Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-02-2014 Ran by User at 2014-02-12 20:36:59 Run:1 Running from C:\Users\User\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM-x32 - No Name - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No File FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 dump_wmimmc; \??\C:\Program Files\gPotato.eu\Rappelz\GameGuard\dump_wmimmc.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 TDEIO; \??\C:\Windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys [X] Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WebCake Desktop" /f C:\Program Files\Enigma Software Group C:\Program Files (x86)\MediaPlayerV1 C:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP Folder: C:\Windows\system32\GroupPolicy Folder: C:\Windows\SysWOW64\GroupPolicy Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {F05BE2D7-06EE-4634-9904-928228DD9C5F} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Value deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} => Key not found. HKLM\Software\Wow6432Node\MozillaPlugins\@Nero.com/KM => Key deleted successfully. C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL => Moved successfully. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. dump_wmimmc => Service deleted successfully. esgiguard => Service deleted successfully. TDEIO => Service deleted successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WebCake Desktop" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= C:\Program Files\Enigma Software Group => Moved successfully. C:\Program Files (x86)\MediaPlayerV1 => Moved successfully. C:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP => Moved successfully. ========================= Folder: C:\Windows\system32\GroupPolicy ======================== 2013-06-05 17:55 - 2014-02-10 15:59 - 0000000 ____D () C:\Windows\system32\GroupPolicy\Machine 2013-06-05 17:55 - 2013-06-05 17:55 - 0000000 ____D () C:\Windows\system32\GroupPolicy\User 2013-06-05 17:55 - 2014-02-10 15:59 - 0000234 _____ () C:\Windows\system32\GroupPolicy\gpt.ini 2013-06-05 17:55 - 2013-06-05 17:55 - 0000382 _____ () C:\Windows\system32\GroupPolicy\User\Registry.pol 2014-02-10 15:59 - 2014-02-10 15:59 - 0000358 _____ () C:\Windows\system32\GroupPolicy\Machine\Registry.pol ====== End of Folder: ====== ========================= Folder: C:\Windows\SysWOW64\GroupPolicy ======================== 2014-02-10 15:59 - 2014-02-10 15:59 - 0000011 _____ () C:\Windows\SysWOW64\GroupPolicy\gpt.ini ====== End of Folder: ====== ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {F05BE2D7-06EE-4634-9904-928228DD9C5F} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ==== End of Fixlog ====