Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-05-2014 1 Ran by Darek at 2014-05-24 20:23:26 Run:1 Running from C:\Users\Darek\Downloads\Programs Boot Mode: Normal ============================================== Content of fixlist: ***************** StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {9BFB3A14-7B0F-4D86-BEF0-3D8135714873} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=668083&p={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&affID=121845&babsrc=SP_ss&mntrId=565EC4850804C41A SearchScopes: HKCU - {9BFB3A14-7B0F-4D86-BEF0-3D8135714873} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=668083&p={searchTerms} HKU\S-1-5-21-3183270048-2252803029-1860483952-1001\...\Policies\Explorer: [] Task: {069402CA-FF24-4D49-99DF-259716B39380} - System32\Tasks\Math Problem Solver Optimize => C:\Users\Darek\AppData\Local\Math Problem Solver\Optimize.exe [2014-01-20] () Task: {1C16178A-BF83-47AF-A93A-A0A6D02F0BD5} - \AdobeFlashPlayerUpdate 2 No Task File Task: {47018E3D-3DD2-4D6E-BA1B-E94D8D49E21A} - System32\Tasks\{6D22FC70-97D5-43F7-B433-857CE1A82D57} => Y:\Smieci\UltraMon.v3.2.2.x64.Incl.Keymaker-BLiZZARD\b-um3226\keygen.exe Task: {7AABF834-792B-4550-85E5-86C250C20D41} - System32\Tasks\{48FC6D3A-D0D1-45C3-8947-BCCEC14CA802} => Y:\Smieci\UltraMon.v3.2.2.x64.Incl.Keymaker-BLiZZARD\b-um3226\keygen.exe Task: {8B5B5107-E6E2-41EA-BA5B-F2AB3A0F526B} - \AdobeFlashPlayerUpdate No Task File Task: {9BCFCB8F-4B14-40D4-BA59-706243890239} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect Task: {CD0321FA-210B-4D5F-9300-4B0F22A26A76} - System32\Tasks\Math Problem Solver CPU => C:\Users\Darek\AppData\Local\Math Problem Solver\cpu\Solve.exe Task: {EF857A88-C616-4B64-9858-95C29CDD6551} - System32\Tasks\{1C709EFA-5EBE-4354-A157-A52423A30CC8} => Z:\Blazing Angels 2 Secret Missions of WWII\Bin\BA2.exe S3 btmaudio; system32\drivers\btmaud.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 SBIOSIO; \??\C:\Users\Darek\AppData\Local\Temp\__Samsung_Update\SBIOSIO64.sys [X] C:\ProgramData\DSearchLink C:\Users\Darek\AppData\Local\Google C:\Users\Darek\AppData\Local\Math Problem Solver C:\Users\Darek\AppData\Roaming\mozilla\Firefox\Profiles\mData C:\Users\Darek\Downloads\Intel_Download_Manager_Installer.exe C:\Users\Darek\Documents\Optimizer Pro Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reboot: ***************** HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BFB3A14-7B0F-4D86-BEF0-3D8135714873} => Key deleted successfully. HKCR\CLSID\{9BFB3A14-7B0F-4D86-BEF0-3D8135714873} => Key not found. HKU\S-1-5-21-3183270048-2252803029-1860483952-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{069402CA-FF24-4D49-99DF-259716B39380} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{069402CA-FF24-4D49-99DF-259716B39380} => Key deleted successfully. C:\Windows\System32\Tasks\Math Problem Solver Optimize => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Math Problem Solver Optimize => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{1C16178A-BF83-47AF-A93A-A0A6D02F0BD5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1C16178A-BF83-47AF-A93A-A0A6D02F0BD5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47018E3D-3DD2-4D6E-BA1B-E94D8D49E21A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47018E3D-3DD2-4D6E-BA1B-E94D8D49E21A} => Key deleted successfully. C:\Windows\System32\Tasks\{6D22FC70-97D5-43F7-B433-857CE1A82D57} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6D22FC70-97D5-43F7-B433-857CE1A82D57} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7AABF834-792B-4550-85E5-86C250C20D41} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AABF834-792B-4550-85E5-86C250C20D41} => Key deleted successfully. C:\Windows\System32\Tasks\{48FC6D3A-D0D1-45C3-8947-BCCEC14CA802} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{48FC6D3A-D0D1-45C3-8947-BCCEC14CA802} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8B5B5107-E6E2-41EA-BA5B-F2AB3A0F526B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B5B5107-E6E2-41EA-BA5B-F2AB3A0F526B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9BCFCB8F-4B14-40D4-BA59-706243890239} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BCFCB8F-4B14-40D4-BA59-706243890239} => Key deleted successfully. C:\Windows\System32\Tasks\BrowserProtect => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserProtect => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD0321FA-210B-4D5F-9300-4B0F22A26A76} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD0321FA-210B-4D5F-9300-4B0F22A26A76} => Key deleted successfully. C:\Windows\System32\Tasks\Math Problem Solver CPU => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Math Problem Solver CPU => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF857A88-C616-4B64-9858-95C29CDD6551} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF857A88-C616-4B64-9858-95C29CDD6551} => Key deleted successfully. C:\Windows\System32\Tasks\{1C709EFA-5EBE-4354-A157-A52423A30CC8} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1C709EFA-5EBE-4354-A157-A52423A30CC8} => Key deleted successfully. btmaudio => Service deleted successfully. catchme => Service deleted successfully. SBIOSIO => Service deleted successfully. C:\ProgramData\DSearchLink => Moved successfully. C:\Users\Darek\AppData\Local\Google => Moved successfully. C:\Users\Darek\AppData\Local\Math Problem Solver => Moved successfully. C:\Users\Darek\AppData\Roaming\mozilla\Firefox\Profiles\mData => Moved successfully. C:\Users\Darek\Downloads\Intel_Download_Manager_Installer.exe => Moved successfully. C:\Users\Darek\Documents\Optimizer Pro => Moved successfully. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====