Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-04-2015 Ran by Kaktus at 2015-04-22 12:29:42 Run:1 Running from C:\Users\Kaktus\Desktop\FRST Loaded Profiles: Kaktus (Available profiles: Kaktus) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION SearchScopes: HKU\S-1-5-21-3030238434-3008618196-960345281-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3030238434-3008618196-960345281-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3030238434-3008618196-960345281-1001 -> {1C21D719-C031-482D-A625-A9A98863372B} URL = Toolbar: HKU\S-1-5-21-3030238434-3008618196-960345281-1001 -> No Name - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - No File HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe, BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit Task: {EEB95C0A-9515-4DC1-B7D6-9E93B520CFB0} - System32\Tasks\{297C785B-E46A-4172-BE39-1E59FADA07D0} => pcalua.exe -a "C:\GOG Games\Planescape Torment\Setup-GhostDog's-PST-UI.exe" -d "C:\GOG Games\Planescape Torment" Task: {F3B69E76-FCEB-42A9-88BE-72AC309B2B6C} - System32\Tasks\{3F25AC42-5546-4903-AC1C-E71A6801619F} => pcalua.exe -a E:\GraphPad.Prism.v5.01.Retail.Incl.Keymaker-ZWT\setup.exe -d E:\GraphPad.Prism.v5.01.Retail.Incl.Keymaker-ZWT S3 AmUStor; \SystemRoot\system32\drivers\AmUStor.SYS [X] C:\Program Files (x86)\ActiveDiscount C:\Program Files (x86)\AdDToThis C:\Program Files (x86)\Mozilla Firefox\extensions C:\Program Files (x86)\Mozilla Firefox\plugins C:\Program Files (x86)\SpaceCCoeuPonuApp C:\Program Files (x86)\The Key for YouTube C:\ProgramData\*.bdinstall.bin C:\ProgramData\{6102b12a-c37a-1cde-6102-2b12ac37c4ab} C:\ProgramData\{c5a24645-6934-8e8c-c5a2-246456931915} C:\ProgramData\2609058157272681152 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mount&Blade Warband C:\ProgramData\Temp C:\Users\Kaktus\AppData\Roaming\appdataFr3.bin C:\Users\Kaktus\AppData\Roaming\Microsoft\Word\Final%20Year%20project%20report%20(draft)304393153058117901\Final%20Year%20project%20report%20(draft).docx.lnk EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKU\S-1-5-21-3030238434-3008618196-960345281-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-3030238434-3008618196-960345281-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. "HKU\S-1-5-21-3030238434-3008618196-960345281-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1C21D719-C031-482D-A625-A9A98863372B}" => Key deleted successfully. HKCR\CLSID\{1C21D719-C031-482D-A625-A9A98863372B} => Key not found. HKU\S-1-5-21-3030238434-3008618196-960345281-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30CEEEA2-3742-40E4-85DD-812BF1CBB83D} => value deleted successfully. HKCR\CLSID\{30CEEEA2-3742-40E4-85DD-812BF1CBB83D} => Key not found. HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EEB95C0A-9515-4DC1-B7D6-9E93B520CFB0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEB95C0A-9515-4DC1-B7D6-9E93B520CFB0}" => Key deleted successfully. C:\Windows\System32\Tasks\{297C785B-E46A-4172-BE39-1E59FADA07D0} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{297C785B-E46A-4172-BE39-1E59FADA07D0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3B69E76-FCEB-42A9-88BE-72AC309B2B6C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3B69E76-FCEB-42A9-88BE-72AC309B2B6C}" => Key deleted successfully. C:\Windows\System32\Tasks\{3F25AC42-5546-4903-AC1C-E71A6801619F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3F25AC42-5546-4903-AC1C-E71A6801619F}" => Key deleted successfully. AmUStor => Service deleted successfully. C:\Program Files (x86)\ActiveDiscount => Moved successfully. C:\Program Files (x86)\AdDToThis => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\plugins => Moved successfully. C:\Program Files (x86)\SpaceCCoeuPonuApp => Moved successfully. C:\Program Files (x86)\The Key for YouTube => Moved successfully. C:\ProgramData\*.bdinstall.bin => Moved successfully. C:\ProgramData\{6102b12a-c37a-1cde-6102-2b12ac37c4ab} => Moved successfully. C:\ProgramData\{c5a24645-6934-8e8c-c5a2-246456931915} => Moved successfully. C:\ProgramData\2609058157272681152 => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mount&Blade Warband => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\Kaktus\AppData\Roaming\appdataFr3.bin => Moved successfully. C:\Users\Kaktus\AppData\Roaming\Microsoft\Word\Final%20Year%20project%20report%20(draft)304393153058117901\Final%20Year%20project%20report%20(draft).docx.lnk => Moved successfully. EmptyTemp: => Removed 2.2 GB temporary data. The system needed a reboot. ==== End of Fixlog 12:31:30 ====