Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-12-2014 Ran by ADMIN at 2014-12-11 15:15:22 Run:1 Running from C:\ Loaded Profile: ADMIN (Available profiles: ADMIN) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-1064554875-340528550-2733695748-1000\...\Run: [Search Protection] => C:\Users\ADMIN\AppData\Roaming\Search Protection\SP.EXE [1127224 2014-12-04] () Task: {01B13DEE-0EBC-44E7-875D-60A3AC10B86B} - System32\Tasks\Auslogics\BoostSpeed\Start BoostSpeed ?n ADMIN logon => C:\Program Files (x86)\Auslogics\BoostSpeed\BoostSpeed.exe Task: {E6B59B20-BBC7-4F70-9C08-16201FBD99A5} - System32\Tasks\Auslogics\BoostSpeed\Scan and Repair => Rundll32.exe TaskSchedulerHelper.dll,RunTask "BoostSpeed.exe" "-UseTray -Schedule" HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com SearchScopes: HKU\S-1-5-21-1064554875-340528550-2733695748-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1064554875-340528550-2733695748-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Browser Extensions -> {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} -> C:\Users\ADMIN\AppData\Roaming\BrowserExtensions\Coupons64.dll No File C:\Program Files (x86)\Auslogics C:\ProgramData\Auslogics C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics C:\Users\ADMIN\AppData\Roaming\Search Protection C:\Windows\System32\Tasks\Auslogics RemoveDirectory: C:\Users\ADMIN\Desktop\Stare dane programu Firefox Reg: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection" /f EmptyTemp: ***************** Processes closed successfully. HKU\S-1-5-21-1064554875-340528550-2733695748-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Search Protection => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{01B13DEE-0EBC-44E7-875D-60A3AC10B86B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01B13DEE-0EBC-44E7-875D-60A3AC10B86B}" => Key deleted successfully. Could not move "C:\Windows\System32\Tasks\Auslogics\BoostSpeed\Start BoostSpeed ?n ADMIN logon" => Scheduled to move on reboot. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Auslogics\BoostSpeed\Start BoostSpeed ?n ADMIN logon" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E6B59B20-BBC7-4F70-9C08-16201FBD99A5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B59B20-BBC7-4F70-9C08-16201FBD99A5}" => Key deleted successfully. C:\Windows\System32\Tasks\Auslogics\BoostSpeed\Scan and Repair => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Auslogics\BoostSpeed\Scan and Repair" => Key deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. "HKU\S-1-5-21-1064554875-340528550-2733695748-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKU\S-1-5-21-1064554875-340528550-2733695748-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key deleted successfully. "HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}" => Key deleted successfully. "HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}" => Key deleted successfully. C:\Program Files (x86)\Auslogics => Moved successfully. C:\ProgramData\Auslogics => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics => Moved successfully. C:\Users\ADMIN\AppData\Roaming\Search Protection => Moved successfully. C:\Windows\System32\Tasks\Auslogics => Moved successfully. "C:\Users\ADMIN\Desktop\Stare dane programu Firefox" => Removed successfully. ========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 702.4 MB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-12-11 15:18:15)<= C:\Windows\System32\Tasks\Auslogics\BoostSpeed\Start BoostSpeed ?n ADMIN logon => Is moved successfully. ==== End of Fixlog ====