Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-02-2014 Ran by Rusher at 2014-02-08 17:09:19 Run:1 Running from C:\Users\Rusher\Desktop\programsy Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {8582702B-8107-4617-B473-870868C8687C} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-08-24] () Task: {8EA0CE7E-07C8-41A5-929B-0F1458CD472A} - System32\Tasks\FoxTab => C:\Users\Rusher\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE Task: {990DA3FA-C461-4F48-9C47-1B76C5B08B70} - System32\Tasks\Torntv V6.0-updater => C:\Program Files (x86)\Torntv V6.0\Torntv V6.0-updater.exe [2013-11-29] (installdaddy) Task: {9A224064-B548-43AC-9FC8-DAEBC2D96BDC} - System32\Tasks\DealPlyUpdate => C:\Program Task: {D3BB0EA2-F0E5-4C20-A2D4-9A30D23F42C0} - System32\Tasks\Torntv V6.0-firefoxinstaller => C:\Program Files (x86)\Torntv V6.0\Torntv V6.0-firefoxinstaller.exe [2013-11-29] () Task: {EDB19EC2-DB6F-44FC-86E8-DBDC8DD56DF2} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-08-24] () Task: {F06A518B-6C0F-498A-84D5-1F203A0720E3} - System32\Tasks\{2D6AA906-C93D-461E-B571-35D90F84CE79} => D:\Warhammer 40.000 Dawn of War - DARK CRUSADE\DarkCrusade.exe Task: {F3E841F5-BFC3-442C-AF78-5060D539AD67} - System32\Tasks\Game_Booster_AutoUpdate => D:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Rusher\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\Torntv V6.0-firefoxinstaller.job => C:\Program Files (x86)\Torntv V6.0\Torntv V6.0-firefoxinstaller.exe Task: C:\Windows\Tasks\Torntv V6.0-updater.job => C:\Program Files (x86)\Torntv V6.0\Torntv V6.0-updater.exe HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1377244360 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1377244360 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1377244360 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1375793149 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1375793149 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1375793149 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?utm_source=b&utm_medium=bnd&from=bnd&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1375793149 SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=D641162F68B6C954&affID=119357&tsp=4996 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=D641162F68B6C954&affID=119357&tsp=4996 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547550A9E384_J2150050CTEXRDCTEXRDX&ts=1377244360 BHO-x32: No Name - {2316c625-b487-4410-a1a5-ff040b65245f} - No File BHO-x32: DealPly Shopping - {9cf699ca-2174-4ed8-bec1-ba82095edce0} - C:\Program Files (x86)\DealPly\DealPlyIE.dll No File BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.24.6\bh\delta.dll No File Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.24.6\deltaTlbr.dll No File FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll () FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll () CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Rusher\AppData\Roaming\BabSolution\CR\Delta.crx [2014-01-08] CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - \User Data\Default\Extensions\newtab.crx [2013-08-23] CHR HKLM-x32\...\Chrome\Extension: [koalekbhpbggkcfhkkbolikjoaobbppi] - C:\Program Files (x86)\PutLockerDownloader\PutLockerDownloader10.crx [2013-04-11] S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-24] () S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-24] () R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [424104 2013-08-23] (Taiwan Shui Mu Chih Ching Technology Limited.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 WinRing0_1_2_0; \??\D:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" C:\Users\Rusher\AppData\Roaming\0F1F1C2Y1H1P1C0I0T C:\Users\Rusher\AppData\Roaming\BabSolution C:\Users\Rusher\AppData\Roaming\Babylon C:\Users\Rusher\AppData\Roaming\Dealply C:\Users\Rusher\AppData\Roaming\eIntaller C:\Users\Rusher\AppData\Roaming\FoxTab ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8582702B-8107-4617-B473-870868C8687C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8582702B-8107-4617-B473-870868C8687C} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineCore => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8EA0CE7E-07C8-41A5-929B-0F1458CD472A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EA0CE7E-07C8-41A5-929B-0F1458CD472A} => Key deleted successfully. C:\Windows\System32\Tasks\FoxTab => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{990DA3FA-C461-4F48-9C47-1B76C5B08B70} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{990DA3FA-C461-4F48-9C47-1B76C5B08B70} => Key deleted successfully. C:\Windows\System32\Tasks\Torntv V6.0-updater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Torntv V6.0-updater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9A224064-B548-43AC-9FC8-DAEBC2D96BDC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A224064-B548-43AC-9FC8-DAEBC2D96BDC} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D3BB0EA2-F0E5-4C20-A2D4-9A30D23F42C0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3BB0EA2-F0E5-4C20-A2D4-9A30D23F42C0} => Key deleted successfully. C:\Windows\System32\Tasks\Torntv V6.0-firefoxinstaller => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Torntv V6.0-firefoxinstaller => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EDB19EC2-DB6F-44FC-86E8-DBDC8DD56DF2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EDB19EC2-DB6F-44FC-86E8-DBDC8DD56DF2} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F06A518B-6C0F-498A-84D5-1F203A0720E3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F06A518B-6C0F-498A-84D5-1F203A0720E3} => Key deleted successfully. C:\Windows\System32\Tasks\{2D6AA906-C93D-461E-B571-35D90F84CE79} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2D6AA906-C93D-461E-B571-35D90F84CE79} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F3E841F5-BFC3-442C-AF78-5060D539AD67} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E841F5-BFC3-442C-AF78-5060D539AD67} => Key deleted successfully. C:\Windows\System32\Tasks\Game_Booster_AutoUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Game_Booster_AutoUpdate => Key deleted successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\FoxTab.job => Moved successfully. C:\Windows\Tasks\Torntv V6.0-firefoxinstaller.job => Moved successfully. C:\Windows\Tasks\Torntv V6.0-updater.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316c625-b487-4410-a1a5-ff040b65245f} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{2316c625-b487-4410-a1a5-ff040b65245f} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9cf699ca-2174-4ed8-bec1-ba82095edce0} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9cf699ca-2174-4ed8-bec1-ba82095edce0} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Key deleted successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=3 => Key deleted successfully. C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=9 => Key deleted successfully. C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde => Key deleted successfully. "C:\Users\Rusher\AppData\Roaming\BabSolution\CR\Delta.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo => Key deleted successfully. \User Data\Default\Extensions\newtab.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\koalekbhpbggkcfhkkbolikjoaobbppi => Key deleted successfully. C:\Program Files (x86)\PutLockerDownloader\PutLockerDownloader10.crx => Moved successfully. dealplylive => Service deleted successfully. dealplylivem => Service deleted successfully. winzipersvc => Service deleted successfully. catchme => Service deleted successfully. WinRing0_1_2_0 => Service deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => Key deleted successfully. C:\Users\Rusher\AppData\Roaming\0F1F1C2Y1H1P1C0I0T => Moved successfully. C:\Users\Rusher\AppData\Roaming\BabSolution => Moved successfully. C:\Users\Rusher\AppData\Roaming\Babylon => Moved successfully. C:\Users\Rusher\AppData\Roaming\Dealply => Moved successfully. C:\Users\Rusher\AppData\Roaming\eIntaller => Moved successfully. C:\Users\Rusher\AppData\Roaming\FoxTab => Moved successfully. ==== End of Fixlog ====