Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-10-2014 02 Ran by User at 2014-10-16 22:14:49 Run:1 Running from C:\Users\User\Desktop Loaded Profile: User (Available profiles: User) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:8888;https=127.0.0.1:8888 SearchScopes: HKLM-x32 - DefaultScope value is missing. CHR HKLM-x32\...\Chrome\Extension: [panpiecllaicaafneoofcmdgmbcihhnd] - C:\ProgramData\AskPartnerNetwork\Toolbar\BTR-V7\CRX\ToolbarCR.crx [] AlternateDataStreams: C:\Windows:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} AlternateDataStreams: C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} S3 CV2K1; system32\DRIVERS\cv2k1.sys [X] S3 ESEADriver2; \??\C:\Users\User\AppData\Local\Temp\ESEADriver2.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 MSICDSetup; \??\E:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] Task: {3673ED95-580C-4C22-98B1-36193F7DE05C} - System32\Tasks\{D4DA4D93-1118-4511-85D3-64AE59E51C32} => Chrome.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=6.20.0.104&LastError=12002 Task: {7D468182-A241-49A9-AA5A-4072E0CBE307} - System32\Tasks\{2DBB3E1D-069B-4D2C-960F-EBA6B6AE8D73} => Chrome.exe http://ui.skype.com/ui/0/6.16.59.105/pl/abandoninstall?page=tsProgressBar Task: {F5872684-BF8F-483E-92F2-805FF00AF48E} - System32\Tasks\{774F77AC-453B-441A-A6C7-D8ABB242297E} => Chrome.exe http://ui.skype.com/ui/0/6.20.0.104/pl/abandoninstall?page=tsBing DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4254522D-5637-006A-76A7-A75C790C0F02} DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes C:\Users\User\AppData\Local\_ C:\Users\User\AppData\Roaming\YaTQA EmptyTemp: ***************** Processes closed successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\panpiecllaicaafneoofcmdgmbcihhnd" => Key deleted successfully. "C:\ProgramData\AskPartnerNetwork\Toolbar\BTR-V7\CRX\ToolbarCR.crx" => File/Directory not found. C:\Windows => ":{DA6227CB-326B-4B4D-9A81-04B61F1538DD}" ADS removed successfully. C:\Windows\System32 => ":{DA6227CB-326B-4B4D-9A81-04B61F1538DD}" ADS removed successfully. CV2K1 => Service deleted successfully. ESEADriver2 => Service deleted successfully. esgiguard => Service deleted successfully. MSICDSetup => Service deleted successfully. NTIOLib_1_0_C => Service deleted successfully. xhunter1 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3673ED95-580C-4C22-98B1-36193F7DE05C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3673ED95-580C-4C22-98B1-36193F7DE05C}" => Key deleted successfully. C:\Windows\System32\Tasks\{D4DA4D93-1118-4511-85D3-64AE59E51C32} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D4DA4D93-1118-4511-85D3-64AE59E51C32}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D468182-A241-49A9-AA5A-4072E0CBE307}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D468182-A241-49A9-AA5A-4072E0CBE307}" => Key deleted successfully. C:\Windows\System32\Tasks\{2DBB3E1D-069B-4D2C-960F-EBA6B6AE8D73} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2DBB3E1D-069B-4D2C-960F-EBA6B6AE8D73}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F5872684-BF8F-483E-92F2-805FF00AF48E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5872684-BF8F-483E-92F2-805FF00AF48E}" => Key deleted successfully. C:\Windows\System32\Tasks\{774F77AC-453B-441A-A6C7-D8ABB242297E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{774F77AC-453B-441A-A6C7-D8ABB242297E}" => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4254522D-5637-006A-76A7-A75C790C0F02} => Key Deleted successfully. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => Key Deleted successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes => Key Deleted successfully. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => Key Deleted successfully. C:\Users\User\AppData\Local\_ => Moved successfully. C:\Users\User\AppData\Roaming\YaTQA => Moved successfully. EmptyTemp: => Removed 1 GB temporary data. The system needed a reboot. ==== End of Fixlog ====