Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-10-2014 Ran by mrukk at 2014-10-12 12:14:55 Run:2 Running from C:\Users\mrukk\Desktop Loaded Profile: mrukk (Available profiles: mrukk) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey SearchScopes: HKCU - {A2AC704F-665E-47D8-8821-53B5662B197E} URL = FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\FRST\Quarantine RemoveDirectory: C:\Program Files (x86)\Mozilla Firefox RemoveDirectory: C:\ProgramData\McAfee RemoveDirectory: C:\ProgramData\Norton RemoveDirectory: C:\Users\Default\AppData\Local\Pokki RemoveDirectory: C:\Users\Default User\AppData\Local\Pokki RemoveDirectory: C:\Users\mrukk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiicmmpkicnndkhlnnloilpgncbpkbjj RemoveDirectory: C:\Users\mrukk\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho RemoveDirectory: C:\Users\mrukk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom RemoveDirectory: C:\Users\mrukk\Desktop\FRST-OlderVersion CMD: del /q C:\WINDOWS\SysWOW64\sqlite3.dll EmptyTemp: ***************** Processes closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HotKeysCmds => value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Persistence => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mcui_exe => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A2AC704F-665E-47D8-8821-53B5662B197E}" => Key deleted successfully. "HKCR\CLSID\{A2AC704F-665E-47D8-8821-53B5662B197E}" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0" => Key deleted successfully. C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll => Moved successfully. "C:\AdwCleaner" => removed successfully. "C:\FRST\Quarantine" => removed successfully. "C:\Program Files (x86)\Mozilla Firefox" => removed successfully. "C:\ProgramData\McAfee" => removed successfully. Could not remove "C:\ProgramData\Norton\{311739EB-5C94-4EE1-B911-2D1F005060F4}\NARA_4.3.0.14\CmnClnt\ccSetMgr\settings_4.3.0.14.dat" => Scheduled to remove on reboot. Could not remove "C:\ProgramData\Norton\{311739EB-5C94-4EE1-B911-2D1F005060F4}\NARA_4.3.0.14\Connections\connectn.dat" => Scheduled to remove on reboot. Could not remove "C:\ProgramData\Norton\{311739EB-5C94-4EE1-B911-2D1F005060F4}\NARA_4.3.0.14\Logs\ARA_LogFile.etl" => Scheduled to remove on reboot. Could not remove "C:\ProgramData\Norton" => Scheduled to remove on reboot. "C:\Users\Default\AppData\Local\Pokki" => removed successfully. "C:\Users\Default User\AppData\Local\Pokki" => File/Directory not found. "C:\Users\mrukk\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiicmmpkicnndkhlnnloilpgncbpkbjj" => removed successfully. "C:\Users\mrukk\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho" => removed successfully. "C:\Users\mrukk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom" => removed successfully. "C:\Users\mrukk\Desktop\FRST-OlderVersion" => File/Directory not found. ========= del /q C:\WINDOWS\SysWOW64\sqlite3.dll ========= ========= End of CMD: ========= EmptyTemp: => Removed 227.3 MB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-10-12 12:17:24)<= C:\ProgramData\Norton\{311739EB-5C94-4EE1-B911-2D1F005060F4}\NARA_4.3.0.14\CmnClnt\ccSetMgr\settings_4.3.0.14.dat => Is removed successfully. C:\ProgramData\Norton\{311739EB-5C94-4EE1-B911-2D1F005060F4}\NARA_4.3.0.14\Connections\connectn.dat => Is removed successfully. C:\ProgramData\Norton\{311739EB-5C94-4EE1-B911-2D1F005060F4}\NARA_4.3.0.14\Logs\ARA_LogFile.etl => Is removed successfully. C:\ProgramData\Norton => Removed successfully. ==== End of Fixlog ====