Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2013 01 Ran by PC at 2013-12-15 22:27:03 Run:1 Running from D:\Download\Programs Boot Mode: Normal ============================================== Content of fixlist: ***************** 2013-11-28 04:22 - 2013-11-28 04:22 - 00000000 ____D C:\ProgramData\Guard.Mail.Ru 2013-11-28 02:12 - 2013-12-15 12:46 - 00000000 ____D C:\Users\PC\AppData\Roaming\DRPSu HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.ru/cnt/9134 URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: HKCU - Спутник@Mail.Ru - {09900DE8-1DCA-443F-9243-26FF581438AF} - C:\Program Files (x86)\Mail.Ru\Sputnik\MailRuSputnik.dll No File SearchScopes: HKCU - {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb BHO-x32: MailRuBHO Class - {8984B388-A5BB-4DF7-B274-77B879E179DB} - C:\Program Files (x86)\Mail.Ru\Sputnik\MailRuSputnik.dll No File Toolbar: HKLM-x32 - Спутник@Mail.Ru - {09900DE8-1DCA-443F-9243-26FF581438AF} - C:\Program Files (x86)\Mail.Ru\Sputnik\MailRuSputnik.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File S3 atillk64; \??\C:\Users\PC\Desktop\winflash20113\atillk64.sys [x] S3 cpuz136; \??\C:\Users\PC\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 NPF; system32\drivers\NPF.sys [x] S3 WinRing0_1_2_0; \??\C:\Users\PC\AppData\Local\Temp\tmp35A8.tmp [x] S3 xhunter1; \??\C:\Windows\xhunter1.sys [x] Reg: reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** C:\ProgramData\Guard.Mail.Ru => Moved successfully. C:\Users\PC\AppData\Roaming\DRPSu => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. Default URLSearchHook was restored successfully . HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{09900DE8-1DCA-443F-9243-26FF581438AF} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{09900DE8-1DCA-443F-9243-26FF581438AF} => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060} => Key deleted successfully. HKCR\CLSID\{E88E0043-C9D4-4e33-8555-FEE4F5B63060} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{8984B388-A5BB-4DF7-B274-77B879E179DB} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{09900DE8-1DCA-443F-9243-26FF581438AF} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{09900DE8-1DCA-443F-9243-26FF581438AF} => Key not found. HKLM\Software\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0 => Key deleted successfully. C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll not found. atillk64 => Service deleted successfully. cpuz136 => Service deleted successfully. EagleX64 => Service deleted successfully. NPF => Service deleted successfully. WinRing0_1_2_0 => Service deleted successfully. xhunter1 => Service deleted successfully. ========= reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====