Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 12-02-2014 01 Ran by Anna at 2014-02-13 15:50:53 Run:1 Running from C:\Users\Anna\Desktop\Nowy folder Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files\BuzzSearch\updateBuzzSearch.exe () C:\Program Files\BuzzSearch\bin\utilBuzzSearch.exe S2 bonanzadealslive; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-27] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-27] (BonanzaDeals) R2 Update BuzzSearch; C:\Program Files\BuzzSearch\updateBuzzSearch.exe [80160 2014-02-11] () R2 Util BuzzSearch; C:\Program Files\BuzzSearch\bin\utilBuzzSearch.exe [80160 2014-02-11] () S2 DatamngrCoordinator; C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [X] AppInit_DLLs: C:\PROGRA~2\Wincert\WIN32C~1.DLL => C:\ProgramData\Wincert\win32cert.dll [7168 2013-11-04] () AppInit_DLLs: C:\PROGRA~1\MOVIES~1\Datamngr\mgrldr.dll => File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browsemngr.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browsermngr.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\bundlesweetimsetup.exe: [Debugger] tasklist.exe IFEO\cltmngsvc.exe: [Debugger] tasklist.exe IFEO\delta babylon.exe: [Debugger] tasklist.exe IFEO\delta tb.exe: [Debugger] tasklist.exe IFEO\delta2.exe: [Debugger] tasklist.exe IFEO\deltainstaller.exe: [Debugger] tasklist.exe IFEO\deltasetup.exe: [Debugger] tasklist.exe IFEO\deltatb.exe: [Debugger] tasklist.exe IFEO\deltatb_2501-c733154b.exe: [Debugger] tasklist.exe IFEO\iminentsetup.exe: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\rjatydimofu.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\sweetimsetup.exe: [Debugger] tasklist.exe IFEO\tbdelta.exetoolbar783881609.exe: [Debugger] tasklist.exe HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll Task: {79F8A8D3-1AE4-4463-892E-916CD86F852B} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-27] (BonanzaDeals) Task: {7A8737D2-CA63-45D6-9C38-F83C40379319} - System32\Tasks\Update Bonanza => C:\Users\Anna\AppData\Roaming\UpdateBonanza\UpdateProc\UpdateTask.exe [2013-04-12] () Task: {A88B98C2-5C0C-49E9-9B94-CB4049D20B75} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-27] (BonanzaDeals) Task: {C76A4E0B-D39B-4A88-9A9A-1F65F0F0F549} - System32\Tasks\BonanzaDealsUpdate => C:\Program Task: {F2763F91-1D49-4D14-BED8-F8B30CD3E0EB} - System32\Tasks\Bonanza => C:\Users\Anna\AppData\Roaming\Bonanza\UpdateProc\UpdateTask.exe [2013-04-30] () Task: C:\Windows\Tasks\Bonanza.job => C:\Users\Anna\AppData\Roaming\Bonanza\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe Task: C:\Windows\Tasks\Update Bonanza.job => C:\Users\Anna\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10645A&gct=hp&d=406-429&v=n10781-213&t=4 SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=429&systemid=406&v=n10781-213&apn_uid=4516562624904700&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=429&systemid=406&v=n10781-213&apn_uid=4516562624904700&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} BHO: Movies Toolbar (Dist. by Bandoo Media, Inc.) - {3d86a75b-cb6b-4764-885d-ca6336f04ba2} - C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll () BHO: BuzzSearch - {5cf5a690-c8f4-488e-9d20-f21aef602d41} - C:\Program Files\BuzzSearch\BuzzSearchBHO.dll (BuzzSearch) BHO: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files\BonanzaDeals\BonanzaDealsIE.dll (BonanzaDeals) Toolbar: HKLM - Movies Toolbar (Dist. by Bandoo Media, Inc.) - {3d86a75b-cb6b-4764-885d-ca6336f04ba2} - C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll () FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) C:\Program Files\BonanzaDealsLive C:\Program Files\Movies Toolbar C:\ProgramData\Wincert ***************** [292] C:\Program Files\BuzzSearch\updateBuzzSearch.exe => Process closed successfully. [388] C:\Program Files\BuzzSearch\bin\utilBuzzSearch.exe => Process closed successfully. bonanzadealslive => Service deleted successfully. bonanzadealslivem => Service deleted successfully. Update BuzzSearch => Service deleted successfully. Util BuzzSearch => Service deleted successfully. DatamngrCoordinator => Service deleted successfully. "C:\\PROGRA~2\\Wincert\\WIN32C~1.DLL" => Value Data removed successfully. "C:\\PROGRA~1\\MOVIES~1\\Datamngr\\mgrldr.dll" => Value Data removed successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsemngr.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsermngr.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bundlesweetimsetup.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cltmngsvc.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\delta babylon.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\delta tb.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\delta2.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\deltainstaller.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\deltasetup.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\deltatb.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\deltatb_2501-c733154b.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\iminentsetup.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rjatydimofu.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\sweetimsetup.exe => Key not found. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\tbdelta.exetoolbar783881609.exe => Key not found. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x86 => Value deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79F8A8D3-1AE4-4463-892E-916CD86F852B} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F8A8D3-1AE4-4463-892E-916CD86F852B} => Error deleting key C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A8737D2-CA63-45D6-9C38-F83C40379319} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A8737D2-CA63-45D6-9C38-F83C40379319} => Error deleting key C:\Windows\System32\Tasks\Update Bonanza => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Bonanza => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A88B98C2-5C0C-49E9-9B94-CB4049D20B75} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A88B98C2-5C0C-49E9-9B94-CB4049D20B75} => Error deleting key C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C76A4E0B-D39B-4A88-9A9A-1F65F0F0F549} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C76A4E0B-D39B-4A88-9A9A-1F65F0F0F549} => Error deleting key C:\Windows\System32\Tasks\BonanzaDealsUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F2763F91-1D49-4D14-BED8-F8B30CD3E0EB} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F2763F91-1D49-4D14-BED8-F8B30CD3E0EB} => Error deleting key C:\Windows\System32\Tasks\Bonanza => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bonanza => Error deleting key C:\Windows\Tasks\Bonanza.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\Update Bonanza.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3d86a75b-cb6b-4764-885d-ca6336f04ba2} => Key deleted successfully. HKCR\CLSID\{3d86a75b-cb6b-4764-885d-ca6336f04ba2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5cf5a690-c8f4-488e-9d20-f21aef602d41} => Key deleted successfully. HKCR\CLSID\{5cf5a690-c8f4-488e-9d20-f21aef602d41} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17} => Key deleted successfully. HKCR\CLSID\{fe063412-bea4-4d76-8ed3-183be6220d17} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{3d86a75b-cb6b-4764-885d-ca6336f04ba2} => Value deleted successfully. HKCR\CLSID\{3d86a75b-cb6b-4764-885d-ca6336f04ba2} => Key not found. HKLM\Software\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3 => Key deleted successfully. C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll => Moved successfully. HKLM\Software\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9 => Key deleted successfully. C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll not found. C:\Program Files\BonanzaDealsLive => Moved successfully. C:\Program Files\Movies Toolbar => Moved successfully. C:\ProgramData\Wincert => Moved successfully. ==== End of Fixlog ====