Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01 Ran by User at 2014-03-15 20:47:18 Run:1 Running from D:\download\czcionki Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files\BrowseSmart\updateBrowseSmart.exe () C:\Program Files\BrowseSmart\bin\utilBrowseSmart.exe R2 Update BrowseSmart; C:\Program Files\BrowseSmart\updateBrowseSmart.exe [348960 2014-03-15] () R2 Util BrowseSmart; C:\Program Files\BrowseSmart\bin\utilBrowseSmart.exe [348960 2014-03-14] () S3 catchme; \??\C:\Users\User\AppData\Local\Temp\catchme.sys [X] S3 clwvd; system32\DRIVERS\clwvd.sys [X] HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=82013038_111_hao_pg HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=9400001A6BB7936D&affID=119828&tsp=4990 SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=9400001A6BB7936D&affID=119828&tsp=4990 SearchScopes: HKCU - {0FC81C9F-FFBD-40AB-9749-F25BFBCD58DC} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=C09AA283-CAC1-4C1B-9A84-8D6428BD12D8&apn_sauid=F74A6388-9558-4924-92E2-EA19B36542B2 FF Plugin: @adobe.com/AdobeReader - C:\Users\User\Desktop\opera portable\CommonFiles\Plugins\nppdf32.dll No File FF Plugin: @java.com/JavaPlugin - C:\Users\User\Desktop\opera portable\CommonFiles\Java\bin\plugin2\npjp2.dll No File Task: {15735B28-06CC-4766-A26C-E79A2C27D677} - System32\Tasks\DTReg => C:\Users\User\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe <==== ATTENTION Task: {200B9D25-8BE9-469D-A497-50F1D3906CA7} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files\AVG Secure Search\PostInstall\ROC.exe HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" C:\Program Files\mozilla firefox\plugins C:\Program Files\Common Files\ApnStub.exe C:\Program Files\Common Files\ApnToolbarInstaller.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ĂŔÍĽ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\美图 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hao123楌面版 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirtualDubMod C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MX Skype Recorder C:\Users\User\AppData\Local\Mobogenie C:\Users\User\AppData\Roaming\360Login C:\Users\User\AppData\Roaming\360mobilemgr C:\Users\User\AppData\Roaming\Babylon C:\Users\User\AppData\Roaming\baidu C:\Users\User\AppData\Roaming\DefaultTab C:\Users\User\AppData\Roaming\Thinstall C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ĂŔÍĽż´ż´.lnk C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\美图秀秀.lnk C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\美图秀秀.lnk C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\ĂŔÍĽż´ż´.lnk C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\360安全浏览器 C:\Users\User\Favorites\*.url C:\Users\User\Favorites\Links\*.url C:\Users\User\Favorites\常用 C:\Users\User\Desktop\programy\美图秀秀.lnk C:\Users\User\Desktop\programy\Animation Shop 3.lnk C:\Users\User\Desktop\programy\Brain Challenge.lnk C:\Users\User\Desktop\programy\DAEMON Tools Lite.lnk C:\Users\User\Desktop\programy\DAEMON Tools Pro.lnk C:\Users\User\Desktop\programy\Easy GIF Animator.lnk C:\Users\User\Desktop\programy\Flv Audio Video Extractor.lnk C:\Users\User\Desktop\programy\Free FLV Converter.lnk C:\Users\User\Desktop\programy\Google Chrome.lnk C:\Users\User\Desktop\programy\ipla.lnk C:\Users\User\Desktop\programy\McAfee Security Scan Plus.lnk C:\Users\User\Desktop\programy\osu!.lnk C:\Users\User\Desktop\programy\Play 123 Free Solitaire.lnk C:\Users\User\Documents\Corel\Próbki CorelDRAW X5\target.lnk Reboot: ***************** [1976] C:\Program Files\BrowseSmart\updateBrowseSmart.exe => Process closed successfully. [2528] C:\Program Files\BrowseSmart\bin\utilBrowseSmart.exe => Process closed successfully. Update BrowseSmart => Service deleted successfully. Util BrowseSmart => Service stopped successfully. Util BrowseSmart => Service deleted successfully. catchme => Service deleted successfully. clwvd => Service deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0FC81C9F-FFBD-40AB-9749-F25BFBCD58DC} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0FC81C9F-FFBD-40AB-9749-F25BFBCD58DC} => Key not found. HKLM\Software\MozillaPlugins\@adobe.com/AdobeReader => Key deleted successfully. C:\Users\User\Desktop\opera portable\CommonFiles\Plugins\nppdf32.dll not found. HKLM\Software\MozillaPlugins\@java.com/JavaPlugin => Key deleted successfully. C:\Users\User\Desktop\opera portable\CommonFiles\Java\bin\plugin2\npjp2.dll not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15735B28-06CC-4766-A26C-E79A2C27D677} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15735B28-06CC-4766-A26C-E79A2C27D677} => Key deleted successfully. C:\Windows\System32\Tasks\DTReg => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DTReg => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{200B9D25-8BE9-469D-A497-50F1D3906CA7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{200B9D25-8BE9-469D-A497-50F1D3906CA7} => Key deleted successfully. C:\Windows\System32\Tasks\ROC_JAN2013_TB_rmv => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ROC_JAN2013_TB_rmv => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => Key deleted successfully. C:\Program Files\Mozilla Firefox\plugins => Moved successfully. C:\Program Files\Common Files\ApnStub.exe => Moved successfully. C:\Program Files\Common Files\ApnToolbarInstaller.exe => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ĂŔÍĽ => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\美图 => Moved successfully. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hao123楌面版" => File/Directory not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirtualDubMod => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MX Skype Recorder => Moved successfully. C:\Users\User\AppData\Local\Mobogenie => Moved successfully. C:\Users\User\AppData\Roaming\360Login => Moved successfully. C:\Users\User\AppData\Roaming\360mobilemgr => Moved successfully. C:\Users\User\AppData\Roaming\Babylon => Moved successfully. C:\Users\User\AppData\Roaming\baidu => Moved successfully. C:\Users\User\AppData\Roaming\DefaultTab => Moved successfully. C:\Users\User\AppData\Roaming\Thinstall => Moved successfully. C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ĂŔÍĽż´ż´.lnk => Moved successfully. C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\美图秀秀.lnk => Moved successfully. C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\美图秀秀.lnk => Moved successfully. C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\ĂŔÍĽż´ż´.lnk => Moved successfully. "C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\360安全浏览器" => File/Directory not found. C:\Users\User\Favorites\*.url => Moved successfully. C:\Users\User\Favorites\Links\*.url => Moved successfully. C:\Users\User\Favorites\常用 => Moved successfully. C:\Users\User\Desktop\programy\美图秀秀.lnk => Moved successfully. C:\Users\User\Desktop\programy\Animation Shop 3.lnk => Moved successfully. C:\Users\User\Desktop\programy\Brain Challenge.lnk => Moved successfully. C:\Users\User\Desktop\programy\DAEMON Tools Lite.lnk => Moved successfully. C:\Users\User\Desktop\programy\DAEMON Tools Pro.lnk => Moved successfully. C:\Users\User\Desktop\programy\Easy GIF Animator.lnk => Moved successfully. C:\Users\User\Desktop\programy\Flv Audio Video Extractor.lnk => Moved successfully. C:\Users\User\Desktop\programy\Free FLV Converter.lnk => Moved successfully. C:\Users\User\Desktop\programy\Google Chrome.lnk => Moved successfully. C:\Users\User\Desktop\programy\ipla.lnk => Moved successfully. C:\Users\User\Desktop\programy\McAfee Security Scan Plus.lnk => Moved successfully. C:\Users\User\Desktop\programy\osu!.lnk => Moved successfully. C:\Users\User\Desktop\programy\Play 123 Free Solitaire.lnk => Moved successfully. C:\Users\User\Documents\Corel\Próbki CorelDRAW X5\target.lnk => Moved successfully. The system needed a reboot. ==== End of Fixlog ====