Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:30-05-2014 Ran by Albert at 2014-05-30 21:46:22 Run:1 Running from C:\Users\Albert\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** (Tlapia) C:\Program Files\sysTPL\sysTPLMonitor.exe R2 sysTPLMonitor.exe; C:\Program Files\sysTPL\sysTPLMonitor.exe [392984 2014-04-13] (Tlapia) S2 sysTPLService.exe; C:\Program Files\sysTPL\sysTPLService.exe [394520 2014-04-13] (Tlapia) R1 {55685567-4840-4a91-962b-49a412e9485a}Gw; C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw.sys [52920 2014-05-26] (StdLib) S3 BRSptSvc; "C:\programdata\bitraider\BRSptSvc.exe" [X] S3 BRDriver; \??\C:\programdata\bitraider\BRDriver.sys [X] HKU\S-1-5-21-3471368258-3413815123-251901639-1000\...\Run: [MyCuteBuddy] => "C:\Program Files\My Cute Buddy\myCuteBuddy.exe" "file:///C:/Program Files/My Cute Buddy/Content/Cute Kitty/piticho.buddy" /m /u HKU\S-1-5-21-3471368258-3413815123-251901639-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MyCuteBuddy] => "C:\Program Files\My Cute Buddy\myCuteBuddy.exe" "file:///C:/Program Files/My Cute Buddy/Content/Cute Kitty/piticho.buddy" /m /u SearchScopes: HKLM - DefaultScope value is missing. C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw.sys C:\Users\Albert\Downloads\IrfanView(12867).exe Task: {0AE8B980-6440-4479-9289-6A4566173F9D} - System32\Tasks\WOT WFRI1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {2592DD56-6669-4DFD-8D2B-ABDDE888A886} - System32\Tasks\WOT WW1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {2626E990-FCD6-4F2F-8D58-55FB486E5A26} - System32\Tasks\WOT W1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {4400D820-6067-425D-9967-5306C514F7E7} - System32\Tasks\WOT WTHUR1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {5295F8A2-2C50-43BC-8344-41E6A7C65F64} - System32\Tasks\WOT WMON1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {9E094C02-1E32-482D-B884-262C520D8245} - System32\Tasks\WOT T => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {A0E780B5-9010-4403-BC90-25B8B34517A8} - System32\Tasks\WOT WW2 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {EFBAB020-B459-4CDC-8F4C-8F0205513500} - System32\Tasks\WOT WTUE1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {F2F49C7B-29B1-4A6F-9D46-4B1242ED3A7E} - System32\Tasks\WOT WWED1 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {FEE3A67C-A0F7-4011-8D70-77BB8A348D3C} - System32\Tasks\WOT W2 => Firefox.exe http://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh advfirewall reset Reboot: ***************** [2412] C:\Program Files\sysTPL\sysTPLMonitor.exe => Process closed successfully. sysTPLMonitor.exe => Service deleted successfully. sysTPLService.exe => Service deleted successfully. {55685567-4840-4a91-962b-49a412e9485a}Gw => Service stopped successfully. {55685567-4840-4a91-962b-49a412e9485a}Gw => Service deleted successfully. BRSptSvc => Service deleted successfully. BRDriver => Service deleted successfully. HKU\S-1-5-21-3471368258-3413815123-251901639-1000\Software\Microsoft\Windows\CurrentVersion\Run\\MyCuteBuddy => Value deleted successfully. HKU\S-1-5-21-3471368258-3413815123-251901639-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Run\\MyCuteBuddy => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw.sys => Moved successfully. C:\Users\Albert\Downloads\IrfanView(12867).exe => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0AE8B980-6440-4479-9289-6A4566173F9D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0AE8B980-6440-4479-9289-6A4566173F9D} => Key deleted successfully. C:\Windows\System32\Tasks\WOT WFRI1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WFRI1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2592DD56-6669-4DFD-8D2B-ABDDE888A886} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2592DD56-6669-4DFD-8D2B-ABDDE888A886} => Key deleted successfully. C:\Windows\System32\Tasks\WOT WW1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2626E990-FCD6-4F2F-8D58-55FB486E5A26} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2626E990-FCD6-4F2F-8D58-55FB486E5A26} => Key deleted successfully. C:\Windows\System32\Tasks\WOT W1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT W1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4400D820-6067-425D-9967-5306C514F7E7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4400D820-6067-425D-9967-5306C514F7E7} => Key deleted successfully. C:\Windows\System32\Tasks\WOT WTHUR1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTHUR1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5295F8A2-2C50-43BC-8344-41E6A7C65F64} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5295F8A2-2C50-43BC-8344-41E6A7C65F64} => Key deleted successfully. C:\Windows\System32\Tasks\WOT WMON1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WMON1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E094C02-1E32-482D-B884-262C520D8245} => Key not found. C:\Windows\System32\Tasks\WOT T not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT T => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A0E780B5-9010-4403-BC90-25B8B34517A8} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0E780B5-9010-4403-BC90-25B8B34517A8} => Key deleted successfully. C:\Windows\System32\Tasks\WOT WW2 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW2 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EFBAB020-B459-4CDC-8F4C-8F0205513500} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFBAB020-B459-4CDC-8F4C-8F0205513500} => Key deleted successfully. C:\Windows\System32\Tasks\WOT WTUE1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTUE1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F2F49C7B-29B1-4A6F-9D46-4B1242ED3A7E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F2F49C7B-29B1-4A6F-9D46-4B1242ED3A7E} => Key deleted successfully. C:\Windows\System32\Tasks\WOT WWED1 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WWED1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FEE3A67C-A0F7-4011-8D70-77BB8A348D3C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEE3A67C-A0F7-4011-8D70-77BB8A348D3C} => Key deleted successfully. C:\Windows\System32\Tasks\WOT W2 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT W2 => Key deleted successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ====