Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-02-2014 01 Ran by Wolny at 2014-02-26 15:44:59 Run:1 Running from C:\Users\Wolny\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {020BD2E9-A708-40CC-B575-FDFDC9CE5313} - System32\Tasks\DSite => C:\Users\Wolny\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE Task: {0DA7F3A8-F4EF-43E1-A9DC-E0847796EC96} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-08-18] (DealPly Technologies Ltd) Task: {CE8485C4-41DD-4A75-B2FA-B5C74B20A012} - System32\Tasks\Dealply => C:\Users\Wolny\AppData\Roaming\Dealply\UpdateProc\UpdateTask.exe [2013-08-18] () Task: {FF3C8ADF-4787-436D-9402-6AD86650040B} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-08-18] (DealPly Technologies Ltd) Task: C:\Windows\Tasks\Dealply.job => C:\Users\Wolny\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-18] (DealPly Technologies Ltd) S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-18] (DealPly Technologies Ltd) BHO-x32: DealPly Shopping - {ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly) Toolbar: HKLM-x32 - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchou.com/?id=cae1c7490000000000007e2f68dd72ba&affilt=5 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {1A0D13F6-ABA2-4C17-982B-EE8A3ABFC83D} URL = http://searchou.com/?q={searchTerms}&id=cae1c7490000000000007e2f68dd72ba&affilt=5&r=632 SearchScopes: HKCU - {1A0D13F6-ABA2-4C17-982B-EE8A3ABFC83D} URL = http://searchou.com/?q={searchTerms}&id=cae1c7490000000000007e2f68dd72ba&affilt=5&r=632 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear GroupPolicyUsers\S-1-5-21-2118033502-355515093-2729502331-1001\User: Group Policy restriction detected R3 ALSysIO; \??\C:\Users\Wolny\AppData\Local\Temp\ALSysIO64.sys [X] C:\Users\Wolny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly C:\Users\Wolny\AppData\Roaming\DSite ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{020BD2E9-A708-40CC-B575-FDFDC9CE5313} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{020BD2E9-A708-40CC-B575-FDFDC9CE5313} => Key deleted successfully. C:\Windows\System32\Tasks\DSite => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0DA7F3A8-F4EF-43E1-A9DC-E0847796EC96} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DA7F3A8-F4EF-43E1-A9DC-E0847796EC96} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE8485C4-41DD-4A75-B2FA-B5C74B20A012} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE8485C4-41DD-4A75-B2FA-B5C74B20A012} => Key deleted successfully. C:\Windows\System32\Tasks\Dealply => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FF3C8ADF-4787-436D-9402-6AD86650040B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF3C8ADF-4787-436D-9402-6AD86650040B} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineCore => Key deleted successfully. C:\Windows\Tasks\Dealply.job => Moved successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => Moved successfully. dealplylive => Service deleted successfully. dealplylivem => Service deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1A0D13F6-ABA2-4C17-982B-EE8A3ABFC83D} => Key deleted successfully. HKCR\CLSID\{1A0D13F6-ABA2-4C17-982B-EE8A3ABFC83D} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. C:\Windows\system32\GroupPolicyUsers\S-1-5-21-2118033502-355515093-2729502331-1001\User => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. ALSysIO => Service deleted successfully. "C:\Users\Wolny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly" directory move: C:\Users\Wolny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly Help.url => Moved successfully. C:\Users\Wolny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly.url => Moved successfully. C:\Users\Wolny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\Uninstall DealPly.lnk => Moved successfully. "C:\Users\Wolny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly" => Directory moved successfully. C:\Users\Wolny\AppData\Roaming\DSite => Moved successfully. The system needs a manual reboot. ==== End of Fixlog ====