Fix result of Farbar Recovery Scan Tool (x64) Version:13-06-2015 Ran by Tomek at 2015-06-19 21:02:14 Run:1 Running from C:\Users\Tomek\Desktop\Logi Loaded Profiles: Tomek (Available Profiles: Tomek) Boot Mode: Normal ============================================== fixlist content: ***************** ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1433102646&z=d282853e91228df8a145aabg0z5c2c3g8eco3qfzdc&from=wpc&uid=WDCXWD10EARS-003BB1_WD-WCAV5N79763597635 ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1433102646&z=d282853e91228df8a145aabg0z5c2c3g8eco3qfzdc&from=wpc&uid=WDCXWD10EARS-003BB1_WD-WCAV5N79763597635 ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0\WSE on the Web.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1433102646&z=d282853e91228df8a145aabg0z5c2c3g8eco3qfzdc&from=wpc&uid=WDCXWD10EARS-003BB1_WD-WCAV5N79763597635 ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1433102646&z=d282853e91228df8a145aabg0z5c2c3g8eco3qfzdc&from=wpc&uid=WDCXWD10EARS-003BB1_WD-WCAV5N79763597635 ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1433102646&z=d282853e91228df8a145aabg0z5c2c3g8eco3qfzdc&from=wpc&uid=WDCXWD10EARS-003BB1_WD-WCAV5N79763597635 ShortcutWithArgument: C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.mystartsearch.com/?type=sc&ts=1433102646&z=d282853e91228df8a145aabg0z5c2c3g8eco3qfzdc&from=wpc&uid=WDCXWD10EARS-003BB1_WD-WCAV5N79763597635 HKLM-x32\...\Run: [NPSStartup] => [X] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.c...q={searchTerms} HKU\S-1-5-21-3484077856-2024222258-2036092784-1000\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.c...q={searchTerms} HKU\S-1-5-21-3484077856-2024222258-2036092784-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006 SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms} SearchScopes: HKU\S-1-5-21-3484077856-2024222258-2036092784-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms} BHO: No Name -> {B4B3EC85-72C1-4A89-99AA-C2B1B73CDFF7} -> No File Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File C:\Program Files (x86)\Quebles Emoticons C:\Program Files (x86)\PriuceMinuss C:\ProgramData\{5c964c43-f602-5fc6-5c96-64c43f60310f} EmptyTemp: ***************** C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Shortcut argument removed successfully. C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument removed successfully. C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft WSE 3.0\WSE on the Web.lnk => Shortcut argument removed successfully. C:\Users\Tomek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument restored successfully C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument removed successfully. C:\Users\Tomek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Shortcut argument removed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => value removed successfully "HKLM\SOFTWARE\Policies\Google" => key removed successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-3484077856-2024222258-2036092784-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-3484077856-2024222258-2036092784-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully HKCR\Wow6432Node\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found. HKU\S-1-5-21-3484077856-2024222258-2036092784-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4B3EC85-72C1-4A89-99AA-C2B1B73CDFF7}" => key removed successfully HKCR\CLSID\{B4B3EC85-72C1-4A89-99AA-C2B1B73CDFF7} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value removed successfully "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => key removed successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found. C:\Program Files (x86)\Quebles Emoticons => moved successfully. C:\Program Files (x86)\PriuceMinuss => moved successfully. C:\ProgramData\{5c964c43-f602-5fc6-5c96-64c43f60310f} => moved successfully. EmptyTemp: => 532.1 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 21:03:37 ====