Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013 Ran by slimosolo at 2013-10-04 01:01:55 Run:1 Running from C:\Users\slimosolo\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038773 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038773 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038773 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038773 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038773 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038779&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038779&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038779&type=default&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380038779&type=default&q={searchTerms} Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File CHR StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=HitachiXHTS543225L9SA00_080826FB0F00LLGK189BX&ts=1380043353 2013-09-24 18:06 - 2013-09-24 19:29 - 00000000 ____D C:\Users\slimosolo\AppData\Local\DProtect 2013-09-24 18:05 - 2013-09-24 18:05 - 00581488 _____ C:\Users\slimosolo\Downloads\SharePod 3.9.9_isdmgr.exe ***************** HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41564952-412D-5637-00A7-7A786E7484D7} => Value deleted successfully. HKCR\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. "C:\Users\slimosolo\AppData\Local\DProtect" directory move: Could not move "C:\Users\slimosolo\AppData\Local\DProtect\config.dat" => Scheduled to move on reboot. Could not move "C:\Users\slimosolo\AppData\Local\DProtect\DProtectSvc.exe" => Scheduled to move on reboot. Could not move "C:\Users\slimosolo\AppData\Local\DProtect\DPUninstall.exe" => Scheduled to move on reboot. Could not move "C:\Users\slimosolo\AppData\Local\DProtect\eBP.dll" => Scheduled to move on reboot. Could not move "C:\Users\slimosolo\AppData\Local\DProtect\eBPSD.dll" => Scheduled to move on reboot. Could not move "C:\Users\slimosolo\AppData\Local\DProtect\eDelayinfo.edb" => Scheduled to move on reboot. Could not move "C:\Users\slimosolo\AppData\Local\DProtect\eGdpSvc.exe" => Scheduled to move on reboot. C:\Users\slimosolo\AppData\Local\DProtect\log\DProtectSvc.LOG => Moved successfully. C:\Users\slimosolo\AppData\Local\DProtect\log\DPService_(null)_20130924181319467.dmp => Moved successfully. C:\Users\slimosolo\AppData\Local\DProtect\log\DPService_(null)_20130926202805809.dmp => Moved successfully. C:\Users\slimosolo\AppData\Local\DProtect\log\DPService_(null)_20130927181030638.dmp => Moved successfully. C:\Users\slimosolo\AppData\Local\DProtect\log\DPService_(null)_20130928064758546.dmp => Moved successfully. Could not move "C:\Users\slimosolo\AppData\Local\DProtect" directory. => Scheduled to move on reboot. C:\Users\slimosolo\Downloads\SharePod 3.9.9_isdmgr.exe => Moved successfully. =========== Result of Scheduled Files to move =========== "C:\Users\slimosolo\AppData\Local\DProtect\config.dat" => File could not move. "C:\Users\slimosolo\AppData\Local\DProtect\DProtectSvc.exe" => File could not move. "C:\Users\slimosolo\AppData\Local\DProtect\DPUninstall.exe" => File could not move. "C:\Users\slimosolo\AppData\Local\DProtect\eBP.dll" => File could not move. "C:\Users\slimosolo\AppData\Local\DProtect\eBPSD.dll" => File could not move. "C:\Users\slimosolo\AppData\Local\DProtect\eDelayinfo.edb" => File could not move. "C:\Users\slimosolo\AppData\Local\DProtect\eGdpSvc.exe" => File could not move. "C:\Users\slimosolo\AppData\Local\DProtect" => Directory could not move. ==== End of Fixlog ====