Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-07-2014 Ran by Toshba at 2014-07-22 15:33:20 Run:1 Running from C:\Users\Toshba\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [syqukqbodkr] => C:\Windows\nazkhumgcqehvsxjca.exe [614400 2014-07-21] () HKLM-x32\...\Run: [eqoyugxqlylnawald] => C:\Users\Toshba\AppData\Local\Temp\laboncwsqgwbrqxlgglb.exe [614400 2014-07-21] () HKLM-x32\...\RunOnce: [pwpulsesiqyv] => nazkhumgcqehvsxjca.exe . HKLM-x32\...\RunOnce: [xifojukcwiuvhcfp] => C:\Users\Toshba\AppData\Local\Temp\aqsggwronevbssaplmsjj.exe [614400 2014-07-21] () HKLM\...\Policies\Explorer\Run: [owqwowjypyhfo] => C:\Windows\nazkhumgcqehvsxjca.exe [614400 2014-07-21] ( ()) HKLM\...\Policies\Explorer\Run: [xctwlqamag] => C:\Users\Toshba\AppData\Local\Temp\laboncwsqgwbrqxlgglb.exe [614400 2014-07-21] ( ()) HKU\S-1-5-21-831562436-1945061552-1814410315-1000\...\Run: [syqukqbodkr] => C:\Users\Toshba\AppData\Local\Temp\eqoyugxqlylnawald.exe [614400 2014-07-21] () <===== ATTENTION HKU\S-1-5-21-831562436-1945061552-1814410315-1000\...\Run: [pytatcqgyisrbu] => ymmywkdyvkzdsqwjdcg.exe HKU\S-1-5-21-831562436-1945061552-1814410315-1000\...\RunOnce: [scygakzqjuffqkm] => nazkhumgcqehvsxjca.exe . HKU\S-1-5-21-831562436-1945061552-1814410315-1000\...\RunOnce: [pwpulsesiqyv] => C:\Users\Toshba\AppData\Local\Temp\ymmywkdyvkzdsqwjdcg.exe [614400 2014-07-21] () <===== ATTENTION HKU\S-1-5-21-831562436-1945061552-1814410315-1000\...\Policies\system: [DisableRegistryTools] 1 AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [94088 2014-07-07] (Skytech Co., Ltd.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1404744618&from=smt&uid=HitachiXHTS547564A9E384_130518J2330053E41SVBX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1404744618&from=smt&uid=HitachiXHTS547564A9E384_130518J2330053E41SVBX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1404744618&from=smt&uid=HitachiXHTS547564A9E384_130518J2330053E41SVBX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1404744618&from=smt&uid=HitachiXHTS547564A9E384_130518J2330053E41SVBX SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=1387&r=2014/07/15&hid=16084081155648035549&lg=EN&cc=PL&unqvl=56 SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=1387&r=2014/07/15&hid=16084081155648035549&lg=EN&cc=PL&unqvl=56 CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X] C:\Windows\eqoyugxqlylnawald.exe Reboot: ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\syqukqbodkr => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\eqoyugxqlylnawald => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\HKLM-x32\...\RunOnce: [pwpulsesiqyv] => nazkhumgcqehvsxjca.exe . => Value not found. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\HKLM-x32\...\RunOnce: [xifojukcwiuvhcfp] => C:\Users\Toshba\AppData\Local\Temp\aqsggwronevbssaplmsjj.exe [614400 2014-07-21] () => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\owqwowjypyhfo => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\xctwlqamag => value deleted successfully. HKU\S-1-5-21-831562436-1945061552-1814410315-1000\Software\Microsoft\Windows\CurrentVersion\Run\\syqukqbodkr => value deleted successfully. HKU\S-1-5-21-831562436-1945061552-1814410315-1000\Software\Microsoft\Windows\CurrentVersion\Run\\pytatcqgyisrbu => value deleted successfully. HKU\S-1-5-21-831562436-1945061552-1814410315-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\S-1-5-21-831562436-1945061552-1814410315-1000\...\RunOnce: [scygakzqjuffqkm] => nazkhumgcqehvsxjca.exe . => Value not found. HKU\S-1-5-21-831562436-1945061552-1814410315-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\S-1-5-21-831562436-1945061552-1814410315-1000\...\RunOnce: [pwpulsesiqyv] => C:\Users\Toshba\AppData\Local\Temp\ymmywkdyvkzdsqwjdcg.exe [614400 2014-07-21] () <===== ATTENTION => Value not found. HKU\S-1-5-21-831562436-1945061552-1814410315-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableRegistryTools => value deleted successfully. "C:\PROGRA~2\SupTab\SEARCH~1.DLL" => Value Data removed successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. 'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}' => Key deleted successfully. 'HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}' => Key deleted successfully. 'HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}'=> Key not found. 'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully. gupdate => Service deleted successfully. gupdatem => Service deleted successfully. C:\Windows\eqoyugxqlylnawald.exe => Moved successfully. The system needed a reboot. ==== End of Fixlog ====