Fix result of Farbar Recovery Scan Tool (x86) Version: 11-07-2015 Ran by Samsung at 2015-07-11 19:01:04 Run:1 Running from C:\Users\Samsung\Desktop Loaded Profiles: Samsung (Available Profiles: Samsung) Boot Mode: Normal ============================================== fixlist content: ***************** Task: {026F0EB1-4DF4-4B4F-B378-2A6C371920C9} - System32\Tasks\{4B2FFD53-CEB4-433F-92C8-13575CBB1FA4} => pcalua.exe -a "C:\Program Files\PLAY ONLINE\uninst.exe" Task: {0F692952-7E0F-4194-9F9E-42EE64428F6C} - System32\Tasks\{6717F9D9-475A-4171-A96B-682F21BBFDA1} => pcalua.exe -a "C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" -c /z-uninstall Task: {6B02A7A4-038B-49A4-995F-95FD0E209A33} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe C:\Program Files\MiuiTab SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.istartsur...q={searchTerms} BHO: LuckyTab Class -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} -> C:\Program Files\MiuiTab\SupTab.dll [2015-06-24] (Thinknice Co. Limited) Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Toolbar: HKU\S-1-5-21-1205272132-2967772875-2806619080-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File FF DefaultSearchEngine: istartsurf FF SelectedSearchEngine: istartsurf FF SearchPlugin: C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6ktw6af8.default\searchplugins\istartsurf.xml [2015-07-10] FF Extension: Search Enginer - C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6ktw6af8.default\Extensions\sweetsearch@gmail.com [2015-07-10] FF HKLM\...\Firefox\Extensions: [sweetsearch@gmail.com] - C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6ktw6af8.default\extensions\sweetsearch@gmail.com CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\ R2 IHProtect Service; C:\Program Files\MiuiTab\ProtectService.exe [125112 2015-06-24] (XTab system) S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X] S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] C:\ProgramData\IHProtectUpDate C:\Users\Samsung\Desktop\SpyHunter-Installer.exe EmptyTemp: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{026F0EB1-4DF4-4B4F-B378-2A6C371920C9}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{026F0EB1-4DF4-4B4F-B378-2A6C371920C9}" => key removed successfully. C:\Windows\System32\Tasks\{4B2FFD53-CEB4-433F-92C8-13575CBB1FA4} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4B2FFD53-CEB4-433F-92C8-13575CBB1FA4}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0F692952-7E0F-4194-9F9E-42EE64428F6C}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F692952-7E0F-4194-9F9E-42EE64428F6C}" => key removed successfully. C:\Windows\System32\Tasks\{6717F9D9-475A-4171-A96B-682F21BBFDA1} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6717F9D9-475A-4171-A96B-682F21BBFDA1}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6B02A7A4-038B-49A4-995F-95FD0E209A33}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6B02A7A4-038B-49A4-995F-95FD0E209A33}" => key removed successfully. C:\Windows\System32\Tasks\SpyHunter4Startup => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup" => key removed successfully. "C:\Program Files\MiuiTab" => File/Folder not found. HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully. "HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found. HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key not found. HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key not found. HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => key not found. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => key not found. HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} => key not found. HKCR\CLSID\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} => key not found. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= HKU\S-1-5-21-1205272132-2967772875-2806619080-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. Firefox DefaultSearchEngine removed successfully. Firefox SelectedSearchEngine removed successfully. "C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6ktw6af8.default\searchplugins\istartsurf.xml" => not found. C:\Users\Samsung\AppData\Roaming\Mozilla\Firefox\Profiles\6ktw6af8.default\Extensions\sweetsearch@gmail.com => not found. HKLM\Software\Mozilla\Firefox\Extensions\\sweetsearch@gmail.com => value not found. "HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => key removed successfully. IHProtect Service => Service not found. ewusbnet => Service removed successfully. ew_hwusbdev => Service removed successfully. ew_usbenumfilter => Service removed successfully. huawei_cdcacm => Service removed successfully. huawei_enumerator => Service removed successfully. huawei_ext_ctrl => Service removed successfully. huawei_wwanecm => Service removed successfully. hwdatacard => Service removed successfully. "C:\ProgramData\IHProtectUpDate" => File/Folder not found. C:\Users\Samsung\Desktop\SpyHunter-Installer.exe => moved successfully. EmptyTemp: => 441.2 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 19:02:40 ====