Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-12-2014 01 Ran by Paulinka at 2014-12-11 19:02:04 Run:1 Running from D:\PC_HELP_RU Loaded Profile: Paulinka (Available profiles: Paulinka) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1383316283&from=cor&uid=WDCXWD3200BEVT-22ZCT0_WD-WX90A992232122321 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383316283&from=cor&uid=WDCXWD3200BEVT-22ZCT0_WD-WX90A992232122321&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383316283&from=cor&uid=WDCXWD3200BEVT-22ZCT0_WD-WX90A992232122321&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383316283&from=cor&uid=WDCXWD3200BEVT-22ZCT0_WD-WX90A992232122321&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.com/web/?type=ds&ts=1383316283&from=cor&uid=WDCXWD3200BEVT-22ZCT0_WD-WX90A992232122321&q={searchTerms} SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-3453456924-2562164534-3920574783-1000 -> DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=5452fb47000000000000000000000000 SearchScopes: HKU\S-1-5-21-3453456924-2562164534-3920574783-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchTerms}&affID=119370&babsrc=SP_ss&mntrId=5452fb47000000000000000000000000 SearchScopes: HKU\S-1-5-21-3453456924-2562164534-3920574783-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={B9C74FB1-DD8A-4892-8118-D2EE4A246833}&mid=ab371f49cd7147d398a4d16f642adaf7-e161a93104eaf741d93155fade9eef6dced24665&lang=en&ds=co011&coid=&cmpid=&pr=sa&d=2013-06-22 21:33:18&v=18.1.9.799&pid=safeguard&sg=0&sap=dsp&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank Toolbar: HKU\S-1-5-21-3453456924-2562164534-3920574783-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files (x86)\T-Mobile\InternetManager_Z\Bin\addon FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.9.799 HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\...\Run: [AdobeBridge] => [X] Task: {08375E42-536C-4832-A95F-CF6F509D3FE1} - System32\Tasks\FoxTab => C:\Users\Paulinka\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {4376E3BC-071B-4267-BCA7-6D1E3F0FEA97} - System32\Tasks\{DF4CA663-8A7D-42D4-8420-D5404A0CE79B} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=6.6.0.106&LastError=12002 Task: {D31288D5-3695-4795-92B9-06FE3B03A72F} - System32\Tasks\DSite => C:\Users\Paulinka\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe [2013-02-20] () <==== ATTENTION Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Paulinka\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml C:\Program Files (x86)\mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml C:\ProgramData\WPM C:\Users\Paulinka\AppData\Roaming\0D1F1S1C1P0P1C1F1N1C1T1H2UtF1E1I C:\Users\Paulinka\AppData\Roaming\0F1F1C2Y1H1P1C0I0T C:\Users\Paulinka\AppData\Roaming\Babylon C:\Users\Paulinka\AppData\Roaming\DSite C:\Users\Paulinka\AppData\Roaming\FoxTab C:\Users\Paulinka\AppData\Roaming\Video Converter Packages Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f EmptyTemp: ***************** Processes closed successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => Key deleted successfully. "HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => Key not found. HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key deleted successfully. "HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => Key not found. "HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => value deleted successfully. "HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93}" => Key not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com => value deleted successfully. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\avg@toolbar => Value not found. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-3453456924-2562164534-3920574783-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{08375E42-536C-4832-A95F-CF6F509D3FE1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08375E42-536C-4832-A95F-CF6F509D3FE1}" => Key deleted successfully. C:\Windows\System32\Tasks\FoxTab => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4376E3BC-071B-4267-BCA7-6D1E3F0FEA97}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4376E3BC-071B-4267-BCA7-6D1E3F0FEA97}" => Key deleted successfully. C:\Windows\System32\Tasks\{DF4CA663-8A7D-42D4-8420-D5404A0CE79B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DF4CA663-8A7D-42D4-8420-D5404A0CE79B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D31288D5-3695-4795-92B9-06FE3B03A72F}" => Key not found. C:\Windows\System32\Tasks\DSite not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite" => Key not found. C:\Windows\Tasks\FoxTab.job => Moved successfully. C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml => Moved successfully. C:\Program Files (x86)\mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml => Moved successfully. C:\ProgramData\WPM => Moved successfully. "C:\Users\Paulinka\AppData\Roaming\0D1F1S1C1P0P1C1F1N1C1T1H2UtF1E1I" => File/Directory not found. "C:\Users\Paulinka\AppData\Roaming\0F1F1C2Y1H1P1C0I0T" => File/Directory not found. C:\Users\Paulinka\AppData\Roaming\Babylon => Moved successfully. C:\Users\Paulinka\AppData\Roaming\DSite => Moved successfully. "C:\Users\Paulinka\AppData\Roaming\FoxTab" => File/Directory not found. "C:\Users\Paulinka\AppData\Roaming\Video Converter Packages" => File/Directory not found. ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ALLUpdate" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 603.1 MB temporary data. The system needed a reboot. ==== End of Fixlog ====