Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-01-2014 Ran by Bogdan at 2014-01-05 23:45:00 Run:1 Running from C:\Documents and Settings\Bogdan\Moje dokumenty\Pobieranie\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKCU\...\Run: [DAEMON Tools Lite] - rem "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun HKCU\...\Policies\Explorer: [NoCDBurning] 0 BootExecute: autocheck autochk * sasnative32sdnclean.exe SearchScopes: HKLM - {24A62A83-6394-48FC-BF6C-EF6ABED09DC7} URL = http://www.zumie.com/?prt=ZUMIE156&keywords={searchTerms} SearchScopes: HKCU - {0CA24C3C-9EBF-4775-8673-57EA6B6FB376} URL = http://search.yahoo.com/search?ei=utf-8&fr=vmn&type=vdio2&p={searchTerms} SearchScopes: HKCU - {209787F8-8763-48B6-ADC8-E83F74F070E1} URL = http://www.dealio.com/products.html?kwd={searchTerms} SearchScopes: HKCU - {94D57B42-E3BA-4C01-B98A-8CCA2FCBF29E} URL = http://www.zumie.com/?prt=ZumFreez&keywords={searchTerms} SearchScopes: HKCU - {A903B7AE-3A5E-4b2a-ACAE-0AD3EDCF0F22} URL = http://search.supermario-toolbar.com/search?p=Q&ts=ne&w={searchTerms}&csrc=search-field Toolbar: HKCU - No Name - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll No File R0 pavboot; C:\Windows\System32\drivers\pavboot.sys [28544 2008-06-19] (Panda Security, S.L.) S3 BCASPROT; \??\C:\Program Files\Systweak\Advanced System Protector\sasprot32.sys [x] S3 Cardex; \??\C:\WINDOWS\system32\drivers\TBPANEL.SYS [x] S3 catchme; \??\C:\DOCUME~1\Bogdan\USTAWI~1\Temp\catchme.sys [x] S3 cpuz135; \??\C:\WINDOWS\TEMP\cpuz135\cpuz135_x32.sys [x] U4 dwshd; \SystemRoot\System32\drivers\dwshd.sys [x] S3 MEMSWEEP2; \??\C:\WINDOWS\system32\519C.tmp [x] U3 TlntSvr; C:\Documents and Settings\All Users\Dane aplikacji\Doctor Web C:\Documents and Settings\All Users\Dane aplikacji\DriverScanner C:\Documents and Settings\All Users\Dane aplikacji\G DATA C:\Documents and Settings\All Users\Dane aplikacji\InstallMate C:\Documents and Settings\All Users\Dane aplikacji\MSScanAppDataDir C:\Documents and Settings\Bogdan\.android C:\Documents and Settings\Bogdan\daemonprocess.txt C:\Documents and Settings\Bogdan\Doctor Web C:\Documents and Settings\Bogdan\Dane aplikacji\PCToolsFirewallPlus C:\Documents and Settings\Bogdan\Dane aplikacji\PCToolsSpamMonitorPlus C:\Documents and Settings\Bogdan\Dane aplikacji\SystemUp C:\Documents and Settings\Bogdan\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\Bogdan\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\Bogdan\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Program Files\Mobogenie C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP C:\Windows\System32\drivers\pavboot.sys Reg: reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg add HKLM\SYSTEM\CurrentControlSet\services\Beep /v ImagePath /t REG_EXPAND_SZ /d System32\Drivers\beep.sys /f CMD: netsh winsock reset ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoCDBurning => Value deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{24A62A83-6394-48FC-BF6C-EF6ABED09DC7} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{24A62A83-6394-48FC-BF6C-EF6ABED09DC7} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0CA24C3C-9EBF-4775-8673-57EA6B6FB376} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0CA24C3C-9EBF-4775-8673-57EA6B6FB376} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{209787F8-8763-48B6-ADC8-E83F74F070E1} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{209787F8-8763-48B6-ADC8-E83F74F070E1} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{94D57B42-E3BA-4C01-B98A-8CCA2FCBF29E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{94D57B42-E3BA-4C01-B98A-8CCA2FCBF29E} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A903B7AE-3A5E-4b2a-ACAE-0AD3EDCF0F22} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{A903B7AE-3A5E-4b2a-ACAE-0AD3EDCF0F22} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} => Value deleted successfully. HKCR\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} => Key not found. HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer => Key deleted successfully. C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll not found. pavboot => Service deleted successfully. BCASPROT => Service deleted successfully. Cardex => Service deleted successfully. catchme => Service deleted successfully. cpuz135 => Service deleted successfully. dwshd => Service deleted successfully. MEMSWEEP2 => Service deleted successfully. TlntSvr => Service deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\Doctor Web => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\DriverScanner => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\G DATA => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\InstallMate => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\MSScanAppDataDir => Moved successfully. C:\Documents and Settings\Bogdan\.android => Moved successfully. C:\Documents and Settings\Bogdan\daemonprocess.txt => Moved successfully. C:\Documents and Settings\Bogdan\Doctor Web => Moved successfully. C:\Documents and Settings\Bogdan\Dane aplikacji\PCToolsFirewallPlus => Moved successfully. C:\Documents and Settings\Bogdan\Dane aplikacji\PCToolsSpamMonitorPlus => Moved successfully. C:\Documents and Settings\Bogdan\Dane aplikacji\SystemUp => Moved successfully. C:\Documents and Settings\Bogdan\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\Bogdan\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. "C:\Documents and Settings\Bogdan\Ustawienia lokalne\Dane aplikacji\Mobogenie" => File/Directory not found. "C:\Program Files\Mobogenie" => File/Directory not found. C:\WINDOWS\220FB0354744483A9A0B41DF77061583.TMP => Moved successfully. C:\Windows\System32\drivers\pavboot.sys => Moved successfully. ========= reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= End of Reg: ========= ========= reg add HKLM\SYSTEM\CurrentControlSet\services\Beep /v ImagePath /t REG_EXPAND_SZ /d System32\Drivers\beep.sys /f ========= Operacja ukoÅ„czona pomyÅ›lnie ========= End of Reg: ========= ========= netsh winsock reset ========= Pomy˜lnie zresetowano Winsock Catalog. Musisz ponownie uruchomi† komputer, aby ukoäczy† resetowanie. ========= End of CMD: ========= The system needs a manual reboot. ==== End of Fixlog ====