Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-09-2014 Ran by Administrator at 2014-09-13 04:43:29 Run:1 Running from C:\Documents and Settings\Administrator\Pulpit Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-09-06] (globalUpdate) [File not signed] S2 IePluginServices; C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices\PluginService.exe [715656 2014-09-02] (Cherished Technololgy LIMITED) S2 Update innoApp; "C:\Program Files\innoApp\updateinnoApp.exe" [X] S2 Util innoApp; "C:\Program Files\innoApp\bin\utilinnoApp.exe" [X] R1 {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t; C:\WINDOWS\System32\drivers\{3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t.sys [55096 2014-09-06] (StdLib) S3 catchme; \??\C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\catchme.sys [X] HKLM\...99B7938DA9E4}\LocalServer32: [Default-wmiprvse] <==== ATTENTION! Task: C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-1.job => C:\Program Files\TheHDvid-Codec V10\TheHDvid-Codec V10-codedownloader.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-11.job => C:\Program Files\TheHDvid-Codec V10\af2b85a3-771c-43ef-84ac-f4e258b85f62-11.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-2.job => C:\Program Files\TheHDvid-Codec V10\af2b85a3-771c-43ef-84ac-f4e258b85f62-2.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-5.job => C:\Program Files\TheHDvid-Codec V10\af2b85a3-771c-43ef-84ac-f4e258b85f62-5.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409657388&from=ild&uid=ST3160815AS_6RX7VYXG&q={searchTerms} BHO: TheHDvid-Codec V10 -> {11111111-1111-1111-1111-110611331115} -> C:\Program Files\TheHDvid-Codec V10\TheHDvid-Codec V10-bho.dll (home) CHR HKLM\...\Chrome\Extension: [fohlobpjdcjjcnpdpfjcdfofgkoaemjc] - C:\Documents and Settings\Administrator\Dane aplikacji\Chrome_manager\src.crx [2012-09-11] CHR HKLM\...\Chrome\Extension: [gbdabnfmdemcjjadpkpjibhhacggangd] - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\novo_price_comparison.crx [2012-09-11] CHR HKLM\...\Chrome\Extension: [ijblflkdjdopkpdgllkmlbgcffjbnfda] - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx [2012-09-11] CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12] CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-09-02] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" C:\feeddl.dat C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla C:\Documents and Settings\Administrator\Dane aplikacji\support@mozilla.com C:\Documents and Settings\Administrator\Dane aplikacji\VOPackage C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent\uTorrent*.exe C:\Documents and Settings\Administrator\Menu Start\Programy\LSHunter.TV C:\Documents and Settings\Administrator\Menu Start\Programy\VOPackage C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\globalUpdate C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\TheFreeHD-Sport TV V10 C:\Documents and Settings\All Users\Dane aplikacji\*.dat C:\Documents and Settings\All Users\Dane aplikacji\eSafe C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices C:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect C:\Program Files\globalUpdate C:\Program Files\innoApp C:\Program Files\LSHunter.TV C:\Program Files\Mozilla Firefox C:\Program Files\predm C:\Program Files\sizlsearch C:\Program Files\TheHDvid-Codec V10 C:\Program Files\QuickTime\qttask*.exe c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension C:\WINDOWS\system32\Drivers\{3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t.sys C:\Windows\Tasks\*.job Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheHDvid-Codec V10" /f Reg: reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Mozilla /f Reg: reg delete HKLM\SOFTWARE\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f EmptyTemp: ***************** Processes closed successfully. globalUpdatem => Service deleted successfully. IePluginServices => Service stopped successfully. IePluginServices => Service deleted successfully. Update innoApp => Service deleted successfully. Util innoApp => Service deleted successfully. {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t => Unable to stop service {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t => Service deleted successfully. catchme => Service deleted successfully. HKLM\Software\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\\Default => Value was restored successfully. C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-1.job => Moved successfully. C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-11.job => Moved successfully. C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-2.job => Moved successfully. C:\WINDOWS\Tasks\af2b85a3-771c-43ef-84ac-f4e258b85f62-5.job => Moved successfully. C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully. C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611331115}" => Key deleted successfully. "HKCR\CLSID\{11111111-1111-1111-1111-110611331115}" => Key deleted successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\fohlobpjdcjjcnpdpfjcdfofgkoaemjc" => Key deleted successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Chrome_manager\src.crx => Moved successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\gbdabnfmdemcjjadpkpjibhhacggangd" => Key deleted successfully. "C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\novo_price_comparison.crx" => File/Directory not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\ijblflkdjdopkpdgllkmlbgcffjbnfda" => Key deleted successfully. "C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtab.crx" => File/Directory not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\nneajnkjbffgblleaoojgaacokifdkhm" => Key deleted successfully. C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx => Moved successfully. "HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma" => Key deleted successfully. C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\newtabv3.crx => Moved successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys" => Key deleted successfully. C:\feeddl.dat => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\support@mozilla.com => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\VOPackage => Moved successfully. C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent\uTorrent*.exe => Moved successfully. C:\Documents and Settings\Administrator\Menu Start\Programy\LSHunter.TV => Moved successfully. C:\Documents and Settings\Administrator\Menu Start\Programy\VOPackage => Moved successfully. C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\globalUpdate => Moved successfully. C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\TheFreeHD-Sport TV V10 => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\*.dat => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\eSafe => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\IePluginServices => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\WindowsMangerProtect => Moved successfully. C:\Program Files\globalUpdate => Moved successfully. "C:\Program Files\innoApp" => File/Directory not found. C:\Program Files\LSHunter.TV => Moved successfully. C:\Program Files\Mozilla Firefox => Moved successfully. "C:\Program Files\predm" => File/Directory not found. "C:\Program Files\sizlsearch" => File/Directory not found. C:\Program Files\TheHDvid-Codec V10 => Moved successfully. C:\Program Files\QuickTime\qttask*.exe => Moved successfully. c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. C:\WINDOWS\system32\Drivers\{3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}t.sys => Moved successfully. C:\Windows\Tasks\*.job => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheHDvid-Codec V10" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Mozilla /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\mozilla.org /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= EmptyTemp: => Removed 4.2 GB temporary data. The system needed a reboot. ==== End of Fixlog ====