Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-09-2013 04 Ran by Krzysztof at 2013-09-14 14:48:07 Run:1 Running from C:\Users\Krzysztof\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {14950861-08C2-45A1-8C6F-1BA95F08544B} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-08-20] (DealPly Technologies Ltd) Task: {40016252-0EB6-4B51-9746-E299851AE7CF} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-08-20] (DealPly Technologies Ltd) Task: {95CBDE9B-5495-4087-9F4E-38817DB06D90} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{02A67C2F-0480-4149-9B28-1227FBA0ABBC}.exe Task: {C5C3C909-F9F2-4EBC-917D-B894474412F5} - System32\Tasks\DealPlyUpdate => C:\Program Task: {E93BB999-EE4E-4F4F-A4AA-8BCBD9DB46BC} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{B12E3ABB-8CC2-4FC5-92D9-063C853AB868}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{B12E3ABB-8CC2-4FC5-92D9-063C853AB868}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{02A67C2F-0480-4149-9B28-1227FBA0ABBC}.exe Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe Task: C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe R2 AddonsHelper; C:\Users\Krzysztof\AppData\Local\Temp\OCS\Downloads\9f8cc62c3640bf6eb115b4c78bb22a3f\8a2438a7aa1e858526caff1f4deab159\AddonsHelper.exe [896512 2013-08-31] () S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-20] (DealPly Technologies Ltd) S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-08-20] (DealPly Technologies Ltd) R2 vToolbarUpdater14.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe [965296 2013-02-15] () R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [303680 2013-08-22] (Wsys Co., Ltd.) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] HKLM-x32\...\RunOnce: [upt4pc_pl_16.exe] - C:\Users\Krzysztof\AppData\Local\tuto4pc_pl_16\upt4pc_pl_16.exe -runonce [3154416 2013-07-30] () HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [tuto4pc_pl_16] - C:\Program Files (x86)\tuto4pc_pl_16\tuto4pc_pl_16.exe [3977712 2013-07-30] () HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.firetab.org/?type=ds3nt HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1377248097 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1377248097 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1377248097 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1377248097 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1377248097 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1373563591 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1373563591 SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1373563591 SearchScopes: HKLM-x32 - DefaultScope {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = http://www.firetab.org/?type=ds3se&p={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1373563591 SearchScopes: HKLM-x32 - {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = http://www.firetab.org/?type=ds3se&p={searchTerms} SearchScopes: HKCU - DefaultScope {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = http://www.firetab.org/?type=ds3se&p={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.my-online-search.com/?q={searchTerms}&babsrc=SP_ofln&mntrId=B0BD70F3952C1FF7&cat=delta&dlb=2&affID=119357&tt=280813_dt&tsp=4991 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=ST95005620AS_5YX06M2AXXXX5YX06M2A&ts=1377248097 SearchScopes: HKCU - {721061fb-eb79-4568-a03c-3ce26d68dae9} URL = http://www.firetab.org/?type=ds3se&p={searchTerms} SearchScopes: HKCU - {95D84A0C-FEF3-47E3-9F00-2CE0C046619A} URL = BHO-x32: DNS Error Helper - {9B6B03F1-16CF-4491-BBBB-E872802DD717} - C:\ProgramData\DNSErrorHelper\bho.dll () BHO-x32: DealPly Shopping - {9cf699ca-2174-4ed8-bec1-ba82095edce0} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly) FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF HKLM-x32\...\Firefox\Extensions: [dnshelp@dnshelp.com] - C:\Users\Krzysztof\AppData\Roaming\Helper CHR HKLM-x32\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files (x86)\Betcat\WebCakeLayers.crx C:\ProgramData\DealPlyLive C:\ProgramData\DNSErrorHelper C:\ProgramData\DSearchLink C:\ProgramData\eSafe C:\Program Files (x86)\DealPly C:\Program Files (x86)\DealPlyLive C:\Program Files (x86)\Common Files\AVG Secure Search C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml C:\Program Files (x86)\mozilla firefox C:\Program Files (x86)\WinZipper C:\Users\Krzysztof\AppData\Local\avgchrome C:\Users\Krzysztof\AppData\Local\eorezo C:\Users\Krzysztof\AppData\Local\DealPlyLive C:\Users\Krzysztof\AppData\Local\Lollipop C:\Users\Krzysztof\AppData\Roaming\Babylon C:\Users\Krzysztof\AppData\Roaming\Dealply C:\Users\Krzysztof\AppData\Roaming\eIntaller C:\Users\Krzysztof\AppData\Roaming\File Scout C:\Users\Krzysztof\AppData\Roaming\Helper C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly C:\Users\Krzysztof\AppData\Roaming\Mozilla C:\Users\Krzysztof\AppData\Roaming\WebApp C:\Users\Krzysztof\Downloads\SoftonicDownloader_dla_battlefield-2.exe ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{14950861-08C2-45A1-8C6F-1BA95F08544B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{14950861-08C2-45A1-8C6F-1BA95F08544B} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{40016252-0EB6-4B51-9746-E299851AE7CF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40016252-0EB6-4B51-9746-E299851AE7CF} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineCore => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{95CBDE9B-5495-4087-9F4E-38817DB06D90} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95CBDE9B-5495-4087-9F4E-38817DB06D90} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5C3C909-F9F2-4EBC-917D-B894474412F5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5C3C909-F9F2-4EBC-917D-B894474412F5} => Key deleted successfully. C:\Windows\System32\Tasks\DealPlyUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E93BB999-EE4E-4F4F-A4AA-8BCBD9DB46BC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E93BB999-EE4E-4F4F-A4AA-8BCBD9DB46BC} => Key deleted successfully. C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_HP_rmv => Key deleted successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => Moved successfully. AddonsHelper => Service deleted successfully. dealplylive => Service deleted successfully. dealplylivem => Service deleted successfully. vToolbarUpdater14.1.7 => Service deleted successfully. WsysSvc => Service deleted successfully. EagleX64 => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upt4pc_pl_16.exe => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\tuto4pc_pl_16 => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{721061fb-eb79-4568-a03c-3ce26d68dae9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{721061fb-eb79-4568-a03c-3ce26d68dae9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{721061fb-eb79-4568-a03c-3ce26d68dae9} => Key deleted successfully. HKCR\CLSID\{721061fb-eb79-4568-a03c-3ce26d68dae9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95D84A0C-FEF3-47E3-9F00-2CE0C046619A} => Key deleted successfully. HKCR\CLSID\{95D84A0C-FEF3-47E3-9F00-2CE0C046619A} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9B6B03F1-16CF-4491-BBBB-E872802DD717} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9B6B03F1-16CF-4491-BBBB-E872802DD717} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9cf699ca-2174-4ed8-bec1-ba82095edce0} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9cf699ca-2174-4ed8-bec1-ba82095edce0} => Key deleted successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=3 => Key deleted successfully. C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll => Moved successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=9 => Key deleted successfully. C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\dnshelp@dnshelp.com => Value deleted successfully. C:\ProgramData\DealPlyLive => Moved successfully. C:\ProgramData\DNSErrorHelper => Moved successfully. C:\ProgramData\DSearchLink => Moved successfully. C:\ProgramData\eSafe => Moved successfully. C:\Program Files (x86)\DealPly => Moved successfully. C:\Program Files (x86)\DealPlyLive => Moved successfully. C:\Program Files (x86)\Common Files\AVG Secure Search => Moved successfully. C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml => Moved successfully. C:\Program Files (x86)\mozilla firefox => Moved successfully. C:\Program Files (x86)\WinZipper => Moved successfully. C:\Users\Krzysztof\AppData\Local\avgchrome => Moved successfully. C:\Users\Krzysztof\AppData\Local\eorezo => Moved successfully. C:\Users\Krzysztof\AppData\Local\DealPlyLive => Moved successfully. C:\Users\Krzysztof\AppData\Local\Lollipop => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\Babylon => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\Dealply => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\eIntaller => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\File Scout => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\Helper => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Krzysztof\AppData\Roaming\WebApp => Moved successfully. C:\Users\Krzysztof\Downloads\SoftonicDownloader_dla_battlefield-2.exe => Moved successfully. The system needs a manual reboot. ==== End of Fixlog ====