Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01 Ran by Oem5 at 2014-03-15 17:22:56 Run:1 Running from C:\Users\Oem5\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files\WebConnect\updateWebConnect.exe () C:\Program Files\WebConnect\bin\utilWebConnect.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=BA8674DE2BBF5F31&affID=119357&tt=240913_91215&tsp=5019 SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=BA8674DE2BBF5F31&affID=119357&tt=240913_91215&tsp=5019 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=BA8674DE2BBF5F31&affID=119357&tt=240913_91215&tsp=5019 BHO: WebConnect - {2316c625-b487-4410-a1a5-ff040b65245f} - C:\Program Files\WebConnect\WebConnectBHO.dll (Web Connect) R2 Update WebConnect; C:\Program Files\WebConnect\updateWebConnect.exe [348968 2014-03-15] () R2 Util WebConnect; C:\Program Files\WebConnect\bin\utilWebConnect.exe [348968 2014-03-15] () S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] Task: {009378B4-8D96-4296-9FA6-4A74F4A2F699} - System32\Tasks\{BB1492CE-914E-4859-A00E-814257652BA2} => C:\Program Files\GTA San andreas - collections\Deluxe\gta_sa.exe Task: {15E53574-1C81-48F7-BBA4-9FC96EBC3A47} - System32\Tasks\{FCE96FCE-7E8A-48C9-9C75-5B3B551DA822} => C:\Program Files\GTA San andreas - collections\Deluxe\gta_sa.exe Task: {504FAB3E-E04E-48BF-82B6-9CA116444CE1} - System32\Tasks\{4823E9E6-9D80-4D3D-949A-AE57854A04FB} => C:\Users\Oem5\Downloads\DSJ\DSJ 2.1\DSJ\DSJ.EXE [2000-12-31] () Task: {5231439B-21DC-4D0C-AE70-199E353C116B} - System32\Tasks\{56B69B58-0C75-495E-97DC-C3C4F71B81D1} => C:\Users\Oem5\Downloads\DSJ\DSJ 2.1\DSJ\DSJ.EXE [2000-12-31] () Task: {5CAA3422-5456-46A6-B611-D50AFD60FF6B} - System32\Tasks\{C5FFC13C-D1C6-4F7D-BE28-75D81A3CE5D7} => C:\Users\Oem5\Downloads\DSJ\DSJ 2.1\DSJ\DSJ.EXE [2000-12-31] () Task: {B9A8FB73-7357-44C3-83F6-411F61A28A7C} - System32\Tasks\{30A72B37-7185-4B34-935C-0892CA9CDF3C} => C:\Users\Oem5\Downloads\DSJ\DSJ 2.1\DSJ\DSJ.EXE [2000-12-31] () Task: {EB7D29A5-A6AB-44F4-A6B1-7E369853FF2F} - System32\Tasks\{47E51DCA-9EB3-419C-8EE9-05E48C35588C} => C:\Users\Oem5\Downloads\DSJ\DSJ 2.1\DSJ\DSJ.EXE [2000-12-31] () Task: {F3A404FA-9A63-43A1-B238-F4FC3573C8CF} - System32\Tasks\{4ACD6A37-9765-47E7-91BE-EC439DBCE53D} => C:\Users\Oem5\Downloads\DSJ\DSJ 2.1\DSJ\DSJ.EXE [2000-12-31] () Task: {FCE13C96-C833-44E8-95E4-CCE44FEED6A4} - System32\Tasks\{106E59D4-13C5-4A75-8BD2-83BE758364A3} => C:\Users\Oem5\Downloads\DSJ\DSJ 2.1\DSJ\DSJ.EXE [2000-12-31] () C:\Program Files\Enigma Software Group C:\Users\Oem5\AppData\Local\Google C:\Users\Oem5\AppData\Roaming\BabSolution C:\Users\Oem5\AppData\Roaming\Babylon C:\Users\Oem5\AppData\Roaming\driveridentifier C:\Users\Oem5\AppData\Roaming\Funmoods C:\Users\Oem5\AppData\Roaming\newnext.me C:\Users\Oem5\AppData\Roaming\OpenCandy C:\Users\Oem5\Downloads\Avira-Free-Antivirus(13119).exe C:\Users\Oem5\Downloads\sdstart.exe C:\Users\Oem5\Downloads\SpyHunter-Installer.exe C:\Windows\455F074C814E4520B69B5584BD90400C.TMP Reg: reg delete HKLM\SOFTWARE\Google /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Reboot: ***************** C:\Program Files\WebConnect\updateWebConnect.exe => No running process found C:\Program Files\WebConnect\bin\utilWebConnect.exe => No running process found HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316c625-b487-4410-a1a5-ff040b65245f} => Key not found. HKCR\CLSID\{2316c625-b487-4410-a1a5-ff040b65245f} => Key not found. Update WebConnect => Service not found. Util WebConnect => Service not found. esgiguard => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{009378B4-8D96-4296-9FA6-4A74F4A2F699} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{009378B4-8D96-4296-9FA6-4A74F4A2F699} => Key deleted successfully. C:\Windows\System32\Tasks\{BB1492CE-914E-4859-A00E-814257652BA2} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BB1492CE-914E-4859-A00E-814257652BA2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15E53574-1C81-48F7-BBA4-9FC96EBC3A47} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15E53574-1C81-48F7-BBA4-9FC96EBC3A47} => Key deleted successfully. C:\Windows\System32\Tasks\{FCE96FCE-7E8A-48C9-9C75-5B3B551DA822} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FCE96FCE-7E8A-48C9-9C75-5B3B551DA822} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{504FAB3E-E04E-48BF-82B6-9CA116444CE1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{504FAB3E-E04E-48BF-82B6-9CA116444CE1} => Key deleted successfully. C:\Windows\System32\Tasks\{4823E9E6-9D80-4D3D-949A-AE57854A04FB} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4823E9E6-9D80-4D3D-949A-AE57854A04FB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5231439B-21DC-4D0C-AE70-199E353C116B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5231439B-21DC-4D0C-AE70-199E353C116B} => Key deleted successfully. C:\Windows\System32\Tasks\{56B69B58-0C75-495E-97DC-C3C4F71B81D1} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{56B69B58-0C75-495E-97DC-C3C4F71B81D1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5CAA3422-5456-46A6-B611-D50AFD60FF6B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5CAA3422-5456-46A6-B611-D50AFD60FF6B} => Key deleted successfully. C:\Windows\System32\Tasks\{C5FFC13C-D1C6-4F7D-BE28-75D81A3CE5D7} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C5FFC13C-D1C6-4F7D-BE28-75D81A3CE5D7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B9A8FB73-7357-44C3-83F6-411F61A28A7C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B9A8FB73-7357-44C3-83F6-411F61A28A7C} => Key deleted successfully. C:\Windows\System32\Tasks\{30A72B37-7185-4B34-935C-0892CA9CDF3C} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{30A72B37-7185-4B34-935C-0892CA9CDF3C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB7D29A5-A6AB-44F4-A6B1-7E369853FF2F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB7D29A5-A6AB-44F4-A6B1-7E369853FF2F} => Key deleted successfully. C:\Windows\System32\Tasks\{47E51DCA-9EB3-419C-8EE9-05E48C35588C} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{47E51DCA-9EB3-419C-8EE9-05E48C35588C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3A404FA-9A63-43A1-B238-F4FC3573C8CF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3A404FA-9A63-43A1-B238-F4FC3573C8CF} => Key deleted successfully. C:\Windows\System32\Tasks\{4ACD6A37-9765-47E7-91BE-EC439DBCE53D} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4ACD6A37-9765-47E7-91BE-EC439DBCE53D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FCE13C96-C833-44E8-95E4-CCE44FEED6A4} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCE13C96-C833-44E8-95E4-CCE44FEED6A4} => Key deleted successfully. C:\Windows\System32\Tasks\{106E59D4-13C5-4A75-8BD2-83BE758364A3} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{106E59D4-13C5-4A75-8BD2-83BE758364A3} => Key deleted successfully. C:\Program Files\Enigma Software Group => Moved successfully. C:\Users\Oem5\AppData\Local\Google => Moved successfully. C:\Users\Oem5\AppData\Roaming\BabSolution => Moved successfully. C:\Users\Oem5\AppData\Roaming\Babylon => Moved successfully. C:\Users\Oem5\AppData\Roaming\driveridentifier => Moved successfully. C:\Users\Oem5\AppData\Roaming\Funmoods => Moved successfully. C:\Users\Oem5\AppData\Roaming\newnext.me => Moved successfully. C:\Users\Oem5\AppData\Roaming\OpenCandy => Moved successfully. C:\Users\Oem5\Downloads\Avira-Free-Antivirus(13119).exe => Moved successfully. C:\Users\Oem5\Downloads\sdstart.exe => Moved successfully. C:\Users\Oem5\Downloads\SpyHunter-Installer.exe => Moved successfully. C:\Windows\455F074C814E4520B69B5584BD90400C.TMP => Moved successfully. ========= reg delete HKLM\SOFTWARE\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====