Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-09-2013 02 Ran by Maciek at 2013-10-06 12:28:34 Run:3 Running from C:\Users\Maciek\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** R2 Update Whilokii; C:\Program Files (x86)\Whilokii\updateWhilokii.exe [206616 2013-09-26] (Whilokii) R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [480376 2013-10-03] (Wsys Co., Ltd.) C:\windows\Tasks\DigitalSite.job C:\windows\System32\Tasks\DigitalSite C:\Users\Maciek\AppData\Roaming\DigitalSite C:\Users\Maciek\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z C:\ProgramData\eSafe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810708&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810708&type=default&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810708&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810708&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO-x32: Whilokii - {204df522-9a96-4a72-abb0-60f7a216d6d2} - C:\Program Files (x86)\Whilokii\Whilokiibho.dll (Whilokii) FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qvo6.xml CHR StartMenuInternet: Google Chrome - C:\Users\Maciek\AppData\Local\Google\Chrome\Application\chrome.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=SAMSUNGXHM321HI_S26VJ9FB819712&ts=1380810707 CHR HKLM-x32\...\Chrome\Extension: [dlmdlmoekcipeicfbnohedgkglmbhcla] - C:\Program Files (x86)\Whilokii\dlmdlmoekcipeicfbnohedgkglmbhcla.crx ***************** Update Whilokii => Service not found. WsysSvc => Service deleted successfully. C:\windows\Tasks\DigitalSite.job => Moved successfully. C:\windows\System32\Tasks\DigitalSite => Moved successfully. "C:\Users\Maciek\AppData\Roaming\DigitalSite" directory move: C:\Users\Maciek\AppData\Roaming\DigitalSite\UpdateProc\config.dat => Moved successfully. C:\Users\Maciek\AppData\Roaming\DigitalSite\UpdateProc\prod.dat => Moved successfully. C:\Users\Maciek\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT => Moved successfully. C:\Users\Maciek\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT => Moved successfully. C:\Users\Maciek\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe => Moved successfully. Could not move "C:\Users\Maciek\AppData\Roaming\DigitalSite" directory. => Scheduled to move on reboot. C:\Users\Maciek\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z => Moved successfully. C:\ProgramData\eSafe => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{204df522-9a96-4a72-abb0-60f7a216d6d2} => Key not found. HKCR\Wow6432Node\CLSID\{204df522-9a96-4a72-abb0-60f7a216d6d2} => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => Value was restored successfully. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qvo6.xml => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlmdlmoekcipeicfbnohedgkglmbhcla => Key not found. "C:\Program Files (x86)\Whilokii\dlmdlmoekcipeicfbnohedgkglmbhcla.crx" => File/Directory not found. =========== Result of Scheduled Files to move =========== "C:\Users\Maciek\AppData\Roaming\DigitalSite" => Directory could not move. ==== End of Fixlog ====