Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-01-2015 Ran by Marta at 2015-01-23 06:32:53 Run:2 Running from C:\Users\Marta\Desktop Loaded Profiles: Marta (Available profiles: UpdatusUser & Marta) Boot Mode: Normal ============================================== Content of fixlist: ***************** CMD: type C:\AdwCleaner\AdwCleaner[S0].txt S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_39 -> C:\windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) RemoveDirectory: C:\!KillBox RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\FRST\Quarantine RemoveDirectory: C:\MATS RemoveDirectory: C:\Program Files (x86)\Spybot - Search & Destroy RemoveDirectory: C:\ProgramData\Spybot - Search & Destroy RemoveDirectory: C:\Users\Marta\Desktop\FRST-OlderVersion RemoveDirectory: C:\Users\Marta\Desktop\Stare dane programu Firefox CMD: del /q C:\Users\Marta\Desktop\x8k1mu41.exe Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** ========= type C:\AdwCleaner\AdwCleaner[S0].txt ========= # AdwCleaner v4.108 - Log utworzony 18/01/2015 o 17:07:27 # Aktualizacja 17/01/2015 przez Xplode # Database : 2015-01-13.2 [Live] # System operacyjny : Windows 7 Home Premium Service Pack 1 (64 bits) # U¿ytkownik : Marta - MARTA-KOMPUTER # Œcie¿ka : C:\Users\Marta\Desktop\adwcleaner_4.108.exe # Opcja : Usuñ ***** [ Us³ugi ] ***** Us³uga Usuniêto : Skype C2C Service ***** [ Pliki / Foldery ] ***** Folder Usuniêto : C:\ProgramData\4d09ce8d5400296d Folder Usuniêto : C:\ProgramData\Ask Folder Usuniêto : C:\ProgramData\IBUpdaterService Folder Usuniêto : C:\ProgramData\Tarma Installer Folder Usuniêto : C:\ProgramData\WPM Folder Usuniêto : C:\ProgramData\AlawarWrapper Folder Usuniêto : C:\ProgramData\GraeAtSave4U Folder Usuniêto : C:\ProgramData\SaveNeewaAppza Folder Usuniêto : C:\ProgramData\5551195122105854317 Folder Usuniêto : C:\Program Files (x86)\Bench Folder Usuniêto : C:\Program Files (x86)\file scout Folder Usuniêto : C:\Program Files (x86)\GreenTree Applications Folder Usuniêto : C:\Program Files (x86)\Mobogenie Folder Usuniêto : C:\Program Files (x86)\predm Folder Usuniêto : C:\Program Files (x86)\DeltaFix Folder Usuniêto : C:\Program Files (x86)\Flash Saving Folder Usuniêto : C:\Program Files (x86)\GraeAtSave4U Folder Usuniêto : C:\Program Files (x86)\SaveNeewaAppza Folder Usuniêto : C:\Users\Marta\AppData\Local\Freesofttoday Folder Usuniêto : C:\Users\Marta\AppData\Local\lollipop Folder Usuniêto : C:\Users\Marta\AppData\Local\Mobogenie Folder Usuniêto : C:\Users\Marta\AppData\Local\SwvUpdater Folder Usuniêto : C:\Users\Marta\AppData\Roaming\eType Folder Usuniêto : C:\Users\Marta\AppData\Roaming\goforfiles Folder Usuniêto : C:\Users\Marta\AppData\Roaming\PerformerSoft Folder Usuniêto : C:\Users\Marta\AppData\Roaming\SimilarSites Folder Usuniêto : C:\Users\Marta\AppData\Roaming\Systweak Folder Usuniêto : C:\Users\Marta\AppData\Roaming\Updater Folder Usuniêto : C:\Users\Marta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop Folder Usuniêto : C:\Users\Public\Documents\AlawarWrapper Folder Usuniêto : C:\Users\wangzhisong\AppData\Local\Mobogenie Folder Usuniêto : C:\Users\Marta\AppData\Roaming\Mozilla\Firefox\Profiles\pa4imslo.default\Extensions\U@64t.net Plik Usuniêto : C:\windows\System32\roboot64.exe Plik Usuniêto : C:\Users\Marta\daemonprocess.txt Plik Usuniêto : C:\Users\Marta\AppData\Roaming\Mozilla\Firefox\Profiles\pa4imslo.default\searchplugins\Askcom.xml Plik Usuniêto : C:\Users\Marta\AppData\Roaming\Mozilla\Firefox\Profiles\pa4imslo.default\user.js ***** [ Zadania ] ***** Zadanie Usuniêto : bench-sys Zadanie Usuniêto : GoforFilesUpdate Zadanie Usuniêto : IHUninstallTrackingTASK ***** [ Skróty ] ***** ***** [ Rejestr ] ***** Klucz Usuniêto : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Klucz Usuniêto : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Klucz Usuniêto : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc Klucz Usuniêto : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{065C1A21-97F8-45FB-A9F0-861B60FACEC8} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{3204358F-5904-46A6-841F-D6B5BE3EF4E3} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{3AE67737-0E3E-44AA-AA5E-46A68BF017FF} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{3EE5B726-044A-48D2-AA7B-049BD9A0F62A} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{60FBBE03-57FF-49D8-B38E-053D3F489825} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{6A5182F1-C0B8-42B8-96CC-7F329CD46913} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{6C153418-8E4D-4FAF-AF27-5201E38463A7} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{A26A2F05-AC4D-4A1E-9531-9125F7309B78} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{CC5D6240-7DF0-435D-9B9B-F8586A99DE86} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{F343045E-E20A-46E1-82D8-9962C43EFC9E} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{FBB360DC-CB6C-4D6A-808A-2C773151BFFF} Klucz Usuniêto : HKLM\SOFTWARE\Classes\CLSID\{FFD7DDAC-EC28-42A5-8D39-917B9078604B} Klucz Usuniêto : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Klucz Usuniêto : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Klucz Usuniêto : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Klucz Usuniêto : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Klucz Usuniêto : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} Klucz Usuniêto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Klucz Usuniêto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Klucz Usuniêto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} Wartoœæ Usuniêto : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Klucz Usuniêto : [x64] HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Klucz Usuniêto : [x64] HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Klucz Usuniêto : [x64] HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Klucz Usuniêto : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Klucz Usuniêto : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8AA519B6-ACAF-44E1-B2FB-E8F460F79F4A} Klucz Usuniêto : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Klucz Usuniêto : HKCU\Software\DSNR Labs Klucz Usuniêto : HKCU\Software\filescout Klucz Usuniêto : HKCU\Software\GoforFiles Klucz Usuniêto : HKCU\Software\InstallCore Klucz Usuniêto : HKCU\Software\Softonic Klucz Usuniêto : HKCU\Software\systweak Klucz Usuniêto : HKCU\Software\TutoTag Klucz Usuniêto : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} Klucz Usuniêto : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Klucz Usuniêto : HKLM\SOFTWARE\Bench Klucz Usuniêto : HKLM\SOFTWARE\FreeSoftToday Klucz Usuniêto : HKLM\SOFTWARE\GoforFiles Klucz Usuniêto : HKLM\SOFTWARE\Tutorials Klucz Usuniêto : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} Klucz Usuniêto : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Klucz Usuniêto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} Klucz Usuniêto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0} Klucz Usuniêto : [x64] HKLM\SOFTWARE\Tarma Installer ***** [ Przegl¹darki internetowe ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Mozilla Firefox v35.0 (x86 pl) [pa4imslo.default\prefs.js] - Wpis usuniêty : user_pref("browser.search.order.1", "Ask.com"); [pa4imslo.default\prefs.js] - Wpis usuniêty : user_pref("extensions.INSWcPgflK9i1jUz.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...] -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [11331 octets] - [17/01/2015 19:31:47] AdwCleaner[R1].txt - [11240 octets] - [18/01/2015 08:07:47] AdwCleaner[R2].txt - [8841 octets] - [18/01/2015 16:17:24] AdwCleaner[R3].txt - [8901 octets] - [18/01/2015 16:57:55] AdwCleaner[S0].txt - [7833 octets] - [18/01/2015 17:07:27] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7893 octets] ########## ========= End of CMD: ========= gupdate => Service deleted successfully. gupdatem => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39" => Key deleted successfully. C:\windows\SysWOW64\npdeployJava1.dll => Moved successfully. "C:\!KillBox" => Removed successfully. "C:\AdwCleaner" => Removed successfully. "C:\FRST\Quarantine" => Removed successfully. "C:\MATS" => Removed successfully. "C:\Program Files (x86)\Spybot - Search & Destroy" => Removed successfully. "C:\ProgramData\Spybot - Search & Destroy" => Removed successfully. "C:\Users\Marta\Desktop\FRST-OlderVersion" => Removed successfully. "C:\Users\Marta\Desktop\Stare dane programu Firefox" => Removed successfully. ========= del /q C:\Users\Marta\Desktop\x8k1mu41.exe ========= ========= End of CMD: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog 06:33:15 ====