Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013 Ran by tds at 2013-10-19 16:57:45 Run:1 Running from C:\Users\tds\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\tds\AppData\Roaming\minert C:\Users\tds\AppData\Roaming\minerd C:\Users\tds\AppData\Local\Google AlternateDataStreams: C:\Windows:27A9E4560CEE80AC HKCU\...\Run: [minerd] - "C:\Users\tds\AppData\Roaming\minerd\nircmd.exe" exec hide "C:\Users\tds\AppData\Roaming\minerd\start.bat" HKCU\...\Run: [minert] - "C:\Users\tds\AppData\Roaming\minert\nircmd.exe" exec hide "C:\Users\tds\AppData\Roaming\minert\start.bat" HKCU\...\Run: [Hoolapp Android] - "C:\Users\tds\AppData\Roaming\HOOLAP~1\Hoolapp.exe" /Minimized HKCU\...\Run: [Pokki] - "%LOCALAPPDATA%\Pokki\Engine\pokki.exe" HKLM-x32\...\Run: [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe" HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] - C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?searchsource=10&cui=un39948887164765202&um=2&ctid=ct3289847&sspv=tb_t5 URLSearchHook: (No Name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - No File SearchScopes: HKLM-x32 - DefaultScope {1F6E33D8-5929-47E3-90E6-D269865FDE37} URL = SearchScopes: HKLM-x32 - {01bd49d7-c76b-4310-8beb-14d7e5f322c6} URL = http://search.easylifeapp.com/?q={searchTerms}&pid=658&src=ie2&r=2013/05/27&hid=504504536&lg=EN&cc=GB SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10005&barid={BBDA8324-51B8-11E2-9285-00242139113A} SearchScopes: HKCU - DefaultScope {1F6E33D8-5929-47E3-90E6-D269865FDE37} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289847&CUI=UN39948887164765202&UM=2&SSPV=TB_T5 SearchScopes: HKCU - {01bd49d7-c76b-4310-8beb-14d7e5f322c6} URL = http://search.easylifeapp.com/?q={searchTerms}&pid=658&src=ie2&r=2013/05/27&hid=504504536&lg=EN&cc=GB SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A61D00242139113A&affID=119357&tt=110713_9126&tsp=4942 SearchScopes: HKCU - {1F6E33D8-5929-47E3-90E6-D269865FDE37} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289847&CUI=UN39948887164765202&UM=2&SSPV=TB_T5 SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10005&barid={BBDA8324-51B8-11E2-9285-00242139113A} BHO-x32: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} - No File Task: {F4F030BC-D730-471E-95AF-53F8B1609729} - \schedule!3036567561 No Task File Task: C:\Windows\Tasks\schedule!3036567561.job => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll No File S3 dgderdrv; System32\drivers\dgderdrv.sys [x] S3 Gmer; System32\DRIVERS\gmer.sys [x] S3 GPU-Z; \??\x:\temp\temp\GPU-Z.sys [x] S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [x] S3 NVR0Dev; \??\C:\Windows\nvoclk64.sys [x] S1 StarOpen; No ImagePath Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ***************** C:\Users\tds\AppData\Roaming\minert => Moved successfully. C:\Users\tds\AppData\Roaming\minerd => Moved successfully. C:\Users\tds\AppData\Local\Google => Moved successfully. C:\Windows => ":27A9E4560CEE80AC" ADS removed successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\minerd => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\minert => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Hoolapp Android => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Pokki => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\iSkysoft Helper Compact.exe => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{687578b9-7132-4a7a-80e4-30ee31099e03} => Value deleted successfully. HKCR\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} => Key deleted successfully. HKCR\CLSID\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1F6E33D8-5929-47E3-90E6-D269865FDE37} => Key deleted successfully. HKCR\CLSID\{1F6E33D8-5929-47E3-90E6-D269865FDE37} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{687578B9-7132-4A7A-80E4-30EE31099E03} => Value deleted successfully. HKCR\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F4F030BC-D730-471E-95AF-53F8B1609729} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4F030BC-D730-471E-95AF-53F8B1609729} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\schedule!3036567561 => Key deleted successfully. C:\Windows\Tasks\schedule!3036567561.job => Moved successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0 => Key deleted successfully. C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll not found. dgderdrv => Service deleted successfully. Gmer => Service deleted successfully. GPU-Z => Service deleted successfully. IntcAzAudAddService => Service deleted successfully. NVR0Dev => Service deleted successfully. StarOpen => Service deleted successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====