Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 30-04-2014 01 Ran by Ewa at 2014-04-30 15:11:43 Run:1 Running from C:\Users\Ewa\Desktop\pobierane Boot Mode: Normal ============================================== Content of fixlist: ***************** SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID=121845&babsrc=SP_ss&mntrId=A6CDD85D4C90965F Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File FF user.js: detected! => C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\d51b2sku.default\user.js FF SearchPlugin: C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\d51b2sku.default\searchplugins\delta.xml FF NetworkProxy: "type", 0 C:\Program Files (x86)\mozilla firefox\plugins C:\Users\Ewa\AppData\Roaming\Babylon Task: {4ECD52EF-4B89-406E-AC00-D15C2281ED27} - \{57E79126-84DD-43B6-B9A6-0DF1629C531B} No Task File <==== ATTENTION Task: {A241B6B2-42F7-4145-8226-AD4AA1142AD7} - \{392F9F59-8EF7-4EEE-BD9C-6D29E518BE69} No Task File <==== ATTENTION Task: {A76B6B3A-972C-4CC9-8A4E-AF631DDD0E12} - \{89ACDF50-9411-4E44-8339-4B28A78B1F92} No Task File <==== ATTENTION Task: {C2D89BB7-8475-48DD-8E59-33E1829B51FA} - \{395DF40E-BE0E-4D63-B4A7-5B87AA6C146E} No Task File <==== ATTENTION Task: {C92C6C91-1EF1-40D7-AB60-5D3BCD20D672} - \{98EB835F-27EE-4EB1-9921-D33925EF12A2} No Task File <==== ATTENTION Task: {D0470C7F-F1D8-415F-AEA3-C8655CA59B88} - \{1DD70685-AE09-4770-9BBE-A219ED106486} No Task File <==== ATTENTION Task: {D4721F6E-4838-4173-A1F1-E938F8693CBD} - \{F0511430-DC08-4500-92FC-CBEEF50C0EBB} No Task File <==== ATTENTION Task: {EEF6D477-03D3-4183-B2D4-2D85607FEB68} - System32\Tasks\PCConfidential => C:\Program Files (x86)\Winferno\PC Confidential\PCConfidential.exe Task: {F75F3293-EB66-4E93-9343-5C405FE29086} - \{872563AF-BC31-4EC0-972F-4D91DE6FADC9} No Task File <==== ATTENTION Task: {FA60F3CD-E527-4A4F-BA78-5C7553D5B159} - \{63D73128-0BA2-4980-80BE-14A474434505} No Task File <==== ATTENTION Task: C:\Windows\Tasks\PCConfidential.job => C:\Program Files (x86)\Winferno\PC Confidential\PCConfidential.exe HKLM-x32\...\Run: [NPSStartup] => [X] ***************** HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\d51b2sku.default\user.js => Moved successfully. C:\Users\Ewa\AppData\Roaming\Mozilla\Firefox\Profiles\d51b2sku.default\searchplugins\delta.xml => Moved successfully. Firefox Proxy settings were reset. C:\Program Files (x86)\Mozilla Firefox\plugins => Moved successfully. C:\Users\Ewa\AppData\Roaming\Babylon => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4ECD52EF-4B89-406E-AC00-D15C2281ED27} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4ECD52EF-4B89-406E-AC00-D15C2281ED27} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{57E79126-84DD-43B6-B9A6-0DF1629C531B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A241B6B2-42F7-4145-8226-AD4AA1142AD7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A241B6B2-42F7-4145-8226-AD4AA1142AD7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{392F9F59-8EF7-4EEE-BD9C-6D29E518BE69} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A76B6B3A-972C-4CC9-8A4E-AF631DDD0E12} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A76B6B3A-972C-4CC9-8A4E-AF631DDD0E12} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{89ACDF50-9411-4E44-8339-4B28A78B1F92} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C2D89BB7-8475-48DD-8E59-33E1829B51FA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2D89BB7-8475-48DD-8E59-33E1829B51FA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{395DF40E-BE0E-4D63-B4A7-5B87AA6C146E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C92C6C91-1EF1-40D7-AB60-5D3BCD20D672} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C92C6C91-1EF1-40D7-AB60-5D3BCD20D672} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{98EB835F-27EE-4EB1-9921-D33925EF12A2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D0470C7F-F1D8-415F-AEA3-C8655CA59B88} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0470C7F-F1D8-415F-AEA3-C8655CA59B88} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1DD70685-AE09-4770-9BBE-A219ED106486} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D4721F6E-4838-4173-A1F1-E938F8693CBD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4721F6E-4838-4173-A1F1-E938F8693CBD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F0511430-DC08-4500-92FC-CBEEF50C0EBB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EEF6D477-03D3-4183-B2D4-2D85607FEB68} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEF6D477-03D3-4183-B2D4-2D85607FEB68} => Key deleted successfully. C:\Windows\System32\Tasks\PCConfidential => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCConfidential => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F75F3293-EB66-4E93-9343-5C405FE29086} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F75F3293-EB66-4E93-9343-5C405FE29086} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{872563AF-BC31-4EC0-972F-4D91DE6FADC9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA60F3CD-E527-4A4F-BA78-5C7553D5B159} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA60F3CD-E527-4A4F-BA78-5C7553D5B159} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{63D73128-0BA2-4980-80BE-14A474434505} => Key deleted successfully. C:\Windows\Tasks\PCConfidential.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => Value deleted successfully. ==== End of Fixlog ====