Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-09-2013 Ran by Asus at 2013-09-09 17:29:35 Run:1 Running from C:\ Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {7A84754A-2925-49D2-81D0-2EE1E01C735C} - System32\Tasks\DealPly => C:\Users\Asus\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe [2013-03-19] () Task: {80442B51-3B7F-41B3-8C56-1FB1E4560863} - System32\Tasks\EPUpdater => C:\Users\Asus\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-08-04] () Task: {EF877950-8C03-4BA8-9729-73F8F31EC2F5} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [NTRedirect] - C:\Users\Asus\AppData\Roaming\BabSolution\Shared\enhancedNT.dll [188400 2013-08-28] () HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=8EABB6DBC9AB1619&affID=119357&tsp=4994 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.v9.com/?utm_source=b&utm_medium=update&from=update&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=1369827415 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.v9.com/?utm_source=b&utm_medium=update&from=update&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=1369827415 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.v9.com/?utm_source=b&utm_medium=update&from=update&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=1369827415 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.v9.com/?utm_source=b&utm_medium=update&from=update&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=1369827415 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://en.v9.com/?utm_source=b&utm_medium=update&from=update&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=1369827415 URLSearchHook: (No Name) - {539F76FD-084E-4858-86D5-62F02F54AE86} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://en.v9.com/?utm_source=b&utm_medium=update&from=update&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=1369827415 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=0 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=0 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=0 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=0 SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=0 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=8EABB6DBC9AB1619&affID=119357&tsp=4994 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=0 BHO-x32: MinibarBHO - {AA74D58F-ACD0-450D-A85E-6C04B171C044} - C:\Program Files (x86)\Minibar\Minibar.dll (KangoExtensions) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\qvo6.xml FF Extension: AppsHat - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\kaoglxnj.default\Extensions\{97A78363-B868-4B48-AC91-A783A31215AF} FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HitachiXHTS547575A9E384_J2140054KKEH3AKKEH3AX&ts=1377293110 CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Asus\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM-x32\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files (x86)\WebCake\WebCakeLayers.crx R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [424104 2013-08-23] (Taiwan Shui Mu Chih Ching Technology Limited.) S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [x] C:\Users\Asus\AppData\Roaming\sp_data.sys C:\Users\Asus\AppData\Local\Minibar C:\Users\Asus\AppData\Local\Babylon C:\Users\Asus\AppData\Roaming\BabSolution C:\Users\Asus\AppData\Roaming\Babylon C:\Users\Asus\AppData\Roaming\DealPly C:\Users\Asus\AppData\Roaming\eDownload C:\Users\Asus\AppData\Roaming\eIntaller C:\Users\Asus\AppData\Roaming\SimilarSites C:\Users\Asus\AppData\Roaming\temp C:\Program Files (x86)\Minibar C:\ProgramData\Babylon C:\ProgramData\eSafe ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A84754A-2925-49D2-81D0-2EE1E01C735C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A84754A-2925-49D2-81D0-2EE1E01C735C} => Key deleted successfully. C:\Windows\System32\Tasks\DealPly => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{80442B51-3B7F-41B3-8C56-1FB1E4560863} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80442B51-3B7F-41B3-8C56-1FB1E4560863} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF877950-8C03-4BA8-9729-73F8F31EC2F5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF877950-8C03-4BA8-9729-73F8F31EC2F5} => Key deleted successfully. C:\Windows\System32\Tasks\Desk 365 RunAsStdUser => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Key deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NTRedirect => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\\{539F76FD-084E-4858-86D5-62F02F54AE86} => Value deleted successfully. HKCR\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044} => Key deleted successfully. C:\Program Files (x86)\mozilla firefox\searchplugins\qvo6.xml => Moved successfully. C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\kaoglxnj.default\Extensions\{97A78363-B868-4B48-AC91-A783A31215AF} => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde => Key deleted successfully. C:\Users\Asus\AppData\Roaming\BabSolution\CR\Delta.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh => Key deleted successfully. "C:\Program Files (x86)\WebCake\WebCakeLayers.crx" => File/Directory not found. winzipersvc => Service deleted successfully. mcbootdelaystartsvc => Service deleted successfully. C:\Users\Asus\AppData\Roaming\sp_data.sys => Moved successfully. C:\Users\Asus\AppData\Local\Minibar => Moved successfully. C:\Users\Asus\AppData\Local\Babylon => Moved successfully. C:\Users\Asus\AppData\Roaming\BabSolution => Moved successfully. C:\Users\Asus\AppData\Roaming\Babylon => Moved successfully. "C:\Users\Asus\AppData\Roaming\DealPly" directory move: C:\Users\Asus\AppData\Roaming\DealPly\UpdateProc\config.dat => Moved successfully. C:\Users\Asus\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe => Moved successfully. Could not move "C:\Users\Asus\AppData\Roaming\DealPly" directory. => Scheduled to move on reboot. C:\Users\Asus\AppData\Roaming\eDownload => Moved successfully. C:\Users\Asus\AppData\Roaming\eIntaller => Moved successfully. C:\Users\Asus\AppData\Roaming\SimilarSites => Moved successfully. C:\Users\Asus\AppData\Roaming\temp => Moved successfully. C:\Program Files (x86)\Minibar => Moved successfully. C:\ProgramData\Babylon => Moved successfully. C:\ProgramData\eSafe => Moved successfully. =========== Result of Scheduled Files to move =========== "C:\Users\Asus\AppData\Roaming\DealPly" => Directory could not move. ==== End of Fixlog ====