Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-03-2014 02 Ran by rodzinka at 2014-03-06 16:27:24 Run:1 Running from C:\Users\rodzinka.user-Komputer\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {0F3A7AD4-8B83-4F1B-AC02-8C99099D7D36} - \DealPlyLiveUpdateTaskMachineUA No Task File Task: {1D5636A3-86A9-471D-B9B0-018DDF453908} - \EPUpdater No Task File Task: {4A4E1E4B-5C65-4371-9A52-9446C448B6E6} - System32\Tasks\{7716DFF0-9096-485C-8039-734638EEF14D} => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe Task: {62D1848B-0792-4755-A191-EDBC11A5CF8D} - \DealPlyLiveUpdateTaskMachineCore No Task File Task: {6AC16403-4C95-4444-9E98-B008C1B6C557} - \Desk 365 RunAsStdUser No Task File Task: {734797AC-8916-4736-BC55-919DF69A6939} - \BonanzaDealsLiveUpdateTaskMachineCore No Task File Task: {74E4D264-57F6-4FE6-8614-6DA649F50E03} - \BonanzaDealsUpdate No Task File Task: {8E68BC4F-E97B-4DE7-A4AB-C0C3741676DC} - \Omiga Plus RunAsStdUser No Task File Task: {9BD2239C-3409-4FBC-A55A-3E54D472766E} - \BonanzaDealsLiveUpdateTaskMachineUA No Task File Task: {AE3C7355-E3FA-467A-A7BD-87FB26D0F5A6} - System32\Tasks\DTReg => C:\Users\rodzinka.user-Komputer\AppData\Roaming\defaulttab\defaulttab\DTReg.exe [2014-02-06] (Search Results, LLC) Task: {B7FF19C2-A40D-4637-A016-2C8AE69BED00} - \Program aktualizacji online firmy Adobe. No Task File Task: {D88E2FA5-CD99-416A-8E8E-7BF2F0B21022} - System32\Tasks\Go for FilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mysearchresults.com/?c=3524&t=01 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {44631301-9E9A-4D74-9A29-26070680D12A} URL = http://www.mysearchresults.com/search?c=3519&t=01&q={searchTerms} Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] U3 aftcaaob; \??\C:\Users\RODZIN~1.USE\AppData\Local\Temp\aftcaaob.sys [X] C:\Users\rodzinka.user-Komputer\Downloads\everesthome220(dobreprogramy.pl).exe C:\Program Files (x86)\G Data C:\ProgramData\G Data C:\Users\rodzinka.user-Komputer\AppData\Local\Mobogenie C:\Users\rodzinka.user-Komputer\AppData\Roaming\newnext.me C:\Users\rodzinka.user-Komputer\daemonprocess.txt C:\Users\rodzinka.user-Komputer\AppData\Local\genienext Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_14" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetIM" /f ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0F3A7AD4-8B83-4F1B-AC02-8C99099D7D36} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F3A7AD4-8B83-4F1B-AC02-8C99099D7D36} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D5636A3-86A9-471D-B9B0-018DDF453908} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D5636A3-86A9-471D-B9B0-018DDF453908} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4A4E1E4B-5C65-4371-9A52-9446C448B6E6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A4E1E4B-5C65-4371-9A52-9446C448B6E6} => Key deleted successfully. C:\Windows\System32\Tasks\{7716DFF0-9096-485C-8039-734638EEF14D} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7716DFF0-9096-485C-8039-734638EEF14D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{62D1848B-0792-4755-A191-EDBC11A5CF8D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{62D1848B-0792-4755-A191-EDBC11A5CF8D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineCore => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6AC16403-4C95-4444-9E98-B008C1B6C557} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6AC16403-4C95-4444-9E98-B008C1B6C557} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{734797AC-8916-4736-BC55-919DF69A6939} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{734797AC-8916-4736-BC55-919DF69A6939} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{74E4D264-57F6-4FE6-8614-6DA649F50E03} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74E4D264-57F6-4FE6-8614-6DA649F50E03} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8E68BC4F-E97B-4DE7-A4AB-C0C3741676DC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E68BC4F-E97B-4DE7-A4AB-C0C3741676DC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Omiga Plus RunAsStdUser => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9BD2239C-3409-4FBC-A55A-3E54D472766E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BD2239C-3409-4FBC-A55A-3E54D472766E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AE3C7355-E3FA-467A-A7BD-87FB26D0F5A6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE3C7355-E3FA-467A-A7BD-87FB26D0F5A6} => Key deleted successfully. C:\Windows\System32\Tasks\DTReg => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DTReg => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7FF19C2-A40D-4637-A016-2C8AE69BED00} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7FF19C2-A40D-4637-A016-2C8AE69BED00} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Program aktualizacji online firmy Adobe. => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D88E2FA5-CD99-416A-8E8E-7BF2F0B21022} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D88E2FA5-CD99-416A-8E8E-7BF2F0B21022} => Key deleted successfully. C:\Windows\System32\Tasks\Go for FilesUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Go for FilesUpdate => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{44631301-9E9A-4D74-9A29-26070680D12A} => Key deleted successfully. HKCR\CLSID\{44631301-9E9A-4D74-9A29-26070680D12A} => Key not found. HKCR\PROTOCOLS\Handler\linkscanner => Key deleted successfully. HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key not found. HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully. HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key not found. HKCR\Wow6432Node\PROTOCOLS\Handler\linkscanner => Key not found. HKCR\Wow6432Node\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => Key not found. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. cpuz135 => Service deleted successfully. gdrv => Service deleted successfully. Synth3dVsc => Service deleted successfully. tsusbhub => Service deleted successfully. VGPU => Service deleted successfully. aftcaaob => Service not found. C:\Users\rodzinka.user-Komputer\Downloads\everesthome220(dobreprogramy.pl).exe => Moved successfully. C:\Program Files (x86)\G Data => Moved successfully. C:\ProgramData\G Data => Moved successfully. C:\Users\rodzinka.user-Komputer\AppData\Local\Mobogenie => Moved successfully. C:\Users\rodzinka.user-Komputer\AppData\Roaming\newnext.me => Moved successfully. C:\Users\rodzinka.user-Komputer\daemonprocess.txt => Moved successfully. C:\Users\rodzinka.user-Komputer\AppData\Local\genienext => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NextLive" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\fst_pl_14" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SweetIM" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====