Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-02-2014 02 Ran by 8760w at 2014-02-10 10:14:56 Run:1 Running from D:\Downloads\czyszczenie\czyszczenie Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0BtAtA0Ezy0BtD0AzytBzztN0D0Tzu0CtBzyyCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1708644432 SearchScopes: HKLM - DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0BtAtA0Ezy0BtD0AzytBzztN0D0Tzu0CtBzyyCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1708644432 SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0BtAtA0Ezy0BtD0AzytBzztN0D0Tzu0CtBzyyCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1708644432 SearchScopes: HKLM-x32 - DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0BtAtA0Ezy0BtD0AzytBzztN0D0Tzu0CtBzyyCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1708644432 SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM-x32 - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0BtAtA0Ezy0BtD0AzytBzztN0D0Tzu0CtBzyyCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1708644432 SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0BtAtA0Ezy0BtD0AzytBzztN0D0Tzu0CtBzyyCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1708644432 SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0BtAtA0Ezy0BtD0AzytBzztN0D0Tzu0CtBzyyCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1708644432 SearchScopes: HKCU - {94E2C989-325D-4155-90EF-021448C11A10} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=B62F1526-CFF7-4857-B4B8-AD2793D7B3AB&apn_sauid=C7821DF8-EF2F-43E3-8378-7C25E6F38009 FF Plugin-x32: @VideoDownloadConverter_ScriptHelper.com/Plugin - C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll No File Task: {3982DB91-5C2C-40D1-A20C-8868C52CA6A8} - System32\Tasks\Plus-HD-4.9-firefoxinstaller => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-firefoxinstaller.exe [2014-01-17] (Plus HD) <==== ATTENTION Task: {4A27AF5F-81F9-469A-81BE-E8A15253B0D6} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => D:\SYSTEM~2\TEMP\{1E958434-3153-49DA-91BE-25013F70243C}.exe Task: {4ACDD268-2E59-407A-A720-169DDA45E492} - System32\Tasks\Plus-HD-4.9-codedownloader => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-codedownloader.exe <==== ATTENTION Task: {6132A639-EE34-43AA-B97E-BE2FD573C069} - System32\Tasks\{081976A8-1C50-4B31-B469-92A5EEC52D76} => H:\DOKUMENTY\MUZA\KARAOKE\van_basco204.exe Task: {8CF8C386-E681-43A1-8606-2FC8E2E25E45} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => D:\SYSTEM~2\TEMP\{4A1B796D-028E-4A7D-BB54-5E185555CFB8}.exe Task: {943AED09-168D-4AE5-A2F2-19BDF8204E74} - System32\Tasks\{CED56C0B-0191-4162-95B2-2796BBC6EC6B} => H:\DOKUMENTY\MUZA\KARAOKE\van_basco204.exe Task: {DC530CEA-E2EB-4B80-8676-E93C7DC299D2} - System32\Tasks\APSnotifierCA => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: {EADA46AB-7F8F-403F-BADF-6E9E58ED3524} - System32\Tasks\Plus-HD-4.9-chromeinstaller => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-chromeinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\APSnotifierCA.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => D:\SYSTEM~2\TEMP\{4A1B796D-028E-4A7D-BB54-5E185555CFB8}.exe Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => D:\SYSTEM~2\TEMP\{1E958434-3153-49DA-91BE-25013F70243C}.exe Task: C:\windows\Tasks\Plus-HD-4.9-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-chromeinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-4.9-codedownloader.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-codedownloader.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-4.9-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-4.9\Plus-HD-4.9-firefoxinstaller.exe <==== ATTENTION Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X] HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" HKU\S-1-5-21-613750702-59970734-1986175197-1001\...\Run: [HW_OPENEYE_OUC_blueconnect] - C:\Program Files (x86)\blueconnect\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) HKU\S-1-5-21-613750702-59970734-1986175197-1001\...\Run: [Akamai NetSession Interface] - C:\Users\8760w\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [X] S3 BlueletSCOAudio; system32\DRIVERS\BlueletSCOAudio.sys [X] S3 BT; system32\DRIVERS\btnetdrv.sys [X] S0 BTHidEnum; System32\Drivers\vbtenum.sys [X] S0 BTHidMgr; System32\Drivers\BTHidMgr.sys [X] S3 VComm; system32\DRIVERS\VComm.sys [X] S3 VcommMgr; System32\Drivers\VcommMgr.sys [X] C:\Program Files (x86)\BringStar C:\Program Files (x86)\Foxtab C:\Users\8760w\AppData\Local\AnyProtectScannerSetup.exe C:\Users\8760w\AppData\Local\funmoods-speeddial_sf.crx C:\Users\8760w\AppData\Local\funmoods.crx C:\Users\8760w\AppData\Roaming\systweak C:\Users\8760w\AppData\Roaming\Temp C:\windows\System32\Tasks\{CEFA8D50-85F4-4DFD-9CA1-05E77DB63DBF} Reg: reg export "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec" C:\MyFreeCodec.reg ***************** HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => Key deleted successfully. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key deleted successfully. HKCR\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => Key deleted successfully. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{94E2C989-325D-4155-90EF-021448C11A10} => Key deleted successfully. HKCR\CLSID\{94E2C989-325D-4155-90EF-021448C11A10} => Key not found. HKLM\Software\Wow6432Node\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin => Key deleted successfully. C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3982DB91-5C2C-40D1-A20C-8868C52CA6A8} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3982DB91-5C2C-40D1-A20C-8868C52CA6A8} => Key deleted successfully. C:\Windows\System32\Tasks\Plus-HD-4.9-firefoxinstaller => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-4.9-firefoxinstaller => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4A27AF5F-81F9-469A-81BE-E8A15253B0D6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A27AF5F-81F9-469A-81BE-E8A15253B0D6} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4ACDD268-2E59-407A-A720-169DDA45E492} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4ACDD268-2E59-407A-A720-169DDA45E492} => Key deleted successfully. C:\Windows\System32\Tasks\Plus-HD-4.9-codedownloader => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-4.9-codedownloader => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6132A639-EE34-43AA-B97E-BE2FD573C069} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6132A639-EE34-43AA-B97E-BE2FD573C069} => Key deleted successfully. C:\Windows\System32\Tasks\{081976A8-1C50-4B31-B469-92A5EEC52D76} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{081976A8-1C50-4B31-B469-92A5EEC52D76} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8CF8C386-E681-43A1-8606-2FC8E2E25E45} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CF8C386-E681-43A1-8606-2FC8E2E25E45} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{943AED09-168D-4AE5-A2F2-19BDF8204E74} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{943AED09-168D-4AE5-A2F2-19BDF8204E74} => Key deleted successfully. C:\Windows\System32\Tasks\{CED56C0B-0191-4162-95B2-2796BBC6EC6B} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CED56C0B-0191-4162-95B2-2796BBC6EC6B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DC530CEA-E2EB-4B80-8676-E93C7DC299D2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC530CEA-E2EB-4B80-8676-E93C7DC299D2} => Key deleted successfully. C:\Windows\System32\Tasks\APSnotifierCA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierCA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EADA46AB-7F8F-403F-BADF-6E9E58ED3524} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EADA46AB-7F8F-403F-BADF-6E9E58ED3524} => Key deleted successfully. C:\Windows\System32\Tasks\Plus-HD-4.9-chromeinstaller => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-4.9-chromeinstaller => Key deleted successfully. C:\windows\Tasks\APSnotifierCA.job => Moved successfully. C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully. C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\windows\Tasks\Plus-HD-4.9-chromeinstaller.job => Moved successfully. C:\windows\Tasks\Plus-HD-4.9-codedownloader.job => Moved successfully. C:\windows\Tasks\Plus-HD-4.9-firefoxinstaller.job => Moved successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\APSDaemon => Value deleted successfully. HKU\S-1-5-21-613750702-59970734-1986175197-1001\Software\Microsoft\Windows\CurrentVersion\Run\\HW_OPENEYE_OUC_blueconnect => Value deleted successfully. HKU\S-1-5-21-613750702-59970734-1986175197-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => Value deleted successfully. BlueletAudio => Service deleted successfully. BlueletSCOAudio => Service deleted successfully. BT => Service deleted successfully. BTHidEnum => Service deleted successfully. BTHidMgr => Service deleted successfully. VComm => Service deleted successfully. VcommMgr => Service deleted successfully. C:\Program Files (x86)\BringStar => Moved successfully. C:\Program Files (x86)\Foxtab => Moved successfully. C:\Users\8760w\AppData\Local\AnyProtectScannerSetup.exe => Moved successfully. C:\Users\8760w\AppData\Local\funmoods-speeddial_sf.crx => Moved successfully. C:\Users\8760w\AppData\Local\funmoods.crx => Moved successfully. C:\Users\8760w\AppData\Roaming\systweak => Moved successfully. C:\Users\8760w\AppData\Roaming\Temp => Moved successfully. C:\windows\System32\Tasks\{CEFA8D50-85F4-4DFD-9CA1-05E77DB63DBF} => Moved successfully. ========= reg export "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec" C:\MyFreeCodec.reg ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====