Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-05-2014 Ran by Wiesia at 2014-05-02 10:25:28 Run:1 Running from D:\Inne\frst Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs: C:\PROGRA~2\Linkey\IEEXTE~1\iedll64.dll => C:\PROGRA~2\Linkey\IEEXTE~1\iedll64.dll File Not Found IFEO\jumpflip: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe URLSearchHook: HKLM-x32 - Default Value = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=132&itype=n&ver=12349&tm=331&src=ds&p={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=132&itype=n&ver=12349&tm=331&src=ds&p={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=132&itype=n&ver=12349&tm=331&src=ds&p={searchTerms} SearchScopes: HKCU - {BB94644F-CDB5-4AB0-8C8B-C351002924E5} URL = http://www.gsrch.com/#q={searchTerms} BHO: No Name - {4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} - No File BHO: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No File BHO-x32: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File BHO-x32: No Name - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No File Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml C:\Program Files (x86)\mozilla firefox\plugins Task: {6785F3A5-A6AE-4BB3-B3E5-4F85599B4B58} - System32\Tasks\Hoolapp Init => C:\Users\Wiesia\AppData\Roaming\HOOLAP~1\Hoolapp.exe <==== ATTENTION Task: {8C005A53-78E4-4E8D-9C29-05D8FCE1136B} - System32\Tasks\Hoolapp For Android => C:\Users\Wiesia\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION S2 UpdaterSvcWiseEnhance; "C:\Program Files (x86)\WiseEnhance\updater.exe" [X] S2 vosr; C:\Users\Wiesia\AppData\Roaming\VOPackage\VOsrv.exe [X] S3 CtClsFlt; system32\DRIVERS\CtClsFlt.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] C:\Program Files (x86)\MSECache C:\Program Files (x86)\SiteRecommend C:\Program Files (x86)\Spybot - Search & Destroy C:\ProgramData\F-Secure C:\ProgramData\Lavasoft C:\ProgramData\MAGIX C:\ProgramData\Spybot - Search & Destroy C:\ProgramData\TEMP C:\Users\Wiesia\AppData\Local\Google\Chrome C:\Users\Wiesia\AppData\Local\nsb5B44.tmp C:\Users\Wiesia\AppData\Roaming\eCyber C:\Users\Wiesia\AppData\Roaming\HoolappForAndroid C:\Users\Wiesia\AppData\Roaming\iSafe C:\Users\Wiesia\AppData\Roaming\LavasoftStatistics C:\Users\Wiesia\AppData\Roaming\MAGIX C:\Users\Wiesia\AppData\Roaming\TestApp C:\Users\Wiesia\AppData\Roaming\tmp C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP C:\Windows\system32\Drivers\iSafeKrnlBoot.sys Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Hoolapp Android" /f CMD: sc config "Mobile Partner. RunOuc" start= demand ***************** "C:\PROGRA~2\Linkey\IEEXTE~1\iedll64.dll" => Value Data removed successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera => Key deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key deleted successfully. HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB94644F-CDB5-4AB0-8C8B-C351002924E5} => Key deleted successfully. HKCR\CLSID\{BB94644F-CDB5-4AB0-8C8B-C351002924E5} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} => Key deleted successfully. HKCR\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key deleted successfully. HKCR\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Value deleted successfully. HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Value deleted successfully. HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\plugins => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{6785F3A5-A6AE-4BB3-B3E5-4F85599B4B58} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6785F3A5-A6AE-4BB3-B3E5-4F85599B4B58} => Key deleted successfully. C:\Windows\System32\Tasks\Hoolapp Init => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hoolapp Init => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8C005A53-78E4-4E8D-9C29-05D8FCE1136B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C005A53-78E4-4E8D-9C29-05D8FCE1136B} => Key deleted successfully. C:\Windows\System32\Tasks\Hoolapp For Android => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hoolapp For Android => Key deleted successfully. UpdaterSvcWiseEnhance => Service deleted successfully. vosr => Service deleted successfully. CtClsFlt => Service deleted successfully. esgiguard => Service deleted successfully. C:\Program Files (x86)\MSECache => Moved successfully. C:\Program Files (x86)\SiteRecommend => Moved successfully. C:\Program Files (x86)\Spybot - Search & Destroy => Moved successfully. C:\ProgramData\F-Secure => Moved successfully. C:\ProgramData\Lavasoft => Moved successfully. C:\ProgramData\MAGIX => Moved successfully. C:\ProgramData\Spybot - Search & Destroy => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\Users\Wiesia\AppData\Local\Google\Chrome => Moved successfully. C:\Users\Wiesia\AppData\Local\nsb5B44.tmp => Moved successfully. C:\Users\Wiesia\AppData\Roaming\eCyber => Moved successfully. C:\Users\Wiesia\AppData\Roaming\HoolappForAndroid => Moved successfully. C:\Users\Wiesia\AppData\Roaming\iSafe => Moved successfully. C:\Users\Wiesia\AppData\Roaming\LavasoftStatistics => Moved successfully. C:\Users\Wiesia\AppData\Roaming\MAGIX => Moved successfully. C:\Users\Wiesia\AppData\Roaming\TestApp => Moved successfully. C:\Users\Wiesia\AppData\Roaming\tmp => Moved successfully. C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP => Moved successfully. C:\Windows\system32\Drivers\iSafeKrnlBoot.sys => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Hoolapp Android" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "Mobile Partner. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ==== End of Fixlog ====