Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-09-2013 Ran by daniel at 2013-09-07 04:32:17 Run:1 Running from C:\Users\daniel\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\...\Run: [tuto4pc_pl_16] - C:\Program Files\tuto4pc_pl_16\tuto4pc_pl_16.exe [3977712 2013-07-30] () HKLM\...\RunOnce: [upt4pc_pl_16.exe] - C:\Users\daniel\AppData\Local\tuto4pc_pl_16\upt4pc_pl_16.exe -runonce [3154416 2013-07-30] () HKCU\...\Run: [WebCake Desktop] - C:\Users\daniel\AppData\Roaming\Tepfel\WebCakeDesktop.exe [52504 2013-08-10] (Bake Cake) HKCU\...\Run: [Microsoft Windows System] - C:\Users\daniel\P-7-78-8964-9648-3874\windll.exe [48640 2013-08-28] () MountPoints2: {7b41fd9f-f067-11e2-8087-806e6f6e6963} - G:\Run.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=A69D94DE80204B83&affID=123621&tsp=4982 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=A69D94DE80204B83&affID=119357&tt=070813_wt3&tsp=4972 SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A69D94DE80204B83&affID=123621&tsp=4982 SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A69D94DE80204B83&affID=123621&tsp=4982 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: WebCake - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files\Tepfel\WebCakeIEClient.dll (Let Them Eat Web-Cake LLC) CHR HKLM\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files\Tepfel\WebCakeLayers.crx Task: {1DEB668E-AB79-42A7-AA49-2A304FF1FCD0} - System32\Tasks\DSite => C:\Users\daniel\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [2013-08-12] () Task: C:\Windows\Tasks\DSite.job => C:\Users\daniel\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE R2 BrowserDefendert; C:\ProgramData\BrowserDefender\2.6.1562.220\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2838480 2013-08-13] () R2 WebCakeUpdater; C:\Program Files\Tepfel\WebCakeDesktop.Updater.exe [51992 2013-08-10] (cake bake) S3 gdrv; \??\C:\Windows\gdrv.sys [x] C:\Users\daniel\P-7-78-8964-9648-3874 C:\Users\daniel\AppData\Local\avgchrome C:\Users\daniel\AppData\Local\eorezo C:\Users\daniel\AppData\Local\Lollipop C:\Users\daniel\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z C:\Users\daniel\AppData\Roaming\Babylon C:\Users\daniel\AppData\Roaming\DSite C:\Users\daniel\Qtrax C:\ProgramData\Babylon C:\Windows\System32\searchplugins C:\Windows\System32\Extensions ***************** HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\tuto4pc_pl_16 => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\upt4pc_pl_16.exe => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\WebCake Desktop => Value not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Microsoft Windows System => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b41fd9f-f067-11e2-8087-806e6f6e6963} => Key deleted successfully. HKCR\CLSID\{7b41fd9f-f067-11e2-8087-806e6f6e6963} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} => Key not found. HKCR\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} => Key not found. HKLM\SOFTWARE\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh => Key not found. "C:\Program Files\Tepfel\WebCakeLayers.crx" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DEB668E-AB79-42A7-AA49-2A304FF1FCD0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DEB668E-AB79-42A7-AA49-2A304FF1FCD0} => Key deleted successfully. C:\Windows\System32\Tasks\DSite => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DSite => Key deleted successfully. C:\Windows\Tasks\DSite.job => Moved successfully. BrowserDefendert => Service not found. WebCakeUpdater => Service not found. gdrv => Service deleted successfully. C:\Users\daniel\P-7-78-8964-9648-3874 => Moved successfully. C:\Users\daniel\AppData\Local\avgchrome => Moved successfully. C:\Users\daniel\AppData\Local\eorezo => Moved successfully. C:\Users\daniel\AppData\Local\Lollipop => Moved successfully. "C:\Users\daniel\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z" => File/Directory not found. C:\Users\daniel\AppData\Roaming\Babylon => Moved successfully. "C:\Users\daniel\AppData\Roaming\DSite" directory move: C:\Users\daniel\AppData\Roaming\DSite\UpdateProc\config.dat => Moved successfully. C:\Users\daniel\AppData\Roaming\DSite\UpdateProc\TTL.DAT => Moved successfully. Could not move "C:\Users\daniel\AppData\Roaming\DSite" directory. => Scheduled to move on reboot. C:\Users\daniel\Qtrax => Moved successfully. C:\ProgramData\Babylon => Moved successfully. C:\Windows\System32\searchplugins => Moved successfully. C:\Windows\System32\Extensions => Moved successfully. =========== Result of Scheduled Files to move =========== "C:\Users\daniel\AppData\Roaming\DSite" => Directory could not move. ==== End of Fixlog ====