Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 10-02-2014 Ran by Ja at 2014-02-10 22:17:18 Run:1 Running from C:\Documents and Settings\Ja\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\Documents and Settings\All Users\Dane aplikacji\WPM\wprotectmanager.exe () C:\Program Files\SecretSauce\updateSecretSauce.exe () C:\Program Files\SecretSauce\bin\utilSecretSauce.exe Task: C:\WINDOWS\Tasks\At1.job => C:\DOCUME~1\Ja\DANEAP~1\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION S2 savesenselive; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-02-06] (SaveSense) S3 savesenselivem; C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-02-06] (SaveSense) R2 Update SecretSauce; C:\Program Files\SecretSauce\updateSecretSauce.exe [80160 2014-02-05] () R2 Util SecretSauce; C:\Program Files\SecretSauce\bin\utilSecretSauce.exe [80160 2014-02-05] () R2 Wpm; C:\Documents and Settings\All Users\Dane aplikacji\WPM\wprotectmanager.exe [499856 2013-12-28] (Cherished Technololgy LIMITED) S4 SkypeUpdate; "C:\Program Files\Skype\Updater\Updater.exe" [X] S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [X] S3 vtany; \??\C:\WINDOWS\vtany.sys [X] S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X] HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Run: [4StoryPrePatch] - E:\4Story_PL\PrePatch.exe HKU\S-1-5-21-343818398-1708537768-1801674531-1003\...\Run: [Spol] - http://www.toya.net.pl/~spol/site/index.htm HKU\S-1-5-21-343818398-1708537768-1801674531-1003\...\Run: [NextLive] - C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Ja\Dane aplikacji\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-343818398-1708537768-1801674531-1003\...\Run: [EADM] - "D:\Origin\Origin.exe" -AutoStart HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aartemis.com/?type=hp&ts=1388240093&from=cor&uid=WDCXWD800BB-00FRA0_WD-WCAJD1279037 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://aartemis.com/?type=hp&ts=1388240093&from=cor&uid=WDCXWD800BB-00FRA0_WD-WCAJD1279037 SearchScopes: HKLM - DefaultScope value is missing. BHO: SaveSense - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\SaveSense\SaveSenseIE.dll (SaveSense) CHR HKLM\...\Chrome\Extension: [dbpebffoameokfhnaaedmefjncfboino] - C:\Program Files\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx [2014-02-10] CHR HKCU\...\Chrome\Extension: [iibmmjhgclhlahmjniokmhleigemjpbh] - C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\CRE\iibmmjhgclhlahmjniokmhleigemjpbh.crx [2014-02-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION C:\Program Files\Mobogenie C:\Documents and Settings\Ja\Dane aplikacji\DownLite C:\Documents and Settings\Ja\Dane aplikacji\newnext.me C:\Documents and Settings\Ja\Dane aplikacji\Mozilla C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\CRE C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\genienext C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Mobogenie Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** [1740] C:\Documents and Settings\All Users\Dane aplikacji\WPM\wprotectmanager.exe => Process closed successfully. [2288] C:\Program Files\SecretSauce\updateSecretSauce.exe => Process closed successfully. C:\Program Files\SecretSauce\bin\utilSecretSauce.exe => No running process found C:\WINDOWS\Tasks\At1.job => Moved successfully. C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => Moved successfully. C:\WINDOWS\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => Moved successfully. savesenselive => Service deleted successfully. savesenselivem => Service deleted successfully. Update SecretSauce => Service deleted successfully. Util SecretSauce => Service deleted successfully. Wpm => Service deleted successfully. SkypeUpdate => Service deleted successfully. EagleXNt => Service deleted successfully. vtany => Service deleted successfully. xhunter1 => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\4StoryPrePatch => Value deleted successfully. HKU\S-1-5-21-343818398-1708537768-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\Spol => Value deleted successfully. HKU\S-1-5-21-343818398-1708537768-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKU\S-1-5-21-343818398-1708537768-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Run\\EADM => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99} => Key deleted successfully. HKCR\CLSID\{71e129ff-6c2a-4984-818c-7e2c998b8d99} => Key deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\dbpebffoameokfhnaaedmefjncfboino => Key deleted successfully. C:\Program Files\SecretSauce\dbpebffoameokfhnaaedmefjncfboino.crx => Moved successfully. HKCU\SOFTWARE\Google\Chrome\Extensions\iibmmjhgclhlahmjniokmhleigemjpbh => Key deleted successfully. "C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\CRE\iibmmjhgclhlahmjniokmhleigemjpbh.crx" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Documents and Settings\Ja\Dane aplikacji\DownLite => Moved successfully. C:\Documents and Settings\Ja\Dane aplikacji\newnext.me => Moved successfully. C:\Documents and Settings\Ja\Dane aplikacji\Mozilla => Moved successfully. "C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\CRE" => File/Directory not found. C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\genienext => Moved successfully. C:\Documents and Settings\Ja\Ustawienia lokalne\Dane aplikacji\Mobogenie => Moved successfully. ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= The system needs a manual reboot. ==== End of Fixlog ====