Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by Małgorzata at 2014-04-06 11:59:49 Run:1 Running from C:\Users\Małgorzata\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found SearchScopes: HKCU - DefaultScope {E759AAE3-BEE1-4837-8345-018769AE7FD7} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms} SearchScopes: HKCU - {E759AAE3-BEE1-4837-8345-018769AE7FD7} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms} BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit) C:\Users\Małgorzata\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja C:\Users\Małgorzata\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd C:\Windows\system32\roboot64.exe C:\Users\Małgorzata\AppData\Roaming\sweet-page C:\Users\Małgorzata\AppData\Roaming\Opera Software C:\Users\Małgorzata\AppData\Local\Opera Software C:\Windows\System32\Tasks\Opera D7 C:\Windows\System32\Tasks\Opera D6 C:\Windows\System32\Tasks\Opera D5 C:\Users\Małgorzata\AppData\Local\Temp\*.dll C:\Users\Małgorzata\AppData\Local\Temp\*.exe Task: {BD340A31-771B-4E92-B1E3-25EED266E148} - System32\Tasks\Opera D6 => C:\Program Files (x86)\Opera\launcher.exe Task: {9F3F122E-E00B-4487-94F8-ABF2BD92BE62} - System32\Tasks\Opera D5 => C:\Program Files (x86)\Opera\launcher.exe Task: {172F3FB9-ED37-41BD-B58F-E6B68E11A0CC} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: {38487C41-4917-4812-B8ED-1E31A64A69CE} - System32\Tasks\Opera D7 => C:\Program Files (x86)\Opera\launcher.exe Task: {8B53DB4F-FDBA-408C-9CFF-D21D024BFEFD} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: {97613172-AB67-4953-BAA0-B24ABF6A8B86} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION ***************** "C:\\PROGRA~2\\SupTab\\SEARCH~2.DLL" => Value Data removed successfully. "C:\\PROGRA~2\\SupTab\\SEARCH~1.DLL" => Value Data removed successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E759AAE3-BEE1-4837-8345-018769AE7FD7} => Key deleted successfully. HKCR\CLSID\{E759AAE3-BEE1-4837-8345-018769AE7FD7} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => Key deleted successfully. C:\Users\Małgorzata\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja => Moved successfully. C:\Users\Małgorzata\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd => Moved successfully. C:\Windows\system32\roboot64.exe => Moved successfully. C:\Users\Małgorzata\AppData\Roaming\sweet-page => Moved successfully. C:\Users\Małgorzata\AppData\Roaming\Opera Software => Moved successfully. C:\Users\Małgorzata\AppData\Local\Opera Software => Moved successfully. C:\Windows\System32\Tasks\Opera D7 => Moved successfully. C:\Windows\System32\Tasks\Opera D6 => Moved successfully. C:\Windows\System32\Tasks\Opera D5 => Moved successfully. C:\Users\Małgorzata\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Małgorzata\AppData\Local\Temp\*.exe => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD340A31-771B-4E92-B1E3-25EED266E148} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD340A31-771B-4E92-B1E3-25EED266E148} => Key deleted successfully. C:\Windows\System32\Tasks\Opera D6 not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D6 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F3F122E-E00B-4487-94F8-ABF2BD92BE62} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F3F122E-E00B-4487-94F8-ABF2BD92BE62} => Key deleted successfully. C:\Windows\System32\Tasks\Opera D5 not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D5 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{172F3FB9-ED37-41BD-B58F-E6B68E11A0CC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{172F3FB9-ED37-41BD-B58F-E6B68E11A0CC} => Key deleted successfully. C:\Windows\System32\Tasks\RegClean Pro_UPDATES => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{38487C41-4917-4812-B8ED-1E31A64A69CE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38487C41-4917-4812-B8ED-1E31A64A69CE} => Key deleted successfully. C:\Windows\System32\Tasks\Opera D7 not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D7 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8B53DB4F-FDBA-408C-9CFF-D21D024BFEFD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B53DB4F-FDBA-408C-9CFF-D21D024BFEFD} => Key deleted successfully. C:\Windows\System32\Tasks\RegClean Pro => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{97613172-AB67-4953-BAA0-B24ABF6A8B86} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97613172-AB67-4953-BAA0-B24ABF6A8B86} => Key deleted successfully. C:\Windows\System32\Tasks\RegClean Pro_DEFAULT => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT => Key deleted successfully. C:\Windows\Tasks\RegClean Pro_DEFAULT.job => Moved successfully. C:\Windows\Tasks\RegClean Pro_UPDATES.job => Moved successfully. ==== End of Fixlog ====