Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-07-2014 Ran by JA at 2014-07-28 19:09:42 Run:3 Running from C:\Users\JA\Desktop\FRST Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {25A6EC9B-7D8D-4520-9426-85180A9EEEB8} - System32\Tasks\4320 => Wscript.exe C:\Users\JA\AppData\Local\Temp\launchie.vbs //B Task: {304E4752-CFC9-4B54-923B-6BF23386BEA0} - \QtraxPlayer No Task File <==== ATTENTION Task: {716C595D-2265-47A0-8587-06CDBF511198} - \Program aktualizacji online firmy Adobe. No Task File <==== ATTENTION Task: {E2D34351-2564-4416-A6B4-73C0725AD049} - System32\Tasks\{EE3D62CB-3607-4656-892F-F7EB4C4761F9} => Firefox.exe C:\Program Files (x86)\Mozilla Firefox\mozjs.dll HKLM-x32\...\Run: [DApp] => C:\Program Files\PCDApp\start.vbs HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1427198255-2518711745-748073939-1000\...\Policies\system: [DisableChangePassword] 0 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 massfilter_hs; system32\drivers\massfilter_hs.sys [X] S1 SASDIFSV; \??\C:\Users\JA\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [X] S1 SASKUTIL; \??\C:\Users\JA\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [X] S1 VIAPFD; \SystemRoot\System32\Drivers\VIAPFD.SYS [X] S3 zgwhsmdm; system32\DRIVERS\gwhsmdm.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\26871035.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\75853406.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\26871035.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\75853406.sys => ""="Driver" Reboot: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{25A6EC9B-7D8D-4520-9426-85180A9EEEB8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25A6EC9B-7D8D-4520-9426-85180A9EEEB8}" => Key deleted successfully. C:\Windows\System32\Tasks\4320 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4320" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{304E4752-CFC9-4B54-923B-6BF23386BEA0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{304E4752-CFC9-4B54-923B-6BF23386BEA0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QtraxPlayer" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{716C595D-2265-47A0-8587-06CDBF511198}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{716C595D-2265-47A0-8587-06CDBF511198}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Program aktualizacji online firmy Adobe." => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E2D34351-2564-4416-A6B4-73C0725AD049}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2D34351-2564-4416-A6B4-73C0725AD049}" => Key deleted successfully. C:\Windows\System32\Tasks\{EE3D62CB-3607-4656-892F-F7EB4C4761F9} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EE3D62CB-3607-4656-892F-F7EB4C4761F9}" => Key deleted successfully. C:\Program Files (x86)\Mozilla Firefox\mozjs.dll => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\DApp => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => value deleted successfully. HKU\S-1-5-21-1427198255-2518711745-748073939-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableChangePassword => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. esgiguard => Service deleted successfully. massfilter => Service deleted successfully. massfilter_hs => Service deleted successfully. SASDIFSV => Service deleted successfully. SASKUTIL => Service deleted successfully. VIAPFD => Service deleted successfully. zgwhsmdm => Service deleted successfully. ZTEusbmdm6k => Service deleted successfully. ZTEusbnmea => Service deleted successfully. ZTEusbser6k => Service deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\26871035.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\75853406.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\26871035.sys" => Key deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\75853406.sys" => Key deleted successfully. The system needed a reboot. ==== End of Fixlog ====