Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 17-11-2013 02 Ran by USER at 2013-11-18 13:59:33 Run:1 Running from C:\Users\USER\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {72484409-7924-41C3-B5A8-7EA63DB97BE1} - System32\Tasks\Dealply => C:\Users\USER\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE Task: {72C73285-4669-4939-8EDB-4BDC1F8C9D6D} - System32\Tasks\Hoolapp For Android => C:\Users\USER\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE C:\Users\USER\AppData\Roaming\Dealply C:\Users\USER\AppData\Roaming\HOOLAP~1 Task: {95024117-10C3-4BD6-A211-DBD5C9548913} - System32\Tasks\DealPlyUpdate => C:\Program Task: {BAEF4C24-76B4-4E1F-AB58-2C8CA4E08653} - System32\Tasks\Hoolapp Init => C:\Users\USER\AppData\Roaming\HOOLAP~1\Hoolapp.exe Task: C:\Windows\Tasks\Dealply.job => C:\Users\USER\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000Core.job => C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000UA.job => C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {6429C6B6-0B18-4B4B-B540-5817D8332D62} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000UA => C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-08] (Facebook Inc.) Task: {18B57A10-59A8-4223-BA6A-8B6B648D2FE2} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000Core => C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-08] (Facebook Inc.) HKLM\...\Run: [DATAMNGR] - C:\PROGRA~1\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE C:\PROGRA~1\BEARSH~1 HKCU\...\Run: [Facebook Update] - C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-10-08] (Facebook Inc.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-hom...1&ts=1380418408 Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page" HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-hom...1&ts=1380418408 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-hom...1&ts=1380418408 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-hom...1&ts=1380418408 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-hom...1&ts=1380418408 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.c...1&ts=1377720625 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.c...1&ts=1377720625 SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-re...q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69} URL = http://search.bearsh...q={searchTerms} SearchScopes: HKCU - URL http://isearch.babyl...40FE0CB4E268068 SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = http://start.facemoo...earchTerms}&f=4 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://isearch.babyl...40FE0CB4E268068 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = http://websearch.ask...AC-EF271A271863 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-...q={searchTerms} SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/sta...q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search-re...q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69} URL = http://search.bearsh...q={searchTerms} SearchScopes: HKCU - {A6722584-4A36-4956-B012-45CEE59D1929} URL = http://search.softon...b4e268068&r=820 BHO: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll () BHO: WebConnect - {2316c625-b487-4410-a1a5-ff040b65245f} - C:\Program Files\WebConnect\WebConnectBHO.dll (Web Connect) HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN) C:\Program Files\AskPartnerNetwork DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKLM - MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll () BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\qvo6.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\SearchTheWeb.xml FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe http://www.delta-hom...1&ts=1380418408 CHR Extension: (WebConnect) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon\1.0.0_0 CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM\...\Chrome\Extension: [ajcghoegamlabppilamagaddfdfamden] - C:\Program Files\LyricsArt\116.crx CHR HKLM\...\Chrome\Extension: [bgnjcnjlaajofpendibcoodneacalfho] - C:\Program Files\SuperLyrics\Chrome.crx CHR HKLM\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files\Softonic\Softonic\1.8.19.3\Softonic.crx HR HKLM\...\Chrome\Extension: [ieakfmpjhljbpbfpldjkddkjmmgjmgon] - C:\Program Files\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx CHR HKLM\...\Chrome\Extension: [ihflimipbcaljfnojhhknppphnnciiif] - C:\Program Files\facemoods.com\facemoods\1.4.17.9\facemoods.crx R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.) R2 IBUpdaterService; C:\ProgramData\IBUpdaterService\ibsvc.exe [642464 2013-01-16] () R2 Update WebConnect; C:\Program Files\WebConnect\updateWebConnect.exe [65320 2013-10-04] (WebConnect) R2 Util WebConnect; C:\Program Files\WebConnect\bin\utilWebConnect.exe [65320 2013-10-04] (WebConnect) R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [303680 2013-08-28] (Wsys Co., Ltd.) C:\ProgramData\eSafe C:\Program Files\WebConnect 2013-11-18 02:44 - 2013-11-18 02:44 - 00000000 ____D C:\Users\USER\AppData\Local\AskPartnerNetwork 2013-11-18 02:27 - 2013-11-18 02:27 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-11-18 02:27 - 2013-11-18 02:27 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-11-18 02:26 - 2013-11-18 02:26 - 00000000 ____D C:\ProgramData\APN 2013-11-18 03:15 - 2013-09-14 01:39 - 00000000 ____D C:\ProgramData\BitGuard 2013-11-18 03:10 - 2013-05-26 18:29 - 00000000 ____D C:\Users\USER\AppData\Roaming\Dealply 2013-11-18 03:05 - 2013-02-28 00:06 - 00000000 ____D C:\Program Files\SuperLyrics 2013-11-18 02:44 - 2013-11-18 02:44 - 00000000 ____D C:\Users\USER\AppData\Local\AskPartnerNetwork 2013-11-18 02:27 - 2013-11-18 02:27 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-11-18 02:27 - 2013-11-18 02:27 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-11-18 02:26 - 2013-11-18 02:26 - 00000000 ____D C:\ProgramData\APN 2013-11-18 02:20 - 2012-04-10 23:38 - 00000000 ____D C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FoxTab FLV Player 2013-11-18 02:20 - 2012-04-10 23:38 - 00000000 ____D C:\Program Files\FoxTabFLVPlayer 2013-11-10 19:43 - 2013-08-28 21:10 - 00000000 ____D C:\ProgramData\eSafe C:\Users\USER\AppData\Local\Temp\ICReinstall_ccleaner.exe C:\Users\USER\AppData\Local\Temp\uninst1.exe S3 andnetadb; System32\Drivers\lgandnetadb.sys [x] S3 AndNetDiag; system32\DRIVERS\lgandnetdiag.sys [x] S3 ANDNetModem; system32\DRIVERS\lgandnetmodem.sys [x] S3 andnetndis; system32\DRIVERS\lgandnetndis.sys [x] S3 catchme; \??\C:\Users\USER\AppData\Local\Temp\catchme.sys [x] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 LgBttPort; system32\DRIVERS\lgbtport.sys [x] S3 lgbusenum; system32\DRIVERS\lgbtbus.sys [x] S3 LGVMODEM; system32\DRIVERS\lgvmodem.sys [x] S3 usbbus; system32\DRIVERS\lgusbbus.sys [x] S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [x] S3 USBModem; system32\DRIVERS\lgusbmodem.sys [x] ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72484409-7924-41C3-B5A8-7EA63DB97BE1} => Key not found. C:\Windows\System32\Tasks\Dealply not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{72C73285-4669-4939-8EDB-4BDC1F8C9D6D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72C73285-4669-4939-8EDB-4BDC1F8C9D6D} => Key deleted successfully. C:\Windows\System32\Tasks\Hoolapp For Android => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hoolapp For Android => Key deleted successfully. "C:\Users\USER\AppData\Roaming\Dealply" => File/Directory not found. "C:\Users\USER\AppData\Roaming\HOOLAP~1" directory move: Could not move "C:\Users\USER\AppData\Roaming\HOOLAP~1" directory. => Scheduled to move on reboot. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95024117-10C3-4BD6-A211-DBD5C9548913} => Key not found. C:\Windows\System32\Tasks\DealPlyUpdate not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{BAEF4C24-76B4-4E1F-AB58-2C8CA4E08653} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BAEF4C24-76B4-4E1F-AB58-2C8CA4E08653} => Key deleted successfully. C:\Windows\System32\Tasks\Hoolapp Init => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hoolapp Init => Key deleted successfully. C:\Windows\Tasks\Dealply.job not found. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000Core.job => Moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000UA.job => Moved successfully. C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6429C6B6-0B18-4B4B-B540-5817D8332D62} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6429C6B6-0B18-4B4B-B540-5817D8332D62} => Key deleted successfully. C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000UA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000UA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{18B57A10-59A8-4223-BA6A-8B6B648D2FE2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18B57A10-59A8-4223-BA6A-8B6B648D2FE2} => Key deleted successfully. C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000Core => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-1424421345-115930411-479481771-1000Core => Key deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR => Value not found. C:\PROGRA~1\BEARSH~1 => Moved successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page" => Value not found. ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page" =========