Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-06-2014 Ran by Marcin at 2014-06-10 22:19:08 Run:1 Running from C:\Users\Marcin\Desktop\frst Boot Mode: Normal ============================================== Content of fixlist: ***************** (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe (Fuyu LIMITED) C:\ProgramData\WindowsProtectManger\wprotectmanager.exe R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) R2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe [573344 2014-06-03] (Fuyu LIMITED) R1 {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64; C:\Windows\System32\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64.sys [61112 2014-05-22] (StdLib) S3 ASUSProcObsrv; \??\E:\I386\AsPrOb64.sys [X] S3 GPU-Z; \??\C:\Users\Marcin\AppData\Local\Temp\GPU-Z.sys [X] Task: {B29B09DD-D2CD-4C36-9A7B-B83D69216697} - System32\Tasks\SN.Booster-S-1532781606 => c:\programdata\superbapp\sn.booster\SN.Booster.exe Task: C:\windows\Tasks\SN.Booster-S-1532781606.job => c:\programdata\superbapp\sn.booster\SN.Booster.exe HKLM-x32\...\Run: [fst_pl_121] => [X] HKU\S-1-5-21-3157971982-3015690372-1238881662-1001\...\Run: [UpdateChecker] => C:\Users\Marcin\AppData\Local\Popajar\UpdateChecker\UpdateCheckerApp.exe [7168 2014-01-16] (Popajar, inc) AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1401808341&from=tt4u&uid=WDCXWD5000LPVX-80V0TT0_WD-WX31A437749377493&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1401808341&from=tt4u&uid=WDCXWD5000LPVX-80V0TT0_WD-WX31A437749377493&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1401808341&from=tt4u&uid=WDCXWD5000LPVX-80V0TT0_WD-WX31A437749377493&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1401808341&from=tt4u&uid=WDCXWD5000LPVX-80V0TT0_WD-WX31A437749377493&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1401808341&from=tt4u&uid=WDCXWD5000LPVX-80V0TT0_WD-WX31A437749377493 SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.amaizingsearches.info/?l=1&q={searchTerms}&pid=34&r=2014/04/11&hid=2754579029231123871&lg=EN&cc=PL&unqvl=51 SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.amaizingsearches.info/?l=1&q={searchTerms}&pid=34&r=2014/04/11&hid=2754579029231123871&lg=EN&cc=PL&unqvl=51 SearchScopes: HKCU - {47B18540-12A2-4075-9B82-64CA780E5281} URL = http://www.idg.pl?q={searchTerms} SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.amaizingsearches.info/?l=1&q={searchTerms}&pid=34&r=2014/04/11&hid=2754579029231123871&lg=EN&cc=PL&unqvl=51 BHO: save neT - {408AC802-3DAF-C6DB-FC20-9E605D02E1CA} - C:\Program Files (x86)\save neT\uw.x64.dll () BHO: YoutubeAdblocker - {47B66310-E516-6CD1-FC87-7E7EB0A06125} - C:\Program Files (x86)\YoutubeAdblocker\1FnAtoQk7d.x64.dll () BHO: SNT - {74DD4B8D-FB69-6F7A-550B-4F1DA72C6F4B} - C:\Program Files (x86)\SNT\vd.x64.dll () CHR HKLM-x32\...\Chrome\Extension: [fjbbjfdilbioabojmcplalojlmdngbjl] - C:\Users\Marcin\AppData\Local\Temp\swlfiles\smileyswelovetoolbar.crx [2013-11-13] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION C:\Program Files (x86)\mozilla firefox\plugins C:\Program Files (x86)\save neT C:\Program Files (x86)\predm C:\Program Files (x86)\SNT C:\Program Files (x86)\SupTab C:\Program Files (x86)\trolatunt C:\Program Files (x86)\YoutubeAdblocker C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} C:\ProgramData\AVG C:\ProgramData\b7ba9ac877c2f2fd C:\ProgramData\IePluginServices C:\ProgramData\save neT C:\ProgramData\SNT C:\ProgramData\YoutubeAdblocker C:\Temp C:\Users\Marcin\AppData\Local\AVG C:\Users\Marcin\AppData\Roaming\AVG C:\Users\Marcin\AppData\Roaming\OpenCandy C:\Users\Marcin\AppData\Roaming\rmi C:\Users\Marcin\AppData\Roaming\SendSpace C:\Users\Marcin\Downloads\321D.tmp C:\windows\system32\Drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64.sys Reboot: ***************** [1720] C:\ProgramData\IePluginServices\PluginService.exe => Process closed successfully. [1820] C:\ProgramData\WindowsProtectManger\wprotectmanager.exe => Process closed successfully. IePluginServices => Service stopped successfully. IePluginServices => Service deleted successfully. WindowsProtectManger => Service deleted successfully. {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64 => Unable to stop service {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64 => Service deleted successfully. ASUSProcObsrv => Service deleted successfully. GPU-Z => Service deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B29B09DD-D2CD-4C36-9A7B-B83D69216697}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B29B09DD-D2CD-4C36-9A7B-B83D69216697}' => Key deleted successfully. C:\Windows\System32\Tasks\SN.Booster-S-1532781606 => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SN.Booster-S-1532781606' => Key deleted successfully. C:\windows\Tasks\SN.Booster-S-1532781606.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_121 => value deleted successfully. HKU\S-1-5-21-3157971982-3015690372-1238881662-1001\Software\Microsoft\Windows\CurrentVersion\Run\\UpdateChecker => value deleted successfully. "C:\PROGRA~2\SupTab\SEARCH~2.DLL" => Value Data removed successfully. "C:\PROGRA~2\SupTab\SEARCH~1.DLL" => Value Data removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackTrayMenu.lnk => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. 'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}'=> Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{47B18540-12A2-4075-9B82-64CA780E5281}' => Key deleted successfully. 'HKCR\CLSID\{47B18540-12A2-4075-9B82-64CA780E5281}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}' => Key deleted successfully. 'HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{408AC802-3DAF-C6DB-FC20-9E605D02E1CA}' => Key deleted successfully. 'HKCR\CLSID\{408AC802-3DAF-C6DB-FC20-9E605D02E1CA}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47B66310-E516-6CD1-FC87-7E7EB0A06125}' => Key deleted successfully. 'HKCR\CLSID\{47B66310-E516-6CD1-FC87-7E7EB0A06125}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74DD4B8D-FB69-6F7A-550B-4F1DA72C6F4B}' => Key deleted successfully. 'HKCR\CLSID\{74DD4B8D-FB69-6F7A-550B-4F1DA72C6F4B}' => Key deleted successfully. 'HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fjbbjfdilbioabojmcplalojlmdngbjl' => Key deleted successfully. "C:\Users\Marcin\AppData\Local\Temp\swlfiles\smileyswelovetoolbar.crx" => File/Directory not found. 'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully. C:\Program Files (x86)\mozilla firefox\plugins => Moved successfully. C:\Program Files (x86)\save neT => Moved successfully. C:\Program Files (x86)\predm => Moved successfully. C:\Program Files (x86)\SNT => Moved successfully. C:\Program Files (x86)\SupTab => Moved successfully. C:\Program Files (x86)\trolatunt => Moved successfully. C:\Program Files (x86)\YoutubeAdblocker => Moved successfully. C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} => Moved successfully. C:\ProgramData\AVG => Moved successfully. C:\ProgramData\b7ba9ac877c2f2fd => Moved successfully. C:\ProgramData\IePluginServices => Moved successfully. C:\ProgramData\save neT => Moved successfully. C:\ProgramData\SNT => Moved successfully. C:\ProgramData\YoutubeAdblocker => Moved successfully. C:\Temp => Moved successfully. C:\Users\Marcin\AppData\Local\AVG => Moved successfully. C:\Users\Marcin\AppData\Roaming\AVG => Moved successfully. C:\Users\Marcin\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Marcin\AppData\Roaming\rmi => Moved successfully. C:\Users\Marcin\AppData\Roaming\SendSpace => Moved successfully. C:\Users\Marcin\Downloads\321D.tmp => Moved successfully. C:\windows\system32\Drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w64.sys => Moved successfully. The system needed a reboot. ==== End of Fixlog ====