Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-09-2014 01 Ran by Tomek at 2014-09-10 11:43:54 Run:1 Running from C:\Users\Tomek\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1397911756&from=amt&uid=ST9500420AS_5VJ5H405XXXX5VJ5H405&q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = FF HKLM-x32\...\Firefox\Extensions: [quick_start@gmail.com] - C:\Users\Tomek\AppData\Roaming\Mozilla\Firefox\Profiles\o8qhx26e.default\extensions\quick_start@gmail.com R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [705136 2014-04-11] (Cherished Technololgy LIMITED) C:\ProgramData\IePluginService U4 BT; No ImagePath U4 BTCOM; No ImagePath U4 BTCOMBUS; No ImagePath U4 Btcsrusb; No ImagePath S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] U4 HPSLPSVC; No ImagePath S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] U4 RSUSBSTOR; No ImagePath EmptyTemp: ***************** Processes closed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\quick_start@gmail.com => value deleted successfully. IePluginService => Service deleted successfully. C:\ProgramData\IePluginService => Moved successfully. BT => Service deleted successfully. BTCOM => Service deleted successfully. BTCOMBUS => Service deleted successfully. Btcsrusb => Service deleted successfully. cpuz136 => Service deleted successfully. HPSLPSVC => Service deleted successfully. nvvad_WaveExtensible => Service deleted successfully. RSUSBSTOR => Service deleted successfully. EmptyTemp: => Removed 265.4 MB temporary data. The system needed a reboot. ==== End of Fixlog ====