Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 02-09-2013 Ran by dom at 2013-09-02 12:25:51 Run:1 Running from C:\Users\dom\FRST Boot Mode: Safe Mode (with Networking) ============================================== Content of fixlist: ***************** Task: {3C520B31-DB48-424C-87CC-C73758513F59} - System32\Tasks\schedule!3036567561 => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe No File Task: {935C299B-8C07-4F2D-8B29-C306D3B2DEB0} - System32\Tasks\Funmoods => C:\Users\dom\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE No File Task: {F6C9830A-7A6B-4C5B-A02F-896AACD1ECEB} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files\Desk 365\desk365.exe No File Task: {F6D627C2-1FE5-4CB9-A060-D74616A163FC} - System32\Tasks\RunAsStdUser Task for VeohWebPlayer => C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe No File Task: C:\Windows\Tasks\schedule!3036567561.job => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe HKLM\...\Run: [] - [x] HKLM\...\Run: [PrivitizeVPN] - C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe [196784 2012-09-10] (OOO Industry) SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = ${SEARCH_URL}{searchTerms} SearchScopes: HKCU - ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} SearchScopes: HKCU - {41A9D399-8957-4D2A-B67A-5BD8189A24F7} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} SearchScopes: HKCU - {6E0D3B48-294C-4C8A-A662-67D397A12EE6} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKCU - {7BCFBE45-C1C7-4429-808B-8933AE2A611A} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=2A2DB687-76FA-4271-8E9D-48D4050AC7D9&apn_sauid=CF24F8FD-8F46-4A20-A43C-EB4527B6F520 SearchScopes: HKCU - {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://searchab.com/?aff=7&uid=e9638150-6e45-11e2-8046-001a4d3a465b&q={searchTerms} SearchScopes: HKCU - {BBBAEB8B-8876-4F5C-98F8-1EF4512710BD} URL = http://start.funmoods.com/results.php?f=4&a=ironto&q={searchTerms} BHO: Sueearcho-NewTab - {81CA7226-C39F-A516-3D0A-C753606FC9DB} - C:\ProgramData\Sueearcho-NewTab\5182303e60993.dll No File BHO: continueotiossave - {81EB8223-3C5A-3C5D-E696-D34F4CD43D83} - C:\ProgramData\continueotiossave\51822ffa02527.dll No File BHO: sayfEE osyAve - {CEC1280B-2F1F-FFD4-6658-9223BB2E948D} - C:\ProgramData\sayfEE osyAve\51dac3eb662a5.dll No File BHO: SearchNewTab - {F9A35743-9FA3-4705-5952-DCC4DD98C0F3} - C:\ProgramData\SearchNewTab\51dac41dcd7c1.dll No File Toolbar: HKLM - Babylon Toolbar - {41B62AD3-5D43-40D1-9D43-F3539C1DB452} - C:\Program Files\Babylon Toolbar\tbcore3.dll () Unlock: HKLM\SYSTEM\CurrentControlSet\Services\sptd S4 vToolbarUpdater13.2.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [x] R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [26984 2012-11-08] (AVG Technologies) S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x] S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [x] C:\Windows\system32\drivers\avgtpx86.sys Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: del /q C:\Users\dom\AppData\Local\Temp*.html CMD: rd /s /q "C:\Program Files\Mozilla Firefox" ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3C520B31-DB48-424C-87CC-C73758513F59} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C520B31-DB48-424C-87CC-C73758513F59} => Key not found. C:\Windows\System32\Tasks\schedule!3036567561 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\schedule!3036567561 => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{935C299B-8C07-4F2D-8B29-C306D3B2DEB0} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{935C299B-8C07-4F2D-8B29-C306D3B2DEB0} => Key not found. C:\Windows\System32\Tasks\Funmoods => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Funmoods => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6C9830A-7A6B-4C5B-A02F-896AACD1ECEB} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6C9830A-7A6B-4C5B-A02F-896AACD1ECEB} => Key not found. C:\Windows\System32\Tasks\Desk 365 RunAsStdUser => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6D627C2-1FE5-4CB9-A060-D74616A163FC} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6D627C2-1FE5-4CB9-A060-D74616A163FC} => Key not found. C:\Windows\System32\Tasks\RunAsStdUser Task for VeohWebPlayer => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser Task for VeohWebPlayer => Key not found. C:\Windows\Tasks\schedule!3036567561.job => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\PrivitizeVPN => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{80c554b9-c7f8-4a21-9471-06d606da78a2} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\ToolbarSearchProviderProgress => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{41A9D399-8957-4D2A-B67A-5BD8189A24F7} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{41A9D399-8957-4D2A-B67A-5BD8189A24F7} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6E0D3B48-294C-4C8A-A662-67D397A12EE6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6E0D3B48-294C-4C8A-A662-67D397A12EE6} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7BCFBE45-C1C7-4429-808B-8933AE2A611A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7BCFBE45-C1C7-4429-808B-8933AE2A611A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{80c554b9-c7f8-4a21-9471-06d606da78a2} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{80c554b9-c7f8-4a21-9471-06d606da78a2} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BBBAEB8B-8876-4F5C-98F8-1EF4512710BD} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BBBAEB8B-8876-4F5C-98F8-1EF4512710BD} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{81CA7226-C39F-A516-3D0A-C753606FC9DB} => Key deleted successfully. HKCR\CLSID\{81CA7226-C39F-A516-3D0A-C753606FC9DB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{81EB8223-3C5A-3C5D-E696-D34F4CD43D83} => Key deleted successfully. HKCR\CLSID\{81EB8223-3C5A-3C5D-E696-D34F4CD43D83} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CEC1280B-2F1F-FFD4-6658-9223BB2E948D} => Key deleted successfully. HKCR\CLSID\{CEC1280B-2F1F-FFD4-6658-9223BB2E948D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9A35743-9FA3-4705-5952-DCC4DD98C0F3} => Key deleted successfully. HKCR\CLSID\{F9A35743-9FA3-4705-5952-DCC4DD98C0F3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{41B62AD3-5D43-40D1-9D43-F3539C1DB452} => Value deleted successfully. HKCR\CLSID\{41B62AD3-5D43-40D1-9D43-F3539C1DB452} => Key deleted successfully. "HKLM\SYSTEM\CurrentControlSet\Services\sptd" => Error unlocking key. vToolbarUpdater13.2.0 => Service deleted successfully. avgtp => Service deleted successfully. EagleXNt => Service deleted successfully. sptd => Service not found. C:\Windows\system32\drivers\avgtpx86.sys => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= del /q C:\Users\dom\AppData\Local\Temp*.html ========= ========= End of CMD: ========= ========= rd /s /q "C:\Program Files\Mozilla Firefox" ========= ========= End of CMD: ========= The system needs a manual reboot. ==== End of Fixlog ====