Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-04-2014 Ran by asus at 2014-04-19 15:31:14 Run:1 Running from C:\Users\asus\Downloads\Nowy folder Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe () C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe R2 Update Mega Browse; C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe [350496 2014-04-17] () R2 Util Mega Browse; C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe [350496 2014-04-17] () R1 wStLibG64; C:\Windows\System32\drivers\wStLibG64.sys [61120 2014-03-25] (StdLib) S3 cpuz135; \??\C:\Users\asus\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] Task: {468A200B-4897-4E55-BF1F-DD49321100C3} - System32\Tasks\MySearchDial => C:\Users\asus\AppData\Roaming\mysearchdial\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\asus\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=ir_14_14_ff&cd=2XzuyEtN2Y1L1Qzu0D0CzzyD0D0Ezy0Fzz0B0AtDtC0AzyyDtN0D0Tzu0SzztBtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCyC0A0DyC0CtBzytGyEyE0FzytGtDyDtA0DtGtDtB0AzztGtCzzyCtDyEzztCtD0CyBtC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzytAtDyD0Fzy0FtGtAtDyBzztGzytCtAyBtGyC0CtA0AtGyC0DyDzz0Bzz0ByE0AyByEzy2Q&cr=1906506504&ir= HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=ir_14_14_ff&cd=2XzuyEtN2Y1L1Qzu0D0CzzyD0D0Ezy0Fzz0B0AtDtC0AzyyDtN0D0Tzu0SzztBtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCyC0A0DyC0CtBzytGyEyE0FzytGtDyDtA0DtGtDtB0AzztGtCzzyCtDyEzztCtD0CyBtC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzytAtDyD0Fzy0FtGtAtDyBzztGzytCtAyBtGyC0CtA0AtGyC0DyDzz0Bzz0ByE0AyByEzy2Q&cr=1906506504&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=ir_14_14_ff&cd=2XzuyEtN2Y1L1Qzu0D0CzzyD0D0Ezy0Fzz0B0AtDtC0AzyyDtN0D0Tzu0SzztBtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCyC0A0DyC0CtBzytGyEyE0FzytGtDyDtA0DtGtDtB0AzztGtCzzyCtDyEzztCtD0CyBtC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzytAtDyD0Fzy0FtGtAtDyBzztGzytCtAyBtGyC0CtA0AtGyC0DyDzz0Bzz0ByE0AyByEzy2Q&cr=1906506504&ir= SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_14_ff&cd=2XzuyEtN2Y1L1Qzu0D0CzzyD0D0Ezy0Fzz0B0AtDtC0AzyyDtN0D0Tzu0SzztBtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCyC0A0DyC0CtBzytGyEyE0FzytGtDyDtA0DtGtDtB0AzztGtCzzyCtDyEzztCtD0CyBtC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzytAtDyD0Fzy0FtGtAtDyBzztGzytCtAyBtGyC0CtA0AtGyC0DyDzz0Bzz0ByE0AyByEzy2Q&cr=1906506504&ir= SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_14_ff&cd=2XzuyEtN2Y1L1Qzu0D0CzzyD0D0Ezy0Fzz0B0AtDtC0AzyyDtN0D0Tzu0SzztBtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCyC0A0DyC0CtBzytGyEyE0FzytGtDyDtA0DtGtDtB0AzztGtCzzyCtDyEzztCtD0CyBtC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzytAtDyD0Fzy0FtGtAtDyBzztGzytCtAyBtGyC0CtA0AtGyC0DyDzz0Bzz0ByE0AyByEzy2Q&cr=1906506504&ir= SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_14_ff&cd=2XzuyEtN2Y1L1Qzu0D0CzzyD0D0Ezy0Fzz0B0AtDtC0AzyyDtN0D0Tzu0SzztBtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCyC0A0DyC0CtBzytGyEyE0FzytGtDyDtA0DtGtDtB0AzztGtCzzyCtDyEzztCtD0CyBtC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzytAtDyD0Fzy0FtGtAtDyBzztGzytCtAyBtGyC0CtA0AtGyC0DyDzz0Bzz0ByE0AyByEzy2Q&cr=1906506504&ir= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_14_ff&cd=2XzuyEtN2Y1L1Qzu0D0CzzyD0D0Ezy0Fzz0B0AtDtC0AzyyDtN0D0Tzu0SzztBtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCyC0A0DyC0CtBzytGyEyE0FzytGtDyDtA0DtGtDtB0AzztGtCzzyCtDyEzztCtD0CyBtC0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzytAtDyD0Fzy0FtGtAtDyBzztGzytCtAyBtGyC0CtA0AtGyC0DyDzz0Bzz0ByE0AyByEzy2Q&cr=1906506504&ir= SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = BHO-x32: Mega Browse - {4e6cd411-ce62-4584-97ff-6afbcf6900af} - C:\Program Files (x86)\Mega Browse\MegaBrowsebho.dll (Mega Browse) BHO-x32: mysearchdial Helper Object - {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll (MySearchDial) Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll (MySearchDial) C:\Program Files (x86)\Google C:\Users\asus\AppData\Local\Google C:\Users\asus\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\asus\AppData\Roaming\sp_data.sys C:\Users\asus\AppData\Roaming\systweak C:\Users\asus\Downloads\avast-Free-Antivirus(13266)(1).exe C:\Windows\System32\drivers\wStLibG64.sys Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ***************** [2516] C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe => Process closed successfully. [2860] C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe => Process closed successfully. Update Mega Browse => Service deleted successfully. Util Mega Browse => Service stopped successfully. Util Mega Browse => Service deleted successfully. wStLibG64 => Unable to stop service wStLibG64 => Service deleted successfully. cpuz135 => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{468A200B-4897-4E55-BF1F-DD49321100C3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{468A200B-4897-4E55-BF1F-DD49321100C3} => Key deleted successfully. C:\Windows\System32\Tasks\MySearchDial => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySearchDial => Key deleted successfully. C:\Windows\Tasks\MySearchDial.job => Moved successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => Key deleted successfully. HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => Key deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mcui_exe => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} => Key deleted successfully. HKCR\CLSID\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e6cd411-ce62-4584-97ff-6afbcf6900af} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{4e6cd411-ce62-4584-97ff-6afbcf6900af} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{3004627E-F8E9-4E8B-909D-316753CBA923} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923} => Key deleted successfully. C:\Program Files (x86)\Google => Moved successfully. C:\Users\asus\AppData\Local\Google => Moved successfully. C:\Users\asus\AppData\Local\Temp\fp_pl_pfs_installer.exe => Moved successfully. C:\Users\asus\AppData\Roaming\sp_data.sys => Moved successfully. C:\Users\asus\AppData\Roaming\systweak => Moved successfully. C:\Users\asus\Downloads\avast-Free-Antivirus(13266)(1).exe => Moved successfully. C:\Windows\System32\drivers\wStLibG64.sys => Moved successfully. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====