Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-02-2014 Ran by Aoeseo at 2014-02-18 01:02:58 Run:1 Running from C:\Users\Aoeseo\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1388676203&from=wpm0102&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&ts=1380577515 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&ts=1380577515 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1388676203&from=wpm0102&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1388676203&from=wpm0102&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1388676203&from=wpm0102&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE http://www.delta-homes.com/?type=sc&ts=1388676203&from=wpm0102&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388676203&from=wpm0102&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1388676203&from=wpm0102&uid=WDCXWD5000AAKX-00ERMA0_WD-WCC2EH59451994519&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B21E001E101F1ED9&affID=119828&tt=080913_nch&tsp=4999 SearchScopes: HKCU - {3E19EFB9-0C34-4FC0-B477-CDBB03D26022} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=C5A91EB5-70A1-4946-9DA5-01B1242D0757&apn_sauid=FADFCD84-FAC8-4B2C-9133-4D8F7950CE93 CHR HKCU\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\Aoeseo\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2013-09-26] CHR HKLM-x32\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\Aoeseo\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2013-09-26] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Task: {4962F270-05AB-4049-90A8-24C99CDEB5EE} - System32\Tasks\BonanzaDealsUpdate => C:\Program Task: {4D3E6C6D-00A3-4E4F-A2CD-FD164BF0501C} - System32\Tasks\{0F987157-8651-4605-81C8-42EB1CC79EC6} => F:\Setup.exe Task: {5F9824C8-6AA5-40D9-AD7C-779C6846142F} - System32\Tasks\{72357A7F-8E3A-4323-8A4A-F7B7CC523428} => F:\Setup.exe Task: {DD18E098-5F07-43C2-A84E-D573315647E2} - System32\Tasks\BrowserDefendert => Sc.exe start BrowserDefendert S2 BrowserDefendert; C:\ProgramData\BrowserDefender\2.6.1562.221\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [X] S2 AODDriver4.2; \??\C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver2.sys [X] S3 DUMeterDrv; \??\C:\Program Files (x86)\DU Meter\DUMETR64.SYS [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 massfilter_lte; \??\C:\Windows\system32\drivers\massfilter_lte.sys [X] S3 zgdcat; system32\DRIVERS\zgdcat.sys [X] S3 zgdcdiag; system32\DRIVERS\zgdcdiag.sys [X] S3 zgdcmdm; system32\DRIVERS\zgdcmdm.sys [X] S3 zgdcnet; system32\DRIVERS\zgdcnet.sys [X] S3 zgdcnmea; system32\DRIVERS\zgdcnmea.sys [X] C:\ProgramData\eSafe C:\ProgramData\WPM C:\Users\Aoeseo\AppData\Local\CRE C:\Users\Aoeseo\AppData\Roaming\desktop.ini C:\Users\Aoeseo\AppData\Roaming\Mozilla C:\Program Files (x86)\Mozilla Firefox Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f CMD: sc config "Internet w Cyfrowym Polsacie. RunOuc" start= demand ***************** HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3E19EFB9-0C34-4FC0-B477-CDBB03D26022} => Key deleted successfully. HKCR\CLSID\{3E19EFB9-0C34-4FC0-B477-CDBB03D26022} => Key not found. HKCU\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda => Key deleted successfully. "C:\Users\Aoeseo\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda => Key deleted successfully. "C:\Users\Aoeseo\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx" => File/Directory not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4962F270-05AB-4049-90A8-24C99CDEB5EE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4962F270-05AB-4049-90A8-24C99CDEB5EE} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4D3E6C6D-00A3-4E4F-A2CD-FD164BF0501C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D3E6C6D-00A3-4E4F-A2CD-FD164BF0501C} => Key deleted successfully. C:\Windows\System32\Tasks\{0F987157-8651-4605-81C8-42EB1CC79EC6} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0F987157-8651-4605-81C8-42EB1CC79EC6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5F9824C8-6AA5-40D9-AD7C-779C6846142F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F9824C8-6AA5-40D9-AD7C-779C6846142F} => Key deleted successfully. C:\Windows\System32\Tasks\{72357A7F-8E3A-4323-8A4A-F7B7CC523428} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{72357A7F-8E3A-4323-8A4A-F7B7CC523428} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DD18E098-5F07-43C2-A84E-D573315647E2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD18E098-5F07-43C2-A84E-D573315647E2} => Key deleted successfully. C:\Windows\System32\Tasks\BrowserDefendert => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert => Key deleted successfully. BrowserDefendert => Service deleted successfully. AODDriver4.2 => Service deleted successfully. DUMeterDrv => Service deleted successfully. EagleX64 => Service deleted successfully. massfilter_lte => Service deleted successfully. zgdcat => Service deleted successfully. zgdcdiag => Service deleted successfully. zgdcmdm => Service deleted successfully. zgdcnet => Service deleted successfully. zgdcnmea => Service deleted successfully. C:\ProgramData\eSafe => Moved successfully. C:\ProgramData\WPM => Moved successfully. "C:\Users\Aoeseo\AppData\Local\CRE" => File/Directory not found. C:\Users\Aoeseo\AppData\Roaming\desktop.ini => Moved successfully. C:\Users\Aoeseo\AppData\Roaming\Mozilla => Moved successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "Internet w Cyfrowym Polsacie. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ==== End of Fixlog ====