Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-09-2014 01 Ran by Media at 2014-09-24 05:08:39 Run:1 Running from C:\Users\Media\Desktop\Nowy folder Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-2002578763-3834841585-2894884081-1001\...\Run: [Yahoo! Search] => C:\Users\Media\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzuzy0C0ByBtD0DtC0D0EyDtAyB0C0CyByDtN0D0Tzu0CtByEyCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=409711820 SearchScopes: HKLM-x32 - Backup.Old.DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} SearchScopes: HKLM-x32 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1Qzuzy0C0ByBtD0DtC0D0EyDtAyB0C0CyByDtN0D0Tzu0CtByEyCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=409711820 SearchScopes: HKCU - Backup.Old.DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Task: {09A8B45B-7A9A-4643-B4CF-170ADEA6FEF6} - System32\Tasks\Yahoo! Search Udpater => C:\Users\Media\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrsetup.exe Task: {6635039E-DAC2-4CB3-BDD1-3A6F867632D2} - System32\Tasks\{056BAE49-F8DC-4862-9C64-15F59F42B98A} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=5.0.0.156.259&LastError=404 Task: {6A6E99E6-FC82-4032-B5BC-05B4D3378AED} - System32\Tasks\{46CC9C09-E919-463A-A857-61A3308DFB56} => Iexplore.exe http://ui.skype.com/ui/0/5.10.0.115.259/pl/abandoninstall?source=lightinstaller&page=tsInstall Task: {781A960F-3EE6-4A8A-BFB8-7152AC60798E} - System32\Tasks\{690B0C16-D596-459D-8425-6CB21E062768} => Firefox.exe Task: {B5B25082-C247-45C0-9D78-EECEB5156843} - System32\Tasks\{1A73E328-0D25-49CB-918C-66C56858E2F4} => Firefox.exe Task: {C8DAA606-8DFB-43FA-85E6-554CF52F5069} - System32\Tasks\{31FA67F2-EA51-4C07-892D-7BDA956E97F3} => Firefox.exe Task: {F3050076-CBE2-4D42-BF21-E91BDFA777AD} - System32\Tasks\{110C1679-876F-49D3-8503-C1AF2959DCF7} => Chrome.exe CustomCLSID: HKU\S-1-5-21-2002578763-3834841585-2894884081-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Media\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File S2 Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [X] U3 BcmSqlStartupSvc; No ImagePath U2 CLKMSVC10_3A60B698; No ImagePath U2 CLKMSVC10_C3B3B687; No ImagePath U2 DriverService; No ImagePath U2 IAStorDataMgrSvc; No ImagePath U2 iATAgentService; No ImagePath U2 idealife Update Service; No ImagePath U3 IGRS; No ImagePath U2 IviRegMgr; No ImagePath U2 nvUpdatusService; No ImagePath U2 Oasis2Service; No ImagePath U2 PCCarerService; No ImagePath U2 ReadyComm.DirectRouter; No ImagePath U2 RichVideo; No ImagePath U2 RtLedService; No ImagePath U2 SeaPort; No ImagePath U2 SoftwareService; No ImagePath U3 SQLWriter; No ImagePath U2 Stereo Service; No ImagePath C:\Users\Media\AppData\Local\Google C:\Users\Media\Downloads\*(*)*.exe Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\GIMP Packages" /f Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Skype Packages" /f EmptyTemp: ***************** Processes closed successfully. HKU\S-1-5-21-2002578763-3834841585-2894884081-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo! Search => value deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. "HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope => value deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\Backup.Old.DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. "HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value deleted successfully. "HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{09A8B45B-7A9A-4643-B4CF-170ADEA6FEF6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09A8B45B-7A9A-4643-B4CF-170ADEA6FEF6}" => Key deleted successfully. C:\Windows\System32\Tasks\Yahoo! Search Udpater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Search Udpater" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6635039E-DAC2-4CB3-BDD1-3A6F867632D2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6635039E-DAC2-4CB3-BDD1-3A6F867632D2}" => Key deleted successfully. C:\Windows\System32\Tasks\{056BAE49-F8DC-4862-9C64-15F59F42B98A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{056BAE49-F8DC-4862-9C64-15F59F42B98A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A6E99E6-FC82-4032-B5BC-05B4D3378AED}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A6E99E6-FC82-4032-B5BC-05B4D3378AED}" => Key deleted successfully. C:\Windows\System32\Tasks\{46CC9C09-E919-463A-A857-61A3308DFB56} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{46CC9C09-E919-463A-A857-61A3308DFB56}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{781A960F-3EE6-4A8A-BFB8-7152AC60798E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{781A960F-3EE6-4A8A-BFB8-7152AC60798E}" => Key deleted successfully. C:\Windows\System32\Tasks\{690B0C16-D596-459D-8425-6CB21E062768} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{690B0C16-D596-459D-8425-6CB21E062768}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5B25082-C247-45C0-9D78-EECEB5156843}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B25082-C247-45C0-9D78-EECEB5156843}" => Key deleted successfully. C:\Windows\System32\Tasks\{1A73E328-0D25-49CB-918C-66C56858E2F4} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1A73E328-0D25-49CB-918C-66C56858E2F4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C8DAA606-8DFB-43FA-85E6-554CF52F5069}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8DAA606-8DFB-43FA-85E6-554CF52F5069}" => Key deleted successfully. C:\Windows\System32\Tasks\{31FA67F2-EA51-4C07-892D-7BDA956E97F3} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{31FA67F2-EA51-4C07-892D-7BDA956E97F3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3050076-CBE2-4D42-BF21-E91BDFA777AD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3050076-CBE2-4D42-BF21-E91BDFA777AD}" => Key deleted successfully. C:\Windows\System32\Tasks\{110C1679-876F-49D3-8503-C1AF2959DCF7} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{110C1679-876F-49D3-8503-C1AF2959DCF7}" => Key deleted successfully. "HKU\S-1-5-21-2002578763-3834841585-2894884081-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully. Nero BackItUp Scheduler 4.0 => Service deleted successfully. BcmSqlStartupSvc => Service deleted successfully. CLKMSVC10_3A60B698 => Service deleted successfully. CLKMSVC10_C3B3B687 => Service deleted successfully. DriverService => Service deleted successfully. IAStorDataMgrSvc => Service deleted successfully. iATAgentService => Service deleted successfully. idealife Update Service => Service deleted successfully. IGRS => Service deleted successfully. IviRegMgr => Service deleted successfully. nvUpdatusService => Service deleted successfully. Oasis2Service => Service deleted successfully. PCCarerService => Service deleted successfully. ReadyComm.DirectRouter => Service deleted successfully. RichVideo => Service deleted successfully. RtLedService => Service deleted successfully. SeaPort => Service deleted successfully. SoftwareService => Service deleted successfully. SQLWriter => Service deleted successfully. Stereo Service => Service deleted successfully. C:\Users\Media\AppData\Local\Google => Moved successfully. C:\Users\Media\Downloads\*(*)*.exe => Moved successfully. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\GIMP Packages" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Skype Packages" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 28.3 GB temporary data. The system needed a reboot. ==== End of Fixlog ====