Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-04-2014 01 Ran by as at 2014-04-13 00:40:41 Run:1 Running from C:\Users\as\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files (x86)\BrowseMark\updater.exe R2 UpdaterSvcBrowseMark; C:\Program Files (x86)\BrowseMark\updater.exe [110592 2014-04-02] () U3 tmlwf; U3 tmwfp; HKLM-x32\...\Run: [NPSStartup] - [X] Task: {06DDF41B-0B8B-4349-B7B6-50A4A377F364} - System32\Tasks\{BACE3563-06BD-4B48-85E4-6C7C90C259A9} => E:\DEViANCE\keygen.exe Task: {096209D0-7AE3-4DF8-A498-2CE84CB94181} - System32\Tasks\{6A38902A-E586-416F-B8B9-C0D7E9B81419} => E:\DEViANCE\keygen.exe Task: {1A6DE5E6-95A5-44B6-8868-C41B9E0F987A} - System32\Tasks\{64AF3A06-676F-4DB1-BDBC-C7864641AF4B} => E:\DEViANCE\keygen.exe Task: {34FD50A9-4411-486B-AF71-9AD81A21BAF5} - System32\Tasks\{C5189E19-D2C3-4AF4-B3F6-65284275AE69} => C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-05-26] () Task: {71C5930E-C260-4FD8-B736-E2CA80F7CE4B} - System32\Tasks\{8F3198CE-1BAB-4CB6-B225-0D50CEDDCCF8} => E:\DEViANCE\keygen.exe Task: {8D5E8B41-424D-4605-BF48-5517919CCF6A} - System32\Tasks\{939C09E2-39ED-4426-84D9-4EEA8B4067E3} => C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2010-05-26] () Task: {9EEBF6C3-4A56-4120-93AA-A7BD8F0448FB} - System32\Tasks\{A4FCAE04-0FBE-4E27-8CE6-966299ACB86A} => E:\DEViANCE\keygen.exe Task: {BE649C8D-D97C-44F3-9BE3-65B3FC7C7527} - System32\Tasks\SK.Enabler-S-1495795506 => c:\programdata\quickset\sk.enabler\SK.Enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\SK.Enabler-S-1495795506.job => c:\programdata\quickset\sk.enabler\SK.Enabler.exe <==== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_ss&mntrId=3C542225D3C43D23&affID=128492&tsp=5209 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie URLSearchHook: HKLM-x32 - (No Name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - No File URLSearchHook: HKCU - (No Name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - No File URLSearchHook: HKCU - (No Name) - {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - No File SearchScopes: HKLM - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0A0E0DtA0F0AtCtA0DzytDtN0D0Tzu0CtBzztCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1797550259 SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0A0E0DtA0F0AtCtA0DzytDtN0D0Tzu0CtBzztCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1797550259 SearchScopes: HKLM-x32 - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0A0E0DtA0F0AtCtA0DzytDtN0D0Tzu0CtBzztCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1797550259 SearchScopes: HKLM-x32 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&chnl=iron2&cd=2XzuyEtN2Y1L1QzuzytD0EyC0B0A0E0DtA0F0AtCtA0DzytDtN0D0Tzu0CtBzztCtN1L2XzutBtFtBtFtDtFtAyEyE&cr=1797550259 SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1098640 SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=12&q={searchTerms}&barid={3D80ACBE-D21C-42C4-9284-DEA8D6EBAD45} SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=3C542225D3C43D23&affID=128492&tsp=5209 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=3C542225D3C43D23&affID=128492&tsp=5209 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKCU - {6BB4347B-C7EE-4A25-9466-484B0F9452B3} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=38A80C81-1AA2-4371-8B63-FBF520CDCA59&apn_sauid=03D683E7-1908-4F41-ABF1-80418FB08E0B SearchScopes: HKCU - {C2526D9C-173B-4AF4-98E7-814D9DC761E0} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481033 SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=12&q={searchTerms}&barid={3D80ACBE-D21C-42C4-9284-DEA8D6EBAD45} BHO-x32: No Name - {e7e8ed77-2fba-4ec6-bc07-65de4de6709f} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - No File FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\as\AppData\Local\funmoods.crx [2014-04-07] CHR HKLM\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\Users\as\AppData\Local\funmoods-speeddial_sf.crx [2012-10-07] CHR HKCU\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\Users\as\AppData\Local\funmoods-speeddial_sf.crx [2012-10-07] CHR HKLM-x32\...\Chrome\Extension: [cjpglkicenollcignonpgiafdgfeehoj] - C:\Users\as\AppData\Local\funmoods-speeddial_sf.crx [2012-10-07] C:\Users\as\Downloads\Niepotwierdzony*.crdownload C:\Users\as\Downloads\OTL 3.2.69.0_isdmgr.exe C:\Users\as\Downloads\OTL 3.2.69.0_isdmgr (1).exe C:\Users\as\Downloads\SoftonicDownloader_dla_nero-cd-dvd-speed.exe CMD: for /d %f in (C:\Users\as\AppData\Local\{*}) do rd /s /q "%f" Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reboot: ***************** [2884] C:\Program Files (x86)\BrowseMark\updater.exe => Process closed successfully. UpdaterSvcBrowseMark => Service deleted successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06DDF41B-0B8B-4349-B7B6-50A4A377F364} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06DDF41B-0B8B-4349-B7B6-50A4A377F364} => Key deleted successfully. C:\Windows\System32\Tasks\{BACE3563-06BD-4B48-85E4-6C7C90C259A9} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BACE3563-06BD-4B48-85E4-6C7C90C259A9} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{096209D0-7AE3-4DF8-A498-2CE84CB94181} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{096209D0-7AE3-4DF8-A498-2CE84CB94181} => Key deleted successfully. C:\Windows\System32\Tasks\{6A38902A-E586-416F-B8B9-C0D7E9B81419} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6A38902A-E586-416F-B8B9-C0D7E9B81419} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1A6DE5E6-95A5-44B6-8868-C41B9E0F987A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A6DE5E6-95A5-44B6-8868-C41B9E0F987A} => Key deleted successfully. C:\Windows\System32\Tasks\{64AF3A06-676F-4DB1-BDBC-C7864641AF4B} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{64AF3A06-676F-4DB1-BDBC-C7864641AF4B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{34FD50A9-4411-486B-AF71-9AD81A21BAF5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{34FD50A9-4411-486B-AF71-9AD81A21BAF5} => Key deleted successfully. C:\Windows\System32\Tasks\{C5189E19-D2C3-4AF4-B3F6-65284275AE69} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C5189E19-D2C3-4AF4-B3F6-65284275AE69} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71C5930E-C260-4FD8-B736-E2CA80F7CE4B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71C5930E-C260-4FD8-B736-E2CA80F7CE4B} => Key deleted successfully. C:\Windows\System32\Tasks\{8F3198CE-1BAB-4CB6-B225-0D50CEDDCCF8} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8F3198CE-1BAB-4CB6-B225-0D50CEDDCCF8} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D5E8B41-424D-4605-BF48-5517919CCF6A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D5E8B41-424D-4605-BF48-5517919CCF6A} => Key deleted successfully. C:\Windows\System32\Tasks\{939C09E2-39ED-4426-84D9-4EEA8B4067E3} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{939C09E2-39ED-4426-84D9-4EEA8B4067E3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9EEBF6C3-4A56-4120-93AA-A7BD8F0448FB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9EEBF6C3-4A56-4120-93AA-A7BD8F0448FB} => Key deleted successfully. C:\Windows\System32\Tasks\{A4FCAE04-0FBE-4E27-8CE6-966299ACB86A} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A4FCAE04-0FBE-4E27-8CE6-966299ACB86A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BE649C8D-D97C-44F3-9BE3-65B3FC7C7527} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE649C8D-D97C-44F3-9BE3-65B3FC7C7527} => Key deleted successfully. C:\Windows\System32\Tasks\SK.Enabler-S-1495795506 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SK.Enabler-S-1495795506 => Key deleted successfully. C:\Windows\Tasks\SK.Enabler-S-1495795506.job => Moved successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{ecdee021-0d17-467f-a1ff-c7a115230949} => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ecdee021-0d17-467f-a1ff-c7a115230949} => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{d43723ae-1ae1-4a25-a6a4-bf0929273cab} => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6BB4347B-C7EE-4A25-9466-484B0F9452B3} => Key deleted successfully. HKCR\CLSID\{6BB4347B-C7EE-4A25-9466-484B0F9452B3} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C2526D9C-173B-4AF4-98E7-814D9DC761E0} => Key deleted successfully. HKCR\CLSID\{C2526D9C-173B-4AF4-98E7-814D9DC761E0} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e7e8ed77-2fba-4ec6-bc07-65de4de6709f} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{e7e8ed77-2fba-4ec6-bc07-65de4de6709f} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully. HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Value deleted successfully. HKCR\CLSID\{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} => Key not found. HKLM\Software\Wow6432Node\MozillaPlugins\@Nero.com/KM => Key deleted successfully. C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh => Key deleted successfully. "C:\Users\as\AppData\Local\funmoods.crx" => File/Directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj => Key deleted successfully. C:\Users\as\AppData\Local\funmoods-speeddial_sf.crx => Moved successfully. HKCU\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj => Key deleted successfully. "C:\Users\as\AppData\Local\funmoods-speeddial_sf.crx" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj => Key deleted successfully. "C:\Users\as\AppData\Local\funmoods-speeddial_sf.crx" => File/Directory not found. C:\Users\as\Downloads\Niepotwierdzony*.crdownload => Moved successfully. C:\Users\as\Downloads\OTL 3.2.69.0_isdmgr.exe => Moved successfully. C:\Users\as\Downloads\OTL 3.2.69.0_isdmgr (1).exe => Moved successfully. C:\Users\as\Downloads\SoftonicDownloader_dla_nero-cd-dvd-speed.exe => Moved successfully. ========= for /d %f in (C:\Users\as\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====