Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-02-2014 01 Ran by Damian at 2014-02-12 10:38:23 Run:2 Running from C:\Users\Damian\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files (x86)\Cling Clang\updateClingClang.exe () C:\Program Files (x86)\Cling Clang\bin\utilClingClang.exe HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1392023715&from=tt4u&uid=TOSHIBAXMQ01ABD050_93P5S0FHSXX93P5S0FHS&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1392023715&from=tt4u&uid=TOSHIBAXMQ01ABD050_93P5S0FHSXX93P5S0FHS&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1392023715&from=tt4u&uid=TOSHIBAXMQ01ABD050_93P5S0FHSXX93P5S0FHS&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1392023715&from=tt4u&uid=TOSHIBAXMQ01ABD050_93P5S0FHSXX93P5S0FHS&q={searchTerms} BHO: No Name - {EA34C851-D481-49F5-A356-3A8B0A8F3B7E} - No File BHO-x32: Cling Clang - {aa9aa36b-5b7b-4996-b083-83ef84d53b19} - C:\Program Files (x86)\Cling Clang\ClingClangbho.dll (Cling Clang) BHO-x32: No Name - {EA34C851-D481-49F5-A356-3A8B0A8F3B7E} - No File Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Task: {A387D444-B956-452A-9DD8-B88755ADC265} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2013-12-18] () <==== ATTENTION Task: C:\windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION HKLM-x32\...\Run: [fst_pl_49] - [X] R2 Update Cling Clang; C:\Program Files (x86)\Cling Clang\updateClingClang.exe [80160 2014-02-11] () R2 Util Cling Clang; C:\Program Files (x86)\Cling Clang\bin\utilClingClang.exe [80160 2014-02-11] () S2 Update RightSurf; "C:\Program Files (x86)\RightSurf\updateRightSurf.exe" [X] S2 Util RightSurf; "C:\Program Files (x86)\RightSurf\bin\utilRightSurf.exe" [X] C:\Program Files (x86)\Bench C:\Program Files (x86)\SupTab C:\Program Files (x86)\predm C:\ProgramData\WPM C:\ProgramData\IePluginService C:\Users\Damian\AppData\Local\Temp\*.exe C:\Users\Damian\AppData\Local\Temp\*.dll C:\Users\Damian\AppData\Roaming\eCyber C:\Users\Damian\AppData\Roaming\iSafe C:\Users\Damian\Downloads\CDCoverCreator_downloader-6vM8J6SL.exe C:\Users\Damian\Downloads\Disketch 1.00_isdmgr.exe C:\Users\Damian\Downloads\VirtualDub(13335).exe C:\Users\Damian\Downloads\WinRAR(12398).exe C:\Users\Damian\Downloads\yet_another_cleaner.exe C:\windows\system32\log C:\windows\System32\Tasks\{FAD799B3-33CF-4A40-BC43-0CE2F09350A4} ***************** [2832] C:\Program Files (x86)\Cling Clang\updateClingClang.exe => Process closed successfully. [1560] C:\Program Files (x86)\Cling Clang\bin\utilClingClang.exe => Process closed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} => Key deleted successfully. HKCR\CLSID\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{aa9aa36b-5b7b-4996-b083-83ef84d53b19} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{aa9aa36b-5b7b-4996-b083-83ef84d53b19} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EA34C851-D481-49F5-A356-3A8B0A8F3B7E} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully. HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A387D444-B956-452A-9DD8-B88755ADC265} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A387D444-B956-452A-9DD8-B88755ADC265} => Error deleting key C:\Windows\System32\Tasks\bench-sys => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bench-sys => Error deleting key C:\windows\Tasks\bench-sys.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_49 => Value deleted successfully. Update Cling Clang => Service deleted successfully. Util Cling Clang => Service deleted successfully. Update RightSurf => Service deleted successfully. Util RightSurf => Service deleted successfully. C:\Program Files (x86)\Bench => Moved successfully. C:\Program Files (x86)\SupTab => Moved successfully. C:\Program Files (x86)\predm => Moved successfully. C:\ProgramData\WPM => Moved successfully. C:\ProgramData\IePluginService => Moved successfully. C:\Users\Damian\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\Damian\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Damian\AppData\Roaming\eCyber => Moved successfully. C:\Users\Damian\AppData\Roaming\iSafe => Moved successfully. C:\Users\Damian\Downloads\CDCoverCreator_downloader-6vM8J6SL.exe => Moved successfully. C:\Users\Damian\Downloads\Disketch 1.00_isdmgr.exe => Moved successfully. C:\Users\Damian\Downloads\VirtualDub(13335).exe => Moved successfully. C:\Users\Damian\Downloads\WinRAR(12398).exe => Moved successfully. C:\Users\Damian\Downloads\yet_another_cleaner.exe => Moved successfully. C:\windows\system32\log => Moved successfully. C:\windows\System32\Tasks\{FAD799B3-33CF-4A40-BC43-0CE2F09350A4} => Moved successfully. ==== End of Fixlog ====