Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2013 01 Ran by Toshiba at 2013-12-15 14:08:45 Run:1 Running from C:\Users\Toshiba\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** SearchScopes: HKLM-x32 - {2AB23AD3-4C06-4FD4-9085-A723BAD56367} URL = http://startsear.ch/?aff=1&q={searchTerms} SearchScopes: HKLM-x32 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://startsear.ch/?aff=2&src=sp&cf=0801c342-de39-11e0-96d8-b482fef8c13d&q={searchTerms} BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF Extension: vShare Add-On - C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\ybskeien.default\Extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Toshiba\AppData\Local\foxtab_speeddial.crx CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Toshiba\AppData\Local\foxtab_speeddial.crx CHR HKLM-x32\...\Chrome\Extension: [gbdabnfmdemcjjadpkpjibhhacggangd] - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\novo_price_comparison.crx Task: {3B735E6F-769C-467C-899A-011C76236F86} - \BonanzaDealsUpdate No Task File Task: {3D3AEA87-F545-4240-A09F-A7CB7D21FC68} - System32\Tasks\e-pity2012_kwiecien => C:\Program Files (x86)\e-file\e-pity2012\signxml.exe Task: {420FFB46-B74F-4297-8F1B-66442CE1C04F} - System32\Tasks\Go for FilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe Task: {655AA2EC-21F6-4C98-AACD-2ABAB831651C} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {CAD77EDE-38A2-46BC-8201-697388F66592} - System32\Tasks\FoxTab => C:\Users\Toshiba\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {FA7A17F3-CA15-4EEB-BCDD-1751131D18D3} - System32\Tasks\e-pity2012_styczen => C:\Program Files (x86)\e-file\e-pity2012\signxml.exe Task: {FCBA13F4-4FB8-45A9-911E-3E7779FA6FBE} - System32\Tasks\RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Toshiba\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION HKCU\...\Run: [AdobeBridge] - [x] S3 Tosrfcom; No ImagePath S3 nmwcdnsucx64; system32\drivers\nmwcdnsucx64.sys [x] S3 nmwcdnsux64; system32\drivers\nmwcdnsux64.sys [x] S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x] S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [x] Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search" /f ***************** HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2AB23AD3-4C06-4FD4-9085-A723BAD56367} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{2AB23AD3-4C06-4FD4-9085-A723BAD56367} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. C:\Users\Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\ybskeien.default\Extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\dchmpbaclbiioedakpcldenooikekokm => Key deleted successfully. C:\Users\Toshiba\AppData\Local\foxtab_speeddial.crx => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dchmpbaclbiioedakpcldenooikekokm => Key deleted successfully. "C:\Users\Toshiba\AppData\Local\foxtab_speeddial.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gbdabnfmdemcjjadpkpjibhhacggangd => Key deleted successfully. C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\novo_price_comparison.crx => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3B735E6F-769C-467C-899A-011C76236F86} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B735E6F-769C-467C-899A-011C76236F86} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D3AEA87-F545-4240-A09F-A7CB7D21FC68} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D3AEA87-F545-4240-A09F-A7CB7D21FC68} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2012_kwiecien => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2012_kwiecien => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{420FFB46-B74F-4297-8F1B-66442CE1C04F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{420FFB46-B74F-4297-8F1B-66442CE1C04F} => Key deleted successfully. C:\Windows\System32\Tasks\Go for FilesUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Go for FilesUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{655AA2EC-21F6-4C98-AACD-2ABAB831651C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{655AA2EC-21F6-4C98-AACD-2ABAB831651C} => Key deleted successfully. C:\Windows\System32\Tasks\Ad-Aware Update (Weekly) => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ad-Aware Update (Weekly) => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CAD77EDE-38A2-46BC-8201-697388F66592} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CAD77EDE-38A2-46BC-8201-697388F66592} => Key deleted successfully. C:\Windows\System32\Tasks\FoxTab => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA7A17F3-CA15-4EEB-BCDD-1751131D18D3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA7A17F3-CA15-4EEB-BCDD-1751131D18D3} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2012_styczen => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2012_styczen => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FCBA13F4-4FB8-45A9-911E-3E7779FA6FBE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCBA13F4-4FB8-45A9-911E-3E7779FA6FBE} => Key deleted successfully. C:\Windows\System32\Tasks\RunAsStdUser => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser => Key deleted successfully. C:\Windows\Tasks\Ad-Aware Update (Weekly).job => Moved successfully. C:\Windows\Tasks\FoxTab.job => Moved successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. Tosrfcom => Service deleted successfully. nmwcdnsucx64 => Service deleted successfully. nmwcdnsux64 => Service deleted successfully. pccsmcfd => Service deleted successfully. RSUSBSTOR => Service deleted successfully. ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====