Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-01-2014 01 Ran by Robert at 2014-02-06 19:14:34 Run:1 Running from C:\Documents and Settings\Robert\Pulpit\skanery Boot Mode: Normal ============================================== Content of fixlist: ***************** (ClickMeIn Limited) C:\Program Files\VuuPC\Connectivity.exe HKCU\...\Run: [NextLive] - C:\Documents and Settings\Robert\Dane aplikacji\newnext.me\nengine.dll [1283584 2014-01-06] (NewNextDotMe) HKCU\...\Policies\Explorer: [HideSCAHealth] 1 Winlogon\Notify\WgaLogon: WgaLogon.dll [X] MountPoints2: {c9e94e04-899f-11e3-af0a-001fe2656671} - J:\cdstart.exe ProxyServer: www.facebook.pl HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=SAMSUNG_HD502IJ_S13TJ90QB21856&ts=1355671989 SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=aa684a77-8344-459b-a777-6cc241c978fe&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}&installDate={installDate} SearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchrocket.info/?l=1&q={searchTerms}&pid=700&r=2013/05/28&hid=2570990793&lg=EN&cc=PL&unqvl=16 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.helperbar.com/?publisher=OC&dpid=OC&co=PL&userid=aa684a77-8344-459b-a777-6cc241c978fe&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}&installDate={installDate} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=4C8E001FE2656671&affID=119357&tsp=4983 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=23C2E87D-3350-40F1-AEE1-39983D6B799F&apn_sauid=6C6520A8-ECEB-4137-ACCA-B3DA8427F7F0 BHO: DataMngr - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - No File BHO: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No File BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files\Softonic\softonic\1.5.11.5\bh\softonic.dll (Softonic.com) BHO: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - No File Toolbar: HKLM - Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - No File Toolbar: HKLM - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\softonic\1.5.11.5\softonicTlbr.dll (Softonic.com) Toolbar: HKLM - Linkury Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File CHR HKLM\...\Chrome\Extension: [jifflliplgeajjdhmkcfnngfpgbjonjg] - C:\Program Files\Perion\NewTab\newTab.crx [2012-11-23] CHR HKLM\...\Chrome\Extension: [niogeckbkdcabhnapjbkeiklablhjoca] - C:\Program Files\Perion\ChromeInfoBar\ChromeInfoBar.crx [2012-11-23] CHR HKCU\...\Chrome\Extension: [amfclgbdpgndipgoegfpkkgobahigbcl] - C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\Smartbar/Application\1Extension.crx [2013-05-06] Task: C:\WINDOWS\Tasks\Lyrmix Update.job => C:\Program Files\Lyrmix\LyricsmixUpdate.exe <==== ATTENTION S2 RemoteEngineService; C:\Program Files\VuuPC\remoteengine.exe [2967568 2013-05-22] (ClickMeIn Limited) R2 VuuPCConnectivity; C:\Program Files\VuuPC\Connectivity.exe [4746768 2013-05-22] (ClickMeIn Limited) S2 BrowserDefendert; C:\Documents and Settings\All Users\Dane aplikacji\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [x] S0 ddqdjmt; System32\drivers\otsno.sys [x] U1 luafv; S3 PCAMPR5; \??\C:\WINDOWS\System32\PCAMPR5.SYS [x] S3 rt2870; system32\DRIVERS\rt2870.sys [x] C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software C:\Documents and Settings\All Users\Dane aplikacji\BearShare C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess C:\Documents and Settings\All Users\Dane aplikacji\BrowserDefender C:\Documents and Settings\All Users\Dane aplikacji\Common Files C:\Documents and Settings\All Users\Dane aplikacji\conttiinuoeetOssaVe C:\Documents and Settings\All Users\Dane aplikacji\F4D55F17000485B2006E0D8A8DB91C90 C:\Documents and Settings\All Users\Dane aplikacji\InstallMate C:\Documents and Settings\All Users\Dane aplikacji\StarApp C:\Documents and Settings\All Users\Dane aplikacji\TEMP C:\Documents and Settings\All Users\Dane aplikacji\Wru C:\Documents and Settings\All Users\Dane aplikacji\{E6A6CE03-6563-45AB-89FB-CAA10E4E1475} C:\Documents and Settings\Gość\Ustawienia lokalne\Dane aplikacji\AskToolbar C:\Documents and Settings\Gośka\Ustawienia lokalne\Dane aplikacji\AskToolbar C:\Documents and Settings\Robert\.android C:\Documents and Settings\Robert\.plugin140_03.trace C:\Documents and Settings\Robert\daemonprocess.txt C:\Documents and Settings\Robert\Dane aplikacji\BabMaint.exe C:\Documents and Settings\Robert\Dane aplikacji\0C1I1L1R1J0M1P0I1G C:\Documents and Settings\Robert\Dane aplikacji\BrowserCompanion C:\Documents and Settings\Robert\Dane aplikacji\defaulttab C:\Documents and Settings\Robert\Dane aplikacji\DSite C:\Documents and Settings\Robert\Dane aplikacji\Incredibar.com C:\Documents and Settings\Robert\Dane aplikacji\mediabarbs C:\Documents and Settings\Robert\Dane aplikacji\newnext.me C:\Documents and Settings\Robert\Dane aplikacji\Se Analyzer Tool SA C:\Documents and Settings\Robert\Dane aplikacji\Systweak C:\Documents and Settings\Robert\Dane aplikacji\wincorebsband C:\Documents and Settings\Robert\Menu Start\FoxTab FLV Player C:\Documents and Settings\Robert\Moje dokumenty\Mobogenie C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\cache C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\Mobogenie C:\Program Files\AVAST Software C:\Program Files\FoxTabFLVPlayer C:\Program Files\Mobogenie C:\Program Files\maucampo C:\Program Files\VuuPC C:\WINDOWS\System32\ImHttpComm.dll Reg: reg delete HKCU\Software\Classes\.exe /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search the Web" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\MenuExt\Search the Web" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Bar" /f Reg: reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /f Reg: reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Bar" /f Reg: reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /f Reg: reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java" /f ***************** [1888] C:\Program Files\VuuPC\Connectivity.exe => Process closed successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => Value deleted successfully. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9e94e04-899f-11e3-af0a-001fe2656671} => Key deleted successfully. HKCR\CLSID\{c9e94e04-899f-11e3-af0a-001fe2656671} => Key not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B939CF93-F2CB-443d-956C-DC523D85C9DB} => Key deleted successfully. HKCR\CLSID\{B939CF93-F2CB-443d-956C-DC523D85C9DB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Key deleted successfully. HKCR\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68} => Key deleted successfully. HKCR\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} => Key deleted successfully. HKCR\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Value deleted successfully. HKCR\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} => Value deleted successfully. HKCR\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully. HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg => Key deleted successfully. C:\Program Files\Perion\NewTab\newTab.crx => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\niogeckbkdcabhnapjbkeiklablhjoca => Key deleted successfully. C:\Program Files\Perion\ChromeInfoBar\ChromeInfoBar.crx => Moved successfully. HKCU\SOFTWARE\Google\Chrome\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl => Key deleted successfully. "C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\Smartbar/Application\1Extension.crx" => File/Directory not found. C:\WINDOWS\Tasks\Lyrmix Update.job => Moved successfully. RemoteEngineService => Service deleted successfully. VuuPCConnectivity => Service deleted successfully. BrowserDefendert => Service deleted successfully. ddqdjmt => Service deleted successfully. luafv => Service deleted successfully. PCAMPR5 => Service deleted successfully. rt2870 => Service deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\BearShare => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\BrowserDefender => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Common Files => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\conttiinuoeetOssaVe => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\F4D55F17000485B2006E0D8A8DB91C90 => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\InstallMate => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\StarApp => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\Wru => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\{E6A6CE03-6563-45AB-89FB-CAA10E4E1475} => Moved successfully. C:\Documents and Settings\Gość\Ustawienia lokalne\Dane aplikacji\AskToolbar => Moved successfully. C:\Documents and Settings\Gośka\Ustawienia lokalne\Dane aplikacji\AskToolbar => Moved successfully. C:\Documents and Settings\Robert\.android => Moved successfully. C:\Documents and Settings\Robert\.plugin140_03.trace => Moved successfully. C:\Documents and Settings\Robert\daemonprocess.txt => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\BabMaint.exe => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\0C1I1L1R1J0M1P0I1G => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\BrowserCompanion => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\defaulttab => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\DSite => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\Incredibar.com => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\mediabarbs => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\Se Analyzer Tool SA => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\Systweak => Moved successfully. C:\Documents and Settings\Robert\Dane aplikacji\wincorebsband => Moved successfully. C:\Documents and Settings\Robert\Menu Start\FoxTab FLV Player => Moved successfully. C:\Documents and Settings\Robert\Moje dokumenty\Mobogenie => Moved successfully. C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\cache => Moved successfully. C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\Robert\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. C:\Program Files\AVAST Software => Moved successfully. C:\Program Files\FoxTabFLVPlayer => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Program Files\maucampo => Moved successfully. C:\Program Files\VuuPC => Moved successfully. C:\WINDOWS\System32\ImHttpComm.dll => Moved successfully. ========= reg delete HKCU\Software\Classes\.exe /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\MenuExt\Search the Web" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\MenuExt\Search the Web" /f ========= Błąd: system nie może odnaleźć określonego klucza rejestru lub wartości. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Bar" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Bar" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Search Page" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ==== End of Fixlog ====