Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-01-2014 03 Ran by Leo Carpenter at 2014-01-16 20:53:15 Run:1 Running from C:\Users\Leo Carpenter\Desktop\New folder Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [Chat Logger++] - C:\Users\Leo Carpenter\AppData\Local\Temp\Rar$EX00.754\Chat Logger++.exe [1516544 2012-10-14] () <===== ATTENTION C:\Users\Leo Carpenter\AppData\Local\Temp\Rar$EX00.754\Chat Logger++.exe MountPoints2: G - G:\setup.exe MountPoints2: {2e8e54bb-fe15-11df-931d-4487fcc51651} - N:\Autorun.exe MountPoints2: {55305ef1-92b3-11e1-9da2-4487fcc51651} - P:\iStudio.exe HKU\Guest\...\Run: [SteamCracker.exe] - C:\Users\Guest\AppData\Local\Temp\ [0 ] () <===== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_def_sps HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Before = http://search.hotspotshield.com/g/?c=h HKCU\Software\Microsoft\Internet Explorer\Main,Search Page Before = http://downloads.phpnuke.org/en/index.php?rvs=google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://downloads.phpnuke.org/en/index.php?rvs=google URLSearchHook: HKLM-x32 - (No Name) - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - No File URLSearchHook: HKLM-x32 - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File URLSearchHook: HKLM-x32 - (No Name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No File SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=GB&userid=3f81bba1-31e7-4dcb-bbe6-734d280d6bf9&searchtype=ds&q={searchTerms}&installDate=27/07/2013 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=GB&userid=3f81bba1-31e7-4dcb-bbe6-734d280d6bf9&searchtype=ds&q={searchTerms}&installDate=27/07/2013 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www2.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=E4CB00FF89FCEE49 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll No File C:\Program Files (x86)\Hotspot Shield BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll No File C:\Program Files (x86)\McAfee Security Scan BHO-x32: VideoFileDownload - {68DD98BF-9DE8-418C-89F0-E37AC61CC2D9} - No File BHO-x32: No Name - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File BHO-x32: No Name - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No File BHO-x32: No Name - {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKCU - No Name - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - No File Toolbar: HKCU - No Name - {DD02A4EB-4AFD-4D60-99D8-E67F964CA813} - No File Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File Toolbar: HKCU - No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File Toolbar: HKCU - No Name - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - No File FF NewTab: user_pref("browser.newtab.url", ""); FF DefaultSearchEngine: Delta Search FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=GB&userid=3f81bba1-31e7-4dcb-bbe6-734d280d6bf9&searchtype=ds&installDate=27/07/2013&q= CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File C:\Program Files (x86)\McAfee Security Scan CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) C:\Program Files (x86)\Pando Networks R2 TorchCrashHandler; C:\Users\Leo Carpenter\AppData\Local\Torch\Update\TorchCrashHandler.exe [1206624 2013-07-20] (TorchMedia Inc.) C:\Users\Leo Carpenter\AppData\Local\Torch Task: {5965C81C-351B-4378-B3B6-C8760A0E57B5} - System32\Tasks\RunAsStdUser Task => C:\Users\Leo Carpenter\AppData\Local\cheerychickenSA\bin\1.0.7.0\CheeryChickenSA.exe C:\Users\Leo Carpenter\AppData\Local\cheerychickenSA Task: {74351EE9-D559-4505-905F-EB8C8D30419A} - System32\Tasks\EPUpdater => C:\Users\LEOCAR~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION C:\Users\LEOCAR~1\AppData\Roaming\BABSOL~1 C:\Users\LEOCAR~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe Task: {C3A8F215-2F0F-40BA-8C48-7C56629AC823} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Chat Logger++ => Value deleted successfully. C:\Users\Leo Carpenter\AppData\Local\Temp\Rar$EX00.754\Chat Logger++.exe => Moved successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G => Key deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2e8e54bb-fe15-11df-931d-4487fcc51651} => Key deleted successfully. HKCR\CLSID\{2e8e54bb-fe15-11df-931d-4487fcc51651} => Key not found. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55305ef1-92b3-11e1-9da2-4487fcc51651} => Key deleted successfully. HKCR\CLSID\{55305ef1-92b3-11e1-9da2-4487fcc51651} => Key not found. HKU\Guest\Software\Microsoft\Windows\CurrentVersion\Run\\SteamCracker.exe => Value not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Before => Value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page Before => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{dd02a4eb-4afd-4d60-99d8-e67f964ca813} => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Value deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{c95a4e8e-816d-4655-8c79-d736da1adb6d} => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key deleted successfully. HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully. HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key deleted successfully. HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} => Key deleted successfully. HKCR\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} => Key deleted successfully. "C:\Program Files (x86)\Hotspot Shield" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key deleted successfully. "C:\Program Files (x86)\McAfee Security Scan" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68DD98BF-9DE8-418C-89F0-E37AC61CC2D9} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{68DD98BF-9DE8-418C-89F0-E37AC61CC2D9} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{c95a4e8e-816d-4655-8c79-d736da1adb6d} => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{dd02a4eb-4afd-4d60-99d8-e67f964ca813} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully. HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => Value deleted successfully. HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} => Value deleted successfully. HKCR\CLSID\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DD02A4EB-4AFD-4D60-99D8-E67F964CA813} => Value deleted successfully. HKCR\CLSID\{DD02A4EB-4AFD-4D60-99D8-E67F964CA813} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{472734EA-242A-422B-ADF8-83D1E48CC825} => Value deleted successfully. HKCR\CLSID\{472734EA-242A-422B-ADF8-83D1E48CC825} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Value deleted successfully. HKCR\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D} => Value deleted successfully. HKCR\CLSID\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D} => Key not found. Firefox newtab deleted successfully. Firefox DefaultSearchEngine deleted successfully. Firefox SelectedSearchEngine deleted successfully. Firefox Keyword.URL deleted successfully. C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll not found. "C:\Program Files (x86)\McAfee Security Scan" => File/Directory not found. C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll => Moved successfully. C:\Program Files (x86)\Pando Networks => Moved successfully. TorchCrashHandler => Service deleted successfully. C:\Users\Leo Carpenter\AppData\Local\Torch => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5965C81C-351B-4378-B3B6-C8760A0E57B5} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5965C81C-351B-4378-B3B6-C8760A0E57B5} => Key deleted successfully. C:\Windows\System32\Tasks\RunAsStdUser Task => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser Task => Key deleted successfully. "C:\Users\Leo Carpenter\AppData\Local\cheerychickenSA" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{74351EE9-D559-4505-905F-EB8C8D30419A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74351EE9-D559-4505-905F-EB8C8D30419A} => Key deleted successfully. C:\Windows\System32\Tasks\EPUpdater => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. "C:\Users\LEOCAR~1\AppData\Roaming\BABSOL~1" => File/Directory not found. "C:\Users\LEOCAR~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C3A8F215-2F0F-40BA-8C48-7C56629AC823} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3A8F215-2F0F-40BA-8C48-7C56629AC823} => Key deleted successfully. C:\Windows\System32\Tasks\BitGuard => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard => Key deleted successfully. The system needs a manual reboot. ==== End of Fixlog ====