Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-10-2014 Ran by Tomek at 2014-10-30 11:40:43 Run:2 Running from C:\Users\Tomek\Desktop Loaded Profile: Tomek (Available profiles: Tomek) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: R2 MaintainerSvc2.04.9173792; C:\ProgramData\0fd8dc4b-3fdb-4d7c-a6d4-ff64cff56cc4\maintainer.exe [123680 2014-10-29] () AppInit_DLLs: c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll => c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll File Not Found Task: {09F1EAB7-AFD0-4ED8-9AB8-F7B246116262} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: {A76AF9F4-4BFA-474D-9594-CB9760134E73} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: {D7AE03D5-6A10-4EE5-BBD0-859BA5480AF8} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe CHR Extension: (SweetPacks Chrome Extension) - C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-10-05] SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File C:\Program Files (x86)\NetCrawl C:\Program Files (x86)\Opera C:\ProgramData\0fd8dc4b-3fdb-4d7c-a6d4-ff64cff56cc4 C:\ProgramData\Adobe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Codec Pack C:\Users\Tomek\AppData\Local\Opera C:\Users\Tomek\AppData\Roaming\Opera C:\Users\Tomek\AppData\Roaming\xplugin C:\Windows\SysWOW64\FlashPlayerUpdateService.exe C:\Windows\SysWOW64\Macromed Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\1778669968.portal.qtrax.com /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Tomek\AppData\Local CMD: dir /a C:\Users\Tomek\AppData\LocalLow CMD: dir /a C:\Users\Tomek\AppData\Roaming EmptyTemp: ***************** Processes closed successfully. MaintainerSvc2.04.9173792 => Service deleted successfully. "c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll" => Value Data removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{09F1EAB7-AFD0-4ED8-9AB8-F7B246116262}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09F1EAB7-AFD0-4ED8-9AB8-F7B246116262}" => Key deleted successfully. C:\Windows\System32\Tasks\Adobe Flash Player Updater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A76AF9F4-4BFA-474D-9594-CB9760134E73}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A76AF9F4-4BFA-474D-9594-CB9760134E73}" => Key deleted successfully. C:\Windows\System32\Tasks\AdobeFlashPlayerUpdate => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D7AE03D5-6A10-4EE5-BBD0-859BA5480AF8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7AE03D5-6A10-4EE5-BBD0-859BA5480AF8}" => Key deleted successfully. C:\Windows\System32\Tasks\AdobeFlashPlayerUpdate 2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2" => Key deleted successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully. C:\Users\Tomek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj => Moved successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. "HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. "HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => Key not found. C:\Program Files (x86)\NetCrawl => Moved successfully. C:\Program Files (x86)\Opera => Moved successfully. C:\ProgramData\0fd8dc4b-3fdb-4d7c-a6d4-ff64cff56cc4 => Moved successfully. C:\ProgramData\Adobe => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Codec Pack => Moved successfully. C:\Users\Tomek\AppData\Local\Opera => Moved successfully. C:\Users\Tomek\AppData\Roaming\Opera => Moved successfully. C:\Users\Tomek\AppData\Roaming\xplugin => Moved successfully. C:\Windows\SysWOW64\FlashPlayerUpdateService.exe => Moved successfully. C:\Windows\SysWOW64\Macromed => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\1778669968.portal.qtrax.com /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a "C:\Program Files" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 269C-496B Katalog: C:\Program Files 2014-10-29 15:12 . 2014-10-29 15:12 .. 2012-03-01 12:55 Autodesk 2014-10-24 21:52 CCleaner 2012-03-01 12:52 Common Files 2011-09-28 10:30 CONEXANT 2009-07-14 05:54 174 desktop.ini 2011-09-28 10:33 DIFX 2009-07-14 19:09 DVD Maker 2014-10-29 15:16 Google 2009-07-14 18:55 Internet Explorer 2011-09-28 10:46 Lenovo 2009-07-14 19:09 Microsoft Games 2013-10-14 13:36 MPC-HC 2009-07-14 06:32 MSBuild 2009-07-14 06:32 Reference Assemblies 2011-09-28 10:32 Synaptics 2009-07-14 06:09 Uninstall Information 2009-07-14 18:55 Windows Defender 2009-07-14 19:09 Windows Journal 2009-07-14 18:55 Windows Mail 2009-07-14 18:55 Windows Media Player 2011-09-28 10:22 Windows NT 2009-07-14 18:55 Windows Photo Viewer 2009-07-14 06:32 Windows Portable Devices 2009-07-14 18:55 Windows Sidebar 1 plik(¢w) 174 bajt¢w 25 katalog(¢w) 30ÿ026ÿ108ÿ928 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 269C-496B Katalog: C:\Program Files (x86) 2014-10-30 11:41 . 2014-10-30 11:41 .. 2013-04-03 11:08 Ahead 2013-08-02 20:43 ALDITALKVerbindungsassistent 2012-11-22 10:19 ALLMediaServer 2012-11-22 10:18 ALLPlayer 2011-09-28 10:31 Atheros 2012-03-01 12:48 Autodesk 2011-09-28 10:31 BisonCam 2013-04-23 17:13 Common Files 2012-01-19 18:09 CyberLink 2009-07-14 05:54 174 desktop.ini 2014-10-29 15:16 Google 2014-04-10 19:38 InstallJammer Registry 2011-12-12 13:40 InstallShield Installation Information 2011-09-28 10:29 Intel 2009-07-14 18:55 Internet Explorer 2011-11-01 16:45 IrfanView 2011-09-28 10:33 Lenovo 2012-11-14 18:29 Microsoft Silverlight 2012-03-01 12:31 Microsoft.NET 2009-07-14 06:32 MSBuild 2011-10-04 18:09 NAPI-PROJEKT 2012-04-01 16:07 NapiProjekt 2013-04-23 17:13 Nero 2012-11-21 15:09 OpenOffice.org 3 2011-09-28 10:32 Realtek 2009-07-14 06:32 Reference Assemblies 2013-01-01 15:42 RMVB Converter 2013-01-01 15:47 RMVB Player 2014-04-25 22:09 S.P.D 2012-01-21 00:08 Skype 2014-04-10 19:35 Soldis PROJEKTANT 2013-01-15 19:56 Tetris 2014-09-29 15:52 TomTom International B.V 2009-07-14 05:57 Uninstall Information 2011-09-28 10:31 USB Camera2 2014-04-25 22:10 VirtualDJ 2011-10-04 18:12 Winamp 2011-10-04 18:12 Winamp Detect 2009-07-14 18:55 Windows Defender 2009-07-14 18:55 Windows Mail 2009-07-14 18:55 Windows Media Player 2009-07-14 06:32 Windows NT 2009-07-14 18:55 Windows Photo Viewer 2009-07-14 06:32 Windows Portable Devices 2009-07-14 18:55 Windows Sidebar 2011-10-11 10:29 WinRAR 2011-10-10 19:02 XviD 1 plik(¢w) 174 bajt¢w 48 katalog(¢w) 30ÿ026ÿ104ÿ832 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 269C-496B Katalog: C:\ProgramData 2014-10-30 11:41 . 2014-10-30 11:41 .. 2009-07-14 06:08 Application Data [C:\ProgramData] 2011-09-28 10:31 Atheros 2012-03-06 10:27 Autodesk 2012-11-22 17:22 Babylon 2011-12-12 16:13 CyberLink 2011-09-28 10:22 Dane aplikacji [C:\ProgramData] 2012-07-10 20:32 DatacardService 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2011-09-28 10:22 Dokumenty [C:\Users\Public\Documents] 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2012-04-12 16:39 FLEXnet 2011-10-10 20:52 Gadu-Gadu 10 2013-12-11 10:27 Informer Technologies, Inc 2011-12-12 13:40 install_clap 2011-09-28 10:44 Intel 2011-09-28 10:22 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-08-05 20:37 Microsoft 2012-03-01 12:53 153 Microsoft.SqlServer.Compact.351.32.bc 2013-04-23 17:13 Nero 2014-10-29 15:00 8 ntuser.pol 2011-09-28 10:35 OneKey Recovery 2014-06-25 16:28 PDF Architect 2 2011-12-12 13:41 PDVD 2012-03-09 18:56 PLAY ONLINE 2011-09-28 10:22 Pulpit [C:\Users\Public\Desktop] 2011-11-03 09:51 Skype 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2011-09-28 10:22 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2011-12-12 13:40 Temp 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2011-09-28 10:22 Ulubione [C:\Users\Public\Favorites] 2 plik(¢w) 161 bajt¢w 32 katalog(¢w) 30ÿ026ÿ104ÿ832 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Tomek\AppData\Local ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 269C-496B Katalog: C:\Users\Tomek\AppData\Local 2014-10-30 11:41 . 2014-10-30 11:41 .. 2011-10-24 12:53 Adobe 2014-10-23 14:40 ALLMediaServer 2013-05-18 15:07 ALLPlayer 2012-03-01 13:11 Autodesk 2013-10-14 13:36 avgchrome 2014-06-27 21:55 cache 2013-12-11 12:16 ChomikBox 2014-10-24 21:57 CrashDumps 2011-12-12 13:43 CyberLink 2011-09-28 10:22 Dane aplikacji [C:\Users\Tomek\AppData\Local] 2014-09-29 19:58 Diagnostics 2012-11-26 19:56 DirectDownloader 2013-03-30 16:06 Downloaded Installations 2013-06-25 10:11 ElevatedDiagnostics 2011-09-28 22:07 ESET 2012-01-20 23:56 Facebook 2014-04-26 11:36 96ÿ480 GDIPFONTCACHEV1.DAT 2014-10-29 15:11 Google 2011-09-28 10:22 Historia [C:\Users\Tomek\AppData\Local\Microsoft\Windows\History] 2014-10-29 15:32 4ÿ030ÿ805 IconCache.db 2011-12-12 13:41 MediaServer 2014-07-10 09:52 Microsoft 2014-10-06 20:50 Microsoft Games 2014-09-10 13:45 onlysearch 2014-09-18 14:19 Pay-By-Ads 2014-01-11 16:09 Programs 2014-10-30 11:41 Temp 2011-09-28 10:22 Temporary Internet Files [C:\Users\Tomek\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2014-09-29 16:24 TomTom 2011-10-26 13:26 VirtualStore 2 plik(¢w) 4ÿ127ÿ285 bajt¢w 30 katalog(¢w) 30ÿ026ÿ100ÿ736 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Tomek\AppData\LocalLow ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 269C-496B Katalog: C:\Users\Tomek\AppData\LocalLow 2014-03-23 12:30 . 2014-03-23 12:30 .. 2011-10-24 12:53 Adobe 2013-04-01 14:48 Delta 2013-04-01 14:48 Incredibar.com 2012-03-28 20:05 Microsoft 2013-11-20 17:01 searchgol 2014-10-29 14:51 18ÿ688 SkwConfig.bin 2012-03-12 15:56 Temp 2013-04-03 10:55 Toolbar4 1 plik(¢w) 18ÿ688 bajt¢w 9 katalog(¢w) 30ÿ026ÿ100ÿ736 bajt¢w wolnych ========= End of CMD: ========= ========= dir /a C:\Users\Tomek\AppData\Roaming ========= Wolumin w stacji C nie ma etykiety. Numer seryjny woluminu: 269C-496B Katalog: C:\Users\Tomek\AppData\Roaming 2014-10-30 11:41 . 2014-10-30 11:41 .. 2011-10-24 12:53 Adobe 2013-04-03 11:04 Ahead 2014-09-26 14:13 ALDITALKVerbindungsassistent 2012-03-06 10:27 Autodesk 2011-12-12 13:42 CyberLink 2011-09-28 22:07 ESET 2011-10-13 18:10 Gadu-Gadu 10 2011-09-28 10:22 Identities 2011-09-28 10:27 InstallShield 2011-09-28 10:44 Intel Corporation 2011-11-01 16:45 IrfanView 2011-10-10 14:48 Macromedia 2009-07-14 19:09 Media Center Programs 2014-10-24 21:54 Media Player Classic 2013-08-04 17:45 Microsoft 2012-04-01 16:22 NapiProjekt 2013-04-23 17:36 Nero 2012-11-21 15:10 OpenOffice.org 2014-06-25 16:31 PDF Architect 2 2014-10-24 21:54 Skype 2013-04-01 09:13 Winamp 2011-10-11 11:27 WinRAR 0 plik(¢w) 0 bajt¢w 24 katalog(¢w) 30ÿ026ÿ096ÿ640 bajt¢w wolnych ========= End of CMD: ========= EmptyTemp: => Removed 89.4 MB temporary data. The system needed a reboot. ==== End of Fixlog ====