Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-09-2013 Ran by czekierap at 2013-09-11 10:32:58 Run:1 Running from C:\Users\czekierap\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {15EB30EF-363D-41E1-885C-31D33E2939C2} - System32\Tasks\YourFile Update => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe Task: {8FDFB9E1-FF9D-43F0-B661-0EC8C9E86120} - System32\Tasks\EPUpdater => C:\Users\CZEKIE~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe Task: {CC954482-C1D4-4318-A6DA-20583E23DFB7} - System32\Tasks\DealPlyUpdate => C:\Program Task: {DEEF6192-D92C-407E-8B19-A5917EFA053D} - System32\Tasks\DealPly => C:\Users\CZEKIE~1\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE HKLM\...\Policies\Explorer: [NoActiveDesktop] 1 HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [NTRedirect] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\czekierap\AppData\Roaming\BabSolution\Shared\NTRedirect.dll",Run <===== ATTENTION HKCU\...\Run: [WebCake Desktop] - C:\Users\czekierap\AppData\Roaming\Betcat\WebCakeDesktop.exe [50968 2013-08-29] (WebCake LLC) HKCU\...\Run: [Slick Savings] - C:\Users\czekierap\AppData\Roaming\Slick Savings\CouponsHelper.exe [578368 2013-06-14] (Spigot, Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SearchSettings] - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe [1303360 2013-08-08] (Spigot, Inc.) HKU\UpdatusUser\...\Run: [Power2GoExpress] - NA AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll [2691536 2013-07-26] () URLSearchHook: (No Name) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - No File SearchScopes: HKCU - DefaultScope {06700C55-9E36-43E5-9965-55673A5C6308} URL = http://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {06700C55-9E36-43E5-9965-55673A5C6308} URL = http://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=0E4D9C4E36156211&affID=124001&tsp=4961 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.search.yahoo.com?type=937811&fr=spigot-yhp-ie BHO-x32: WebCake - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\Movdap\WebCakeIEClient.dll (Let Them Eat Web-Cake LLC) BHO-x32: Slick Savings - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\czekierap\AppData\Roaming\Slick Savings\Coupons.dll (Spigot, Inc.) BHO-x32: No Name - {DCC39ACE-709B-44EA-B062-5F6BE2774644} - No File BHO-x32: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\7.4\ytdToolbarIE.dll (Spigot, Inc.) Toolbar: HKLM-x32 - YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\7.4\ytdToolbarIE.dll (Spigot, Inc.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR HKLM-x32\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files (x86)\Movdap\WebCakeLayers.crx CHR HKLM-x32\...\Chrome\Extension: [hbcennhacfaagdopikcegfcobcadeocj] - C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.0.crx CHR HKLM-x32\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Program Files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Users\czekierap\AppData\Local\Slick Savings\coupons.crx CHR HKLM-x32\...\Chrome\Extension: [nohfdhapjjlndfgjnmdlcabloeembdkj] - C:\Users\czekierap\AppData\Roaming\BabSolution\CR\delta2.crx CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File R2 WebCakeUpdater; C:\Program Files (x86)\Movdap\WBDesktop.Updater.1.0.0.16.exe [51992 2013-08-15] (cake bake) U3 BcmSqlStartupSvc; U2 CLKMSVC10_3A60B698; U2 CLKMSVC10_C3B3B687; U2 DriverService; S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] U2 iATAgentService; U2 idealife Update Service; U3 IGRS; U2 IviRegMgr; U2 Oasis2Service; U2 PCCarerService; U2 ReadyComm.DirectRouter; U2 RichVideo; U2 RtLedService; U2 SeaPort; U2 SoftwareService; U3 SQLWriter; ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{15EB30EF-363D-41E1-885C-31D33E2939C2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15EB30EF-363D-41E1-885C-31D33E2939C2} => Key deleted successfully. C:\Windows\System32\Tasks\YourFile Update => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile Update => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8FDFB9E1-FF9D-43F0-B661-0EC8C9E86120} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FDFB9E1-FF9D-43F0-B661-0EC8C9E86120} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC954482-C1D4-4318-A6DA-20583E23DFB7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC954482-C1D4-4318-A6DA-20583E23DFB7} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DEEF6192-D92C-407E-8B19-A5917EFA053D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEEF6192-D92C-407E-8B19-A5917EFA053D} => Key deleted successfully. C:\Windows\System32\Tasks\DealPly => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly => Key deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktop => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktopChanges => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NTRedirect => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\WebCake Desktop => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Slick Savings => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SearchSettings => Value deleted successfully. HKU\UpdatusUser\Software\Microsoft\Windows\CurrentVersion\Run\\Power2GoExpress => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{F3FEE66E-E034-436a-86E4-9690573BEE8A} => Value deleted successfully. HKCR\CLSID\{F3FEE66E-E034-436a-86E4-9690573BEE8A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{06700C55-9E36-43E5-9965-55673A5C6308} => Key deleted successfully. HKCR\CLSID\{06700C55-9E36-43E5-9965-55673A5C6308} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DCC39ACE-709B-44EA-B062-5F6BE2774644} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{DCC39ACE-709B-44EA-B062-5F6BE2774644} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3FEE66E-E034-436a-86E4-9690573BEE8A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{F3FEE66E-E034-436a-86E4-9690573BEE8A} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{F3FEE66E-E034-436a-86E4-9690573BEE8A} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{F3FEE66E-E034-436a-86E4-9690573BEE8A} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh => Key deleted successfully. C:\Program Files (x86)\Movdap\WebCakeLayers.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj => Key deleted successfully. C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.0.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj => Key deleted successfully. C:\Program Files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk => Key deleted successfully. C:\Users\czekierap\AppData\Local\Slick Savings\coupons.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nohfdhapjjlndfgjnmdlcabloeembdkj => Key deleted successfully. "C:\Users\czekierap\AppData\Roaming\BabSolution\CR\delta2.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp => Key deleted successfully. C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx => Moved successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@Nero.com/KM => Key deleted successfully. C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL => Moved successfully. HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc => Key deleted successfully. C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll not found. WebCakeUpdater => Service deleted successfully. BcmSqlStartupSvc => Service deleted successfully. CLKMSVC10_3A60B698 => Service deleted successfully. CLKMSVC10_C3B3B687 => Service deleted successfully. DriverService => Service deleted successfully. hwdatacard => Service deleted successfully. iATAgentService => Service deleted successfully. idealife Update Service => Service deleted successfully. IGRS => Service deleted successfully. IviRegMgr => Service deleted successfully. Oasis2Service => Service deleted successfully. PCCarerService => Service deleted successfully. ReadyComm.DirectRouter => Service deleted successfully. RichVideo => Service deleted successfully. RtLedService => Service deleted successfully. SeaPort => Service deleted successfully. SoftwareService => Service deleted successfully. SQLWriter => Service deleted successfully. The system needs a manual reboot. ==== End of Fixlog ====