Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-08-2014 Ran by User at 2014-08-08 21:10:04 Run:1 Running from C:\Users\User\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {CD7C98E5-DB32-480B-92CD-D9E650CB4ADD} - System32\Tasks\bench-Updater removing Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Task: {EA8197F2-6791-4C8C-B50A-B1C7898F1283} - System32\Tasks\Sk-Enhancer-S-5902107913 => c:\programdata\quickset\sk-enhancer\Sk-Enhancer.exe [2013-11-19] () <==== ATTENTION Task: {F282717F-6569-4C76-B414-B0E3D69D4DC8} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2013-12-18] () <==== ATTENTION Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION Task: C:\Windows\Tasks\bench-Updater removing.job => ? <==== ATTENTION Task: C:\Windows\Tasks\Sk-Enhancer-S-5902107913.job => c:\programdata\quickset\sk-enhancer\Sk-Enhancer.exe <==== ATTENTION c:\programdata\quickset\sk-enhancer\Sk-Enhancer.exe HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [fst_pl_31] => [X] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/ SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.c...q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.c...q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.c...q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://start.qone8.c...q={searchTerms} SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.pur...931&lg=EN&cc=PL CHR HomePage: hxxp://google.com/ CHR RestoreOnStartup: "hxxp://search.gboxapp.com/" CHR StartupUrls: "hxxp://search.gboxapp.com/" CHR Extension: (YouTuAdBlockker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdhkbebpdcohjeldbebgbefmomeadhkl CHR HKLM-x32\...\Chrome\Extension: [cekcjpgehmohobmdiikfnopibipmgnml] - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ [2014-01-15] CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2014-01-15] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 ATP; system32\DRIVERS\cmdatp.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S1 prodrv06; \SystemRoot\System32\drivers\prodrv06.sys [X] C:\ProgramData\HaPPy2Saavei C:\ProgramData\e3e1e0c40f694456 C:\Program Files (x86)\AllSaver C:\ProgramData\AllSaver C:\ProgramData\RRoboSaveR C:\ProgramData\EnjooyCooupon C:\ProgramData\ShopDrop C:\ProgramData\Isaver C:\Windows\Tasks\bench-Updater removing.job C:\Windows\Tasks\bench-sys.job C:\Windows\Tasks\Sk-Enhancer-S-5902107913.job C:\Users\User\AppData\Roaming\cache.ini C:\Users\User\AppData\Local\Temp\AskPIP_FF_.exe C:\Users\User\AppData\Local\Temp\Caramava_bs.exe C:\Users\User\AppData\Local\Temp\drm_dialogs.dll C:\Users\User\AppData\Local\Temp\drm_dyndata_7400008.dll C:\Users\User\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbkav6g.dll C:\Users\User\AppData\Local\Temp\FileZilla_3.7.3_win32-setup.exe C:\Users\User\AppData\Local\Temp\ICReinstall_WinZip175_mfse_fah.exe C:\Users\User\AppData\Local\Temp\msxml6-KB927977-enu-amd64.exe C:\Users\User\AppData\Local\Temp\msxml6-KB927977-enu-x86.exe C:\Users\User\AppData\Local\Temp\ose00000.exe C:\Users\User\AppData\Local\Temp\setup_fst_pl.exe C:\Users\User\AppData\Local\Temp\SkypeSetup.exe C:\Users\User\AppData\Local\Temp\sonarinst.exe C:\Users\User\AppData\Local\Temp\UpdateCheckerSetup.exe C:\Users\User\AppData\Local\Temp\_is5E08.exe C:\Users\User\AppData\Local\Temp\_is6430.exe Reboot: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD7C98E5-DB32-480B-92CD-D9E650CB4ADD}" => Key not found. C:\Windows\System32\Tasks\bench-Updater removing not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bench-Updater removing" => Key not found. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EA8197F2-6791-4C8C-B50A-B1C7898F1283}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA8197F2-6791-4C8C-B50A-B1C7898F1283}" => Key deleted successfully. C:\Windows\System32\Tasks\Sk-Enhancer-S-5902107913 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sk-Enhancer-S-5902107913" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F282717F-6569-4C76-B414-B0E3D69D4DC8}" => Key not found. C:\Windows\System32\Tasks\bench-sys not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bench-sys" => Key not found. C:\Windows\Tasks\bench-sys.job not found. C:\Windows\Tasks\bench-Updater removing.job not found. C:\Windows\Tasks\Sk-Enhancer-S-5902107913.job => Moved successfully. "c:\programdata\quickset\sk-enhancer\Sk-Enhancer.exe" => File/Directory not found. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_31 => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key not found. "HKCR\Wow6432Node\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}" => Key not found. CHR HomePage: hxxp://google.com/ ==> The Chrome "Settings" can be used to fix the entry. CHR RestoreOnStartup: "hxxp://search.gboxapp.com/" ==> The Chrome "Settings" can be used to fix the entry. CHR StartupUrls: "hxxp://search.gboxapp.com/" ==> The Chrome "Settings" can be used to fix the entry. CHR Extension: (YouTuAdBlockker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdhkbebpdcohjeldbebgbefmomeadhkl directory not found. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cekcjpgehmohobmdiikfnopibipmgnml" => Key not found. CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2014-01-15] ==> The Chrome "Settings" can be used to fix the entry. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo" => Key not found. "C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx" => File/Directory not found. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. ATP => Service deleted successfully. catchme => Service deleted successfully. EagleX64 => Service deleted successfully. prodrv06 => Service deleted successfully. "C:\ProgramData\HaPPy2Saavei" => File/Directory not found. C:\ProgramData\e3e1e0c40f694456 => Moved successfully. C:\Program Files (x86)\AllSaver => Moved successfully. C:\ProgramData\AllSaver => Moved successfully. C:\ProgramData\RRoboSaveR => Moved successfully. C:\ProgramData\EnjooyCooupon => Moved successfully. "C:\ProgramData\ShopDrop" => File/Directory not found. "C:\ProgramData\Isaver" => File/Directory not found. "C:\Windows\Tasks\bench-Updater removing.job" => File/Directory not found. "C:\Windows\Tasks\bench-sys.job" => File/Directory not found. "C:\Windows\Tasks\Sk-Enhancer-S-5902107913.job" => File/Directory not found. C:\Users\User\AppData\Roaming\cache.ini => Moved successfully. C:\Users\User\AppData\Local\Temp\AskPIP_FF_.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\Caramava_bs.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\drm_dialogs.dll => Moved successfully. C:\Users\User\AppData\Local\Temp\drm_dyndata_7400008.dll => Moved successfully. "C:\Users\User\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbkav6g.dll" => File/Directory not found. C:\Users\User\AppData\Local\Temp\FileZilla_3.7.3_win32-setup.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\ICReinstall_WinZip175_mfse_fah.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\msxml6-KB927977-enu-amd64.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\msxml6-KB927977-enu-x86.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\ose00000.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\setup_fst_pl.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\SkypeSetup.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\sonarinst.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\UpdateCheckerSetup.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\_is5E08.exe => Moved successfully. C:\Users\User\AppData\Local\Temp\_is6430.exe => Moved successfully. The system needed a reboot. ==== End of Fixlog ====