Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-05-2014 02 Ran by Damian at 2014-05-28 05:34:26 Run:1 Running from C:\Users\Damian\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {0134988F-A444-4862-A13F-331E5459455F} - \BonanzaDealsLiveUpdateTaskMachineUA No Task File <==== ATTENTION Task: {926C2FD2-40F1-4E79-91F6-0A4DB873057B} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe Task: {D5DE39A3-3A99-4608-8939-76B42EF1F9C7} - \BonanzaDealsLiveUpdateTaskMachineCore No Task File <==== ATTENTION S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [X] S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] () S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] C:\Windows\System32\DRIVERS\EsgScanner.sys C:\ProgramData\Kaspersky Lab C:\Users\Damian\AppData\Local\Google Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f CMD: sc config "PLAY ONLINE. RunOuc" start= demand ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0134988F-A444-4862-A13F-331E5459455F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0134988F-A444-4862-A13F-331E5459455F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{926C2FD2-40F1-4E79-91F6-0A4DB873057B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{926C2FD2-40F1-4E79-91F6-0A4DB873057B} => Key deleted successfully. C:\Windows\System32\Tasks\SpyHunter4Startup => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D5DE39A3-3A99-4608-8939-76B42EF1F9C7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D5DE39A3-3A99-4608-8939-76B42EF1F9C7} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Key deleted successfully. SpyHunter 4 Service => Service deleted successfully. EsgScanner => Service deleted successfully. esgiguard => Service deleted successfully. C:\Windows\System32\DRIVERS\EsgScanner.sys => Moved successfully. C:\ProgramData\Kaspersky Lab => Moved successfully. C:\Users\Damian\AppData\Local\Google => Moved successfully. ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= sc config "PLAY ONLINE. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ==== End of Fixlog ====