Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by Maciej at 2014-03-17 15:17:40 Run:1 Running from C:\Users\Maciej\Desktop\Logi Boot Mode: Normal ============================================== Content of fixlist: ***************** (CyberLink ) C:\Users\Maciej\AppData\Roaming\SubFolderName\FileName.exe HKU\S-1-5-21-2475148013-1230956755-3406740402-1001\...\Run: [Key Name] - C:\Users\Maciej\AppData\Roaming\SubFolderName\FileName.exe [742033 2014-01-21] (CyberLink ) HKU\S-1-5-21-2475148013-1230956755-3406740402-1001\...\Run: [tgb32.exe] - C:\Users\Maciej\AppData\Roaming\SubFolderName\FileName.exe [742033 2014-01-21] (CyberLink ) HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=cor&utm_campaign=rg&utm_content=ds&from=cor&uid=ST320LM001XHN-M320MBB_S2URJ9AC732231&ts=1384126033&type=default&q={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = S2 Update FindRight; "C:\Program Files (x86)\FindRight\updateFindRight.exe" [X] S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-11-13] (Anchorfree Inc.) S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X] S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X] C:\ProgramData\Right Soft C:\ProgramData\InstallMate C:\ProgramData\Mozilla C:\Users\Maciej\AppData\Local\CrashDumps C:\Users\Maciej\AppData\Local\Mozilla C:\Users\Maciej\AppData\Roaming\SubFolderName C:\Windows\SysWOW64\scrypt130511Turksglg2tc4032w256l4.bin C:\Windows\SysWOW64\scrypt130511BeaverCreekglg2tc4032w256l4.bin Reboot: ***************** [5076] C:\Users\Maciej\AppData\Roaming\SubFolderName\FileName.exe => Process closed successfully. HKU\S-1-5-21-2475148013-1230956755-3406740402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Key Name => Value deleted successfully. HKU\S-1-5-21-2475148013-1230956755-3406740402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\tgb32.exe => Value deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. Update FindRight => Service deleted successfully. taphss6 => Service deleted successfully. atillk64 => Service deleted successfully. ew_hwusbdev => Service deleted successfully. ew_usbenumfilter => Service deleted successfully. huawei_cdcacm => Service deleted successfully. huawei_enumerator => Service deleted successfully. huawei_ext_ctrl => Service deleted successfully. huawei_wwanecm => Service deleted successfully. C:\ProgramData\Right Soft => Moved successfully. C:\ProgramData\InstallMate => Moved successfully. C:\ProgramData\Mozilla => Moved successfully. C:\Users\Maciej\AppData\Local\CrashDumps => Moved successfully. C:\Users\Maciej\AppData\Local\Mozilla => Moved successfully. C:\Users\Maciej\AppData\Roaming\SubFolderName => Moved successfully. C:\Windows\SysWOW64\scrypt130511Turksglg2tc4032w256l4.bin => Moved successfully. C:\Windows\SysWOW64\scrypt130511BeaverCreekglg2tc4032w256l4.bin => Moved successfully. The system needed a reboot. ==== End of Fixlog ====