Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-04-2014 01 Ran by Ann at 2014-04-26 15:47:25 Run:1 Running from C:\Users\Ann\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Program Files\PCDApp\dgen.exe () C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe () C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe S2 ProtectMonitor; C:\Program Files\PCDApp\StartHelp.exe [97007 2014-04-10] () R2 Update Mega Browse; C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe [350496 2014-04-24] () R2 Util Mega Browse; C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe [350496 2014-04-24] () R1 {29b136c9-938d-4d3d-8df8-d649d9b74d02}Gw64; C:\Windows\System32\drivers\{29b136c9-938d-4d3d-8df8-d649d9b74d02}Gw64.sys [61120 2014-04-24] (StdLib) R3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 MSICDSetup; \??\G:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\G:\NTIOLib_X64.sys [X] FF user.js: detected! => C:\Users\Ann\AppData\Roaming\Mozilla\Firefox\Profiles\erwqno3t.default\user.js BHO: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File BHO-x32: Mega Browse - {4e6cd411-ce62-4584-97ff-6afbcf6900af} - C:\Program Files (x86)\Mega Browse\MegaBrowsebho.dll (Mega Browse) BHO-x32: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File Task: {2C82A972-D712-4301-98CA-2F82266B9244} - System32\Tasks\e-pity2013_kwiecien => C:\Program Files (x86)\e-file\e-pity2013\Assets\signxml.exe Task: {DECAC653-4B26-453F-9DC8-FABC2A3A0709} - System32\Tasks\e-pity2013_styczen => C:\Program Files (x86)\e-file\e-pity2013\Assets\signxml.exe C:\Program Files\Enigma Software Group C:\Program Files (x86)\Mega Browse C:\Users\Ann\Downloads\CodecPerformerSetup.exe C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP C:\Windows\System32\drivers\{29b136c9-938d-4d3d-8df8-d649d9b74d02}Gw64.sys Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DApp" /f Reboot: ***************** [2332] C:\Program Files\PCDApp\dgen.exe => Process closed successfully. [2488] C:\Program Files (x86)\Mega Browse\updateMegaBrowse.exe => Process closed successfully. [2968] C:\Program Files (x86)\Mega Browse\bin\utilMegaBrowse.exe => Process closed successfully. ProtectMonitor => Service deleted successfully. Update Mega Browse => Service deleted successfully. Util Mega Browse => Service deleted successfully. {29b136c9-938d-4d3d-8df8-d649d9b74d02}Gw64 => Unable to stop service {29b136c9-938d-4d3d-8df8-d649d9b74d02}Gw64 => Service deleted successfully. esgiguard => Unable to stop service esgiguard => Service deleted successfully. MSICDSetup => Service deleted successfully. NTIOLib_1_0_C => Service deleted successfully. C:\Users\Ann\AppData\Roaming\Mozilla\Firefox\Profiles\erwqno3t.default\user.js => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => Key deleted successfully. HKCR\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e6cd411-ce62-4584-97ff-6afbcf6900af} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{4e6cd411-ce62-4584-97ff-6afbcf6900af} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C82A972-D712-4301-98CA-2F82266B9244} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C82A972-D712-4301-98CA-2F82266B9244} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2013_kwiecien => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2013_kwiecien => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DECAC653-4B26-453F-9DC8-FABC2A3A0709} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DECAC653-4B26-453F-9DC8-FABC2A3A0709} => Key deleted successfully. C:\Windows\System32\Tasks\e-pity2013_styczen => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\e-pity2013_styczen => Key deleted successfully. C:\Program Files\Enigma Software Group => Moved successfully. C:\Program Files (x86)\Mega Browse => Moved successfully. C:\Users\Ann\Downloads\CodecPerformerSetup.exe => Moved successfully. C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP => Moved successfully. C:\Windows\System32\drivers\{29b136c9-938d-4d3d-8df8-d649d9b74d02}Gw64.sys => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DApp" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= The system needed a reboot. ==== End of Fixlog ====