Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-01-2015 01 Ran by Daria at 2015-01-28 10:56:13 Run:2 Running from D:\Programy Loaded Profiles: Daria (Available profiles: Daria & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} SearchScopes: HKU\S-1-5-21-3125670856-3659484653-3208966508-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={F248F14B-59C6-4A4F-96E1-87DA77C1C3BE}&mid=61f86600962947cda1d029e0253ffe02-7f6672bf4582164481bafc8f4aaf6ed3c4f25650&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2015-01-19 22:53:44&v=4.0.5.7&pid=wtu&sg=&sap=dsp&q={searchTerms} SearchScopes: HKU\S-1-5-21-3125670856-3659484653-3208966508-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms} SearchScopes: HKU\S-1-5-21-3125670856-3659484653-3208966508-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1422013307&from=cor&uid=ST500LT012-1DG142_W3P3YD5RXXXXW3P3YD5R&q={searchTerms} SearchScopes: HKU\S-1-5-21-3125670856-3659484653-3208966508-1001 -> {3B4D267E-D127-44F0-ABFE-5B80AF9624B8} URL = SearchScopes: HKU\S-1-5-21-3125670856-3659484653-3208966508-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = https://mysearch.avg.com/search?cid={F248F14B-59C6-4A4F-96E1-87DA77C1C3BE}&mid=61f86600962947cda1d029e0253ffe02-7f6672bf4582164481bafc8f4aaf6ed3c4f25650&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2015-01-19 22:53:44&v=4.0.5.7&pid=wtu&sg=&sap=dsp&q={searchTerms} BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File Task: {7B63B95B-514F-4E03-BFAE-5D3174352378} - System32\Tasks\{F91AFC00-2D32-4775-A543-D1FBB84F0199} => pcalua.exe -a "C:\Program Files\Acer\Remote Files\AcerRemoteFileSetup.exe" -c -uninstall S1 avgtp; \??\C:\WINDOWS\system32\drivers\avgtpx64.sys [X] U3 aswMBR; \??\C:\Users\Daria\AppData\Local\Temp\aswMBR.sys [X] U3 aswVmm; \??\C:\Users\Daria\AppData\Local\Temp\aswVmm.sys [X] C:\Program Files (x86)\AVG Web TuneUp C:\Program Files (x86)\Opera C:\ProgramData\AVG Security Toolbar C:\ProgramData\Norton C:\ProgramData\WindowsMangerProtect C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Packard Bell Quick Access.lnk C:\Users\Daria\AppData\Local\CrashDumps C:\Users\Daria\AppData\Local\DanuSoft C:\Users\Daria\AppData\Local\Google\Chrome\User Data\Default\Preferences C:\Users\Daria\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* C:\Users\Daria\AppData\Local\Opera Software C:\Users\Daria\AppData\Roaming\Mobogenie C:\Users\Daria\AppData\Roaming\omiga-plus C:\Users\Daria\AppData\Roaming\Opera Software C:\Users\Public\Documents\GenieSoft C:\Users\Public\Pokki C:\WINDOWS\msdownld.tmp EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found. HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3B4D267E-D127-44F0-ABFE-5B80AF9624B8} => Key not found. HKCR\CLSID\{3B4D267E-D127-44F0-ABFE-5B80AF9624B8} => Key not found. HKU\S-1-5-21-3125670856-3659484653-3208966508-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B63B95B-514F-4E03-BFAE-5D3174352378}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B63B95B-514F-4E03-BFAE-5D3174352378}" => Key deleted successfully. C:\Windows\System32\Tasks\{F91AFC00-2D32-4775-A543-D1FBB84F0199} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F91AFC00-2D32-4775-A543-D1FBB84F0199}" => Key deleted successfully. avgtp => Service deleted successfully. aswMBR => Service not found. aswVmm => Service not found. C:\Program Files (x86)\AVG Web TuneUp => Moved successfully. C:\Program Files (x86)\Opera => Moved successfully. "C:\ProgramData\AVG Security Toolbar" => File/Directory not found. C:\ProgramData\Norton => Moved successfully. "C:\ProgramData\WindowsMangerProtect" => File/Directory not found. C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Packard Bell Quick Access.lnk => Moved successfully. C:\Users\Daria\AppData\Local\CrashDumps => Moved successfully. C:\Users\Daria\AppData\Local\DanuSoft => Moved successfully. C:\Users\Daria\AppData\Local\Google\Chrome\User Data\Default\Preferences => Moved successfully. C:\Users\Daria\AppData\Local\Google\Chrome\User Data\Default\Local Storage\*localstorage* => Moved successfully. C:\Users\Daria\AppData\Local\Opera Software => Moved successfully. "C:\Users\Daria\AppData\Roaming\Mobogenie" => File/Directory not found. "C:\Users\Daria\AppData\Roaming\omiga-plus" => File/Directory not found. C:\Users\Daria\AppData\Roaming\Opera Software => Moved successfully. C:\Users\Public\Documents\GenieSoft => Moved successfully. C:\Users\Public\Pokki => Moved successfully. C:\WINDOWS\msdownld.tmp => Moved successfully. EmptyTemp: => Removed 413.9 MB temporary data. The system needed a reboot. ==== End of Fixlog 10:57:07 ====