Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Dariusz at 2015-03-30 22:33:52 Run:2 Running from C:\Users\Dariusz\Downloads Loaded Profiles: UpdatusUser & Dariusz (Available profiles: UpdatusUser & Dariusz) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: CustomCLSID: HKU\S-1-5-21-3374727656-2870280814-1641782053-1002_Classes\CLSID\{61625667-893E-4707-B925-A82B528C00B9}\InprocServer32 -> C:\Users\Dariusz\AppData\Local\StartIsBack\StartIsBack64.dll No File CustomCLSID: HKU\S-1-5-21-3374727656-2870280814-1641782053-1002_Classes\CLSID\{E5C31EC8-C5E6-4E07-957E-944DB4AAD85E}\InprocServer32 -> C:\Users\Dariusz\AppData\Local\StartIsBack\StartIsBack64.dll No File Task: {0843B181-AD67-4715-B44B-6A561AE9EA37} - System32\Tasks\{C0C5185C-9403-4B01-8E2F-2D97A537B1DD} => pcalua.exe -a C:\Users\Dariusz\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1414712191&from=smt&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1414712191&from=smt&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q&q={searchTerms} HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q&q={searchTerms} HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q&q={searchTerms} SearchScopes: HKU\S-1-5-21-3374727656-2870280814-1641782053-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q&q={searchTerms} SearchScopes: HKU\S-1-5-21-3374727656-2870280814-1641782053-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3374727656-2870280814-1641782053-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?type=ds&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q&q={searchTerms} ShortcutWithArgument: C:\Users\Dariusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q ShortcutWithArgument: C:\Users\Dariusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q ShortcutWithArgument: C:\Users\Dariusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.delta-homes.com/?type=sc&ts=1418838280&from=wpm12173&uid=ST500LT012-1DG142_S3P2GW2QXXXXS3P2GW2Q 2015-02-27 14:52 - 2015-02-27 14:25 - 00008192 _____ () C:\shldr.mbr 2015-02-27 14:52 - 2012-11-02 15:23 - 00285747 _____ () C:\shldr 2015-02-27 14:52 - 2015-02-27 14:52 - 00007184 _____ () C:\spyhunter.fix 2015-02-27 14:25 - 2015-02-27 14:25 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKU\S-1-5-21-3374727656-2870280814-1641782053-1002_Classes\CLSID\{61625667-893E-4707-B925-A82B528C00B9}" => Key deleted successfully. "HKU\S-1-5-21-3374727656-2870280814-1641782053-1002_Classes\CLSID\{E5C31EC8-C5E6-4E07-957E-944DB4AAD85E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0843B181-AD67-4715-B44B-6A561AE9EA37}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0843B181-AD67-4715-B44B-6A561AE9EA37}" => Key deleted successfully. C:\Windows\System32\Tasks\{C0C5185C-9403-4B01-8E2F-2D97A537B1DD} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C0C5185C-9403-4B01-8E2F-2D97A537B1DD}" => Key deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully. HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully. HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully. HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => Key not found. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Key not found. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Key not found. "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-3374727656-2870280814-1641782053-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => Key deleted successfully. HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found. C:\Users\Dariusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\Users\Dariusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument was removed successfully. C:\Users\Dariusz\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => Shortcut argument was removed successfully. C:\shldr.mbr => Moved successfully. C:\shldr => Moved successfully. C:\spyhunter.fix => Moved successfully. C:\Program Files (x86)\Enigma Software Group => Moved successfully. EmptyTemp: => Removed 382.2 MB temporary data. The system needed a reboot. ==== End of Fixlog 22:34:43 ====