Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014 Ran by Rafał at 2014-09-13 14:31:38 Run:1 Running from C:\Users\Rafał\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** (TMRG, Inc.) C:\Program Files (x86)\RelevantKnowledge\rlservice.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\Connectivity.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\RemoteEngine.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (SqueakyChocolate, LLC) C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Akamai Technologies, Inc.) C:\Users\Rafał\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Rafał\AppData\Local\Akamai\netsession_win.exe (TMRG, Inc.) C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe (TMRG, Inc.) C:\Program Files (x86)\RelevantKnowledge\rlvknlg32.exe (TMRG, Inc.) C:\Program Files (x86)\RelevantKnowledge\rlvknlg64.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\RemoteEngineHelper.exe (ClickMeIn Limited) C:\Program Files (x86)\VuuPC\RemoteEngineHelper.exe R2 RelevantKnowledge; C:\Program Files (x86)\RelevantKnowledge\rlservice.exe [201496 2014-07-14] (TMRG, Inc.) R2 RemoteEngineService; C:\Program Files (x86)\VuuPC\remoteengine.exe [2967568 2014-05-08] (ClickMeIn Limited) R2 VuuPCConnectivity; C:\Program Files (x86)\VuuPC\Connectivity.exe [4747280 2014-05-08] (ClickMeIn Limited) Task: {8DF0FA75-E3AC-420E-B8AC-F6363B82EBE8} - System32\Tasks\VuuPCUpdateLogin => C:\Program Files (x86)\VuuPC\VuuPCUpdater.exe [2014-05-08] (VuuPC Limited) Task: {A7958BBB-5808-4297-8075-AC10DA5DD878} - System32\Tasks\Math Problem Solver CPU => C:\Users\Rafał\AppData\Local\Math Problem Solver\cpu\Solve.exe Task: {C2147C2B-3C23-4B7F-811F-0FBCF9B3364E} - System32\Tasks\VuuPCUpdate => C:\Program Files (x86)\VuuPC\VuuPCUpdater.exe [2014-05-08] (VuuPC Limited) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey HKLM-x32\...\Run: [NPSStartup] => [X] HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\...\Run: [UpdateChecker] => C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe [7168 2013-08-25] (SqueakyChocolate, LLC) HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\RafaB\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\...\Run: [SpeedUpMyComputer] => C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\...\Run: [FixMyRegistry] => C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [1886840 2013-07-22] () AppInit_DLLs-x32: c:\progra~2\sn0310~1.boo => "c:\progra~2\sn0310~1.boo" File Not Found ShellIconOverlayIdentifiers: SugarSyncBackedUp -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: SugarSyncPending -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: SugarSyncRoot -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: SugarSyncShared -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShortcutWithArgument: C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://start.qone8.com/?type=sc&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9 ShortcutWithArgument: C:\Users\Rafał\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://start.qone8.com/?type=sc&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchsun.info/?pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchsun.info/?pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9&q={searchTerms} SearchScopes: HKLM - {D37AE709-6B4D-46DE-9F96-E9B00E902BC5} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKLM-x32 - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchsun.info/?l=1&q={searchTerms}&pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9&q={searchTerms} SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchsun.info/?l=1&q={searchTerms}&pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52 SearchScopes: HKLM-x32 - {D37AE709-6B4D-46DE-9F96-E9B00E902BC5} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - DefaultScope {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchsun.info/?l=1&q={searchTerms}&pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1382384907&from=cor&uid=WDCXWD10JPVT-24A1YT0_WD-WXD1E33KCAC9KCAC9&q={searchTerms} SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.searchsun.info/?l=1&q={searchTerms}&pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52 SearchScopes: HKCU - {D37AE709-6B4D-46DE-9F96-E9B00E902BC5} URL = Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File FF HKLM-x32\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files (x86)\RelevantKnowledge\firefox CHR HKLM-x32\...\Chrome\Extension: [mkndcbhcgphcfkkddanakjiepeknbgle] - C:\Program Files (x86)\RelevantKnowledge\rlcm.crx [2014-08-18] CHR HomePage: Default -> hxxp://websearch.searchsun.info/?pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52 CHR StartupUrls: Default -> "hxxp://websearch.searchsun.info/?pid=34&r=2014/05/23&hid=11616850016229743367&lg=EN&cc=PL&unqvl=52" C:\ProgramData\Temp C:\Users\Rafał\AppData\Local\Math Problem Solver C:\Users\Rafał\AppData\Roaming\OpenCandy C:\Users\Rafał\AppData\Roaming\SendSpace C:\WINDOWS\SysWOW64\rlls.dll C:\WINDOWS\system32\rlls64.dll RemoveDirectory: K:\$RECYCLE.BIN RemoveDirectory: K:\RECYCLER CMD: attrib /d /s -s -h -r K:\* Folder: D:\Programy\Inventor\Inventor 2013\Bin Reboot: ***************** [2140] C:\Program Files (x86)\RelevantKnowledge\rlservice.exe => Process closed successfully. [2408] C:\Program Files (x86)\VuuPC\Connectivity.exe => Process closed successfully. [3292] C:\Program Files (x86)\VuuPC\RemoteEngine.exe => Process closed successfully. [968] C:\Windows\System32\rundll32.exe => Process closed successfully. [516] C:\Program Files (x86)\SqueakyChocolate\UpdateChecker\UpdateCheckerApp.exe => Process closed successfully. [5792] C:\Windows\SysWOW64\cmd.exe => Process closed successfully. [1408] C:\Users\Rafał\AppData\Local\Akamai\netsession_win.exe => Process closed successfully. [5784] C:\Users\Rafał\AppData\Local\Akamai\netsession_win.exe => Process closed successfully. [7832] C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe => Process closed successfully. C:\Program Files (x86)\RelevantKnowledge\rlvknlg32.exe => No running process found C:\Program Files (x86)\RelevantKnowledge\rlvknlg64.exe => No running process found C:\Program Files (x86)\VuuPC\RemoteEngineHelper.exe => No running process found C:\Program Files (x86)\VuuPC\RemoteEngineHelper.exe => No running process found RelevantKnowledge => Service deleted successfully. RemoteEngineService => Service deleted successfully. VuuPCConnectivity => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8DF0FA75-E3AC-420E-B8AC-F6363B82EBE8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8DF0FA75-E3AC-420E-B8AC-F6363B82EBE8}" => Key deleted successfully. C:\Windows\System32\Tasks\VuuPCUpdateLogin => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\VuuPCUpdateLogin" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7958BBB-5808-4297-8075-AC10DA5DD878}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7958BBB-5808-4297-8075-AC10DA5DD878}" => Key deleted successfully. C:\Windows\System32\Tasks\Math Problem Solver CPU => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Math Problem Solver CPU" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C2147C2B-3C23-4B7F-811F-0FBCF9B3364E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2147C2B-3C23-4B7F-811F-0FBCF9B3364E}" => Key deleted successfully. C:\Windows\System32\Tasks\VuuPCUpdate => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\VuuPCUpdate" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc" => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mcui_exe => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully. HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\Software\Microsoft\Windows\CurrentVersion\Run\\UpdateChecker => value deleted successfully. HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => value deleted successfully. HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SpeedUpMyComputer => value deleted successfully. HKU\S-1-5-21-1792336798-3990740207-2662239168-1001\Software\Microsoft\Windows\CurrentVersion\Run\\FixMyRegistry => value deleted successfully. "c:\progra~2\sn0310~1.boo" => Value Data removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncBackedUp" => Key deleted successfully. "HKCR\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncPending" => Key deleted successfully. "HKCR\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncRoot" => Key deleted successfully. "HKCR\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncShared" => Key deleted successfully. "HKCR\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}" => Key deleted successfully. C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Rafał\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D37AE709-6B4D-46DE-9F96-E9B00E902BC5}" => Key deleted successfully. "HKCR\CLSID\{D37AE709-6B4D-46DE-9F96-E9B00E902BC5}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D37AE709-6B4D-46DE-9F96-E9B00E902BC5}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{D37AE709-6B4D-46DE-9F96-E9B00E902BC5}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key deleted successfully. "HKCR\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D37AE709-6B4D-46DE-9F96-E9B00E902BC5}" => Key deleted successfully. "HKCR\CLSID\{D37AE709-6B4D-46DE-9F96-E9B00E902BC5}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A} => value deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle" => Key deleted successfully. C:\Program Files (x86)\RelevantKnowledge\rlcm.crx => Moved successfully. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\Rafał\AppData\Local\Math Problem Solver => Moved successfully. C:\Users\Rafał\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Rafał\AppData\Roaming\SendSpace => Moved successfully. C:\WINDOWS\SysWOW64\rlls.dll => Moved successfully. C:\WINDOWS\system32\rlls64.dll => Moved successfully. "K:\$RECYCLE.BIN" => removed successfully. "K:\RECYCLER" => removed successfully. ========= attrib /d /s -s -h -r K:\* ========= Access denied - K:\System Volume Information ========= End of CMD: ========= ========================= Folder: D:\Programy\Inventor\Inventor 2013\Bin ======================== 2014-03-10 10:30 - 2014-04-23 23:58 - 0000000 ____D () D:\Programy\Inventor\Inventor 2013\Bin\Bin32 ====== End of Folder: ====== The system needed a reboot. ==== End of Fixlog ====