Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-05-2014 Ran by ASUS at 2014-05-22 15:03:59 Run:1 Running from C:\Users\ASUS\Desktop\adwareanty Boot Mode: Normal ============================================== Content of fixlist: ***************** (Systweak Inc) C: Program Files \ (x86) \ RegClean Pro \ RegCleanPro.exe S2 WajamUpdater; C: \ Program Files (x86) \ Wajam \ Updater \ WajamUpdater.exe [109064 2012-04-24] (Wajam) AppInit_DLLs: C: \ WINDOWS 2 \ SEARCH ~ 1 \ Datamngr \ x64 \ datamngr.dll => C : \ Program Files (x86) \ Searchcore Toolbar \ Datamngr \ x64 \ datamngr.dll [2032568 2012-06-06] (Discordia, LTD) AppInit_DLLs: C: \ PROGRA ~ 2 \ SEARCH ~ 1 \ Datamngr \ x64 \ IEBHO. dll => C: \ Program Files (x86) \ Searchcore Toolbar \ Datamngr \ x64 \ IEBHO.dll [1528760 2012-06-06] (Discordia, LTD) Zadanie: {B7BA6433-ECAD-478A-A865-5A91EA698624} - System32 \ Tasks \ RegClean Pro => C: Program Files \ (x86) \ RegClean Pro \ RegCleanPro.exe [2012-12-10] (Systweak Inc) <==== UWAGA Zadanie: {BAC5428A-A79B-4330-B6F5- FC09F0D1B8BB} - System32 \ Tasks \ {872F07B0-E760-4342-9DAF-C9CD4F0CCC84} => chrome.exe http://ui.skype.com/ui/0/6.6.0.106/pl/abandoninstall?page=tsMain Zadanie: {CDABEFDF-F810-49dB-92C8-A7C0D924E954} - system32 \ Tasks \ {3A01C73D-C39A-444E-9F93-D0703929E411} => iexplore.exe {E706D911-49D5-4886-8A53-8E5168952146} - System32 \ Tasks \ RegClean Pro_UPDATES => C: Program Files \ (x86) \ RegClean Pro \ RegCleanPro.exe [2012-12-10] (Systweak Inc) <=== = Uwaga Zadanie: {ED5213A4-DD2C-4D11-BDA1-73218F01BAEB} - System32 \ Tasks \ RegClean Pro_DEFAULT => C: \ Program Files (x86) \ RegClean Pro \ RegCleanPro.exe [2012-12-10] (Systweak Inc) <==== UWAGA Zadanie: C: \ Windows \ Tasks \ RegClean Pro_DEFAULT.job => C: \ Program Files (x86) \ RegClean Pro \ RegCleanPro.exe <==== UWAGA Zadanie: C: \ WINDOWS \ Tasks \ RegClean Pro_UPDATES.job => C: Program Files \ (x86) \ RegClean Pro \ RegCleanPro.exe <==== UWAGA HKLM \ Software \ Microsoft \ Internet Explorer \ Main, bProtector startowa = HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Backup.Old.Start strona = http://search.babylon.com/?babsrc=HP_Prot SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = HKLM-x32 - Backup.Old.DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} SearchScopes: HKLM-x32 - {7C0E241A-5F78-E361-63F4-7FE542381ECF} URL = http://dts.search-results.com / sr src = IEB & appid = 331121 & SYSTEMID = 426 & sr = 0 & q = {searchTerms}? SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = HKCU - DefaultScope {0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} URL = HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} SearchScopes: HKLM - Backup.Old.DefaultScope {0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} SearchScopes: HKLM - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {7C0E241A-5F78-E361-63F4-7FE542381ECF} URL = HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} URL = http://dts.search-results.com/sr?src=ieb&appid=331121&systemid=426&sr=0&q = {searchTerms} SearchScopes: HKCU - {E918643A-4457 -4B33-81F3-1AC6470B5F72} URL = ! HKCU - ŰźĆîZ § '2 ąŢpv ¨ IIa * X (Z2S (ŰÎŔJşÔÓµť ± ve ° × - (äĽ48Đ ¸ patm6ęo ^ Mp `Eo ÷ _iŁwľ" Au † x ˘ 8 € ŮjŔ ˙ t 'N; AA' [| † 8 S ~ ŹRŮxśňÜ8'Ł-) Xä URL = BHO: DataMngr - {7DA17D5A-5718-4130-A605-FC316C827836} - C: \ Program Files (x86) \ Searchcore Toolbar \ Datamngr \ x64 \ BrowserConnection.dll (Discordia, LTD) BHO-x32: Babylon Toolbar pomocnika - {2EECD738-5844-4a99-B4B6-146BF802613B} - Nie Plik BHO-x32: Winamp Toolbar Ładowarki - {4accc990-3dc7-4456-a734-5cb4b610a7f5} - C: \ Program Files (x86) \ Winamp Toolbar \ winamppltb.dll (AOL Inc) BHO-x32: DataMngr - {7DA17D5A-5718-4130-A605-FC316C827836} - C: \ Program Files (x86) \ Searchcore Toolbar \ Datamngr \ BrowserConnection.dll (Discordia, LTD) BHO-x32: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C: \ Program Files (x86) \ Wajam \ IE \ priam_bho.dll (Wajam) BHO-x32: Searchcore Toolbar - {af6ac4f2-9825 -4fb6-A600-92bc5361f209} - C: Program Files \ (x86) \ Searchcore Toolbar \ Datamngr \ paska narzędzi \ searchcoredtx.dll () Pasek narzędzi: HKLM-x32 - Searchcore Toolbar - {af6ac4f2-9825-a600-4fb6-92bc5361f209} - C: \ Program Files (x86) \ Searchcore Pasek narzędzi \ Datamngr \ paska narzędzi \ searchcoredtx.dll () Pasek narzędzi: HKLM-x32 - Winamp Toolbar - {a0b1221c-a3ff-4f7c-A393-dc63af5301e9} - C: \ Program Files (x86) \ Winamp Toolbar \ winamppltb.dll (AOL Inc) Pasek narzędzi: HKLM - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - Nie Plik Toolbar: HKLM - No Name - {A0B1221C-A3FF-4F7C-A393-DC63AF5301E9 } - Nie Plik Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - Nie Plik CHR HKLM \ ... \ Chrome \ Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C: \ Users \ ASUS \ AppData \ Local \ funmoods-speeddial.crx [03.07.2012] CHR HKLM \ ... \ Chrome \ Extension: [fdloijijlkoblmigdofommgnheckmaki] - C: \ Users \ ASUS \ AppData \ Local \ funmoods.crx [2012-07 - 03] CHR HKLM \ ... \ Chrome \ Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C: \ Users \ ASUS \ AppData \ Local \ funmoods-speeddial.crx [2012-07-03] CHR HKLM \ ... \ Chrome \ Extension : [fdloijijlkoblmigdofommgnheckmaki] - C: \ Users \ ASUS \ AppData \ Local \ funmoods.crx [2012-07-03] CHR-x32 HKLM \ ... \ Chrome \ Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C: \ Users \ ASUS \ AppData \ Local \ funmoods-speeddial.crx [2012-07-03] CHR HKLM-x32 \ ... \ Chrome \ Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C: \ Users \ ASUS \ AppData \ Local \ Wajam \ Chrome \ wajam. CRX [15.05.2012] CHR HKLM-x32 \ ... \ Chrome \ Extension: [pgmfkblbflahhponhjmkcnpjinenhlnc] - C: \ Users \ ASUS \ AppData \ Local \ Vid-Saver \ Chrome \ Vid-Saver.crx [2012 - 05-09] C: \ koniec C: \ Program Files Rejestr ZA stream lnk!. CMD: netsh advfirewall resetu CMD: ipconfig / flushdns Reg: reg delete HKLM \ Software \ Mozilla / f Reg: reg delete HKCU \ Software \ MozillaPlugins / f Reg: reg delete HKLM \ Software \ MozillaPlugins / f Rej : reg delete HKLM \ SOFTWARE \ Wow6432Node \ Mozilla / f Reg: reg delete HKLM \ SOFTWARE \ Wow6432Node \ mozilla.org / f Reg: reg delete HKLM \ Software \ Wow6432Node \ MozillaPlugins / f Reboot: ***************** C: Program Files \ (x86) \ RegClean Pro \ RegCleanPro.exe => No running process found WajamUpdater => Service stopped successfully. WajamUpdater => Service deleted successfully. "C: \ WINDOWS 2 \ SEARCH ~ 1 \ Datamngr \ x64 \ datamngr.dll" => Value Data not found. "C: \ PROGRA ~ 2 \ SEARCH ~ 1 \ Datamngr \ x64 \ IEBHO. dll" => Value Data not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{7C0E241A-5F78-E361-63F4-7FE542381ECF} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7C0E241A-5F78-E361-63F4-7FE542381ECF} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7C0E241A-5F78-E361-63F4-7FE542381ECF} => Key deleted successfully. HKCR\CLSID\{7C0E241A-5F78-E361-63F4-7FE542381ECF} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E918643A-4457 -4B33-81F3-1AC6470B5F72} => Key not found. HKCR\CLSID\{E918643A-4457 -4B33-81F3-1AC6470B5F72} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836} => Key deleted successfully. HKCR\CLSID\{7DA17D5A-5718-4130-A605-FC316C827836} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4accc990-3dc7-4456-a734-5cb4b610a7f5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{4accc990-3dc7-4456-a734-5cb4b610a7f5} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7DA17D5A-5718-4130-A605-FC316C827836} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{af6ac4f2-9825 -4fb6-A600-92bc5361f209} => Key not found. HKCR\Wow6432Node\CLSID\{af6ac4f2-9825 -4fb6-A600-92bc5361f209} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9 } => Value not found. HKCR\CLSID\{A0B1221C-A3FF-4F7C-A393-DC63AF5301E9 } => Key not found. HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully. HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key not found. ========= C: \ Program Files Rejestr ZA stream lnk!. netsh advfirewall resetu CMD: ipconfig / flushdns Reg: reg delete HKLM \ Software \ Mozilla / f Reg: reg delete HKCU \ Software \ MozillaPlugins / f Reg: reg delete HKLM \ Software \ MozillaPlugins / f Rej : reg delete HKLM \ SOFTWARE \ Wow6432Node \ Mozilla / f Reg: reg delete HKLM \ SOFTWARE \ Wow6432Node \ mozilla.org / f Reg: reg delete HKLM \ Software \ Wow6432Node \ MozillaPlugins / f Reboot: ========= Nazwa 'C:' nie jest rozpoznawana jako polecenie wewntrzne lub zewntrzne, program wykonywalny lub plik wsadowy. ========= End of CMD: ========= ==== End of Fixlog ====