Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013 Ran by a184075 at 2013-10-14 17:00:18 Run:1 Running from E:\ Boot Mode: Safe Mode (minimal) ============================================== Content of fixlist: ***************** HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\a184075\AppData\Roaming\data.dat [77312 2013-08-02] () <==== ATTENTION HKCU\...\Run: [Polar Sync] - [x] HKLM\...\Winlogon: [Userinit] C:\Windows\System32\Userinit.exe AppInit_DLLs-x32: c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll [2704352 2013-10-08] () S2 BitGuard; C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3032032 2013-10-08] () Task: {F757758D-84B3-4375-8F98-2FAED5E32656} - System32\Tasks\EPUpdater => C:\Users\a184075\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-08-04] () CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\a184075\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=1C9A0026C67A4AF4&affID=119357&tt=080913_ctrl&tsp=5000 SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.golsearch.com/?q={searchTerms}&babsrc=SP_ss_Btisdt6&mntrId=1C9A0026C67A4AF4&affID=119357&tt=080913_ctrl&tsp=5000 SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.golsearch.com/?q={searchTerms}&babsrc=SP_ss_Btisdt6&mntrId=1C9A0026C67A4AF4&affID=119357&tt=080913_ctrl&tsp=5000 BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.24.6\bh\delta.dll (Delta-search.com) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.24.6\deltaTlbr.dll (Delta-search.com) C:\Users\a184075\AppData\Roaming\data.dat C:\Users\a184075\AppData\Roaming\settings.ini C:\Users\a184075\AppData\Roaming\BabSolution C:\Users\a184075\AppData\Roaming\File Scout ***************** HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Polar Sync => Value deleted successfully. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. BitGuard => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F757758D-84B3-4375-8F98-2FAED5E32656} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F757758D-84B3-4375-8F98-2FAED5E32656} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde => Key deleted successfully. C:\Users\a184075\AppData\Roaming\BabSolution\CR\Delta.crx => Moved successfully. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Key deleted successfully. C:\Users\a184075\AppData\Roaming\data.dat => Moved successfully. C:\Users\a184075\AppData\Roaming\settings.ini => Moved successfully. C:\Users\a184075\AppData\Roaming\BabSolution => Moved successfully. C:\Users\a184075\AppData\Roaming\File Scout => Moved successfully. ==== End of Fixlog ====