Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-12-2013 02 Ran by Maciej at 2013-12-21 21:21:05 Run:1 Running from C:\Documents and Settings\Maciej\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1382898910&from=cor&uid=ST380815AS_6QZ0XBFEXXXX6QZ0XBFE SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382898911&from=cor&uid=ST380815AS_6QZ0XBFEXXXX6QZ0XBFE&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382898911&from=cor&uid=ST380815AS_6QZ0XBFEXXXX6QZ0XBFE&q={searchTerms} SearchScopes: HKCU - {ED4D1056-C38D-4DDE-900F-A767E6AC4FF8} URL = http://szukaj.gazeta.pl/portalSearch.do?s.si(navigation).navigationEnabled=true&s.sm.query={searchTerms} FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe http://start.qone8.com/?type=sc&ts=1382898910&from=cor&uid=ST380815AS_6QZ0XBFEXXXX6QZ0XBFE CHR HKLM\...\Chrome\Extension: [cekcjpgehmohobmdiikfnopibipmgnml] - C:\Documents and Settings\Maciej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ CHR HKLM\...\Chrome\Extension: [mbcjjdjanpccmehilicphhmeobiljcpk] - C:\Program Files\FTDownloader.com\FTDownloader10.crx Task: C:\WINDOWS\Tasks\FTdownloader V4.0-codedownloader.job => C:\Program Files\FTdownloader V4.0\FTdownloader V4.0-codedownloader.exe Task: C:\WINDOWS\Tasks\FTdownloader V4.0-enabler.job => C:\Program Files\FTdownloader V4.0\FTdownloader V4.0-enabler.exe Task: C:\WINDOWS\Tasks\FTdownloader V4.0-updater.job => C:\Program Files\FTdownloader V4.0\FTdownloader V4.0-updater.exe S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [x] S4 InCDFs; system32\drivers\InCDFs.sys [x] S1 InCDPass; system32\drivers\InCDPass.sys [x] S1 InCDRm; system32\drivers\InCDRm.sys [x] S3 MSICPL; \??\F:\install4\MSICPL.sys [x] S3 NTACCESS; \??\F:\NTACCESS.sys [x] S3 SetupNTGLM7X; \??\F:\NTGLM7X.sys [x] CMD: md "C:\Documents and Settings\Maciej\Pulpit\Upload" CMD: copy "C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\3yj7up8d.default\Extensions\ftd@ftd.com.xpi" "C:\Documents and Settings\Maciej\Pulpit\Upload" CMD: copy "C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\3yj7up8d.default\Extensions\ftdownloader2@ftdownloader.com.xpi" "C:\Documents and Settings\Maciej\Pulpit\Upload" CMD: copy "C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\3yj7up8d.default\Extensions\gophoto@gophoto.it.xpi" "C:\Documents and Settings\Maciej\Pulpit\Upload" ***************** HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ED4D1056-C38D-4DDE-900F-A767E6AC4FF8} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{ED4D1056-C38D-4DDE-900F-A767E6AC4FF8} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\cekcjpgehmohobmdiikfnopibipmgnml => Key deleted successfully. C:\Documents and Settings\Maciej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\mbcjjdjanpccmehilicphhmeobiljcpk => Key deleted successfully. C:\Program Files\FTDownloader.com\FTDownloader10.crx => Moved successfully. C:\WINDOWS\Tasks\FTdownloader V4.0-codedownloader.job => Moved successfully. C:\WINDOWS\Tasks\FTdownloader V4.0-enabler.job => Moved successfully. C:\WINDOWS\Tasks\FTdownloader V4.0-updater.job => Moved successfully. GMSIPCI => Service deleted successfully. InCDFs => Service deleted successfully. InCDPass => Service deleted successfully. InCDRm => Service deleted successfully. MSICPL => Service deleted successfully. NTACCESS => Service deleted successfully. SetupNTGLM7X => Service deleted successfully. ========= md "C:\Documents and Settings\Maciej\Pulpit\Upload" ========= ========= End of CMD: ========= ========= copy "C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\3yj7up8d.default\Extensions\ftd@ftd.com.xpi" "C:\Documents and Settings\Maciej\Pulpit\Upload" ========= Liczba skopiowanych plikw: 1. ========= End of CMD: ========= ========= copy "C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\3yj7up8d.default\Extensions\ftdownloader2@ftdownloader.com.xpi" "C:\Documents and Settings\Maciej\Pulpit\Upload" ========= Liczba skopiowanych plikw: 1. ========= End of CMD: ========= ========= copy "C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\3yj7up8d.default\Extensions\gophoto@gophoto.it.xpi" "C:\Documents and Settings\Maciej\Pulpit\Upload" ========= Liczba skopiowanych plikw: 1. ========= End of CMD: ========= ==== End of Fixlog ====