Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-06-2014 Ran by Paweł at 2014-06-06 17:44:32 Run:2 Running from C:\Users\Paweł\Downloads\frst 06,05 Boot Mode: Normal ============================================== Content of fixlist: ***************** S4 WebCake Desktop Updater; "C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe" "C:\Users\Pawe-\AppData\Roaming\WebCake\WebCakeDesktop.exe" S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 massfilter_lte; \??\C:\windows\system32\drivers\massfilter_lte.sys [X] S3 zgdcat; system32\DRIVERS\zgdcat.sys [X] S3 zgdcdiag; system32\DRIVERS\zgdcdiag.sys [X] S3 zgdcmdm; system32\DRIVERS\zgdcmdm.sys [X] S3 zgdcnet; system32\DRIVERS\zgdcnet.sys [X] S3 zgdcnmea; system32\DRIVERS\zgdcnmea.sys [X] HKU\.DEFAULT\...\RunOnce: [] - [X] HKU\S-1-5-19\...\RunOnce: [] - [X] HKU\S-1-5-20\...\RunOnce: [] - [X] HKU\S-1-5-21-2666340739-2498256653-3035462964-1000\...\Policies\Explorer: [NofolderOptions] 0 Task: {10CB747F-820E-4E3E-989B-34469BC094E9} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader Updater\YourFileUpdater.exe [2014-05-20] (http://yourfiledownloader.com) <==== ATTENTION Task: {49A58959-3400-4B38-80C5-E58CF8A113FE} - System32\Tasks\DigitalSite => C:\Users\Paweł\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {7AE693AA-E1E8-4C7D-B64B-A05E41887163} - System32\Tasks\Digital Sites => C:\Users\PAWE~1\AppData\Roaming\DIGITA~2\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {ECEB85FB-663E-44B1-892F-6714A80D4754} - System32\Tasks\DSite => C:\Users\PAWE~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\windows\Tasks\Digital Sites.job => C:\Users\PAWE~1\AppData\Roaming\DIGITA~2\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\windows\Tasks\DigitalSite.job => C:\Users\PAWE~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\windows\Tasks\DSite.job => C:\Users\PAWE~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION AppInit_DLLs: c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll => c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll File Not Found AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll File Not Found ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX ShortcutWithArgument: C:\Users\Paweł\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} SearchScopes: HKCU - {062A0111-06AE-4D8B-BE52-3B27724D95CC} URL = http://websearch.ask.com/redirect?client=ie&tb=SGT&o=APN10374&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AHO&apn_dtid=^YYYYYY^YY^PL&apn_uid=a72d9980-6dc7-4bd7-bfc0-45f9b0fc2182&apn_sauid=1B887098-0C21-441E-8424-8BFC7A3C76B8 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&babsrc=SP_ss_din2g&mntrId=2E6E72B7C3133987&affID=119357&tt=040713_rdrctful&tsp=4937 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1400622543&from=exp&uid=HitachiXHTS547550A9E384_J1120021C2L5WAC2L5WAX&q={searchTerms} SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO-x32: WebCake - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\WebCake\WebCakeIEClient.dll (WebCake LLC) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader C:\Users\Paweł\AppData\Local\Google C:\Users\Paweł\AppData\Roaming\skype.ini C:\Users\Paweł\AppData\Roaming\skype.dat C:\Users\Paweł\AppData\Roaming\Babylon C:\Users\Paweł\AppData\Roaming\Betcat C:\Users\Paweł\AppData\Roaming\File Scout C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage C:\Users\Paweł\Downloads\creative_mediasource_player_5_free_downloader.exe C:\Users\Public\Desktop\YourFile Downloader.lnk Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\WebCake Desktop Updater" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop_03081805" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WebCake Desktop"/f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reg: reg delete "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main" /v "Start Page" /f Reboot: ***************** WebCake Desktop Updater => Service not found. ew_hwusbdev => Service not found. huawei_enumerator => Service not found. massfilter_lte => Service not found. zgdcat => Service not found. zgdcdiag => Service not found. zgdcmdm => Service not found. zgdcnet => Service not found. zgdcnmea => Service not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => Value not found. HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => Value not found. HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => Value not found. HKU\S-1-5-21-2666340739-2498256653-3035462964-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NofolderOptions => Value not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{10CB747F-820E-4E3E-989B-34469BC094E9}'=> Key not found. C:\Windows\System32\Tasks\YourFile DownloaderUpdate not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile DownloaderUpdate'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{49A58959-3400-4B38-80C5-E58CF8A113FE}'=> Key not found. C:\Windows\System32\Tasks\DigitalSite not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AE693AA-E1E8-4C7D-B64B-A05E41887163}'=> Key not found. C:\Windows\System32\Tasks\Digital Sites not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Digital Sites'=> Key not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECEB85FB-663E-44B1-892F-6714A80D4754}'=> Key not found. C:\Windows\System32\Tasks\DSite not found. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite'=> Key not found. C:\windows\Tasks\Digital Sites.job not found. C:\windows\Tasks\DigitalSite.job not found. C:\windows\Tasks\DSite.job not found. "c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll" => Value Data not found. "c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll" => Value Data not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Users\Paweł\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Shortcut argument was removed successfully. C:\Users\Public\Desktop\Mozilla Firefox.lnk => Shortcut argument was removed successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. 'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{062A0111-06AE-4D8B-BE52-3B27724D95CC}'=> Key not found. 'HKCR\CLSID\{062A0111-06AE-4D8B-BE52-3B27724D95CC}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}'=> Key not found. 'HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86}'=> Key not found. 'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}'=> Key not found. 'HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}'=> Key not found. 'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}'=> Key not found. 'HKCR\Wow6432Node\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}'=> Key not found. "C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml" => not found. "C:\ProgramData\Microsoft\Windows\Start Menu\YourFileDownloader" => File/Directory not found. "C:\Users\Paweł\AppData\Local\Google" => File/Directory not found. "C:\Users\Paweł\AppData\Roaming\skype.ini" => File/Directory not found. "C:\Users\Paweł\AppData\Roaming\skype.dat" => File/Directory not found. "C:\Users\Paweł\AppData\Roaming\Babylon" => File/Directory not found. "C:\Users\Paweł\AppData\Roaming\Betcat" => File/Directory not found. "C:\Users\Paweł\AppData\Roaming\File Scout" => File/Directory not found. "C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lollipop.lnk" => File/Directory not found. "C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage" => File/Directory not found. "C:\Users\Paweł\Downloads\creative_mediasource_player_5_free_downloader.exe" => File/Directory not found. "C:\Users\Public\Desktop\YourFile Downloader.lnk" => File/Directory not found. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\WebCake Desktop Updater" /f =========