Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 28-08-2013 Ran by WILO at 2013-08-30 17:06:46 Run:2 Running from C:\Users\WILO\Downloads Boot Mode: Safe Mode (with Networking) ============================================== Content of fixlist: ***************** C:\Users\WILO\*.exe Startup: C:\Users\WILO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\unuuqscgwoknyijugfd.lnk ShortcutTarget: unuuqscgwoknyijugfd.lnk -> C:\Users\WILO\AppData\Local\Temp\dfgujiynkowgcsquunu.bfg (Microsoft Corporation) S2 Winmgmt; C:\PROGRA~2\dfgujiynkowgcsquunu.bfg [x] S2 Update WebConnect; C:\Program Files\WebConnect\updateWebConnect.exe [206632 2013-08-27] (WebConnect) HKCU\...\Run: [NTRedirect] - C:\Users\WILO\AppData\Roaming\BabSolution\Shared\enhancedNT.dll [187888 2013-08-22] () HKCU\...\Runonce: [Del1272765] - cmd.exe /Q /D /c del "C:\Users\WILO\AppData\Local\Temp\0.del" [x] HKLM\...\Runonce: [Del1272765] - cmd.exe /Q /D /c del "C:\Users\WILO\AppData\Local\Temp\0.del" [x] HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=74EF0013E824E803&affID=119357&tsp=4989 SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=74EF0013E824E803&affID=119357&tsp=4989 BHO: WebConnect - {2316c625-b487-4410-a1a5-ff040b65245f} - C:\Program Files\WebConnect\WebConnectbho.dll (Web Connect) BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.24.6\bh\delta.dll (Delta-search.com) Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.24.6\deltaTlbr.dll (Delta-search.com) CHR HKLM\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\WILO\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM\...\Chrome\Extension: [ieakfmpjhljbpbfpldjkddkjmmgjmgon] - C:\Program Files\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx CHR HKLM\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files\vShare.tv plugin\vshareplg.crx Task: {40A07398-57BB-41A8-B9F2-C9AC3BA19DCC} - System32\Tasks\{42AFD9EF-69E3-4295-8F47-8FB58A54A84F} => C:\Users\WILO\Desktop\USBXTAFGUI_v44.exe No File Task: {42B9B2AF-792A-469F-96E4-2DFE6E2B066A} - System32\Tasks\e-pity2012_kwiecien => C:\Program Files\e-file\e-pity2012\signxml.exe No File Task: {59610701-B2AE-47DE-B703-DDFD7A7A5031} - System32\Tasks\e-pity2012_styczen => C:\Program Files\e-file\e-pity2012\signxml.exe No File Task: {AC854DCB-A104-46ED-922E-CBA990B14833} - System32\Tasks\{2E477E0B-3AC3-4CCD-BC51-E0D8EAC29093} => C:\Users\WILO\Desktop\USBXTAFGUI_v44.exe No File C:\Users\WILO\Downloads\DownloadManagerSetup.exe ***************** "C:\Users\WILO\*.exe" => File/Directory not found. C:\Users\WILO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\unuuqscgwoknyijugfd.lnk => Moved successfully. C:\Users\WILO\AppData\Local\Temp\dfgujiynkowgcsquunu.bfg => Moved successfully. Winmgmt => Service restored successfully. Update WebConnect => Service deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NTRedirect => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del1272765 => Value not found. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Del1272765 => Value not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316c625-b487-4410-a1a5-ff040b65245f} => Key deleted successfully. HKCR\CLSID\{2316c625-b487-4410-a1a5-ff040b65245f} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value deleted successfully. HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Key deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde => Key deleted successfully. C:\Users\WILO\AppData\Roaming\BabSolution\CR\Delta.crx => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon => Key deleted successfully. C:\Program Files\WebConnect\ieakfmpjhljbpbfpldjkddkjmmgjmgon.crx => Moved successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj => Key deleted successfully. "C:\Program Files\vShare.tv plugin\vshareplg.crx" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40A07398-57BB-41A8-B9F2-C9AC3BA19DCC} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40A07398-57BB-41A8-B9F2-C9AC3BA19DCC} => Key deleted successfully. C:\Windows\System32\Tasks\{42AFD9EF-69E3-4295-8F47-8FB58A54A84F} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{42AFD9EF-69E3-4295-8F47-8FB58A54A84F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{42B9B2AF-792A-469F-96E4-2DFE6E2B066A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{42B9B2AF-792A-469F-96E4-2DFE6E2B066A} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2012_kwiecien => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2012_kwiecien => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{59610701-B2AE-47DE-B703-DDFD7A7A5031} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59610701-B2AE-47DE-B703-DDFD7A7A5031} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2012_styczen => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2012_styczen => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC854DCB-A104-46ED-922E-CBA990B14833} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC854DCB-A104-46ED-922E-CBA990B14833} => Key deleted successfully. C:\Windows\System32\Tasks\{2E477E0B-3AC3-4CCD-BC51-E0D8EAC29093} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2E477E0B-3AC3-4CCD-BC51-E0D8EAC29093} => Key deleted successfully. C:\Users\WILO\Downloads\DownloadManagerSetup.exe => Moved successfully.