Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-12-2013 02 Ran by Truepicasso at 2013-12-04 12:17:05 Run:1 Running from C:\Users\Truepicasso\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** R2 PirritUpdater; C:\Program Files\Pirrit\AutoUpdater.exe [55296 2013-12-02] () C:\Program Files\Pirrit C:\Users\Truepicasso\AppData\Local\Pirrit Suggestor C:\Users\Truepicasso\AppData\Local\Temp\InstHelper.exe C:\Users\Truepicasso\AppData\Local\Temp\~CFB.tmp HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://search.conduit.com?searchsource=10&ctid=ct2304157 SearchScopes: HKLM - DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 SearchScopes: HKLM - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 SearchScopes: HKCU - DEA5C50FA6954714A68753FCB825C6A7 URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms} BHO: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No File Toolbar: HKCU - No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin HKCU: @onlive.com/OnLiveGameClientDetector,version=1.0.0 - C:\Program Files\OnLive\Plugin\npolgdet.dll No File FF HKLM\...\Firefox\Extensions: [ocr@babylon.com] - f:\Program Files\Babylon\Babylon-Pro\Utils\ocr@babylon.com HKCU\...\Run: [Komunikator] - F:\Program Files\Tlen.pl\tlen.exe S3 AIDA32Driver; \??\C:\Users\Truepicasso\Downloads\aida3942(www.maxprograms.pl)\aida32.sys [x] S3 ATP; system32\DRIVERS\cmdatp.sys [x] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x] S3 EverestDriver; \??\F:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [x] Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}" /f CMD: md C:\Users\Truepicasso\Desktop\Upload CMD: xcopy "C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Preferences" C:\Users\Truepicasso\Desktop\Upload CMD: xcopy /e "C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc" C:\Users\Truepicasso\Desktop\Upload ***************** PirritUpdater => Service deleted successfully. C:\Program Files\Pirrit => Moved successfully. C:\Users\Truepicasso\AppData\Local\Pirrit Suggestor => Moved successfully. C:\Users\Truepicasso\AppData\Local\Temp\InstHelper.exe => Moved successfully. "C:\Users\Truepicasso\AppData\Local\Temp\~CFB.tmp" => File/Directory not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\DEA5C50FA6954714A68753FCB825C6A7 => Key deleted successfully. HKCR\Wow6432Node\CLSID\DEA5C50FA6954714A68753FCB825C6A7 => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d} => Key deleted successfully. HKCR\CLSID\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} => Value deleted successfully. HKCR\CLSID\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully. HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key not found. HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin => Key deleted successfully. C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll not found. HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0 => Key deleted successfully. C:\Program Files\OnLive\Plugin\npolgdet.dll not found. HKLM\Software\Mozilla\Firefox\Extensions\\ocr@babylon.com => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Komunikator => Value deleted successfully. AIDA32Driver => Service deleted successfully. ATP => Service deleted successfully. EagleXNt => Service deleted successfully. EverestDriver => Service deleted successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= md C:\Users\Truepicasso\Desktop\Upload ========= ========= End of CMD: ========= ========= xcopy "C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Preferences" C:\Users\Truepicasso\Desktop\Upload ========= C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Preferences Liczba skopiowanych plik¢w: 1. ========= End of CMD: ========= ========= xcopy /e "C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc" C:\Users\Truepicasso\Desktop\Upload ========= C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc\background.html C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc\background.js C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc\icon_128.png C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc\inject.js C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc\jquery.min.js C:\Users\Truepicasso\AppData\Local\Google\Chrome\User Data\Default\Extensions\ammfplfdkakimnibcghcebgbiiphabgc\manifest.json Liczba skopiowanych plik¢w: 6. ========= End of CMD: ========= The system needs a manual reboot. ==== End of Fixlog ====