Fix result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01 Ran by user (2015-08-02 22:37:10) Run:1 Running from C:\Documents and Settings\user\Pulpit Loaded Profiles: user (Available Profiles: user) Boot Mode: Normal ============================================== fixlist content: ***************** Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\sztuka2.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\prezentacja III rok (2).LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\paragrafy.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\Poster_Żaneta_Broniowska 2015.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\Poster_Żaneta_Broniowska.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\prezentacja III rok.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\program zajec tg - czerwiec 2012.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\program zajec tg - maj 2012.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\snp - lista uczestnikow - podzial na grupy iv.2012.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\snp - lista uczestnikow - podzial na grupy vi.2012 v2.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\sztuka2.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\szyby.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\telefon internet.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\testowanie-1.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\tmobile.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\TOYOTA SALEE.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\UV2.LNK C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\ZDJĘCIA NA ŚCIANĘ.LNK CustomCLSID: HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{0002E005-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{28286AE2-3628-11D4-8168-0050DACFAE5F}\InprocServer32 -> No File CustomCLSID: HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{28286AE3-3628-11D4-8168-0050DACFAE5F}\InprocServer32 -> No File CustomCLSID: HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{44EC053A-400F-11D0-9DCD-00A0C90391D3}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{4969CDC0-6307-11D4-8194-0050DACFAE5F}\InprocServer32 -> No File CustomCLSID: HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{65105120-AB6A-11D4-81E0-0050DACFAE5F}\InprocServer32 -> No File CustomCLSID: HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{FC17C3E0-A694-11D4-81DB-0050DACFAE5F}\InprocServer32 -> No File 2015-08-02 14:23 - 2015-08-02 14:23 - 01139464 ____N () C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugincontainer.exe 2015-08-02 14:30 - 2015-08-02 14:30 - 01074952 ____N () C:\Program Files\Common Files\87737dd0-ad90-4193-bd48-336966b8d777\updater.exe 2015-08-02 16:01 - 2015-08-02 16:01 - 01219336 _____ () C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\8\plugin.exe 2015-08-02 16:01 - 2015-08-02 16:01 - 01759496 _____ () C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\2\plugin.exe 2015-08-02 16:14 - 2015-08-02 16:14 - 01171720 _____ () C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\3\plugin.exe 2015-08-02 06:24 - 2015-08-02 06:24 - 00908040 _____ () C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\7\plugin.exe 2015-08-02 16:14 - 2015-08-02 06:24 - 00055560 _____ () C:\Documents and Settings\user\Ustawienia lokalne\Temp\{BD127E26-532F-461B-AB9D-03BFB5EEC3D0}.xpi C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777 C:\Program Files\Common Files\87737dd0-ad90-4193-bd48-336966b8d777 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com...q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com...q={searchTerms} HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://services.eshi...2FE4C04F8A3}&i= HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com...q={searchTerms} HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com...q={searchTerms} HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://services.eshi...2FE4C04F8A3}&i= HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "http://services.eshi...FE4C04F8A3}&i="<======= ATTENTION SearchScopes: HKU\S-1-5-21-746137067-1390067357-839522115-1003 -> DefaultScope {D7C2796E-F2BA-4A19-8302-C8705E96D074} URL = http://search.eshiel...k={searchTerms} SearchScopes: HKU\S-1-5-21-746137067-1390067357-839522115-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://do-search.com...q={searchTerms} SearchScopes: HKU\S-1-5-21-746137067-1390067357-839522115-1003 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com...q={searchTerms} SearchScopes: HKU\S-1-5-21-746137067-1390067357-839522115-1003 -> {8F9282A3-54E9-4B8F-B7F8-77549B4E2AB2} URL = http://search.yahoo....petb&type=11467 SearchScopes: HKU\S-1-5-21-746137067-1390067357-839522115-1003 -> {D7C2796E-F2BA-4A19-8302-C8705E96D074} URL = http://search.eshiel...k={searchTerms} SearchScopes: HKU\S-1-5-21-746137067-1390067357-839522115-1003 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com...q={searchTerms} BHO: Record Page -> {2335267c-dbba-4dd5-a9d0-c4db8e6a75a4} -> C:\Program Files\Record Page\Extensions\2335267c-dbba-4dd5-a9d0-c4db8e6a75a4.dll [2015-08-02] () C:\Program Files\Record Page FF SelectedSearchEngine: eShield Safe Web FF Homepage: hxxp://services.eshield.com/general/newhometab.php?hometab=home&partner=11467&guid={D524EF42-1786-4BC3-AB58-F2FE4C04F8A3}&i= FF Keyword.URL: hxxp://search.eshield.com/serp?guid={D524EF42-1786-4BC3-AB58-F2FE4C04F8A3}&action=default_search&k= FF Extension: Record Page - C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\z7oxjz15.default-1423939123625\Extensions\{2dd1d62d-6394-45a3-8d61-d2008f76ce9e}.xpi [2015-08-02] R2 Service Mgr RecordPage; C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugincontainer.exe [1139464 2015-08-02] () R2 Update Mgr RecordPage; C:\Program Files\Common Files\87737dd0-ad90-4193-bd48-336966b8d777\updater.exe [1074952 2015-08-02] () S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X] EmptyTemp: ***************** ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\sztuka2.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\prezentacja III rok (2).LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\paragrafy.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\Poster_Żaneta_Broniowska 2015.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\Poster_Żaneta_Broniowska.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\prezentacja III rok.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\program zajec tg - czerwiec 2012.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\program zajec tg - maj 2012.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\snp - lista uczestnikow - podzial na grupy iv.2012.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\snp - lista uczestnikow - podzial na grupy vi.2012 v2.LNK => moved successfully. "C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\sztuka2.LNK" => File/Folder not found. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\szyby.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\telefon internet.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\testowanie-1.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\tmobile.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\TOYOTA SALEE.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\UV2.LNK => moved successfully. C:\Documents and Settings\user\Dane aplikacji\Microsoft\Office\Niedawny\ZDJĘCIA NA ŚCIANĘ.LNK => moved successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{0002E005-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{28286AE2-3628-11D4-8168-0050DACFAE5F}" => key removed successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{28286AE3-3628-11D4-8168-0050DACFAE5F}" => key removed successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{44EC053A-400F-11D0-9DCD-00A0C90391D3}" => key removed successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{4969CDC0-6307-11D4-8194-0050DACFAE5F}" => key removed successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{65105120-AB6A-11D4-81E0-0050DACFAE5F}" => key removed successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003_Classes\CLSID\{FC17C3E0-A694-11D4-81DB-0050DACFAE5F}" => key removed successfully. "C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugincontainer.exe" => File/Folder not found. "C:\Program Files\Common Files\87737dd0-ad90-4193-bd48-336966b8d777\updater.exe" => File/Folder not found. "C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\8\plugin.exe" => File/Folder not found. "C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\2\plugin.exe" => File/Folder not found. "C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\3\plugin.exe" => File/Folder not found. "C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777\plugins\7\plugin.exe" => File/Folder not found. "C:\Documents and Settings\user\Ustawienia lokalne\Temp\{BD127E26-532F-461B-AB9D-03BFB5EEC3D0}.xpi" => File/Folder not found. "C:\Documents and Settings\All Users\Dane aplikacji\87737dd0-ad90-4193-bd48-336966b8d777" => File/Folder not found. "C:\Program Files\Common Files\87737dd0-ad90-4193-bd48-336966b8d777" => File/Folder not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-746137067-1390067357-839522115-1003\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\Tabs => value restored successfully HKU\S-1-5-21-746137067-1390067357-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully. "HKU\S-1-5-21-746137067-1390067357-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKU\S-1-5-21-746137067-1390067357-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. "HKU\S-1-5-21-746137067-1390067357-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8F9282A3-54E9-4B8F-B7F8-77549B4E2AB2}" => key removed successfully. HKCR\CLSID\{8F9282A3-54E9-4B8F-B7F8-77549B4E2AB2} => key not found. HKU\S-1-5-21-746137067-1390067357-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D7C2796E-F2BA-4A19-8302-C8705E96D074} => key not found. HKCR\CLSID\{D7C2796E-F2BA-4A19-8302-C8705E96D074} => key not found. HKU\S-1-5-21-746137067-1390067357-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2335267c-dbba-4dd5-a9d0-c4db8e6a75a4} => key not found. HKCR\CLSID\{2335267c-dbba-4dd5-a9d0-c4db8e6a75a4} => key not found. "C:\Program Files\Record Page" => File/Folder not found. Firefox SelectedSearchEngine removed successfully. Firefox homepage removed successfully. Firefox Keyword.URL removed successfully. C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\z7oxjz15.default-1423939123625\Extensions\{2dd1d62d-6394-45a3-8d61-d2008f76ce9e}.xpi => not found. Service Mgr RecordPage => service not found. Update Mgr RecordPage => service not found. pccsmcfd => service removed successfully. EmptyTemp: => 1.2 GB temporary data Removed. The system needed a reboot. ==== End of Fixlog 22:38:11 ====