Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-10-2014 01 Ran by Kuba at 2014-10-20 23:28:41 Run:1 Running from D:\Instalki\Pliki instalacyjne Loaded Profiles: UpdatusUser & Kuba (Available profiles: UpdatusUser & Kuba) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1413816318&from=cor&uid=SAMSUNGXHM641JI_S26XJ9FB606625&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1413816318&from=cor&uid=SAMSUNGXHM641JI_S26XJ9FB606625&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1413816318&from=cor&uid=SAMSUNGXHM641JI_S26XJ9FB606625&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1413816318&from=cor&uid=SAMSUNGXHM641JI_S26XJ9FB606625&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1413816318&from=cor&uid=SAMSUNGXHM641JI_S26XJ9FB606625 BFF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.sweet-page.com/?type=sc&ts=1413816318&from=cor&uid=SAMSUNGXHM641JI_S26XJ9FB606625 CHR HomePage: Default -> hxxp://www.sweet-page.com/?type=hp&ts=1413816318&from=cor&uid=SAMSUNGXHM641JI_S26XJ9FB606625 HKLM-x32\...\Run: [] => [X] HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-21-2069368038-4120700897-3865020589-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Kuba\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKU\S-1-5-21-2069368038-4120700897-3865020589-1002\...\Policies\Explorer: [] C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\Opera C:\Program Files (x86)\SupTab C:\ProgramData\IePluginServices C:\ProgramData\WindowsMangerProtect C:\Users\Kuba\AppData\Local\Akamai C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Kuba\AppData\Local\Mozilla C:\Users\Kuba\AppData\Local\Opera Software C:\Users\Kuba\AppData\Roaming\ESET C:\Users\Kuba\AppData\Roaming\Mozilla C:\Users\Kuba\AppData\Roaming\Opera Software Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh advfirewall reset EmptyTemp: ***************** Processes closed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. Chrome HomePage deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value deleted successfully. HKU\S-1-5-21-2069368038-4120700897-3865020589-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => value deleted successfully. HKU\S-1-5-21-2069368038-4120700897-3865020589-1002\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value deleted successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\Program Files (x86)\Opera => Moved successfully. C:\Program Files (x86)\SupTab => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\WindowsMangerProtect => Moved successfully. C:\Users\Kuba\AppData\Local\Akamai => Moved successfully. C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Kuba\AppData\Local\Mozilla => Moved successfully. C:\Users\Kuba\AppData\Local\Opera Software => Moved successfully. C:\Users\Kuba\AppData\Roaming\ESET => Moved successfully. C:\Users\Kuba\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Kuba\AppData\Roaming\Opera Software => Moved successfully. ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= EmptyTemp: => Removed 1.3 GB temporary data. The system needed a reboot. ==== End of Fixlog ====