Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-01-2014 01 Ran by Jaro at 2014-01-31 20:52:48 Run:2 Running from C:\Users\Jaro\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe (AutoIt Team) C:\Users\Jaro\AppData\Roaming\AutoIt3\AutoIt3.exe (Mozilla Corporation) C:\Users\Jaro\AppData\Roaming\AutoIt3\FirefoxPortable\App\Firefox\firefox.exe HKLM-x32\...\Run: [] - [x] HKCU\...\Run: [Java] - cmd /c cd %APPDATA%\AutoIt3 & AutoIt3.exe soundmng.txt HKCU\...\Run: [NextLive] - C:\Users\Jaro\AppData\Roaming\newnext.me\nengine.dll [1283584 2013-11-14] (NewNextDotMe) HKCU\...\Policies\Explorer: [] Task: {01E42602-4CBF-4699-937B-BB5FD343E397} - \PutLockerDownloader V6.0-codedownloader No Task File Task: {25F72C9D-95B2-4C21-B7AB-4B8C7F9E3F78} - \PutLockerDownloader V6.0-updater No Task File Task: {46959F48-085A-4CF3-8000-7C07F2297DA6} - \Desk 365 RunAsStdUser No Task File Task: {5D162A3B-C770-436B-BD95-4AB0CDB69BA5} - System32\Tasks\SomotoUpdateCheckerAutoStart => C:\Users\Jaro\AppData\Local\FilesFrog Update Checker\update_checker.exe <==== ATTENTION Task: {A1309EDF-D446-4B88-95A9-9FD5FEB388AE} - \PutLockerDownloader V6.0-chromeinstaller No Task File Task: {BE4D404A-1A56-45AB-BF83-8FC1640970D5} - \PutLockerDownloader V6.0-enabler No Task File Task: {F5E6BC8B-23A5-4056-8F40-DD98FB83D10F} - \PutLockerDownloader V6.0-firefoxinstaller No Task File HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.awesomehp.com/?type=sc&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {A0EF5419-9909-4E42-A923-888511F9CC20} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=402027&p={searchTerms} BHO-x32: SecretSauce - {0ffd0ef2-dbe9-483a-80c4-d2c331da1ce4} - C:\Program Files (x86)\SecretSauce\SecretSaucebho.dll (SecretSauce) BHO-x32: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) FF Extension: No Name - C:\Users\Jaro\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2013-12-06] FF Extension: Pirrit Suggestor - C:\Users\Jaro\AppData\Roaming\Mozilla\Firefox\profiles\extensions\suggestor@pirrit.com.xpi [2013-12-06] CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.awesomehp.com/?type=sc&ts=1391028140&from=ild&uid=ST3500418AS_9VM112KBXXXX9VM112KB R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [493568 2014-01-29] (Cherished Technololgy LIMITED) R2 Update SecretSauce; C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe [102176 2014-01-28] () S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [x] S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [x] C:\Program Files (x86)\SecretSauce C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} C:\ProgramData\AVG C:\ProgramData\WPM C:\Users\Jaro\.android C:\Users\Jaro\AppData\Local\28050 C:\Users\Jaro\AppData\Local\cache C:\Users\Jaro\AppData\Local\genienext C:\Users\Jaro\AppData\Local\Mobogenie C:\Users\Jaro\AppData\Roaming\divx.exe C:\Users\Jaro\AppData\Roaming\launcher.exe C:\Users\Jaro\AppData\Roaming\0F1F1C2Y1H1P1C0I0T C:\Users\Jaro\AppData\Roaming\AutoIt3 C:\Users\Jaro\AppData\Roaming\AVG C:\Users\Jaro\AppData\Roaming\IObit C:\Users\Jaro\AppData\Roaming\newnext.me C:\Users\Jaro\AppData\Roaming\Pirrit C:\Users\Jaro\AppData\Roaming\SharePod C:\Users\Jaro\AppData\Roaming\Slick Savings C:\Users\Jaro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie C:\Windows\SysWOW64\tmp*.tmp Reg: reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe => No running process found C:\Users\Jaro\AppData\Roaming\AutoIt3\AutoIt3.exe => No running process found C:\Users\Jaro\AppData\Roaming\AutoIt3\FirefoxPortable\App\Firefox\firefox.exe => No running process found HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Java => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Value not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01E42602-4CBF-4699-937B-BB5FD343E397} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PutLockerDownloader V6.0-codedownloader => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25F72C9D-95B2-4C21-B7AB-4B8C7F9E3F78} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PutLockerDownloader V6.0-updater => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46959F48-085A-4CF3-8000-7C07F2297DA6} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D162A3B-C770-436B-BD95-4AB0CDB69BA5} => Key not found. C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SomotoUpdateCheckerAutoStart => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1309EDF-D446-4B88-95A9-9FD5FEB388AE} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PutLockerDownloader V6.0-chromeinstaller => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE4D404A-1A56-45AB-BF83-8FC1640970D5} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PutLockerDownloader V6.0-enabler => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5E6BC8B-23A5-4056-8F40-DD98FB83D10F} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PutLockerDownloader V6.0-firefoxinstaller => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A0EF5419-9909-4E42-A923-888511F9CC20} => Key not found. HKCR\CLSID\{A0EF5419-9909-4E42-A923-888511F9CC20} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ffd0ef2-dbe9-483a-80c4-d2c331da1ce4} => Key not found. HKCR\Wow6432Node\CLSID\{0ffd0ef2-dbe9-483a-80c4-d2c331da1ce4} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d} => Key not found. HKCR\Wow6432Node\CLSID\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d} => Key not found. C:\Users\Jaro\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions not found. C:\Users\Jaro\AppData\Roaming\Mozilla\Firefox\profiles\extensions\suggestor@pirrit.com.xpi not found. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. Wpm => Service not found. Update SecretSauce => Service not found. esgiguard => Service not found. huawei_cdcacm => Service not found. huawei_cdcecm => Service not found. huawei_enumerator => Service not found. huawei_ext_ctrl => Service not found. "C:\Program Files (x86)\SecretSauce" => File/Directory not found. "C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}" => File/Directory not found. "C:\ProgramData\AVG" => File/Directory not found. "C:\ProgramData\WPM" => File/Directory not found. "C:\Users\Jaro\.android" => File/Directory not found. "C:\Users\Jaro\AppData\Local\28050" => File/Directory not found. "C:\Users\Jaro\AppData\Local\cache" => File/Directory not found. "C:\Users\Jaro\AppData\Local\genienext" => File/Directory not found. "C:\Users\Jaro\AppData\Local\Mobogenie" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\divx.exe" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\launcher.exe" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\0F1F1C2Y1H1P1C0I0T" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\AutoIt3" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\AVG" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\IObit" => File/Directory not found. C:\Users\Jaro\AppData\Roaming\newnext.me => Moved successfully. "C:\Users\Jaro\AppData\Roaming\Pirrit" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\SharePod" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\Slick Savings" => File/Directory not found. "C:\Users\Jaro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie" => File/Directory not found. "C:\Windows\SysWOW64\tmp*.tmp" => File/Directory not found. ========= reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ==== End of Fixlog ====