Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01 Ran by Wlasciciel at 2014-04-09 22:35:25 Run:1 Running from C:\Users\Wlasciciel\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\ProgramData\IePluginService\PluginService.exe (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe () C:\Program Files\HypeNet\updateHypeNet.exe () C:\Program Files\HypeNet\bin\utilHypeNet.exe () C:\Program Files\HypeNet\bin\FilterApp_C.exe () C:\Program Files\HypeNet\bin\XTLSApp.exe R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [515584 2014-03-17] (Cherished Technololgy LIMITED) R2 Update HypeNet; C:\Program Files\HypeNet\updateHypeNet.exe [350488 2014-04-03] () R2 Util HypeNet; C:\Program Files\HypeNet\bin\utilHypeNet.exe [350488 2014-04-03] () R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [496640 2014-03-21] (Cherished Technololgy LIMITED) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49376 2013-05-09] () R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [175176 2013-06-28] () R1 wStLibG; C:\Windows\System32\drivers\wStLibG.sys [52920 2014-03-25] (StdLib) S3 catchme; \??\C:\Users\WLASCI~1\AppData\Local\Temp\catchme.sys [X] S1 MpKsldb94ad8e; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5EA76B44-1333-4994-A589-7832CF9F483B}\MpKsldb94ad8e.sys [X] AppInit_DLLs: C:\PROGRA~1\SupTab\SEARCH~1.DLL => C:\Program Files\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B&q={searchTerms} SearchScopes: HKCU - {1DD39B51-5928-4D09-94EC-8656C6978B77} URL = http://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10267&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AGY&apn_dtid=^YYYYYY^YY^PL&apn_uid=42ee4fcc-6d61-40fa-a1bb-286e1efca2f7&apn_sauid=85E48FE6-4AD4-413F-81E2-64F9652E5C0E SearchScopes: HKCU - {277D5806-0606-4E73-A17F-AC510595B0C5} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289075&CUI=UN20361405939091307&UM=1 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B&q={searchTerms} SearchScopes: HKCU - {6B863112-EC7B-494D-8640-606A255A3C9C} URL = BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll (Thinknice Co. Limited) BHO: No Name - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No File Toolbar: HKLM - No Name - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No File CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Wlasciciel\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-21] CHR StartMenuInternet: Google Chrome - C:\Users\Administrator\AppData\Local\Google\Chrome\Application\chrome.exe FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe http://start.qone8.com/?type=sc&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://start.qone8.com/?type=sc&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk -> C:\Program Files\Opera\opera.exe (Opera Software) -> hxxp://start.qone8.com/?type=sc&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B ShortcutWithArgument: C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Users\Wlasciciel\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://start.qone8.com/?type=sc&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B ShortcutWithArgument: C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Users\Wlasciciel\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://start.qone8.com/?type=sc&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B ShortcutWithArgument: C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://start.qone8.com/?type=sc&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B ShortcutWithArgument: C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk -> C:\Program Files\Opera\opera.exe (Opera Software) -> hxxp://start.qone8.com/?type=sc&ts=1395395801&from=sien&uid=TOSHIBAXMK2565GSXN_31COB6L6BXX31COB6L6B C:\Windows\System32\drivers\aswVmm.sys.sum C:\Windows\System32\drivers\aswSP.sys.sum C:\Windows\System32\drivers\aswSnx.sys.sum C:\Windows\System32\drivers\aswVmm.sys C:\Windows\System32\drivers\aswRvrt.sys C:\Windows\System32\drivers\wStLibG.sys Reboot: ***************** C:\ProgramData\IePluginService\PluginService.exe => No running process found C:\ProgramData\WPM\wprotectmanager.exe => No running process found C:\Program Files\HypeNet\updateHypeNet.exe => No running process found C:\Program Files\HypeNet\bin\utilHypeNet.exe => No running process found C:\Program Files\HypeNet\bin\FilterApp_C.exe => No running process found C:\Program Files\HypeNet\bin\XTLSApp.exe => No running process found IePluginService => Service deleted successfully. Update HypeNet => Service not found. Util HypeNet => Service not found. Wpm => Service not found. aswRvrt => Service stopped successfully. aswRvrt => Service deleted successfully. aswVmm => Unable to stop service aswVmm => Service deleted successfully. wStLibG => Service stopped successfully. wStLibG => Service deleted successfully. catchme => Service deleted successfully. MpKsldb94ad8e => Service not found. "C:\\PROGRA~1\\SupTab\\SEARCH~1.DLL" => Value Data removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1DD39B51-5928-4D09-94EC-8656C6978B77} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{1DD39B51-5928-4D09-94EC-8656C6978B77} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{277D5806-0606-4E73-A17F-AC510595B0C5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{277D5806-0606-4E73-A17F-AC510595B0C5} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6B863112-EC7B-494D-8640-606A255A3C9C} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6B863112-EC7B-494D-8640-606A255A3C9C} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key deleted successfully. HKCR\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => Key deleted successfully. HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => Value deleted successfully. HKCR\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => Key not found. HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma => Key deleted successfully. C:\Users\Wlasciciel\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => File not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk => File not found. C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk => File not found. C:\Users\Wlasciciel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk => Shortcut argument was removed successfully. C:\Windows\System32\drivers\aswVmm.sys.sum => Moved successfully. C:\Windows\System32\drivers\aswSP.sys.sum => Moved successfully. C:\Windows\System32\drivers\aswSnx.sys.sum => Moved successfully. C:\Windows\System32\drivers\aswVmm.sys => Moved successfully. C:\Windows\System32\drivers\aswRvrt.sys => Moved successfully. C:\Windows\System32\drivers\wStLibG.sys => Moved successfully. The system needed a reboot. ==== End of Fixlog ====