Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-12-2014 02 Ran by Andrrzej Szachta at 2014-12-07 18:11:29 Run:2 Running from C:\Users\Andrrzej Szachta\Documents\Skany i Logi,Naprawa,Fixit.pl Loaded Profile: Andrrzej Szachta (Available profiles: Andrrzej Szachta) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM-x32\...\Run: [mbot_de_241] => [X] HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC7A,,&q={searchTerms} HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC7A,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-2101704784-470427644-3715861599-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmyr4DsGS5n78vMqPWzn-RsCeYwEM8DpnBd6hrxS2YOIgmRzcdpj1iUc5EURTLKx8LXXnD75A8JTL-LiHaPR_yuEjjH9naa_xhPx_CkYtU4chQTwDAX1LX_lEN6MbuU5EYxOF_aqyOAxArGEIU3mPPC7A,,&q={searchTerms} BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File C:\Program Files (x86)\57ab390e-e982-4bd7-86fa-9a065fb4dbbe C:\ProgramData\AVG Security Toolbar C:\Program Files (x86)\CinPlus-2.4cV19.11 C:\Program Files (x86)\LPT C:\Program Files (x86)\predm C:\Program Files (x86)\Temp C:\Program Files (x86)\ver7VeriBrowse C:\Users\Andrrzej Szachta\AppData\Local\LPT C:\Users\Andrrzej Szachta\AppData\Local\Smartbar C:\Users\Andrrzej Szachta\AppData\Roaming\trustedshopper CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a C:\ProgramData CMD: dir /a "C:\Users\Andrrzej Szachta\AppData\Local" CMD: dir /a "C:\Users\Andrrzej Szachta\AppData\LocalLow" CMD: dir /a "C:\Users\Andrrzej Szachta\AppData\Roaming" EmptyTemp: ***************** Processes closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mbot_de_241 => value deleted successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-2101704784-470427644-3715861599-1001\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. "HKU\S-1-5-21-2101704784-470427644-3715861599-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully. "HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. C:\Program Files (x86)\57ab390e-e982-4bd7-86fa-9a065fb4dbbe => Moved successfully. C:\ProgramData\AVG Security Toolbar => Moved successfully. C:\Program Files (x86)\CinPlus-2.4cV19.11 => Moved successfully. C:\Program Files (x86)\LPT => Moved successfully. C:\Program Files (x86)\predm => Moved successfully. C:\Program Files (x86)\Temp => Moved successfully. C:\Program Files (x86)\ver7VeriBrowse => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Local\LPT => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Local\Smartbar => Moved successfully. C:\Users\Andrrzej Szachta\AppData\Roaming\trustedshopper => Moved successfully. ========= dir /a "C:\Program Files" ========= Volume in drive C is Acer Volume Serial Number is ACD0-91AD Directory of C:\Program Files 2014-12-06 16:49 . 2014-12-06 16:49 .. 2013-12-21 05:17 Accessory Store 2013-11-12 07:16 Acer 2013-11-12 06:55 Broadcom 2014-01-10 19:13 CCleaner 2013-08-22 16:36 Common Files 2013-08-22 16:35 174 desktop.ini 2014-04-12 09:27 Elantech 2013-11-12 06:52 Intel 2014-11-23 15:58 Internet Explorer 2014-03-14 09:42 Microsoft Office 2014-08-11 14:07 Microsoft Silverlight 2014-04-12 10:20 MSBuild 2014-04-12 09:28 Realtek 2014-04-12 10:20 Reference Assemblies 2012-07-26 08:22 Uninstall Information 2014-06-20 20:54 VideoLAN 2014-11-23 15:58 Windows Defender 2014-09-19 19:19 Windows Journal 2014-04-12 09:38 Windows Mail 2014-04-12 09:38 Windows Media Player 2014-03-18 11:09 Windows Multimedia Platform 2014-04-12 09:50 Windows NT 2014-04-12 09:38 Windows Photo Viewer 2014-03-18 11:09 Windows Portable Devices 2014-04-12 09:38 Windows Sidebar 2014-12-06 16:39 WindowsApps 2013-08-22 16:36 WindowsPowerShell 1 File(s) 174 bytes 28 Dir(s) 171ÿ885ÿ211ÿ648 bytes free ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Volume in drive C is Acer Volume Serial Number is ACD0-91AD Directory of C:\Program Files (x86) 2014-12-07 18:11 . 2014-12-07 18:11 .. 2013-11-12 07:22 Acer 2014-11-23 15:35 AVG 2014-08-30 21:30 Becker 2014-11-23 15:35 Browsers Apps 2014-12-06 16:49 Common Files 2013-08-22 16:34 174 desktop.ini 2014-07-21 11:57 Google 2014-08-13 21:46 Greener Web 2014-10-12 12:50 HP 2013-11-12 07:18 InstallShield Installation Information 2014-04-12 09:38 Intel 2014-11-23 15:58 Internet Explorer 2014-03-14 09:45 Microsoft Office 2014-08-11 14:07 Microsoft Silverlight 2014-06-21 21:51 Microsoft Works 2014-04-12 09:38 Microsoft.NET 2014-04-12 10:20 MSBuild 2013-06-04 05:32 Nero 2013-11-12 07:04 Qualcomm Atheros 2013-11-12 06:57 Realtek 2014-04-12 10:20 Reference Assemblies 2013-11-12 07:08 Spotify 2014-07-21 12:22 SupTab 2014-06-21 07:11 WildTangent Games 2014-11-23 15:35 Windows Defender 2014-04-12 09:38 Windows Mail 2014-04-12 09:38 Windows Media Player 2014-03-18 11:09 Windows Multimedia Platform 2013-08-22 16:36 Windows NT 2014-04-12 09:38 Windows Photo Viewer 2014-03-18 11:09 Windows Portable Devices 2014-04-12 09:38 Windows Sidebar 2013-08-22 16:36 WindowsPowerShell 2014-01-12 19:50 XSManager 1 File(s) 174 bytes 35 Dir(s) 171ÿ885ÿ211ÿ648 bytes free ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Volume in drive C is Acer Volume Serial Number is ACD0-91AD Directory of C:\ProgramData 2014-12-07 18:11 . 2014-12-07 18:11 .. 2013-11-12 07:20 Acer 2013-08-22 15:45 Application Data [C:\ProgramData] 2014-01-11 22:34 Atheros 2014-08-19 19:16 AVAST Software 2014-08-13 21:39 AVG 2014-11-20 20:41 AVG2014 2014-08-30 19:05 Avg_Update_0814avt 2014-08-13 22:10 boost_interprocess 2013-11-12 07:18 CLSK 2014-09-02 15:46 Common Files 2013-11-12 07:18 CyberLink 2014-04-12 09:50 Dane aplikacji [C:\ProgramData] 2014-06-21 07:10 DatacardService 2013-08-22 15:45 Desktop [C:\Users\Public\Desktop] 2013-08-22 15:45 Documents [C:\Users\Public\Documents] 2014-04-12 09:50 Dokumenty [C:\Users\Public\Documents] 2014-11-23 13:29 HP 2014-10-12 12:50 HP Product Assistant 2014-10-12 12:58 1ÿ255 hpzinstall.log 2013-11-12 07:18 install_clap 2013-11-12 06:52 Intel 2014-05-04 14:43 McAfee 2014-04-12 09:50 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-12-07 17:16 MFAData 2014-06-21 19:03 Microsoft 2014-11-14 19:12 Microsoft Help 2013-12-21 05:36 Mobile Partner 2014-01-12 09:43 Mozilla 2013-06-04 05:32 Nero 2014-01-06 10:45 Norton 2014-08-13 22:10 NortonInstaller 2013-11-12 07:11 OEM 2013-12-21 05:17 OEM_YAHOO 2013-12-21 05:19 Pokki 2014-04-12 09:38 PRICache 2014-04-12 09:50 Pulpit [C:\Users\Public\Desktop] 2013-11-12 07:01 Qualcomm Atheros 2014-04-12 09:42 regid.1991-06.com.microsoft 2013-08-22 15:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2014-04-12 09:50 Szablony [C:\ProgramData\Microsoft\Windows\Templates] 2013-11-12 07:18 Temp 2013-08-22 15:45 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2014-10-12 13:00 WEBREG 2014-06-21 07:11 WildTangent 2014-10-05 08:30 WindowsProtectManger 2014-08-13 21:56 {01BD4FC9-2F86-4706-A62E-774BB7E9D308} 1 File(s) 1ÿ255 bytes 47 Dir(s) 171ÿ885ÿ207ÿ552 bytes free ========= End of CMD: ========= ========= dir /a "C:\Users\Andrrzej Szachta\AppData\Local" ========= Volume in drive C is Acer Volume Serial Number is ACD0-91AD Directory of C:\Users\Andrrzej Szachta\AppData\Local 2014-12-07 18:11 . 2014-12-07 18:11 .. 2014-03-14 09:48 Apps 2014-04-16 21:12 assembly 2014-11-18 20:12 AVG 2014-11-18 20:45 Avg2014 2014-01-11 22:34 BMExplorer 2014-03-14 23:35 clear.fi 2014-03-19 23:24 CrashDumps 2014-04-12 09:35 Dane aplikacji [C:\Users\Andrrzej Szachta\AppData\Local] 2014-11-23 11:39 Deployment 2014-10-09 20:19 Diagnostics 2014-12-07 18:01 ElevatedDiagnostics 2014-11-19 20:44 EmieBrowserModeList 2014-08-15 20:22 EmieSiteList 2014-08-15 20:22 EmieUserList 2014-06-03 20:18 81ÿ512 GDIPFONTCACHEV1.DAT 2014-07-21 11:59 Google 2014-04-12 09:35 Historia [C:\Users\Andrrzej Szachta\AppData\Local\Microsoft\Windows\History] 2014-10-12 13:00 HP 2014-12-06 16:26 12ÿ256 IconCache.db 2014-06-30 08:00 Intel_Corporation 2014-01-12 10:06 Macromedia 2014-03-06 19:21 MFAData 2014-04-12 10:32 Microsoft 2014-03-14 09:41 Microsoft Help 2014-01-12 09:43 Mozilla 2014-10-12 12:23 Packages 2014-07-21 12:21 Pokki 2014-06-20 20:53 Programs 2014-01-12 09:41 Spotify 2014-12-07 18:11 Temp 2014-04-12 09:35 Temporary Internet Files [C:\Users\Andrrzej Szachta\AppData\Local\Microsoft\Windows\INetCache] 2014-07-21 12:23 Unity 2014-04-11 21:02 VirtualStore 2 File(s) 93ÿ768 bytes 33 Dir(s) 171ÿ885ÿ203ÿ456 bytes free ========= End of CMD: ========= ========= dir /a "C:\Users\Andrrzej Szachta\AppData\LocalLow" ========= Volume in drive C is Acer Volume Serial Number is ACD0-91AD Directory of C:\Users\Andrrzej Szachta\AppData\LocalLow 2014-12-06 16:48 . 2014-12-06 16:48 .. 2014-11-29 09:54 EmieBrowserModeList 2014-08-15 20:22 EmieSiteList 2014-08-15 20:22 EmieUserList 2014-06-21 19:03 Microsoft 2014-11-22 11:59 Smartbar 2014-11-19 20:41 Sun 2014-04-16 22:02 Temp 2014-11-19 20:39 trustedshopper 2014-07-21 12:23 Unity 0 File(s) 0 bytes 11 Dir(s) 171ÿ885ÿ203ÿ456 bytes free ========= End of CMD: ========= ========= dir /a "C:\Users\Andrrzej Szachta\AppData\Roaming" ========= Volume in drive C is Acer Volume Serial Number is ACD0-91AD Directory of C:\Users\Andrrzej Szachta\AppData\Roaming 2014-12-07 18:11 . 2014-12-07 18:11 .. 2013-12-21 05:16 Adobe 2014-11-19 20:39 Apple Computer 2013-12-21 05:17 Atheros 2014-08-13 21:38 AVG 2014-03-06 19:25 AVG2014 2014-08-30 21:31 becker 2014-08-09 09:23 BRT 2014-10-12 13:00 HP 2014-10-19 15:58 HpUpdate 2014-04-12 10:32 Identities 2014-01-05 12:54 Macromedia 2014-11-23 15:35 Microsoft 2014-09-01 09:18 1ÿ248 QEDYQJMM 2014-01-12 09:41 Spotify 2014-03-06 19:24 TuneUp Software 2014-04-13 13:24 Unity 2014-09-01 09:18 2ÿ086 VKZRD 2014-11-28 11:00 vlc 2014-01-12 19:52 XSManager 2 File(s) 3ÿ334 bytes 19 Dir(s) 171ÿ885ÿ203ÿ456 bytes free ========= End of CMD: ========= EmptyTemp: => Removed 304.5 MB temporary data. The system needed a reboot. ==== End of Fixlog ====