Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-01-2015 02 Ran by KSIEGOWY at 2015-01-14 16:05:40 Run:2 Running from C:\Users\KSIEGOWY\Desktop\aaa Loaded Profile: KSIEGOWY (Available profiles: KSIEGOWY & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\...\Run: [YTVPack] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\KSIEGOWY\AppData\Local\Ektion\rvvbobqwdyjcc.dll HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\...\Run: [Ezztion] => regsvr32.exe C:\Users\KSIEGOWY\AppData\Local\Ezztion\plc4.dll <===== ATTENTION HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\...\Run: [BluetoothS] => rundll32.exe "%appdata%\BtvStack.dll",BTHF_Register URLSearchHook: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> 7B25F7A08463410AB1D6D9C86FEB050F URL = http://search.babylon.com/?q={searchTerms}&AF=100480&babsrc=SP_ss&mntrId=aa814c8600000000000064315023b703 SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {2AE70A0E-39B8-48D4-9229-9E2C0E150E4B} URL = http://www.search.ask.com/web?p2=^ADN^OSJ000^YY^PL&gct=&itbv=12.0.1.100&o=APN10616&tpid=ORJ-V7&apn_uid=43BDBA54-CA96-429E-8979-478EFC4398ED&apn_ptnrs=ADN&apn_dtid=^OSJ000^YY^PL&apn_dbr=ie_9.0.8112.16476&doi=2013-10-11&trgb=IE&q={searchTerms}&psv= SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMDTDF SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-results.com/sr?src=ieb&appid=102&systemid=406&sr=0&q={searchTerms} SearchScopes: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = Toolbar: HKU\S-1-5-21-3668452077-1106565234-3799211801-1002 -> No Name - {4F524A2D-5637-006A-76A7-7A786E7484D7} - No File HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\35355970.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\57130876.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\35355970.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\57130876.sys => ""="Driver" C:\Users\Administrator\temp C:\Users\KSIEGOWY\AppData\Roaming\Babylon Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: dir /a C:\Users\KSIEGOWY\AppData\Local ***************** Processes closed successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Windows\CurrentVersion\Run\\YTVPack => value deleted successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Ezztion => value deleted successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Windows\CurrentVersion\Run\\BluetoothS => value deleted successfully. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => value deleted successfully. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\7B25F7A08463410AB1D6D9C86FEB050F" => Key deleted successfully. HKCR\CLSID\7B25F7A08463410AB1D6D9C86FEB050F => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2AE70A0E-39B8-48D4-9229-9E2C0E150E4B}" => Key deleted successfully. HKCR\CLSID\{2AE70A0E-39B8-48D4-9229-9E2C0E150E4B} => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}" => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => Key not found. "HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}" => Key deleted successfully. HKCR\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key not found. HKU\S-1-5-21-3668452077-1106565234-3799211801-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4F524A2D-5637-006A-76A7-7A786E7484D7} => value deleted successfully. HKCR\CLSID\{4F524A2D-5637-006A-76A7-7A786E7484D7} => Key not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\35355970.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\57130876.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\35355970.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\57130876.sys" => Key deleted successfully. C:\Users\Administrator\temp => Moved successfully. C:\Users\KSIEGOWY\AppData\Roaming\Babylon => Moved successfully. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= dir /a C:\Users\KSIEGOWY\AppData\Local ========= Wolumin w stacji C to OS Numer seryjny woluminu: AA81-4C86 Katalog: C:\Users\KSIEGOWY\AppData\Local 2015-01-12 14:27 . 2015-01-12 14:27 .. 2014-09-02 13:22 Adobe 2011-11-04 15:53 Dane aplikacji [C:\Users\KSIEGOWY\AppData\Local] 2011-12-05 08:07 Diagnostics 2011-11-04 15:53 DigitalPersona 2013-09-12 12:10 ESET 2013-01-11 11:08 89ÿ992 GDIPFONTCACHEV1.DAT 2011-12-21 11:09 Google 2011-11-04 15:56 Hewlett-Packard 2011-11-04 15:53 Historia [C:\Users\KSIEGOWY\AppData\Local\Microsoft\Windows\History] 2015-01-13 12:55 2ÿ362ÿ399 IconCache.db 2012-08-06 08:49 4ÿ096 keyfile3.drm 2013-05-09 12:39 Microsoft 2014-03-06 14:26 Microsoft Games 2013-05-09 12:38 Microsoft Help 2011-12-21 10:01 PackageAware 2011-12-06 10:52 Panasonic_System_Networks 2011-11-04 16:01 PDFC 2014-10-29 11:15 Programs 2014-03-04 07:21 Skype 2015-01-14 16:05 Temp 2011-11-04 15:53 Temporary Internet Files [C:\Users\KSIEGOWY\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2011-11-04 16:00 VirtualStore 3 plik(¢w) 2ÿ456ÿ487 bajt¢w 21 katalog(¢w) 28ÿ492ÿ177ÿ408 bajt¢w wolnych ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog 16:05:48 ====