Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2014 Ran by Dominika at 2014-12-04 20:36:53 Run:2 Running from C:\Users\Dominika\Desktop\Logi\Frst64 Loaded Profile: Dominika (Available profiles: Dominika) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: SearchScopes: HKLM-x32 -> {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 SearchScopes: HKU\S-1-5-21-1816805013-2468701961-1920383271-1000 -> DefaultScope {208659B4-57CE-4DDF-BCC0-A2C33EF8FDD8} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=402027&p={searchTerms} SearchScopes: HKU\S-1-5-21-1816805013-2468701961-1920383271-1000 -> {208659B4-57CE-4DDF-BCC0-A2C33EF8FDD8} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=402027&p={searchTerms} SearchScopes: HKU\S-1-5-21-1816805013-2468701961-1920383271-1000 -> {EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C} URL = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-10-25] (IObit) HKU\S-1-5-21-1816805013-2468701961-1920383271-1000\...\Run: [DIMDownloading your update...1300677038363] => "C:\Program Files (x86)\Corel\CorelDRAW Graphics Suite X5\Programs\DIM.exe" "c:\programdata\corel\downloads\540215253_610005\1300677038363\dim_params.xml" -Launch=3 -uibase="c:\programdata\corel\messa (the data entry has 47 more characters). Task: {82E61B9D-60B1-4308-B19E-D1EBF8FD2560} - System32\Tasks\{4B23CCCD-CF38-46B8-9EE0-C872E6EBB87E} => Iexplore.exe http://ui.skype.com/ui/0/5.1.0.112.280/en/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled Toolbar: HKU\S-1-5-21-1816805013-2468701961-1920383271-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File FF HKLM-x32\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" C:\Program Files (x86)\Common Files\Spigot C:\Program Files (x86)\IObit C:\Users\Dominika\AppData\Local\Temp*.html C:\Users\Dominika\AppData\Local\Slick Savings C:\Users\Dominika\AppData\Roaming\IObit C:\Users\Dominika\AppData\Roaming\OpenCandy C:\Users\Dominika\AppData\Roaming\Slick Savings DeleteKey: HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions CMD: SET EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key not found. "HKCR\Wow6432Node\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key not found. HKU\S-1-5-21-1816805013-2468701961-1920383271-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found. "HKU\S-1-5-21-1816805013-2468701961-1920383271-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{208659B4-57CE-4DDF-BCC0-A2C33EF8FDD8}" => Key not found. "HKCR\CLSID\{208659B4-57CE-4DDF-BCC0-A2C33EF8FDD8}" => Key not found. "HKU\S-1-5-21-1816805013-2468701961-1920383271-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key not found. "HKCR\CLSID\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}" => Key not found. LiveUpdateSvc => Service not found. HKU\S-1-5-21-1816805013-2468701961-1920383271-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DIMDownloading your update...1300677038363 => Value not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82E61B9D-60B1-4308-B19E-D1EBF8FD2560}" => Key not found. C:\Windows\System32\Tasks\{4B23CCCD-CF38-46B8-9EE0-C872E6EBB87E} not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4B23CCCD-CF38-46B8-9EE0-C872E6EBB87E}" => Key not found. HKU\S-1-5-21-1816805013-2468701961-1920383271-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value not found. "HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => Key not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4} => Value not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com => Value not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc" => Key not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MCODS" => Key not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc" => Key not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MCODS" => Key not found. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MpfService" => Key not found. "C:\Program Files (x86)\Common Files\Spigot" => File/Directory not found. "C:\Program Files (x86)\IObit" => File/Directory not found. "C:\Users\Dominika\AppData\Local\Temp*.html" => File/Directory not found. "C:\Users\Dominika\AppData\Local\Slick Savings" => File/Directory not found. "C:\Users\Dominika\AppData\Roaming\IObit" => File/Directory not found. "C:\Users\Dominika\AppData\Roaming\OpenCandy" => File/Directory not found. "C:\Users\Dominika\AppData\Roaming\Slick Savings" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions => Key not found. ========= SET ========= ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\Dominika\AppData\Roaming CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files CommonProgramW6432=C:\Program Files\Common Files COMPUTERNAME=DOMINIKA-TOSH ComSpec=C:\Windows\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Users\Dominika LOCALAPPDATA=C:\Users\Dominika\AppData\Local LOGONSERVER=\\DOMINIKA-TOSH NUMBER_OF_PROCESSORS=4 OS=Windows_NT Path=C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Windows Live\Shared PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 37 Stepping 2, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=2502 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) ProgramW6432=C:\Program Files PROMPT=$P$G PSModulePath=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\ PUBLIC=C:\Users\Public SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\Windows TEMP=C:\Users\Dominika\AppData\Local\Temp TMP=C:\Users\Dominika\AppData\Local\Temp USERDOMAIN=Dominika-TOSH USERNAME=Dominika USERPROFILE=C:\Users\Dominika windir=C:\Windows ========= End of CMD: ========= EmptyTemp: => Removed 7.4 GB temporary data. The system needed a reboot. ==== End of Fixlog ====