Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:05-07-2014 01 Ran by Pc at 2014-07-08 20:58:43 Run:1 Running from G:\Narzedzia\Diagnostyka dla Picasso\FIRST Boot Mode: Normal ============================================== Content of fixlist: ***************** () G:\Documents and Settings\Pc\Ustawienia lokalne\Dane aplikacji\fst_pl_6\upfst_pl_6.exe () G:\Program Files\ScanTack\bin\utilScanTack.exe () G:\Program Files\ScanTack\bin\ScanTack.PurBrowse.exe () G:\Program Files\ScanTack\updateScanTack.exe () G:\Program Files\ScanTack\bin\ScanTack.BrowserAdapter.exe S2 globalUpdate; G:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-06-19] (globalUpdate) [File not signed] S3 globalUpdatem; G:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-06-19] (globalUpdate) [File not signed] R2 Update ScanTack; G:\Program Files\ScanTack\updateScanTack.exe [318752 2014-07-06] () R2 Util ScanTack; G:\Program Files\ScanTack\bin\utilScanTack.exe [318752 2014-07-06] () R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}t; G:\WINDOWS\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}t.sys [55224 2014-04-24] (StdLib) S3 gdrv; \??\G:\WINDOWS\gdrv.sys [X] HKLM\...\Run: [upfst_pl_6.exe] => G:\Documents and Settings\Pc\Ustawienia lokalne\Dane aplikacji\fst_pl_6\upfst_pl_6.exe [3154416 2013-11-12] () HKU\S-1-5-21-1275210071-117609710-839522115-1003\...\Run: [NextLive] => G:\WINDOWS\system32\rundll32.exe "G:\Documents and Settings\Pc\Dane aplikacji\newnext.me\nengine.dll",EntryPoint -m l Task: G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-1.job => G:\Program Files\Torntv V9.0\Torntv V9.0-codedownloader.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-11.job => G:\Program Files\Torntv V9.0\7e291e36-3b2c-4996-b476-f6e204f59931-11.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-2.job => G:\Program Files\Torntv V9.0\7e291e36-3b2c-4996-b476-f6e204f59931-2.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-4.job => G:\Program Files\Torntv V9.0\7e291e36-3b2c-4996-b476-f6e204f59931-4.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-5.job => G:\Program Files\Torntv V9.0\7e291e36-3b2c-4996-b476-f6e204f59931-5.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-6.job => G:\Program Files\Torntv V9.0\Torntv V9.0-novainstaller.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-7.job => G:\Program Files\Torntv V9.0\Torntv V9.0-nova.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\bench-sys.job => G:\Program Files\Bench\Updater\updater.exe <==== ATTENTION Task: G:\WINDOWS\Tasks\bench-Updater removing.job => ? <==== ATTENTION Task: G:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => G:\Program Files\globalUpdate\Update\GoogleUpdate.exe Task: G:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => G:\Program Files\globalUpdate\Update\GoogleUpdate.exe ShortcutWithArgument: G:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk -> G:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk -> G:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk -> G:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome\Google Chrome.lnk -> G:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\Pc\Pulpit\Internet Explorer.lnk -> G:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\Pc\Menu Start\Programy\Internet Explorer.lnk -> G:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\Pc\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Internet Explorer (bez dodatków).lnk -> G:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\Pc\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> G:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\Pc\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> G:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E ShortcutWithArgument: G:\Documents and Settings\Pc\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Uruchom przeglądarkę Internet Explorer.lnk -> G:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.aartemis.com/web/?type=ds&ts=1387057061&from=cor&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.aartemis.com/web/?type=ds&ts=1387057061&from=cor&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E StartMenuInternet: IEXPLORE.EXE - G:\Program Files\Internet Explorer\iexplore.exe http://aartemis.com/?type=sc&ts=1387057061&from=cor&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E&q={searchTerms} FF Plugin: @staging.google.com/globalUpdate Update;version=10 - G:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin: @staging.google.com/globalUpdate Update;version=4 - G:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin HKCU: BearSharePlugin - G:\Program Files\BearShare Applications\BearShare\npBearSharePlugin.dll (BearShare) FF SearchPlugin: G:\Program Files\mozilla firefox\browser\searchplugins\omiga-plus.xml FF HKLM\...\Firefox\Extensions: [faststartff@gmail.com] - G:\Documents and Settings\Pc\Dane aplikacji\Mozilla\Firefox\Profiles\oiw712qh.default\extensions\faststartff@gmail.com GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR StartMenuInternet: Google Chrome - G:\Program Files\Google\Chrome\Application\chrome.exe http://isearch.omiga-plus.com/?type=sc&ts=1403191939&from=ild&uid=ST500DM002-1BD142_S2AH3K6EXXXXS2AH3K6E G:\Documents and Settings\All Users\Dane aplikacji\2E2FD G:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive G:\Documents and Settings\All Users\Dane aplikacji\TEMP G:\Documents and Settings\Pc\Dane aplikacji\aartemis G:\Documents and Settings\Pc\Dane aplikacji\newnext.me G:\Documents and Settings\Pc\Dane aplikacji\systweak G:\Documents and Settings\Pc\Ustawienia lokalne\Dane aplikacji\globalUpdate G:\Program Files\globalUpdate G:\WINDOWS\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}t.sys G:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup Reg: reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\G:^Documents and Settings^All Users^Menu Start^Programy^Autostart^McAfee Security Scan Plus.lnk" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_19" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_73" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_99" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSC" /f Reboot: ***************** G:\Documents and Settings\Pc\Ustawienia lokalne\Dane aplikacji\fst_pl_6\upfst_pl_6.exe => No running process found G:\Program Files\ScanTack\bin\utilScanTack.exe => No running process found G:\Program Files\ScanTack\bin\ScanTack.PurBrowse.exe => No running process found G:\Program Files\ScanTack\updateScanTack.exe => No running process found G:\Program Files\ScanTack\bin\ScanTack.BrowserAdapter.exe => No running process found globalUpdate => Service deleted successfully. globalUpdatem => Service deleted successfully. Update ScanTack => Unable to stop service Update ScanTack => Service deleted successfully. Util ScanTack => Unable to stop service Util ScanTack => Service deleted successfully. {9acd1534-e8f8-40cb-b5ac-4996fe01175b}t => Unable to stop service {9acd1534-e8f8-40cb-b5ac-4996fe01175b}t => Service deleted successfully. gdrv => Service deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\upfst_pl_6.exe => value deleted successfully. HKU\S-1-5-21-1275210071-117609710-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => value deleted successfully. G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-1.job => Moved successfully. G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-11.job => Moved successfully. G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-2.job => Moved successfully. G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-4.job => Moved successfully. G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-5.job => Moved successfully. G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-6.job => Moved successfully. G:\WINDOWS\Tasks\7e291e36-3b2c-4996-b476-f6e204f59931-7.job => Moved successfully. G:\WINDOWS\Tasks\bench-sys.job => Moved successfully. G:\WINDOWS\Tasks\bench-Updater removing.job => Moved successfully. G:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully. G:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully. G:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\Pc\Pulpit\Internet Explorer.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\Pc\Menu Start\Programy\Internet Explorer.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\Pc\Menu Start\Programy\Akcesoria\Narzędzia systemowe\Internet Explorer (bez dodatków).lnk => Shortcut argument was restored successfully. G:\Documents and Settings\Pc\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\Pc\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk => Shortcut argument was removed successfully. G:\Documents and Settings\Pc\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Uruchom przeglądarkę Internet Explorer.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10' => Key deleted successfully. G:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll => Moved successfully. 'HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4' => Key deleted successfully. G:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll not found. 'HKCU\Software\MozillaPlugins\BearSharePlugin' => Key deleted successfully. G:\Program Files\BearShare Applications\BearShare\npBearSharePlugin.dll => Moved successfully. G:\Program Files\mozilla firefox\browser\searchplugins\omiga-plus.xml => Moved successfully. HKLM\Software\Mozilla\Firefox\Extensions\\faststartff@gmail.com => value deleted successfully. G:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully. G:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully. 'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. "G:\Documents and Settings\All Users\Dane aplikacji\2E2FD" => File/Directory not found. G:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive => Moved successfully. G:\Documents and Settings\All Users\Dane aplikacji\TEMP => Moved successfully. G:\Documents and Settings\Pc\Dane aplikacji\aartemis => Moved successfully. G:\Documents and Settings\Pc\Dane aplikacji\newnext.me => Moved successfully. G:\Documents and Settings\Pc\Dane aplikacji\systweak => Moved successfully. G:\Documents and Settings\Pc\Ustawienia lokalne\Dane aplikacji\globalUpdate => Moved successfully. G:\Program Files\globalUpdate => Moved successfully. G:\WINDOWS\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}t.sys => Moved successfully. G:\WINDOWS\pss\McAfee Security Scan Plus.lnkCommon Startup => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Search" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\G:^Documents and Settings^All Users^Menu Start^Programy^Autostart^McAfee Security Scan Plus.lnk" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_19" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_73" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_99" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSC" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====