Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-01-2014 03 Ran by basiak xd at 2014-01-18 10:44:07 Run:1 Running from C:\Users\basiak xd\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Program Files (x86)\Discount Dragon C:\Program Files (x86)\predm C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\SquirrelWeb C:\ProgramData\AskPartnerNetwork C:\Users\basiak xd\.android C:\Users\basiak xd\daemonprocess.txt C:\Users\basiak xd\AppData\Local\qs.dll C:\Users\basiak xd\AppData\Local\qs64.dll C:\Users\basiak xd\AppData\Local\avgchrome C:\Users\basiak xd\AppData\Local\BenchUpdater C:\Users\basiak xd\AppData\Local\cache C:\Users\basiak xd\AppData\Local\Discount Dragon C:\Users\basiak xd\AppData\Roaming\Codec Pack Packages C:\Users\basiak xd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop C:\Users\basiak xd\AppData\Roaming\Mozilla C:\Users\basiak xd\AppData\Roaming\QuickScan C:\Users\basiak xd\AppData\Roaming\Video Converter Packages C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP C:\Windows\system32\ServiceFilter.ini C:\Windows\system32\AutoRunFilter.ini Task: {131AC02C-4897-4210-A6FB-DE93E7B635C2} - \DSite No Task File Task: {453C2BF7-4AFD-41FC-9D38-5FEDBCF399C0} - \RegClean Pro No Task File Task: {487685E2-9FA4-4111-8509-BD634462E868} - System32\Tasks\{C87AC5D7-256A-4017-8174-878C0E8C9F19} => C:\Program Files (x86)\iPlus\iPlusManager.exe Task: {7CA1204F-04E2-4BE4-A17D-C1D18FB0C65E} - \PC Performer_DEFAULT No Task File Task: {89D71D51-B278-4405-AF07-26B878E4F7ED} - \bench-sys No Task File Task: {8CD4B2F4-13FD-4077-9C9E-D2023DFEF7BA} - \CPU Grid Computing No Task File Task: {A3417DC1-5672-4123-9367-4BF1C43D809C} - \RegClean Pro_UPDATES No Task File Task: {ADD817C1-357A-4EC8-A7F3-B220EA4AF58B} - \bench-S-1-5-21-4256236455-1972928378-2548626097-1000 No Task File Task: {C7D52E4B-BB75-4E44-85A6-F880A104FA77} - \AdobeFlashPlayerUpdate No Task File Task: {CC2C02FC-4342-4639-AAE4-F2EBAB4258E0} - \Funmoods No Task File Task: {D45CE85C-AB79-42C1-A434-7AE2DF9B0E2F} - \RegClean Pro_DEFAULT No Task File Task: {F101388D-2FF6-4ABD-856B-28BA2619E928} - \Dealply No Task File Task: {F36EB091-F44A-4D9C-9695-DDB2DABC77B1} - \PC Performer_UPDATES No Task File Task: {F803049B-0DC4-437F-8A5E-04E08FD6203B} - \AdobeFlashPlayerUpdate 2 No Task File HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File CHR HKLM-x32\...\Chrome\Extension: [pljcgbedjplidkdjahbaalanadmjfgop] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx [2014-01-17] HKCU\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent HKCU\...\Run: [ALLUpdate] - "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep" HKCU\...\Run: [Google+ Auto Backup] - "C:\Users\basiak xd\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart S3 ADSMService; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [x] S3 AmUStor; system32\drivers\AmUStor.SYS [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [x] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [x] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [x] S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [x] S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] S3 massfilter; system32\drivers\massfilter.sys [x] U3 tmlwf; U3 tmwfp; S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x] Reg: reg query HKCU\Software\Policies\Google /s Reg: reg query HKLM\SOFTWARE\Policies\Google /s Reg: reg query HKLM\SOFTWARE\Wow6432Node\Policies\Google /s Reg: reg delete HKCU\Software\Mozilla /f Reg: reg delete HKCU\Software\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\MozillaPlugins /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ***************** C:\Program Files (x86)\Discount Dragon => Moved successfully. C:\Program Files (x86)\predm => Moved successfully. C:\Program Files (x86)\Mozilla Firefox => Moved successfully. C:\Program Files (x86)\SquirrelWeb => Moved successfully. "C:\ProgramData\AskPartnerNetwork" => File/Directory not found. C:\Users\basiak xd\.android => Moved successfully. C:\Users\basiak xd\daemonprocess.txt => Moved successfully. C:\Users\basiak xd\AppData\Local\qs.dll => Moved successfully. C:\Users\basiak xd\AppData\Local\qs64.dll => Moved successfully. C:\Users\basiak xd\AppData\Local\avgchrome => Moved successfully. C:\Users\basiak xd\AppData\Local\BenchUpdater => Moved successfully. C:\Users\basiak xd\AppData\Local\cache => Moved successfully. C:\Users\basiak xd\AppData\Local\Discount Dragon => Moved successfully. C:\Users\basiak xd\AppData\Roaming\Codec Pack Packages => Moved successfully. C:\Users\basiak xd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop => Moved successfully. C:\Users\basiak xd\AppData\Roaming\Mozilla => Moved successfully. C:\Users\basiak xd\AppData\Roaming\QuickScan => Moved successfully. C:\Users\basiak xd\AppData\Roaming\Video Converter Packages => Moved successfully. C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP => Moved successfully. C:\Windows\system32\ServiceFilter.ini => Moved successfully. C:\Windows\system32\AutoRunFilter.ini => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{131AC02C-4897-4210-A6FB-DE93E7B635C2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{131AC02C-4897-4210-A6FB-DE93E7B635C2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{453C2BF7-4AFD-41FC-9D38-5FEDBCF399C0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{453C2BF7-4AFD-41FC-9D38-5FEDBCF399C0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{487685E2-9FA4-4111-8509-BD634462E868} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{487685E2-9FA4-4111-8509-BD634462E868} => Key deleted successfully. C:\Windows\System32\Tasks\{C87AC5D7-256A-4017-8174-878C0E8C9F19} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C87AC5D7-256A-4017-8174-878C0E8C9F19} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7CA1204F-04E2-4BE4-A17D-C1D18FB0C65E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7CA1204F-04E2-4BE4-A17D-C1D18FB0C65E} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Performer_DEFAULT => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89D71D51-B278-4405-AF07-26B878E4F7ED} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89D71D51-B278-4405-AF07-26B878E4F7ED} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bench-sys => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8CD4B2F4-13FD-4077-9C9E-D2023DFEF7BA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CD4B2F4-13FD-4077-9C9E-D2023DFEF7BA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CPU Grid Computing => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3417DC1-5672-4123-9367-4BF1C43D809C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3417DC1-5672-4123-9367-4BF1C43D809C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ADD817C1-357A-4EC8-A7F3-B220EA4AF58B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ADD817C1-357A-4EC8-A7F3-B220EA4AF58B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bench-S-1-5-21-4256236455-1972928378-2548626097-1000 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C7D52E4B-BB75-4E44-85A6-F880A104FA77} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7D52E4B-BB75-4E44-85A6-F880A104FA77} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC2C02FC-4342-4639-AAE4-F2EBAB4258E0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC2C02FC-4342-4639-AAE4-F2EBAB4258E0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Funmoods => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D45CE85C-AB79-42C1-A434-7AE2DF9B0E2F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D45CE85C-AB79-42C1-A434-7AE2DF9B0E2F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F101388D-2FF6-4ABD-856B-28BA2619E928} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F101388D-2FF6-4ABD-856B-28BA2619E928} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F36EB091-F44A-4D9C-9695-DDB2DABC77B1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F36EB091-F44A-4D9C-9695-DDB2DABC77B1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Performer_UPDATES => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F803049B-0DC4-437F-8A5E-04E08FD6203B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F803049B-0DC4-437F-8A5E-04E08FD6203B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2 => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pljcgbedjplidkdjahbaalanadmjfgop => Key not found. "C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx" => File/Directory not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\EA Core => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ALLUpdate => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google+ Auto Backup => Value deleted successfully. ADSMService => Service deleted successfully. AmUStor => Service deleted successfully. esgiguard => Service deleted successfully. ewusbmbb => Service deleted successfully. ewusbnet => Service deleted successfully. ew_hwusbdev => Service deleted successfully. huawei_enumerator => Service deleted successfully. hwdatacard => Service deleted successfully. hwusbdev => Service deleted successfully. IntcAzAudAddService => Service deleted successfully. ipswuio => Service deleted successfully. massfilter => Service deleted successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. ZTEusbmdm6k => Service deleted successfully. ZTEusbnmea => Service deleted successfully. ZTEusbser6k => Service deleted successfully. ========= reg query HKCU\Software\Policies\Google /s ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg query HKLM\SOFTWARE\Policies\Google /s ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg query HKLM\SOFTWARE\Wow6432Node\Policies\Google /s ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKCU\Software\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Mozilla /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\mozilla.org /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\MozillaPlugins /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKCU\Software\Microsoft\Internet Explorer\Search" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====