Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 10-11-2014 Ran by Majka at 2014-11-12 14:26:39 Run:1 Running from C:\Users\Majka\Desktop\Czyszczenie Loaded Profile: Majka (Available profiles: Majka) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: Task: {657318E4-5846-4E48-9533-E9C434C15605} - System32\Tasks\EPUpdater => C:\Users\Majka\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION HKU\S-1-5-21-221829018-2594616874-4046559263-1000\...\Run: [Expressivo] => "C:\Program Files\ivo\Expressivo\expressivo.exe" -t HKU\S-1-5-21-221829018-2594616874-4046559263-1000\...\Run: [dscwmnphi] => rundll32.exe "C:\Users\Majka\AppData\Roaming\kkvncn.dll",qooeek HKLM\...\Run: [] => [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss_din2g&mntrId=EA1D0025D3089582&affID=119357&tsp=4938 SearchScopes: HKLM - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=EA1D0025D3089582&affID=119357&tsp=4938 SearchScopes: HKCU - {C215C51B-6509-4ADC-988A-F804CD478A7D} URL = http://search.avg.com/route/?d=4b3d2cf0&i=23&tp=chrome&q={searchTerms}&lng={language}&ychte=us&nt=1 SearchScopes: HKCU - {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files\AVG\AVG8\avgssie.dll No File BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File Toolbar: HKCU - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File C:\Program Files\mozilla firefox\plugins C:\Program Files\Mozilla Firefoxavg-secure-search.xml C:\Users\Majka\AppData\Roaming\0D1F1S1C1P0P1C1F1N1C1T1H2UtF1E1I C:\Users\Majka\AppData\Roaming\AVG9 C:\Users\Majka\AppData\Roaming\BabSolution C:\Users\Majka\AppData\Roaming\Babylon C:\Users\Majka\AppData\Roaming\BitComet C:\Users\Majka\AppData\Roaming\CometPlayer C:\Users\Majka\AppData\Roaming\systweak C:\Users\Majka\AppData\Roaming\Thinstall C:\Windows\System32\roboot.exe Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVG AntiVirus Free Edition Packages" /f EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{657318E4-5846-4E48-9533-E9C434C15605}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{657318E4-5846-4E48-9533-E9C434C15605}" => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater" => Key deleted successfully. HKU\S-1-5-21-221829018-2594616874-4046559263-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Expressivo => value deleted successfully. HKU\S-1-5-21-221829018-2594616874-4046559263-1000\Software\Microsoft\Windows\CurrentVersion\Run\\dscwmnphi => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. hwdatacard => Service deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key deleted successfully. "HKCR\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. "HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C215C51B-6509-4ADC-988A-F804CD478A7D}" => Key deleted successfully. "HKCR\CLSID\{C215C51B-6509-4ADC-988A-F804CD478A7D}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key deleted successfully. "HKCR\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => Key deleted successfully. "HKCR\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => value deleted successfully. "HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => value deleted successfully. "HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}" => Key deleted successfully.