Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-02-2014 Ran by Edyta at 2014-02-06 15:05:31 Run:2 Running from C:\Users\Edyta\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: C:\PROGRA~2\WS_X64~1.ENA => C:\Program Files (x86)\WS_x64.Enabler [4241408 2014-02-06] () S2 1a34a8e0; C:\Program Files (x86)\WSSvc.dll [175952 2014-02-06] () BHO: SNT - {2F6CA9D3-23CA-C4E7-FCB1-53230630309C} - C:\Program Files (x86)\SNT\CrzTcWh.x64.dll () BHO: YoutubeAdblocker - {53478B71-B85D-296D-D956-CCB3B79B3C25} - C:\Program Files (x86)\YoutubeAdblocker\nNnjGM7Xb.x64.dll () BHO: greeatsavaerr - {68D6A6AC-6CBB-DAA4-23B5-33413534A2FF} - C:\Program Files (x86)\greeatsavaerr\_kLK.x64.dll () HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.webisgreat.info/?pid=2356&r=2014/02/06&hid=12004318192655379658&lg=EN&cc=PL&unqvl=48 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.webisgreat.info/?pid=2356&r=2014/02/06&hid=12004318192655379658&lg=EN&cc=PL&unqvl=48 SearchScopes: HKLM-x32 - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.webisgreat.info/?l=1&q={searchTerms}&pid=2356&r=2014/02/06&hid=12004318192655379658&lg=EN&cc=PL&unqvl=48 SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.webisgreat.info/?l=1&q={searchTerms}&pid=2356&r=2014/02/06&hid=12004318192655379658&lg=EN&cc=PL&unqvl=48 SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.webisgreat.info/?l=1&q={searchTerms}&pid=2356&r=2014/02/06&hid=12004318192655379658&lg=EN&cc=PL&unqvl=48 SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.webisgreat.info/?l=1&q={searchTerms}&pid=2356&r=2014/02/06&hid=12004318192655379658&lg=EN&cc=PL&unqvl=48 C:\Users\Edyta\AppData\Local\Comodo C:\Users\Edyta\AppData\Local\Packages C:\Users\Edyta\AppData\Local\Torch C:\Users\Edyta\Downloads\TandemMod_TrailerPack1.8.1.rar.exe C:\Users\Administrator C:\Users\Gość C:\Users\HomeGroupUser$ CMD: copy "C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Preferences" C:\Users\Edyta\Desktop ***************** "C:\\PROGRA~2\\WS_X64~1.ENA" => Value Data removed successfully. 1a34a8e0 => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F6CA9D3-23CA-C4E7-FCB1-53230630309C} => Key deleted successfully. HKCR\CLSID\{2F6CA9D3-23CA-C4E7-FCB1-53230630309C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53478B71-B85D-296D-D956-CCB3B79B3C25} => Key deleted successfully. HKCR\CLSID\{53478B71-B85D-296D-D956-CCB3B79B3C25} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68D6A6AC-6CBB-DAA4-23B5-33413534A2FF} => Key deleted successfully. HKCR\CLSID\{68D6A6AC-6CBB-DAA4-23B5-33413534A2FF} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key deleted successfully. HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} => Key not found. C:\Users\Edyta\AppData\Local\Comodo => Moved successfully. C:\Users\Edyta\AppData\Local\Packages => Moved successfully. C:\Users\Edyta\AppData\Local\Torch => Moved successfully. C:\Users\Edyta\Downloads\TandemMod_TrailerPack1.8.1.rar.exe => Moved successfully. C:\Users\Administrator => Moved successfully. C:\Users\Gość => Moved successfully. C:\Users\HomeGroupUser$ => Moved successfully. ========= copy "C:\Users\Edyta\AppData\Local\Google\Chrome\User Data\Default\Preferences" C:\Users\Edyta\Desktop ========= Liczba skopiowanych plik�w: 1. ========= End of CMD: ========= ==== End of Fixlog ====