Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-09-2013 Ran by user at 2013-09-23 19:46:47 Run:2 Running from F:\ Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...409d6c4515e9\InprocServer32: [Default-shell32] C:\Users\user\AppData\Roaming\Microsoft\Update\wuausrv_x86.dll ATTENTION! ====> ZeroAccess? HKLM\...\Run: [] - [x] HKCU\...\Run: [LAN Messenger] - [x] StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX1WRJLXXXX5WX1WRJL&ts=1374083119 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST9640320AS_5WX1WRJLXXXX5WX1WRJL&ts=1374083119 BHO: DealPly Shopping - {4B6ACEA2-308A-4876-AD36-57CEC5B4FCC7} - C:\Program Files\DealPly\DealPlyIE.dll No File Task: {BAD99BA9-C40F-49FE-A406-DEC364D2EB45} - System32\Tasks\DealPlyUpdate => C:\Program S2 MBAMScheduler; "\mbamscheduler.exe" [x] S2 MBAMService; "\mbamservice.exe" [x] S1 A2DDA; \??\C:\EmsisoftEmergencyKit\Run\a2ddax86.sys [x] S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [x] ***************** HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} => Key deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\LAN Messenger => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B6ACEA2-308A-4876-AD36-57CEC5B4FCC7} => Key deleted successfully. HKCR\CLSID\{4B6ACEA2-308A-4876-AD36-57CEC5B4FCC7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BAD99BA9-C40F-49FE-A406-DEC364D2EB45} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BAD99BA9-C40F-49FE-A406-DEC364D2EB45} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. MBAMScheduler => Service deleted successfully. MBAMService => Service deleted successfully. A2DDA => Service deleted successfully. DgiVecp => Service deleted successfully. MBAMSwissArmy => Service deleted successfully. ==== End of Fixlog ====