Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-01-2014 Ran by Manikowscy at 2014-01-21 13:02:01 Run:1 Running from C:\Users\Manikowscy\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-10-17] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-10-17] (BonanzaDeals) Task: {5162EC26-5471-446A-9370-DDD2FB89B9E6} - System32\Tasks\BonanzaDealsUpdate => C:\Program Task: {7465CF11-2A8B-4D8D-8F7B-F10D8AC129AF} - \Lyrmix Update No Task File Task: {77C1A693-0E68-4C6F-9F73-266E0F882D59} - System32\Tasks\DigitalSite => C:\Users\Manikowscy\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe [2013-04-12] () Task: {A160B858-AF5E-40C2-ACA7-235FDAC17A6B} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-10-17] (BonanzaDeals) Task: {E9BB1AA5-506A-45B9-83EF-90D899F89C01} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-10-17] (BonanzaDeals) Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\MANIKO~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\Lyrmix Update.job => C:\Program Files (x86)\Lyrmix\LymxUD.exe HKLM-x32\...\Run: [ConvertAd] - C:\Users\Manikowscy\AppData\Local\ConvertAd\ConvertAd.exe HKCU\...\Policies\Explorer: [] BHO-x32: LinkSwift - {323420b6-65e5-4657-8106-a27392d4d4aa} - C:\Program Files (x86)\LinkSwift\LinkSwiftbho.dll (LinkSwift) BHO-x32: Lyrmix - {804efe7d-a8d7-4351-a6df-014d1ed7c6fc} - C:\Program Files (x86)\Lyrmix\133.dll No File BHO-x32: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll (BonanzaDeals) FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF HKCU\...\Firefox\Extensions: [{dde15e35-c9b3-4c30-b055-730c5f4a45d3}] - C:\Program Files (x86)\Lyrmix\133.xpi C:\Program Files (x86)\LinkSwift C:\Users\Manikowscy\AppData\Roaming\OpenCandy C:\Users\Manikowscy\AppData\Local\Temp\*.exe C:\Users\Manikowscy\AppData\Local\Google Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ***************** bonanzadealslive => Service deleted successfully. bonanzadealslivem => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5162EC26-5471-446A-9370-DDD2FB89B9E6} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5162EC26-5471-446A-9370-DDD2FB89B9E6} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7465CF11-2A8B-4D8D-8F7B-F10D8AC129AF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7465CF11-2A8B-4D8D-8F7B-F10D8AC129AF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lyrmix Update => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{77C1A693-0E68-4C6F-9F73-266E0F882D59} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77C1A693-0E68-4C6F-9F73-266E0F882D59} => Key deleted successfully. C:\Windows\System32\Tasks\DigitalSite => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A160B858-AF5E-40C2-ACA7-235FDAC17A6B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A160B858-AF5E-40C2-ACA7-235FDAC17A6B} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E9BB1AA5-506A-45B9-83EF-90D899F89C01} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E9BB1AA5-506A-45B9-83EF-90D899F89C01} => Key deleted successfully. C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Key deleted successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\DigitalSite.job => Moved successfully. C:\Windows\Tasks\Lyrmix Update.job => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ConvertAd => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{323420b6-65e5-4657-8106-a27392d4d4aa} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{323420b6-65e5-4657-8106-a27392d4d4aa} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{804efe7d-a8d7-4351-a6df-014d1ed7c6fc} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{804efe7d-a8d7-4351-a6df-014d1ed7c6fc} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{fe063412-bea4-4d76-8ed3-183be6220d17} => Key deleted successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3 => Key deleted successfully. C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll => Moved successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9 => Key deleted successfully. C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. HKCU\Software\Mozilla\Firefox\Extensions\\{dde15e35-c9b3-4c30-b055-730c5f4a45d3} => Value deleted successfully. C:\Program Files (x86)\LinkSwift => Moved successfully. C:\Users\Manikowscy\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Manikowscy\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\Manikowscy\AppData\Local\Google => Moved successfully. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====