Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-12-2013 Ran by Przemek at 2013-12-11 22:19:37 Run:1 Running from C:\Users\Przemek\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files (x86)\BuzzSearch\updateBuzzSearch.exe () C:\Program Files (x86)\BuzzSearch\bin\utilBuzzSearch.exe R2 Update BuzzSearch; C:\Program Files (x86)\BuzzSearch\updateBuzzSearch.exe [66336 2013-11-08] () R2 Util BuzzSearch; C:\Program Files (x86)\BuzzSearch\bin\utilBuzzSearch.exe [66336 2013-11-25] () S2 hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [x] HKCU\...\Policies\Explorer: [] AppInit_DLLs: C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL [ ] () HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=9679582C80135226&affID=125032&tsp=5033 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST9320325AS_5VE9RLHZXXXX5VE9RLHZ&ts=1379169529 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST9320325AS_5VE9RLHZXXXX5VE9RLHZ&ts=1379169529 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST9320325AS_5VE9RLHZXXXX5VE9RLHZ&ts=1379169529 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST9320325AS_5VE9RLHZXXXX5VE9RLHZ&ts=1379169529 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST9320325AS_5VE9RLHZXXXX5VE9RLHZ&ts=1379169529 SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST9320325AS_5VE9RLHZXXXX5VE9RLHZ&ts=1379169529 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=96795063138A4AD8&affID=119357&tsp=5006 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST9320325AS_5VE9RLHZXXXX5VE9RLHZ&ts=1379169529 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO-x32: BuzzSearch - {5cf5a690-c8f4-488e-9d20-f21aef602d41} - C:\Program Files (x86)\BuzzSearch\BuzzSearchBHO.dll (BuzzSearch) CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx CHR HKLM-x32\...\Chrome\Extension: [jhjjdgbhohaallcimgcmakfiobacimkm] - C:\Program Files (x86)\BuzzSearch\jhjjdgbhohaallcimgcmakfiobacimkm.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Task: {2AEB0640-E9BD-43C3-8476-93F8A78757E2} - System32\Tasks\FoxTab => C:\Users\Przemek\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Przemek\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION C:\Users\Przemek\AppData\Roaming\Babylon C:\Users\Przemek\AppData\Roaming\OpenCandy ***************** [2708] C:\Program Files (x86)\BuzzSearch\updateBuzzSearch.exe => Process closed successfully. [2060] C:\Program Files (x86)\BuzzSearch\bin\utilBuzzSearch.exe => Process closed successfully. Update BuzzSearch => Service deleted successfully. Util BuzzSearch => Service deleted successfully. hardlock => Service deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Value deleted successfully. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5cf5a690-c8f4-488e-9d20-f21aef602d41} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{5cf5a690-c8f4-488e-9d20-f21aef602d41} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo => Key deleted successfully. C:\Users\Przemek\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jhjjdgbhohaallcimgcmakfiobacimkm => Key deleted successfully. C:\Program Files (x86)\BuzzSearch\jhjjdgbhohaallcimgcmakfiobacimkm.crx => Moved successfully. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2AEB0640-E9BD-43C3-8476-93F8A78757E2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AEB0640-E9BD-43C3-8476-93F8A78757E2} => Key deleted successfully. C:\Windows\System32\Tasks\FoxTab => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab => Key deleted successfully. C:\Windows\Tasks\FoxTab.job => Moved successfully. C:\Users\Przemek\AppData\Roaming\Babylon => Moved successfully. C:\Users\Przemek\AppData\Roaming\OpenCandy => Moved successfully. The system needs a manual reboot. ==== End of Fixlog ====