Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014 Ran by Git at 2014-01-06 15:53:55 Run:1 Running from C:\Users\Git\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [] - [x] HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com/?type=sc&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811&q={searchTerms} Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File FF StartMenuInternet: FIREFOX.EXE - D:\Programy\Mozilla Firefox\firefox.exe http://www.nationzoom.com/?type=sc&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.nationzoom.com/?type=sc&ts=1388877550&from=ild&uid=SAMSUNGXHM320JI_S1HQJD0S460811 R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2014-01-05] (Cherished Technololgy LIMITED) S2 Update SecretSauce; "C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe" [x] Task: {3CE85062-7D33-45CF-91EC-2972BA3DC20F} - \AutoKMSDaily No Task File Task: {C02CD642-F70C-41A9-9D3E-2496DCB18847} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe Task: {E0E8625E-CAFB-4D4F-9C3D-5E4307C58E0E} - \AutoKMS No Task File C:\Program Files (x86)\Desk 365 C:\Program Files (x86)\SecretSauce C:\ProgramData\WPM C:\Users\Git\AppData\Local\Cool_Mirage C:\Users\Git\AppData\Roaming\eDownload ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCR\PROTOCOLS\Filter\application/octet-stream => Key deleted successfully. HKCR\CLSID\{1E66F26B-79EE-11D2-8710-00C04F79ED0D} => Key not found. HKCR\PROTOCOLS\Filter\application/x-complus => Key deleted successfully. HKCR\CLSID\{1E66F26B-79EE-11D2-8710-00C04F79ED0D} => Key not found. HKCR\PROTOCOLS\Filter\application/x-msdownload => Key deleted successfully. HKCR\CLSID\{1E66F26B-79EE-11D2-8710-00C04F79ED0D} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. Wpm => Service not found. Update SecretSauce => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3CE85062-7D33-45CF-91EC-2972BA3DC20F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3CE85062-7D33-45CF-91EC-2972BA3DC20F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMSDaily => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C02CD642-F70C-41A9-9D3E-2496DCB18847} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C02CD642-F70C-41A9-9D3E-2496DCB18847} => Key deleted successfully. C:\Windows\System32\Tasks\Desk 365 RunAsStdUser => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E0E8625E-CAFB-4D4F-9C3D-5E4307C58E0E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0E8625E-CAFB-4D4F-9C3D-5E4307C58E0E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS => Key deleted successfully. C:\Program Files (x86)\Desk 365 => Moved successfully. C:\Program Files (x86)\SecretSauce => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\Git\AppData\Local\Cool_Mirage => Moved successfully. C:\Users\Git\AppData\Roaming\eDownload => Moved successfully. ==== End of Fixlog ====