Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-06-2014 Ran by Jakub at 2014-06-16 21:04:03 Run:1 Running from C:\Users\Jakub\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {25B3B1E0-49AF-4B78-A701-3CDD10810BBF} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION Task: {5B71FED8-A04F-46D3-9349-94013F3E298F} - System32\Tasks\DealPly => C:\Users\Jakub\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe [2013-02-27] () <==== ATTENTION Task: {DE67B6BF-0BA5-4D69-B3B2-7ACC83ABC265} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\Jakub\AppData\Local\FilesFrog Update Checker\update_checker.exe <==== ATTENTION HKCU\...\StartupApproved\Run: => "lollipop" C:\ProgramData\IePluginService\PluginService.exe C:\ProgramData\WPM\wprotectmanager.exe C:\ProgramData\IePluginServices\PluginService.exe HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-...q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-pag..._S2U5J9DCA47717 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-pag..._S2U5J9DCA47717 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-...q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-pag...q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-pag...q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-pag..._S2U5J9DCA47717 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-pag..._S2U5J9DCA47717 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-pag...q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-pag..._S2U5J9DCA47717 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-pag..._S2U5J9DCA47717 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-pag...q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-hom..._S2U5J9DCA47717 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-pag...q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-pag...q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-pag...q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.sweet-pag...q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-...q={searchTerms} SearchScopes: HKCU - {14FA74AC-665D-460F-BE92-0F8879FC96FB} URL = SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-...q={searchTerms} FF Homepage: hxxp://www.sweet-page.com/?type=hp&ts=1398714684&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\delta-homes.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml CHR HomePage: hxxp://www.sweet-page.com/?type=hp&ts=1398714684&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 CHR DefaultSearchKeyword: sweet-page CHR DefaultSearchProvider: sweet-page CHR DefaultSearchURL: http://www.sweet-pag...q={searchTerms} CHR Extension: (Quick start) - C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-06-12] CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.delta-hom..._S2U5J9DCA47717 R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [705136 2014-04-11] (Cherished Technololgy LIMITED) R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [761968 2014-06-12] (Cherished Technololgy LIMITED) R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [540304 2014-06-11] (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices C:\Users\Jakub\AppData\Local\Temp\FLVPlayerSetup.exe C:\Users\Jakub\AppData\Local\Temp\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate.exe C:\Users\Jakub\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Jakub\AppData\Local\Temp\OptimizerPro.exe C:\Users\Jakub\AppData\Local\Temp\rad68DD3.tmp_update.exe C:\Users\Jakub\AppData\Local\Temp\splash_lite_setup.exe C:\Users\Jakub\AppData\Local\Temp\UpdateCheckerSetup.exe ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1402575920&from=wpm0612&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1402575920&from=wpm0612&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 ShortcutWithArgument: C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1402575920&from=wpm0612&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 ShortcutWithArgument: C:\Users\Jakub\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1402575920&from=wpm0612&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.delta-homes.com/?type=sc&ts=1402575920&from=wpm0612&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1402575920&from=wpm0612&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 Reboot: ***************** 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{25B3B1E0-49AF-4B78-A701-3CDD10810BBF}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25B3B1E0-49AF-4B78-A701-3CDD10810BBF}' => Key deleted successfully. C:\Windows\System32\Tasks\Desk 365 RunAsStdUser not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5B71FED8-A04F-46D3-9349-94013F3E298F}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B71FED8-A04F-46D3-9349-94013F3E298F}' => Key deleted successfully. C:\Windows\System32\Tasks\DealPly not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DE67B6BF-0BA5-4D69-B3B2-7ACC83ABC265}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE67B6BF-0BA5-4D69-B3B2-7ACC83ABC265}' => Key deleted successfully. C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart' => Key deleted successfully. "C:\ProgramData\IePluginService\PluginService.exe" => File/Directory not found. "C:\ProgramData\WPM\wprotectmanager.exe" => File/Directory not found. "C:\ProgramData\IePluginServices\PluginService.exe" => File/Directory not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{14FA74AC-665D-460F-BE92-0F8879FC96FB}' => Key deleted successfully. 'HKCR\CLSID\{14FA74AC-665D-460F-BE92-0F8879FC96FB}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. Firefox homepage deleted successfully. "C:\Program Files (x86)\mozilla firefox\browser\searchplugins\delta-homes.xml" => not found. "C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml" => not found. CHR HomePage: hxxp://www.sweet-page.com/?type=hp&ts=1398714684&from=cor&uid=ST1000LM024XHN-M101MBB_S2U5J9DCA47717 ==> The Chrome "Settings" can be used to fix the entry. CHR DefaultSearchKeyword: sweet-page ==> The Chrome "Settings" can be used to fix the entry. CHR DefaultSearchProvider: sweet-page ==> The Chrome "Settings" can be used to fix the entry. CHR DefaultSearchURL: http://www.sweet-pag...q={searchTerms} ==> The Chrome "Settings" can be used to fix the entry. C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. IePluginService => Service not found. IePluginServices => Service not found. Wpm => Service not found. "C:\ProgramData\IePluginServices" => File/Directory not found. C:\Users\Jakub\AppData\Local\Temp\FLVPlayerSetup.exe => Moved successfully. C:\Users\Jakub\AppData\Local\Temp\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate.exe => Moved successfully. C:\Users\Jakub\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe => Moved successfully. C:\Users\Jakub\AppData\Local\Temp\OptimizerPro.exe => Moved successfully. C:\Users\Jakub\AppData\Local\Temp\rad68DD3.tmp_update.exe => Moved successfully. C:\Users\Jakub\AppData\Local\Temp\splash_lite_setup.exe => Moved successfully. C:\Users\Jakub\AppData\Local\Temp\UpdateCheckerSetup.exe => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Jakub\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Google Chrome.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Mozilla Firefox.lnk => Shortcut argument was removed successfully. The system needed a reboot. ==== End of Fixlog ====