tady Fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-10-2014 01
Ran by ALA at 2014-10-28 23:29:01 Run:1
Running from C:\Users\ALA\Desktop
Loaded Profile: ALA (Available profiles: ALA)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM-x32\...\Run: [MSStp] => C:\Windows\inf\msstp.vbe
HKLM-x32\...\Run: [mncwmojSrv] => C:\Windows\system32\mncwmoj.vbe
HKLM\...\Policies\Explorer\Run: [2934679997] => C:\ProgramData\mscim.exe [623104 2014-10-27] ( (EFD Software))
HKU\S-1-5-21-3143607116-3805704415-591616805-1000\...\Run: [2934679997] => C:\Users\ALA\AppData\Roaming\mscim.exe
HKU\S-1-5-21-3143607116-3805704415-591616805-1000\...\Run: [50fce1d8cc92b5f2d3d5e28e9bce7d08] => C:\Users\ALA\AppData\Local\Temp\50fce1d8cc92b5f2d3d5e28e9bce7d08.exe [299919 2014-10-27] (Novostrim, Inc.) <===== ATTENTION
HKU\S-1-5-18\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideSCAHealth] 0
Startup: C:\Users\ALA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HDD.vbs ()
Startup: C:\Users\ALA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winxp.vbs ()
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.search.ask.com/?o=APN10653A& ... -15857&t=4
URLSearchHook: HKCU - (No Name) - {55E19115-8EF8-465C-90AC-DEACC491B0CC} - No File
SearchScopes: HKLM-x32 - {0D7562AE-8EF6-416d-A838-AB665251703A} URL =
http://start.facemoods.com/?a=wfxt2&s={ ... }&src=chrm
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL =
http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.as ... =CT2351701
SearchScopes: HKCU - {07E1A5F7-4853-465A-BF84-299A6E798F98} URL =
http://rover.ebay.com/rover/1/710-71511 ... earchTerms}
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL =
http://websearch.ask.com/redirect?clien ... cale=en_EU
SearchScopes: HKCU - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL =
http://www.crawler.com/search/dispatche ... tbid=60327
SearchScopes: HKCU - {23A078D7-C722-48DC-94A5-DF4CC8ACB3BE} URL =
http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {50149EB7-8536-4BFB-AB9F-047BB6D4ECBA} URL =
http://www.amazon.co.uk/gp/search?ie=UT ... nkCode=ur2
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL =
http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL =
http://www.daemon-search.com/search/web?q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
http://search.conduit.com/ResultsExt.as ... =CT2351701
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKCU - No Name - {55E19115-8EF8-465C-90AC-DEACC491B0CC} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
2014-10-28 09:29 - 2014-10-28 09:34 - 00000000 ____D () C:\Users\ALA\AppData\Roaming\tor
2014-10-27 20:08 - 2014-10-27 20:08 - 00000000 ____D () C:\Users\ALA\AppData\Roaming\ExampleFolder
2014-10-27 17:58 - 2014-10-27 17:58 - 00934912 _____ (EFD Software) C:\Users\ALA\AppData\Roaming\suntor.exe
2014-10-27 17:58 - 2014-10-27 17:58 - 00000050 _____ () C:\Users\ALA\AppData\Roaming\suntor.bat
C:\Program Files (x86)\Cube World + Crack [CZ]
C:\Windows\SysWOW64\acumncwmoj.exe
C:\Windows\SysWOW64\lcpmncwmoj.exe
C:\Users\ALA\AppData\Local\Temp\50fce1d8cc92b5f2d3d5e28e9bce7d08.exe
C:\ProgramData\mscim.exe
C:\Users\ALA\AppData\Local\Temp\KB00503602.exe
C:\Users\ALA\AppData\Local\Temp\KB279657501.exe
C:\Users\ALA\AppData\Local\Temp\KB279658171.exe
C:\Users\ALA\AppData\Local\Temp\KB279659123.exe
C:\Users\ALA\AppData\Local\Temp\KB287190196.exe
C:\Users\ALA\AppData\Local\Temp\KB287495896.exe
C:\Users\ALA\AppData\Local\Temp\KB287796931.exe
C:\Users\ALA\AppData\Local\Temp\retds1.exe
C:\Users\ALA\AppData\Local\Temp\reuqie.scr
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\MSStp => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mncwmojSrv => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\2934679997 => value deleted successfully.
HKU\S-1-5-21-3143607116-3805704415-591616805-1000\Software\Microsoft\Windows\CurrentVersion\Run\\2934679997 => Value not found.
HKU\S-1-5-21-3143607116-3805704415-591616805-1000\Software\Microsoft\Windows\CurrentVersion\Run\\50fce1d8cc92b5f2d3d5e28e9bce7d08 => Value not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification => value deleted successfully.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value deleted successfully.
C:\Users\ALA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HDD.vbs => Moved successfully.
C:\Users\ALA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winxp.vbs => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{55E19115-8EF8-465C-90AC-DEACC491B0CC} => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{0D7562AE-8EF6-416d-A838-AB665251703A}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{07E1A5F7-4853-465A-BF84-299A6E798F98}" => Key deleted successfully.
"HKCR\CLSID\{07E1A5F7-4853-465A-BF84-299A6E798F98}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}" => Key deleted successfully.
"HKCR\CLSID\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key deleted successfully.
"HKCR\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{23A078D7-C722-48DC-94A5-DF4CC8ACB3BE}" => Key deleted successfully.
"HKCR\CLSID\{23A078D7-C722-48DC-94A5-DF4CC8ACB3BE}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{50149EB7-8536-4BFB-AB9F-047BB6D4ECBA}" => Key deleted successfully.
"HKCR\CLSID\{50149EB7-8536-4BFB-AB9F-047BB6D4ECBA}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}" => Key deleted successfully.
"HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}" => Key deleted successfully.
"HKCR\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" => Key deleted successfully.
"HKCR\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} => value deleted successfully.
"HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} => value deleted successfully.
"HKCR\Wow6432Node\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}" => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{55E19115-8EF8-465C-90AC-DEACC491B0CC} => value deleted successfully.
"HKCR\CLSID\{55E19115-8EF8-465C-90AC-DEACC491B0CC}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => value deleted successfully.
"HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => value deleted successfully.
"HKCR\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} => value deleted successfully.
"HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}" => Key not found.
C:\Users\ALA\AppData\Roaming\tor => Moved successfully.
"C:\Users\ALA\AppData\Roaming\ExampleFolder" directory move:
C:\Users\ALA\AppData\Roaming\ExampleFolder\Example.bat => Moved successfully.
C:\Users\ALA\AppData\Roaming\ExampleFolder\Example.exe => Moved successfully.
Could not move "C:\Users\ALA\AppData\Roaming\ExampleFolder" directory. => Scheduled to move on reboot.
C:\Users\ALA\AppData\Roaming\suntor.exe => Moved successfully.
C:\Users\ALA\AppData\Roaming\suntor.bat => Moved successfully.
C:\Program Files (x86)\Cube World + Crack [CZ] => Moved successfully.
C:\Windows\SysWOW64\acumncwmoj.exe => Moved successfully.
C:\Windows\SysWOW64\lcpmncwmoj.exe => Moved successfully.
"C:\Users\ALA\AppData\Local\Temp\50fce1d8cc92b5f2d3d5e28e9bce7d08.exe" => File/Directory not found.
C:\ProgramData\mscim.exe => Moved successfully.
"C:\Users\ALA\AppData\Local\Temp\KB00503602.exe" => File/Directory not found.
"C:\Users\ALA\AppData\Local\Temp\KB279657501.exe" => File/Directory not found.
"C:\Users\ALA\AppData\Local\Temp\KB279658171.exe" => File/Directory not found.
"C:\Users\ALA\AppData\Local\Temp\KB279659123.exe" => File/Directory not found.
"C:\Users\ALA\AppData\Local\Temp\KB287190196.exe" => File/Directory not found.
"C:\Users\ALA\AppData\Local\Temp\KB287495896.exe" => File/Directory not found.
"C:\Users\ALA\AppData\Local\Temp\KB287796931.exe" => File/Directory not found.
C:\Users\ALA\AppData\Local\Temp\retds1.exe => Moved successfully.
C:\Users\ALA\AppData\Local\Temp\reuqie.scr => Moved successfully.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-10-28 23:33:17)<=
C:\Users\ALA\AppData\Roaming\ExampleFolder => Is moved successfully.
==== End of Fixlog ====