Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-04-2014 01 Ran by Piotrek at 2014-04-19 10:24:03 Run:1 Running from E:\Chrome-pobrane Boot Mode: Safe Mode (with Networking) ============================================== Content of fixlist: ***************** S2 AntiVirSchedulerService; "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [X] S2 AntiVirService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [X] S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X] R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG) S3 AthBTPort; system32\DRIVERS\btath_flt.sys [X] S3 BTATH_A2DP; system32\drivers\btath_a2dp.sys [X] S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X] S3 BTATH_HCRP; system32\DRIVERS\btath_hcrp.sys [X] S3 BTATH_LWFLT; system32\DRIVERS\btath_lwflt.sys [X] S3 BTATH_RCP; system32\DRIVERS\btath_rcp.sys [X] S3 BtFilter; system32\DRIVERS\btfilter.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 XFDriver64; \??\C:\Program Files (x86)\Xfire2\XFDriver64.sys [X] AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.) AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://istart.webssearches.com/?type=sc&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX ShortcutWithArgument: C:\Users\Piotrek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiajÄ…cy aplikacje Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://istart.webssearches.com/?type=sc&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX ShortcutWithArgument: C:\Users\Piotrek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://istart.webssearches.com/?type=sc&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&AF=108976&babsrc=SP_ss&mntrId=3eea6d32000000000000742f68b2699a SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1395868678&from=amt&uid=HitachiXHTS547550A9E384_J2160051CR7YUDCR7YUDX&q={searchTerms} SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = http://pl.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo BHO: PrivDog Extension - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll (AdTrustMedia) CHR HKLM-x32\...\Chrome\Extension: [ijblflkdjdopkpdgllkmlbgcffjbnfda] - C:\Users\Piotrek\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-02-01] CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Piotrek\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-26] Task: {603EBF61-7E42-447E-A4CA-D3F3E5974CC4} - System32\Tasks\RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION Task: {ACDFA98B-32BC-41B2-BA57-902CFAA2A683} - System32\Tasks\{43DEDC67-20A5-4B12-B53C-3828956DBA72} => E:\Gry\POGSro\POG_SRO\Launcher.exe Task: {DE60D34B-C9B4-4B00-ADC2-EA2FE1E217B4} - System32\Tasks\{3FA2F6A8-3C62-408A-964B-EE1757D82D04} => E:\Gry\POGSro\POG_SRO\Launcher.exe C:\Program Files\AdTrustMedia C:\Program Files (x86)\AdTrustMedia C:\Program Files (x86)\Avira C:\Program Files (x86)\SupTab C:\ProgramData\Adtrustmedia C:\ProgramData\IePluginService C:\ProgramData\WPM C:\Users\Piotrek\AppData\Local\8a562295-241e-4f08-6e6b-b4bd11a3653d C:\Users\Piotrek\AppData\Roaming\ProgSense C:\Users\Piotrek\AppData\Roaming\SupTab C:\Users\Piotrek\AppData\Roaming\webssearches C:\Windows\System32\DRIVERS\avgntflt.sys C:\Windows\System32\DRIVERS\avipbb.sys C:\Windows\System32\DRIVERS\avkmgr.sys CMD: netsh winsock reset Reboot: ***************** AntiVirSchedulerService => Service deleted successfully. AntiVirService => Service deleted successfully. AntiVirWebService => Service deleted successfully. avgntflt => Service deleted successfully. avipbb => Service deleted successfully. avkmgr => Service deleted successfully. AthBTPort => Service deleted successfully. BTATH_A2DP => Service deleted successfully. BTATH_BUS => Service deleted successfully. BTATH_HCRP => Service deleted successfully. BTATH_LWFLT => Service deleted successfully. BTATH_RCP => Service deleted successfully. BtFilter => Service deleted successfully. EagleX64 => Service deleted successfully. VBoxNetFlt => Service deleted successfully. XFDriver64 => Service deleted successfully. "C:\PROGRA~2\SupTab\SEARCH~2.DLL" => Value Data removed successfully. "C:\PROGRA~2\SupTab\SEARCH~1.DLL" => Value Data removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Piotrek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Program uruchamiajÄ…cy aplikacje Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Piotrek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A} => Key deleted successfully. HKCR\CLSID\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} => Key deleted successfully. HKCR\CLSID\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ijblflkdjdopkpdgllkmlbgcffjbnfda => Key deleted successfully. C:\Users\Piotrek\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma => Key deleted successfully. C:\Users\Piotrek\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{603EBF61-7E42-447E-A4CA-D3F3E5974CC4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{603EBF61-7E42-447E-A4CA-D3F3E5974CC4} => Key deleted successfully. C:\Windows\System32\Tasks\RunAsStdUser => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ACDFA98B-32BC-41B2-BA57-902CFAA2A683} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACDFA98B-32BC-41B2-BA57-902CFAA2A683} => Key deleted successfully. C:\Windows\System32\Tasks\{43DEDC67-20A5-4B12-B53C-3828956DBA72} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{43DEDC67-20A5-4B12-B53C-3828956DBA72} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE60D34B-C9B4-4B00-ADC2-EA2FE1E217B4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE60D34B-C9B4-4B00-ADC2-EA2FE1E217B4} => Key deleted successfully. C:\Windows\System32\Tasks\{3FA2F6A8-3C62-408A-964B-EE1757D82D04} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3FA2F6A8-3C62-408A-964B-EE1757D82D04} => Key deleted successfully. C:\Program Files\AdTrustMedia => Moved successfully. C:\Program Files (x86)\AdTrustMedia => Moved successfully. C:\Program Files (x86)\Avira => Moved successfully. C:\Program Files (x86)\SupTab => Moved successfully. C:\ProgramData\Adtrustmedia => Moved successfully. C:\ProgramData\IePluginService => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\Piotrek\AppData\Local\8a562295-241e-4f08-6e6b-b4bd11a3653d => Moved successfully. C:\Users\Piotrek\AppData\Roaming\ProgSense => Moved successfully. C:\Users\Piotrek\AppData\Roaming\SupTab => Moved successfully. C:\Users\Piotrek\AppData\Roaming\webssearches => Moved successfully. C:\Windows\System32\DRIVERS\avgntflt.sys => Moved successfully. C:\Windows\System32\DRIVERS\avipbb.sys => Moved successfully. C:\Windows\System32\DRIVERS\avkmgr.sys => Moved successfully. ========= netsh winsock reset ========= Pomy˜lnie zresetowano Winsock Catalog. Musisz ponownie uruchomi† komputer, aby ukoäczy† resetowanie. ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ====