Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-09-2013 02 Ran by Siedlecki Kacper at 2013-09-12 16:23:54 Run:1 Running from C:\Users\Siedlecki Kacper\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** R2 InfEefaultInstall; C:\Windows\system32\mmci32.exe [117760 2013-07-09] () Task: {8913F2DB-01FB-4112-875C-36F6AC3576F3} - System32\Tasks\Express FilesUpdate => C:\Program Files (x86)\ExpressFiles\EFUpdater.exe Task: {8A7346E7-097E-4D85-92F5-23499472043D} - \EPUpdater No Task File Task: {8C4269BD-A0FE-466B-8DFF-110D328A93B2} - \BrowserDefendert No Task File Task: {8DD1357D-AC97-43AC-BAFC-220057E1EF5C} - \DealPly No Task File Task: {A1DCE046-07E7-43CF-9638-92A06C27672A} - \DealPlyUpdate No Task File Task: {F4F90FBD-D2F4-4B0E-8AB8-5D848148F47F} - System32\Tasks\schedule!3036567561 => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe Task: C:\Windows\Tasks\schedule!3036567561.job => C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe AlternateDataStreams: C:\Users\Siedlecki Kacper\Lokale Einstellungen:D2qduYBngL27GtFqII4oxtMs AlternateDataStreams: C:\Users\Siedlecki Kacper\AppData\Local:D2qduYBngL27GtFqII4oxtMs AlternateDataStreams: C:\Users\Siedlecki Kacper\AppData\Local\Anwendungsdaten:D2qduYBngL27GtFqII4oxtMs AlternateDataStreams: C:\Users\Siedlecki Kacper\AppData\Local\h7ZfgQBNt:Cw2PfIidzjDrDv3Vjg AlternateDataStreams: C:\Users\Siedlecki Kacper\AppData\Local\Temporary Internet Files:HgFHLN8Qlqjff78vU3bv4tW9V C:\Windows\system32\mmci32.exe C:\Users\Siedlecki\HRUPPROG.TXT C:\Program Files (x86)\ExpressFiles C:\Program Files (x86)\Uniblue C:\ProgramData\BetterSoft C:\ProgramData\InstallMate HKLM\...\Run: [] - [x] HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000 HKLM-x32\...\Run: [] - [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] Reg: reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** InfEefaultInstall => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8913F2DB-01FB-4112-875C-36F6AC3576F3} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8913F2DB-01FB-4112-875C-36F6AC3576F3} => Key deleted successfully. C:\Windows\System32\Tasks\Express FilesUpdate => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Express FilesUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A7346E7-097E-4D85-92F5-23499472043D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A7346E7-097E-4D85-92F5-23499472043D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8C4269BD-A0FE-466B-8DFF-110D328A93B2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C4269BD-A0FE-466B-8DFF-110D328A93B2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserDefendert => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8DD1357D-AC97-43AC-BAFC-220057E1EF5C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8DD1357D-AC97-43AC-BAFC-220057E1EF5C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1DCE046-07E7-43CF-9638-92A06C27672A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1DCE046-07E7-43CF-9638-92A06C27672A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F4F90FBD-D2F4-4B0E-8AB8-5D848148F47F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4F90FBD-D2F4-4B0E-8AB8-5D848148F47F} => Key deleted successfully. C:\Windows\System32\Tasks\schedule!3036567561 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\schedule!3036567561 => Key deleted successfully. C:\Windows\Tasks\schedule!3036567561.job => Moved successfully. "C:\Users\Siedlecki Kacper\Lokale Einstellungen" => ":D2qduYBngL27GtFqII4oxtMs" ADS not found. C:\Users\Siedlecki Kacper\AppData\Local => ":D2qduYBngL27GtFqII4oxtMs" ADS removed successfully. "C:\Users\Siedlecki Kacper\AppData\Local\Anwendungsdaten" => ":D2qduYBngL27GtFqII4oxtMs" ADS not found. C:\Users\Siedlecki Kacper\AppData\Local\h7ZfgQBNt => ":Cw2PfIidzjDrDv3Vjg" ADS removed successfully. "C:\Users\Siedlecki Kacper\AppData\Local\Temporary Internet Files" => ":HgFHLN8Qlqjff78vU3bv4tW9V" ADS not found. C:\Windows\system32\mmci32.exe => Moved successfully. C:\Users\Siedlecki\HRUPPROG.TXT => Moved successfully. "C:\Program Files (x86)\ExpressFiles" => File/Directory not found. C:\Program Files (x86)\Uniblue => Moved successfully. "C:\ProgramData\BetterSoft" => File/Directory not found. C:\ProgramData\InstallMate => Moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDriveTypeAutoRun => Value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. EagleX64 => Service deleted successfully. ========= reg add "HKCU\Software\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Der Vorgang wurde erfolgreich beendet. ========= End of Reg: ========= The system needs a manual reboot. ==== End of Fixlog ====