Fix result of Farbar Recovery Scan Tool (x64) Version:30-07-2015 Ran by Piotr (2015-08-01 13:18:13) Run:1 Running from D:\Biblioteki\Pobrane Loaded Profiles: Piotr (Available Profiles: Piotr) Boot Mode: Normal ============================================== fixlist content: ***************** CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsur...q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsur...q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsur...q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-948294637-126623534-2788625075-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-948294637-126623534-2788625075-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-948294637-126623534-2788625075-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-948294637-126623534-2788625075-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.istartsur...q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsur...C1147390C114739 FF NewTab: hxxp://www.istartsurf.com/newtab/?type=nt&ts=1438025515&z=edfa5004c1046cfbbd8e761gcz5cab6efoewdzaqem&from=obw&uid=ADATAXSP920SS_14140C1147390C114739 FF SearchPlugin: C:\Users\Piotr\AppData\Roaming\Mozilla\Firefox\Profiles\ifukcu1k.default\searchplugins\istartsurf.xml [2015-07-27] FF Extension: deskCut - C:\Users\Piotr\AppData\Roaming\Mozilla\Firefox\Profiles\ifukcu1k.default\Extensions\deskCutv2@gmail.com [2015-07-27] FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Piotr\AppData\Roaming\Mozilla\Firefox\Profiles\ifukcu1k.default\extensions\deskCutv2@gmail.com S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] 2015-07-27 21:34 - 2015-07-27 21:34 - 00000000 ____D C:\ProgramData\8982373780703246254 2015-07-27 21:34 - 2015-07-27 21:34 - 00000000 ____D C:\Program Files (x86)\RSS Subscription Extension by 2015-07-27 21:34 - 2015-07-27 21:34 - 00000000 ____D C:\Program Files (x86)\CutThePrice 2015-07-27 21:34 - 2015-07-27 21:34 - 00000000 ____D C:\Program Files (x86)\CuatThePruice 2015-07-27 21:34 - 2015-07-27 21:34 - 00000000 ____D C:\Program Files (x86)\bestadblocker 2015-07-27 21:33 - 2015-07-28 22:19 - 00000000 ____D C:\ProgramData\ahphcahnkamaapjichgaamkckohjfcac 2015-07-27 21:32 - 2015-07-29 20:07 - 00000000 ____D C:\Users\Piotr\AppData\Roaming\istartsurf 2015-07-27 21:32 - 2015-07-28 22:25 - 00000000 ____D C:\ProgramData\{22f70bc9-6994-e68d-22f7-70bc96992f25} 2015-07-27 21:32 - 2015-07-27 21:43 - 00000000 ____D C:\ProgramData\tWinManProt 2015-07-27 21:32 - 2015-07-27 21:43 - 00000000 ____D C:\Program Files (x86)\MiuiTab 2015-07-27 21:32 - 2015-07-27 21:36 - 00000000 ____D C:\Users\Piotr\AppData\Local\ospd_us_013010043 2015-07-27 21:32 - 2015-07-27 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ONESOFTPERDAY 2015-07-27 21:32 - 2015-07-27 21:32 - 00000000 ____D C:\ProgramData\IHProtectUpDate 2015-07-27 21:32 - 2015-07-27 21:32 - 00000000 ____D C:\Program Files (x86)\ospd_us_013010043 EmptyTemp: ***************** "HKLM\SOFTWARE\Policies\Google" => key removed successfully ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-948294637-126623534-2788625075-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\S-1-5-21-948294637-126623534-2788625075-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKU\S-1-5-21-948294637-126623534-2788625075-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. HKU\S-1-5-21-948294637-126623534-2788625075-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully Firefox newtab removed successfully "C:\Users\Piotr\AppData\Roaming\Mozilla\Firefox\Profiles\ifukcu1k.default\searchplugins\istartsurf.xml" => not found. C:\Users\Piotr\AppData\Roaming\Mozilla\Firefox\Profiles\ifukcu1k.default\Extensions\deskCutv2@gmail.com not found. HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\deskCutv2@gmail.com => value not found. Synth3dVsc => service removed successfully tsusbhub => service removed successfully VGPU => service removed successfully "C:\ProgramData\8982373780703246254" => File/Folder not found. C:\Program Files (x86)\RSS Subscription Extension by => moved successfully. "C:\Program Files (x86)\CutThePrice" => File/Folder not found. "C:\Program Files (x86)\CuatThePruice" => File/Folder not found. "C:\Program Files (x86)\bestadblocker" => File/Folder not found. "C:\ProgramData\ahphcahnkamaapjichgaamkckohjfcac" => File/Folder not found. "C:\Users\Piotr\AppData\Roaming\istartsurf" => File/Folder not found. "C:\ProgramData\{22f70bc9-6994-e68d-22f7-70bc96992f25}" => File/Folder not found. C:\ProgramData\tWinManProt => moved successfully. "C:\Program Files (x86)\MiuiTab" => File/Folder not found. C:\Users\Piotr\AppData\Local\ospd_us_013010043 => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ONESOFTPERDAY => moved successfully. "C:\ProgramData\IHProtectUpDate" => File/Folder not found. C:\Program Files (x86)\ospd_us_013010043 => moved successfully. EmptyTemp: => 10.4 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 13:18:28 ====