Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-02-2015
Ran by ventil&pobor at 2015-03-01 12:30:49 Run:1
Running from C:\Users\ventil&pobor\Desktop
Loaded Profiles: ventil&pobor (Available profiles: ventil&pobor)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
Task: C:\Windows\Tasks\SlimDrivers Startup.job => C:\Program Files\SlimDrivers\SlimDrivers.exe
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-18] (Microsoft Corporation)
HKLM\...\Run: [Acer Tour] => [X]
HKLM\...\Run: [eRecoveryService] => [X]
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-2680930136-258757702-4039921453-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5503768 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-2680930136-258757702-4039921453-1000\Software\Microsoft\Internet Explorer\Main,SEARCH PAGE =
http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
HKU\S-1-5-21-2680930136-258757702-4039921453-1000\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2680930136-258757702-4039921453-1000 -> {5EBFC9B2-C8D2-4251-A77E-C7F36AADCDEB} URL =
http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
FF DefaultSearchUrl:
https://www.google.com/search/?trackid=sp-006
FF Homepage:
https://www.google.com/?trackid=sp-006
FF Keyword.URL:
https://www.google.com/search/?trackid=sp-006
2015-02-28 14:00 - 2015-02-28 14:00 - 00112640 _____ (forum.viry.cz) C:\Users\ventil&pobor\Desktop\FRSTLauncher.exe
2015-02-27 22:07 - 2015-02-27 22:10 - 00000000 ____D () C:\AdwCleaner
2015-02-27 22:00 - 2015-02-27 22:00 - 02126848 _____ () C:\Users\ventil&pobor\Desktop\adwcleaner_4.111.exe
2015-02-27 18:04 - 2015-02-27 18:05 - 00000000 ____D () C:\rsit
2015-02-27 18:04 - 2015-02-27 18:05 - 00000000 ____D () C:\Program Files\trend micro
2015-02-27 18:03 - 2015-02-27 18:04 - 01107968 _____ () C:\Users\ventil&pobor\Downloads\RSIT.exe
2015-02-27 17:35 - 2015-02-27 17:35 - 00112107 _____ (forum.viry.cz) C:\Users\ventil&pobor\Downloads\VerzeOS.exe
2015-01-30 18:28 - 2015-01-30 18:28 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
C:\Windows\Tasks\SlimDrivers Startup.job => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Defender => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Acer Tour => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\eRecoveryService => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => value deleted successfully.
HKU\S-1-5-21-2680930136-258757702-4039921453-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-2680930136-258757702-4039921453-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKU\S-1-5-21-2680930136-258757702-4039921453-1000\Software\Microsoft\Internet Explorer\Main\\SearchMigratedDefaultURL => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-2680930136-258757702-4039921453-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5EBFC9B2-C8D2-4251-A77E-C7F36AADCDEB}" => Key deleted successfully.
HKCR\CLSID\{5EBFC9B2-C8D2-4251-A77E-C7F36AADCDEB} => Key not found.
Firefox DefaultSearchUrl deleted successfully.
Firefox homepage deleted successfully.
Firefox Keyword.URL deleted successfully.
"C:\Users\ventil&pobor\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\AdwCleaner => Moved successfully.
C:\Users\ventil&pobor\Desktop\adwcleaner_4.111.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\ventil&pobor\Downloads\RSIT.exe => Moved successfully.
C:\Users\ventil&pobor\Downloads\VerzeOS.exe => Moved successfully.
C:\ProgramData\DP45977C.lfl => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 5.7 GB temporary data.
The system needed a reboot.
==== End of Fixlog 12:39:50 ====