Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-01-2014 Ran by User at 2014-01-19 13:12:56 Run:1 Running from C:\Users\User\Desktop\Logi Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [NextLive] - C:\Users\User\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1389209332&from=cor&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1389209332&from=cor&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=2C4DC018857B4274&affID=123627&tsp=4944 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1389209332&from=cor&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1389282380&from=tt4u&uid=HitachiXHTS545050B9A300_120309PBN408P7JYKALEX&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear SearchScopes: HKCU - {ACE05FB9-18E8-48AC-A0EC-2D474C167A90} URL = SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Task: {2EB8E32A-669E-4BC2-B8BE-000FB834F974} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION Task: {3DD9B98A-7CBD-47E8-871F-1CB9FF650420} - System32\Tasks\SetupManager => C:\Program Files (x86)\Hewlett-Packard\Setup Manager\toaster.exe Task: {9302BD96-E789-4FA3-86F8-A64982E70052} - System32\Tasks\QtraxPlayer => C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe [2013-09-13] (Microsoft Corporation) Task: {FF79ABD2-E200-41ED-B0CC-2FD37C4C27E7} - System32\Tasks\{75440924-481E-49AC-9B6B-775599CEDF08} => Iexplore.exe http://ui.skype.com/ui/0/6.9.0.106/pl/abandoninstall?page=tsProgressBar C:\Program Files (x86)\predm C:\Program Files (x86)\Przyspiesz Komputer C:\Program Files (x86)\VLC Player GPU+ C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} C:\ProgramData\AVG C:\ProgramData\AVG Secure Search C:\ProgramData\BonanzaDealsLive C:\ProgramData\WPM C:\Users\User\.android C:\Users\User\daemonprocess.txt C:\Users\User\AppData\Local\AnyProtectScannerSetup.exe C:\Users\User\AppData\Local\BonanzaDealsLive C:\Users\User\AppData\Local\cache C:\Users\User\AppData\Local\genienext C:\Users\User\AppData\Local\Mobogenie C:\Users\User\AppData\Roaming\0C1I1L1R1J0M1P0I1G C:\Users\User\AppData\Roaming\AVG C:\Users\User\AppData\Roaming\Babylon C:\Users\User\AppData\Roaming\DSite C:\Users\User\AppData\Roaming\File Scout C:\Users\User\AppData\Roaming\newnext.me C:\Users\User\AppData\Roaming\OpenCandy C:\Users\User\AppData\Roaming\PDF Creator Packages C:\Users\User\AppData\Roaming\PDF Reader Packages C:\Users\User\AppData\Roaming\Systweak C:\Users\User\AppData\Roaming\_MDLogs C:\Users\User\AppData\Roaming\mozilla C:\Users\User\Documents\Mobogenie C:\Windows\system32\roboot64.exe C:\Windows\SysWOW64\unrar.dll Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => Key deleted successfully. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ACE05FB9-18E8-48AC-A0EC-2D474C167A90} => Key deleted successfully. HKCR\CLSID\{ACE05FB9-18E8-48AC-A0EC-2D474C167A90} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => Key deleted successfully. HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => Key deleted successfully. HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2EB8E32A-669E-4BC2-B8BE-000FB834F974} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2EB8E32A-669E-4BC2-B8BE-000FB834F974} => Key deleted successfully. C:\Windows\System32\Tasks\BitGuard => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3DD9B98A-7CBD-47E8-871F-1CB9FF650420} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DD9B98A-7CBD-47E8-871F-1CB9FF650420} => Key deleted successfully. C:\Windows\System32\Tasks\SetupManager => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SetupManager => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9302BD96-E789-4FA3-86F8-A64982E70052} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9302BD96-E789-4FA3-86F8-A64982E70052} => Key deleted successfully. C:\Windows\System32\Tasks\QtraxPlayer => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QtraxPlayer => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FF79ABD2-E200-41ED-B0CC-2FD37C4C27E7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF79ABD2-E200-41ED-B0CC-2FD37C4C27E7} => Key deleted successfully. C:\Windows\System32\Tasks\{75440924-481E-49AC-9B6B-775599CEDF08} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{75440924-481E-49AC-9B6B-775599CEDF08} => Key deleted successfully. C:\Program Files (x86)\predm => Moved successfully. C:\Program Files (x86)\Przyspiesz Komputer => Moved successfully. C:\Program Files (x86)\VLC Player GPU+ => Moved successfully. C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} => Moved successfully. C:\ProgramData\AVG => Moved successfully. C:\ProgramData\AVG Secure Search => Moved successfully. C:\ProgramData\BonanzaDealsLive => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\Users\User\.android => Moved successfully. C:\Users\User\daemonprocess.txt => Moved successfully. C:\Users\User\AppData\Local\AnyProtectScannerSetup.exe => Moved successfully. C:\Users\User\AppData\Local\BonanzaDealsLive => Moved successfully. C:\Users\User\AppData\Local\cache => Moved successfully. C:\Users\User\AppData\Local\genienext => Moved successfully. C:\Users\User\AppData\Local\Mobogenie => Moved successfully. C:\Users\User\AppData\Roaming\0C1I1L1R1J0M1P0I1G => Moved successfully. C:\Users\User\AppData\Roaming\AVG => Moved successfully. C:\Users\User\AppData\Roaming\Babylon => Moved successfully. C:\Users\User\AppData\Roaming\DSite => Moved successfully. C:\Users\User\AppData\Roaming\File Scout => Moved successfully. C:\Users\User\AppData\Roaming\newnext.me => Moved successfully. C:\Users\User\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\User\AppData\Roaming\PDF Creator Packages => Moved successfully. C:\Users\User\AppData\Roaming\PDF Reader Packages => Moved successfully. C:\Users\User\AppData\Roaming\Systweak => Moved successfully. C:\Users\User\AppData\Roaming\_MDLogs => Moved successfully. C:\Users\User\AppData\Roaming\mozilla => Moved successfully. C:\Users\User\Documents\Mobogenie => Moved successfully. C:\Windows\system32\roboot64.exe => Moved successfully. C:\Windows\SysWOW64\unrar.dll => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====