Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by admin at 2015-04-07 07:03:55 Run:1 Running from C:\Users\admin\Desktop\logi Loaded Profiles: admin (Available profiles: admin) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: Task: {544B818A-FA33-44EC-9516-1BE6C73970C5} - System32\Tasks\WOYWFU => C:\Users\admin\AppData\Roaming\WOYWFU.exe [2015-03-29] (InstallMoonV29.03) <==== ATTENTION Task: {A1165B29-385C-449F-BD11-1F45358A9CAE} - System32\Tasks\PQST => C:\Users\admin\AppData\Roaming\PQST.exe [2015-03-29] (InstallMoonV29.03) <==== ATTENTION Task: C:\Windows\Tasks\PQST.job => C:\Users\admin\AppData\Roaming\PQST.exe <==== ATTENTION Task: C:\Windows\Tasks\WOYWFU.job => C:\Users\admin\AppData\Roaming\WOYWFU.exe <==== ATTENTION HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [mbot_pl_186] => [X] HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com C:\Program Files (x86)\Google C:\Users\admin\AppData\Local\Opera Software C:\Users\admin\AppData\Roaming\Opera Software C:\Users\admin\AppData\Roaming\PQST C:\Users\admin\AppData\Roaming\PQST.exe C:\Users\admin\AppData\Roaming\WOYWFU C:\Users\admin\AppData\Roaming\WOYWFU.exe C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 Folder: C:\Program Files (x86)\Mozilla Firefox Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{544B818A-FA33-44EC-9516-1BE6C73970C5} => Key not found. C:\Windows\System32\Tasks\WOYWFU not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOYWFU => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1165B29-385C-449F-BD11-1F45358A9CAE} => Key not found. C:\Windows\System32\Tasks\PQST not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PQST => Key not found. C:\Windows\Tasks\PQST.job not found. C:\Windows\Tasks\WOYWFU.job not found. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LManager => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mbot_pl_186 => value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. C:\Program Files (x86)\Google => Moved successfully. C:\Users\admin\AppData\Local\Opera Software => Moved successfully. C:\Users\admin\AppData\Roaming\Opera Software => Moved successfully. "C:\Users\admin\AppData\Roaming\PQST" => File/Directory not found. "C:\Users\admin\AppData\Roaming\PQST.exe" => File/Directory not found. "C:\Users\admin\AppData\Roaming\WOYWFU" => File/Directory not found. "C:\Users\admin\AppData\Roaming\WOYWFU.exe" => File/Directory not found. C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully. ========================= Folder: C:\Program Files (x86)\Mozilla Firefox ======================== 2015-04-06 14:31 - 2015-04-06 14:31 - 0020592 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0000667 _____ () C:\Program Files (x86)\Mozilla Firefox\application.ini 2015-04-06 14:31 - 2015-04-06 14:31 - 0109680 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0283248 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe 2015-04-06 14:31 - 2015-03-27 08:08 - 0004382 _____ () C:\Program Files (x86)\Mozilla Firefox\crashreporter.ini 2015-04-06 14:31 - 2010-05-26 20:41 - 2106216 _____ (Microsoft Corporation) C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2015-04-06 14:31 - 2013-08-22 07:03 - 3466856 _____ (Microsoft Corporation) C:\Program Files (x86)\Mozilla Firefox\d3dcompiler_47.dll 2015-04-06 14:31 - 2015-03-27 06:45 - 0000093 _____ () C:\Program Files (x86)\Mozilla Firefox\dependentlibs.list 2015-04-06 14:31 - 2015-04-06 14:31 - 0376944 _____ (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 0000899 _____ () C:\Program Files (x86)\Mozilla Firefox\freebl3.chk 2015-04-06 14:31 - 2015-04-06 14:31 - 0330864 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\freebl3.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 10397296 _____ (The ICU Project) C:\Program Files (x86)\Mozilla Firefox\icudt52.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 1079920 _____ (The ICU Project) C:\Program Files (x86)\Mozilla Firefox\icuin52.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0825456 _____ (The ICU Project) C:\Program Files (x86)\Mozilla Firefox\icuuc52.dll 2015-04-06 14:31 - 2015-04-01 21:34 - 0023288 _____ () C:\Program Files (x86)\Mozilla Firefox\install.log 2015-04-06 14:31 - 2015-04-06 14:31 - 0042096 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\libEGL.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0871536 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\libGLESv2.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0148080 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 0185432 _____ (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 0017008 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0104048 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\mozglue.dll 2015-04-06 14:31 - 2013-10-05 11:38 - 0455328 _____ (Microsoft Corporation) C:\Program Files (x86)\Mozilla Firefox\msvcp120.dll 2015-04-06 14:31 - 2013-10-05 11:38 - 0970912 _____ (Microsoft Corporation) C:\Program Files (x86)\Mozilla Firefox\msvcr120.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 1675888 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\nss3.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0415344 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0000899 _____ () C:\Program Files (x86)\Mozilla Firefox\nssdbm3.chk 2015-04-06 14:31 - 2015-04-06 14:31 - 0093808 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 11399262 _____ () C:\Program Files (x86)\Mozilla Firefox\omni.ja 2015-04-06 14:31 - 2015-04-06 14:31 - 0000143 _____ () C:\Program Files (x86)\Mozilla Firefox\platform.ini 2015-04-06 14:31 - 2015-04-06 14:31 - 0267888 _____ (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 0172144 _____ (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 0002288 _____ () C:\Program Files (x86)\Mozilla Firefox\precomplete 2015-04-06 14:31 - 2015-04-06 14:31 - 0000662 _____ () C:\Program Files (x86)\Mozilla Firefox\removed-files 2015-04-06 14:31 - 2015-04-06 14:31 - 0205424 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\sandboxbroker.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0000899 _____ () C:\Program Files (x86)\Mozilla Firefox\softokn3.chk 2015-04-06 14:31 - 2015-04-06 14:31 - 0153200 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\softokn3.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0298096 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\updater.exe 2015-04-06 14:31 - 2015-03-27 08:09 - 0001200 _____ () C:\Program Files (x86)\Mozilla Firefox\updater.ini 2015-04-06 14:31 - 2015-03-27 05:27 - 0000132 _____ () C:\Program Files (x86)\Mozilla Firefox\update-settings.ini 2015-04-06 14:31 - 2015-04-06 14:31 - 0002260 _____ () C:\Program Files (x86)\Mozilla Firefox\voucher.bin 2015-04-06 14:31 - 2015-04-06 14:31 - 0132720 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 0091032 _____ (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\webapp-uninstaller.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 0127088 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\wow_helper.exe 2015-04-06 14:31 - 2015-04-06 14:31 - 35088496 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\xul.dll 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\browser 2015-04-06 14:31 - 2015-04-06 14:31 - 0157429 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\blocklist.xml 2015-04-06 14:31 - 2015-03-27 05:31 - 0000040 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\chrome.manifest 2015-04-06 14:31 - 2015-03-27 08:08 - 0000880 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\crashreporter-override.ini 2015-04-06 14:31 - 2015-04-06 14:31 - 13394950 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\browser\components 2015-04-06 14:31 - 2015-04-06 14:31 - 0050800 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll 2015-04-06 14:31 - 2015-03-27 05:31 - 0000034 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\components\components.manifest 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\browser\extensions 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} 2015-04-06 14:31 - 2015-03-27 04:26 - 0001850 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png 2015-04-06 14:31 - 2015-04-06 14:31 - 0001325 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins 2015-04-06 14:31 - 2015-03-27 08:08 - 0002273 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\allegro-pl.xml 2015-04-06 14:31 - 2015-03-27 08:08 - 0018087 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\ddg.xml 2015-04-06 14:31 - 2015-03-27 08:08 - 0026531 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\google.xml 2015-04-06 14:31 - 2015-03-27 08:08 - 0001192 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\merlin-pl.xml 2015-04-06 14:31 - 2015-03-27 08:08 - 0002075 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\pwn-pl.xml 2015-04-06 14:31 - 2015-03-27 08:08 - 0009353 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wikipedia-pl.xml 2015-04-06 14:31 - 2015-03-27 08:08 - 0001238 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wolnelektury-pl.xml 2015-04-06 14:31 - 2015-03-27 08:08 - 0007889 _____ () C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\wp-pl.xml 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\defaults 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\defaults\pref 2015-04-06 14:31 - 2015-03-27 06:49 - 0000250 _____ () C:\Program Files (x86)\Mozilla Firefox\defaults\pref\channel-prefs.js 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\dictionaries 2015-04-06 14:31 - 2015-03-27 08:08 - 0245042 _____ () C:\Program Files (x86)\Mozilla Firefox\dictionaries\pl.aff 2015-04-06 14:31 - 2015-03-27 08:08 - 4405286 _____ () C:\Program Files (x86)\Mozilla Firefox\dictionaries\pl.dic 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\gmp-clearkey 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\gmp-clearkey\0.1 2015-04-06 14:31 - 2015-04-06 14:31 - 0187504 _____ (Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\gmp-clearkey\0.1\clearkey.dll 2015-04-06 14:31 - 2015-03-27 05:28 - 0000258 _____ () C:\Program Files (x86)\Mozilla Firefox\gmp-clearkey\0.1\clearkey.info 2015-04-06 14:31 - 2015-04-06 14:43 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\uninstall 2015-04-06 14:31 - 2015-04-06 14:31 - 0923400 _____ (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe 2015-04-06 14:31 - 2015-04-01 21:34 - 0000322 _____ () C:\Program Files (x86)\Mozilla Firefox\uninstall\shortcuts_log.ini 2015-04-06 14:31 - 2015-04-01 21:34 - 0002003 _____ () C:\Program Files (x86)\Mozilla Firefox\uninstall\uninstall.log 2015-04-06 14:43 - 2015-04-06 14:43 - 0000000 _____ () C:\Program Files (x86)\Mozilla Firefox\uninstall\uninstall.update 2015-04-06 14:31 - 2015-04-06 14:31 - 0000000 ____D () C:\Program Files (x86)\Mozilla Firefox\webapprt 2015-04-06 14:31 - 2015-03-27 08:09 - 0085582 _____ () C:\Program Files (x86)\Mozilla Firefox\webapprt\omni.ja 2015-04-06 14:31 - 2015-04-06 14:31 - 0000495 _____ () C:\Program Files (x86)\Mozilla Firefox\webapprt\webapprt.ini ====== End of Folder: ====== ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 3.2 GB temporary data. The system needed a reboot. ==== End of Fixlog 07:06:27 ====