.1 deleted successfully. Firefox SelectedSearchEngine deleted successfully. Firefox homepage deleted successfully. Firefox Keyword.URL deleted successfully. C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\searchplugins\web-search.xml => Moved successfully. C:\Program Files\mozilla firefox\searchplugins\Search the web.src => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\Extensions\toolbar@ask.com => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\Mozilla\Firefox\Profiles\ykvdiqde.default\Extensions\vshare@toolbar => Moved successfully. aswFsBlk => Service deleted successfully. aswSP => Service deleted successfully. catchme => Service deleted successfully. EraserUtilRebootDrv => Service not found. C:\WINDOWS\MBR.exe => Moved successfully. C:\WINDOWS\NIRCMD.exe => Moved successfully. C:\WINDOWS\PEV.exe => Moved successfully. C:\WINDOWS\SWREG.exe => Moved successfully. C:\WINDOWS\SWSC.exe => Moved successfully. C:\WINDOWS\SWXCACLS.exe => Moved successfully. C:\WINDOWS\sed.exe => Moved successfully. C:\WINDOWS\grep.exe => Moved successfully. C:\WINDOWS\zip.exe => Moved successfully. C:\Qoobox => Moved successfully. C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job => Moved successfully. "C:\Qoobox" => File/Directory not found. ==== End of Fixlog ====