Fix result of Farbar Recovery Scan Tool (x64) Version:25-07-2015 Ran by Tadeusz at 2015-07-27 14:58:56 Run:1 Running from C:\Users\Tadeusz\Downloads Loaded Profiles: Tadeusz (Available Profiles: Tadeusz) Boot Mode: Normal ============================================== fixlist content: ***************** HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1427558249&from=corna&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1427558249&from=corna&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1427558249&from=corna&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1427558249&from=corna&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG&q={searchTerms} HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?type=ds&ts=1432142983&z=fc72101f810b6b59645a5c0gbzcc2o2gbzao2t8b6c&from=wpm05203&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG&q={searchTerms} HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?type=hp&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?type=hp&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.delta-homes.com/web/?type=ds&ts=1432142983&z=fc72101f810b6b59645a5c0gbzcc2o2gbzao2t8b6c&from=wpm05203&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG&q={searchTerms} SearchScopes: HKU\S-1-5-21-2944422745-3718675205-452331776-1001 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2944422745-3718675205-452331776-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2944422745-3718675205-452331776-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2944422745-3718675205-452331776-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2944422745-3718675205-452331776-1001 -> {E64653FC-F85D-4A9C-A59F-86E1F459A462} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2944422745-3718675205-452331776-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\XTab\SupTab.dll No File BHO-x32: Digital More -> {c0b1016f-b7e5-46f0-b415-6bf9e55ab00d} -> C:\Program Files (x86)\Digital More\Extensions\c0b1016f-b7e5-46f0-b415-6bf9e55ab00d.dll No File Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-homes.com/?type=sc&ts=1432142983&z=fc72101f810b6b59645a5c0gbzcc2o2gbzao2t8b6c&from=wpm05203&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG FF NewTab: hxxp://www.delta-homes.com/newtab/?type=nt&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG FF HKLM-x32\...\Firefox\Extensions: [searchengine@gmail.com] - C:\Users\Tadeusz\AppData\Roaming\Mozilla\Firefox\Profiles\u5kmhxcs.default\extensions\searchengine@gmail.com FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Tadeusz\AppData\Roaming\Mozilla\Firefox\Profiles\u5kmhxcs.default\extensions\fftoolbar2014@etech.com FF HKLM-x32\...\Firefox\Extensions: [quick_searchff@gmail.com] - C:\Users\Tadeusz\AppData\Roaming\Mozilla\Firefox\Profiles\u5kmhxcs.default\extensions\quick_searchff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [sweetsearch@gmail.com] - C:\Users\Tadeusz\AppData\Roaming\Mozilla\Firefox\Profiles\u5kmhxcs.default\extensions\sweetsearch@gmail.com FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Tadeusz\AppData\Roaming\Mozilla\Firefox\Profiles\2ilf0w8d.default-1433091564006\extensions\default_newtabff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Tadeusz\AppData\Roaming\Mozilla\Firefox\Profiles\2ilf0w8d.default-1433091564006\extensions\defsearchp@gmail.com StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.delta-homes.com/?type=sc&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe http://www.delta-homes.com/?type=sc&ts=1437596676&z=b9b0287124e86d86721e7b8g7z4cbm6wbt0q3qdmdc&from=wpm07163&uid=ST500LT012-1DG142_S3PHZZKGXXXXS3PHZZKG R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [429568 2015-07-22] (DTools LIMITED) [File not signed] <==== ATTENTION C:\ProgramData\WindowsMangerProtect EmptyTemp: ***************** HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-2944422745-3718675205-452331776-1001\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-2944422745-3718675205-452331776-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\S-1-5-21-2944422745-3718675205-452331776-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. "HKU\S-1-5-21-2944422745-3718675205-452331776-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => key removed successfully HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. "HKU\S-1-5-21-2944422745-3718675205-452331776-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. "HKU\S-1-5-21-2944422745-3718675205-452331776-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E64653FC-F85D-4A9C-A59F-86E1F459A462}" => key removed successfully HKCR\CLSID\{E64653FC-F85D-4A9C-A59F-86E1F459A462} => key not found. "HKU\S-1-5-21-2944422745-3718675205-452331776-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => key removed successfully HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => key removed successfully "HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c0b1016f-b7e5-46f0-b415-6bf9e55ab00d}" => key removed successfully "HKCR\Wow6432Node\CLSID\{c0b1016f-b7e5-46f0-b415-6bf9e55ab00d}" => key removed successfully ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully Firefox newtab removed successfully HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\searchengine@gmail.com => value removed successfully HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\fftoolbar2014@etech.com => value removed successfully HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\quick_searchff@gmail.com => value removed successfully HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\sweetsearch@gmail.com => value removed successfully HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\default_newtabff@gmail.com => value removed successfully HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\defsearchp@gmail.com => value removed successfully HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => value restored successfully HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command\\Default => value restored successfully WindowsMangerProtect => Unable to stop service. WindowsMangerProtect => service removed successfully C:\ProgramData\WindowsMangerProtect => moved successfully. EmptyTemp: => 2.3 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 15:00:23 ====