Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-02-2014 01 Ran by PC at 2014-02-18 23:15:52 Run:1 Running from C:\Users\PC\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1391374155&from=slbnew&uid=HitachiXHTS545032B9A300_101008PBN301GTDT9PJRX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1391374155&from=slbnew&uid=HitachiXHTS545032B9A300_101008PBN301GTDT9PJRX&q={searchTerms} SearchScopes: HKLM - DefaultScope value is missing. CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\PC\AppData\Local\foxtab_speeddial.crx [2013-11-03] CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\PC\AppData\Local\foxtab_speeddial.crx [2013-11-03] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION GroupPolicy: Group Policy on Chrome detected <======= ATTENTION HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe [761024 2013-12-10] () HKU\S-1-5-21-2651684462-118563411-3218343359-1000\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\PC\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l S2 ca82e1a5; "C:\Windows\system32\rundll32.exe" "c:\progra~1\optimi~1\OptProCrashSvc.dll",ServiceMain S2 Update Cling Clang; "C:\Program Files\Cling Clang\updateClingClang.exe" [X] S2 Update DiVapton; "C:\Program Files\DiVapton\updateDiVapton.exe" [X] S2 Update GrabRez; "C:\Program Files\GrabRez\updateGrabRez.exe" [X] S2 Util DiVapton; "C:\Program Files\DiVapton\bin\utilDiVapton.exe" [X] Task: {98511890-DAAC-49AE-8AD7-9776EAF1DB82} - System32\Tasks\{282A0D1B-427A-4D55-A981-7E1F98887817} => E:\setup.exe Task: {BDED1F01-D9B5-4D14-8EA0-2DCE76151D7B} - System32\Tasks\{3F15C611-77E0-4A38-AB05-C6339D9FC777} => E:\setup.exe Task: {C7B16BF0-7768-40BB-9C8F-15459EC1DA0B} - System32 C:\ProgramData\adiaegkmooohhhmimihafeccofkhbgpa C:\ProgramData\aommikdlfdcfodikahalfbeenlooaaip C:\ProgramData\bc8653f6fd957a68 C:\ProgramData\IePluginService C:\ProgramData\saver boX C:\ProgramData\WPM C:\Program Files\Mobogenie C:\Program Files\predm C:\Program Files\SupTab C:\ProgramData\topdoeal C:\Users\PC\AppData\Local\cache C:\Users\PC\AppData\Local\genienext C:\Users\PC\AppData\Local\Mobogenie C:\Users\PC\AppData\Roaming\iSafe C:\Users\PC\AppData\Roaming\nationzoom C:\Users\PC\AppData\Roaming\newnext.me Reg: reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\dchmpbaclbiioedakpcldenooikekokm => Key deleted successfully. C:\Users\PC\AppData\Local\foxtab_speeddial.crx => Moved successfully. HKCU\SOFTWARE\Google\Chrome\Extensions\dchmpbaclbiioedakpcldenooikekokm => Key deleted successfully. "C:\Users\PC\AppData\Local\foxtab_speeddial.crx" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKU\S-1-5-21-2651684462-118563411-3218343359-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully. ca82e1a5 => Service deleted successfully. Update Cling Clang => Service deleted successfully. Update DiVapton => Service deleted successfully. Update GrabRez => Service deleted successfully. Util DiVapton => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{98511890-DAAC-49AE-8AD7-9776EAF1DB82} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{98511890-DAAC-49AE-8AD7-9776EAF1DB82} => Key deleted successfully. C:\Windows\System32\Tasks\{282A0D1B-427A-4D55-A981-7E1F98887817} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{282A0D1B-427A-4D55-A981-7E1F98887817} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BDED1F01-D9B5-4D14-8EA0-2DCE76151D7B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BDED1F01-D9B5-4D14-8EA0-2DCE76151D7B} => Key deleted successfully. C:\Windows\System32\Tasks\{3F15C611-77E0-4A38-AB05-C6339D9FC777} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3F15C611-77E0-4A38-AB05-C6339D9FC777} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C7B16BF0-7768-40BB-9C8F-15459EC1DA0B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7B16BF0-7768-40BB-9C8F-15459EC1DA0B} => Key deleted successfully. C:\Windows\System32 should not be moved. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\TreeTask: {C7B16BF0-7768-40BB-9C8F-15459EC1DA0B} - System32 => Key not found. C:\ProgramData\adiaegkmooohhhmimihafeccofkhbgpa => Moved successfully. C:\ProgramData\aommikdlfdcfodikahalfbeenlooaaip => Moved successfully. C:\ProgramData\bc8653f6fd957a68 => Moved successfully. C:\ProgramData\IePluginService => Moved successfully. "C:\ProgramData\saver boX" => File/Directory not found. C:\ProgramData\WPM => Moved successfully. C:\Program Files\Mobogenie => Moved successfully. C:\Program Files\predm => Moved successfully. C:\Program Files\SupTab => Moved successfully. C:\ProgramData\topdoeal => Moved successfully. C:\Users\PC\AppData\Local\cache => Moved successfully. C:\Users\PC\AppData\Local\genienext => Moved successfully. C:\Users\PC\AppData\Local\Mobogenie => Moved successfully. C:\Users\PC\AppData\Roaming\iSafe => Moved successfully. C:\Users\PC\AppData\Roaming\nationzoom => Moved successfully. C:\Users\PC\AppData\Roaming\newnext.me => Moved successfully. ========= reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needs a manual reboot. ==== End of Fixlog ====