Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-04-2014 03 Ran by Patryk at 2014-04-27 15:39:30 Run:1 Running from C:\Users\Patryk\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Users\Patryk\AppData\Local\fst_pl_96\upfst_pl_96.exe () C:\Program Files (x86)\fst_pl_96\fst_pl_96.exe HKLM-x32\...\Run: [fst_pl_96] => C:\Program Files (x86)\fst_pl_96\fst_pl_96.exe [3985408 2014-03-27] () HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\RunOnce: [upfst_pl_96.exe] - C:\Users\Patryk\AppData\Local\fst_pl_96\upfst_pl_96.exe -runonce [3264512 2014-03-27] () HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-1109735758-1390704349-2981523167-1002\...\Run: [SpeedUpMyComputer] => C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as HKU\S-1-5-21-1109735758-1390704349-2981523167-1002\...\Run: [lollipop_04111812] => "c:\users\patryk\appdata\local\lollipop\lollipop_04111812.exe" lollipop_04111812 Task: {062420C6-9630-4953-8740-F0A16762D2DE} - System32\Tasks\pricemeterwatcher => C:\Users\Patryk\AppData\Local\PriceMeter\pricemeterw.exe <==== ATTENTION Task: {06CCE544-E2A9-4840-B773-FAE45CF4BBA7} - System32\Tasks\pricemeterdownloader => C:\Users\Patryk\AppData\Local\PriceMeter\pricemeterd.exe <==== ATTENTION Task: {70831304-4754-46D2-BEA0-A7E58B25C778} - System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION Task: {A57C7ED6-69D1-40C7-85C4-3BBF0A426036} - System32\Tasks\pricemetertask => C:\Users\Patryk\AppData\Local\PriceMeter\pricemeter.exe <==== ATTENTION Task: {FC0AFBBE-8CA3-4E98-954F-F7B1D63866CB} - System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION FF Plugin-x32: @tools.updatepm.com/PriceMeterLiveUpdate Update;version=3 - C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.updatepm.com/PriceMeterLiveUpdate Update;version=9 - C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll No File ShortcutWithArgument: C:\Users\Patryk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://start.qone8.com/?type=sc&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX ShortcutWithArgument: C:\Users\Patryk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://start.qone8.com/?type=sc&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qone8.com/?type=hp&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.qone8.com/web/?type=ds&ts=1396863566&from=tt4u&uid=HitachiXHTS545032A7E380_TE8B113RHA89KNHA89KNX&q={searchTerms} C:\Program Files (x86)\Freemake C:\Program Files (x86)\iWebar C:\Program Files (x86)\Kaspersky Lab C:\Program Files (x86)\PriceMeterLiveUpdate C:\Program Files (x86)\SmartTweak C:\ProgramData\Freemake C:\ProgramData\Kaspersky Lab C:\ProgramData\PriceMeterLiveUpdate C:\Users\Patryk\.android C:\Users\Patryk\AppData\Local\cache C:\Users\Patryk\AppData\Local\PriceMeter C:\Users\Patryk\AppData\Roaming\sp_data.sys C:\Users\Patryk\AppData\Roaming\Mozilla C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeter C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop C:\Users\Patryk\Documents\Freemake Folder: C:\Windows\system32\GroupPolicy Folder: C:\Windows\SysWOW64\GroupPolicy CMD: for /d %f in (C:\Users\Patryk\AppData\Local\{*}) do rd /s /q "%f" Reboot: ***************** [3740] C:\Users\Patryk\AppData\Local\fst_pl_96\upfst_pl_96.exe => Process closed successfully. [4280] C:\Program Files (x86)\fst_pl_96\fst_pl_96.exe => Process closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_96 => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upfst_pl_96.exe => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => Value deleted successfully. HKU\S-1-5-21-1109735758-1390704349-2981523167-1002\Software\Microsoft\Windows\CurrentVersion\Run\\SpeedUpMyComputer => Value deleted successfully. HKU\S-1-5-21-1109735758-1390704349-2981523167-1002\Software\Microsoft\Windows\CurrentVersion\Run\\lollipop_04111812 => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{062420C6-9630-4953-8740-F0A16762D2DE} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{062420C6-9630-4953-8740-F0A16762D2DE} => Key deleted successfully. C:\Windows\System32\Tasks\pricemeterwatcher => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pricemeterwatcher => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06CCE544-E2A9-4840-B773-FAE45CF4BBA7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06CCE544-E2A9-4840-B773-FAE45CF4BBA7} => Key deleted successfully. C:\Windows\System32\Tasks\pricemeterdownloader => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pricemeterdownloader => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{70831304-4754-46D2-BEA0-A7E58B25C778} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70831304-4754-46D2-BEA0-A7E58B25C778} => Key deleted successfully. C:\Windows\System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PriceMeterLiveUpdateUpdateTaskMachineCore => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A57C7ED6-69D1-40C7-85C4-3BBF0A426036} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A57C7ED6-69D1-40C7-85C4-3BBF0A426036} => Key deleted successfully. C:\Windows\System32\Tasks\pricemetertask => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pricemetertask => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FC0AFBBE-8CA3-4E98-954F-F7B1D63866CB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC0AFBBE-8CA3-4E98-954F-F7B1D63866CB} => Key deleted successfully. C:\Windows\System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PriceMeterLiveUpdateUpdateTaskMachineUA => Key deleted successfully. C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job => Moved successfully. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3 => Key deleted successfully. C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll not found. HKLM\Software\Wow6432Node\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9 => Key deleted successfully. C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll not found. C:\Users\Patryk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Patryk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. C:\Program Files (x86)\Freemake => Moved successfully. C:\Program Files (x86)\iWebar => Moved successfully. C:\Program Files (x86)\Kaspersky Lab => Moved successfully. "C:\Program Files (x86)\PriceMeterLiveUpdate" => File/Directory not found. C:\Program Files (x86)\SmartTweak => Moved successfully. C:\ProgramData\Freemake => Moved successfully. C:\ProgramData\Kaspersky Lab => Moved successfully. C:\ProgramData\PriceMeterLiveUpdate => Moved successfully. C:\Users\Patryk\.android => Moved successfully. C:\Users\Patryk\AppData\Local\cache => Moved successfully. "C:\Users\Patryk\AppData\Local\PriceMeter" => File/Directory not found. C:\Users\Patryk\AppData\Roaming\sp_data.sys => Moved successfully. C:\Users\Patryk\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeter => Moved successfully. C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully. C:\Users\Patryk\Documents\Freemake => Moved successfully. ========================= Folder: C:\Windows\system32\GroupPolicy ======================== 2014-04-04 12:21 - 2014-04-04 12:21 - 0000000 ____D () C:\Windows\system32\GroupPolicy\Machine 2014-04-04 12:21 - 2014-04-04 12:21 - 0000000 ____D () C:\Windows\system32\GroupPolicy\User ====== End of Folder: ====== ========================= Folder: C:\Windows\SysWOW64\GroupPolicy ======================== ====== End of Folder: ====== ========= for /d %f in (C:\Users\Patryk\AppData\Local\{*}) do rd /s /q "%f" ========= ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ====