Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2014 Ran by Goku at 2014-12-06 08:24:58 Run:1 Running from C:\Users\Goku\Downloads Loaded Profiles: Goku & UpdatusUser (Available profiles: Goku & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.us.com/?guid={2CD3B27F-B925-4194-A8C7-ACE1D2832E5E} HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.us.com/?guid={2CD3B27F-B925-4194-A8C7-ACE1D2832E5E} SearchScopes: HKU\S-1-5-21-1163469901-3333247925-1792307710-1000 -> DefaultScope {276109A3-C45B-490B-A964-1CB55042184A} URL = http://search.us.com/serp?guid={F708E7BC-7579-46BD-B69A-C09D766FBFF5}&action=default_search&k={searchTerms} SearchScopes: HKU\S-1-5-21-1163469901-3333247925-1792307710-1000 -> {276109A3-C45B-490B-A964-1CB55042184A} URL = http://search.us.com/serp?guid={F708E7BC-7579-46BD-B69A-C09D766FBFF5}&action=default_search&k={searchTerms} SearchScopes: HKU\S-1-5-21-1163469901-3333247925-1792307710-1000 -> {8AC95EAC-EDE7-4C62-A5ED-840DA604DDE7} URL = http://search.us.com/serp?guid={2CD3B27F-B925-4194-A8C7-ACE1D2832E5E}&action=default_search&k={searchTerms} SearchScopes: HKU\S-1-5-21-1163469901-3333247925-1792307710-1000 -> {8FC273F1-4993-442E-969B-343336AB05B3} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10511 Task: {7EB57724-7EB4-4E08-BAB3-6A563BBD63FA} - System32\Tasks\{69C94FE8-C78F-43E1-B8BF-97655ED92F75} => D:\Reinstall\Microsoft Office Standard 2010 PL\Microsoft Excel 2010.exe Task: {833FAC63-9530-4BA0-869B-9F1116FA1CDA} - System32\Tasks\{1CD05D51-42ED-449A-B0A0-0898351DBFD9} => D:\Reinstall\Microsoft Office Standard 2010 PL\Microsoft Excel 2010.exe Task: {EA4F96A6-D67E-409C-9ECC-B8C6363CE228} - System32\Tasks\{5AF67240-1C9A-47BF-BD0C-CC4CDCAEF3E1} => D:\Reinstall\Microsoft Office Standard 2010 PL\Microsoft Excel 2010.exe C:\Users\UpdatusUser\Desktop\SpeedFan.lnk Reg: reg delete HKLM\SOFTWARE\Google /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{276109A3-C45B-490B-A964-1CB55042184A}" => Key deleted successfully. "HKCR\CLSID\{276109A3-C45B-490B-A964-1CB55042184A}" => Key not found. "HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8AC95EAC-EDE7-4C62-A5ED-840DA604DDE7}" => Key deleted successfully. "HKCR\CLSID\{8AC95EAC-EDE7-4C62-A5ED-840DA604DDE7}" => Key not found. "HKU\S-1-5-21-1163469901-3333247925-1792307710-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8FC273F1-4993-442E-969B-343336AB05B3}" => Key deleted successfully. "HKCR\CLSID\{8FC273F1-4993-442E-969B-343336AB05B3}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7EB57724-7EB4-4E08-BAB3-6A563BBD63FA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7EB57724-7EB4-4E08-BAB3-6A563BBD63FA}" => Key deleted successfully. C:\Windows\System32\Tasks\{69C94FE8-C78F-43E1-B8BF-97655ED92F75} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{69C94FE8-C78F-43E1-B8BF-97655ED92F75}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{833FAC63-9530-4BA0-869B-9F1116FA1CDA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{833FAC63-9530-4BA0-869B-9F1116FA1CDA}" => Key deleted successfully. C:\Windows\System32\Tasks\{1CD05D51-42ED-449A-B0A0-0898351DBFD9} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1CD05D51-42ED-449A-B0A0-0898351DBFD9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA4F96A6-D67E-409C-9ECC-B8C6363CE228}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA4F96A6-D67E-409C-9ECC-B8C6363CE228}" => Key deleted successfully. C:\Windows\System32\Tasks\{5AF67240-1C9A-47BF-BD0C-CC4CDCAEF3E1} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5AF67240-1C9A-47BF-BD0C-CC4CDCAEF3E1}" => Key deleted successfully. C:\Users\UpdatusUser\Desktop\SpeedFan.lnk => Moved successfully. ========= reg delete HKLM\SOFTWARE\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 149.2 MB temporary data. The system needed a reboot. ==== End of Fixlog ====