Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-04-2015 Ran by Bakoma at 2015-05-03 16:44:54 Run:1 Running from C:\Users\Bakoma\Documents\FRST Loaded Profiles: Bakoma (Available profiles: Bakoma) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: HKLM\...\Run: [YTDownloader] => "C:\Program Files\YTDownloader\YTDownloader.exe" /boot HKU\S-1-5-21-504265541-2987985666-2803033952-1000\...\Run: [YTDownloader] => "C:\Program Files\YTDownloader\YTDownloader.exe" /boot S2 sbmntr; \??\C:\PROGRA~1\YTDOWN~1\sbmntr.sys [X] Task: {123AF6E7-BAB3-4E0C-B54E-5E22AF8D698E} - \ShopperProJSUpd No Task File <==== ATTENTION Task: {1A7A1AED-3455-4CB8-9C30-66E16FDC5677} - System32\Tasks\YTDownloader => C:\Program Files\YTDownloader\YTDownloader.exe <==== ATTENTION Task: {489EFAA9-E19D-4941-A383-58EC916E9909} - System32\Tasks\{F068EE3F-48DE-43E2-9032-B90994E5497D} => pcalua.exe -a "C:\Program Files\InstallShield Installation Information\{3A1B1652-D70A-4D19-981E-BB15D0DBF253}\setup.exe" -c -runfromtemp -l0x0409 Task: {561A600F-1744-48A6-A5A4-9B528D2630A1} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION Task: {663D0608-16FA-43BC-AF2B-7155C26EC5BC} - System32\Tasks\SMupdate1 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update1 <==== ATTENTION Task: {6C2CDF17-C260-44AD-A06E-EF2D99B8C57A} - System32\Tasks\{D9825CA2-81A4-4BBB-980C-E4C9214548DB} => pcalua.exe -a C:\Users\Bakoma\Desktop\Incoming\PER3664B_20140513_V1.6\Tools\drvinstaller_X86.exe -d C:\Users\Bakoma\Desktop\Incoming\PER3664B_20140513_V1.6\Tools Task: {840B9536-7169-4A99-9D53-39539F0D48C3} - System32\Tasks\YTDownloaderUpd => C:\Program Files\YTDownloader\updater.exe <==== ATTENTION Task: {D8187495-10DC-4508-A45E-E58F4CF07A5A} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION Task: {DAFF483D-EB3D-479C-A3AB-38ECD29D9F12} - System32\Tasks\BBHJ => C:\Users\Bakoma\AppData\Roaming\BBHJ.exe <==== ATTENTION Task: C:\Windows\Tasks\BBHJ.job => C:\Users\Bakoma\AppData\Roaming\BBHJ.exe <==== ATTENTION C:\Windows\system32\roboot.exe EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value deleted successfully. HKU\S-1-5-21-504265541-2987985666-2803033952-1000\Software\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value deleted successfully. sbmntr => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{123AF6E7-BAB3-4E0C-B54E-5E22AF8D698E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{123AF6E7-BAB3-4E0C-B54E-5E22AF8D698E}" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1A7A1AED-3455-4CB8-9C30-66E16FDC5677}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A7A1AED-3455-4CB8-9C30-66E16FDC5677}" => Key Deleted successfully. C:\Windows\System32\Tasks\YTDownloader => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloader" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{489EFAA9-E19D-4941-A383-58EC916E9909}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{489EFAA9-E19D-4941-A383-58EC916E9909}" => Key deleted successfully. C:\Windows\System32\Tasks\{F068EE3F-48DE-43E2-9032-B90994E5497D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F068EE3F-48DE-43E2-9032-B90994E5497D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{561A600F-1744-48A6-A5A4-9B528D2630A1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{561A600F-1744-48A6-A5A4-9B528D2630A1}" => Key Deleted successfully. C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\SMupdate2" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{663D0608-16FA-43BC-AF2B-7155C26EC5BC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{663D0608-16FA-43BC-AF2B-7155C26EC5BC}" => Key Deleted successfully. C:\Windows\System32\Tasks\SMupdate1 not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMupdate1" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C2CDF17-C260-44AD-A06E-EF2D99B8C57A}" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C2CDF17-C260-44AD-A06E-EF2D99B8C57A}" => Key Deleted successfully. C:\Windows\System32\Tasks\{D9825CA2-81A4-4BBB-980C-E4C9214548DB} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D9825CA2-81A4-4BBB-980C-E4C9214548DB}" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{840B9536-7169-4A99-9D53-39539F0D48C3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{840B9536-7169-4A99-9D53-39539F0D48C3}" => Key Deleted successfully. C:\Windows\System32\Tasks\YTDownloaderUpd => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloaderUpd" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D8187495-10DC-4508-A45E-E58F4CF07A5A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8187495-10DC-4508-A45E-E58F4CF07A5A}" => Key Deleted successfully. C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DAFF483D-EB3D-479C-A3AB-38ECD29D9F12}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DAFF483D-EB3D-479C-A3AB-38ECD29D9F12}" => Key Deleted successfully. C:\Windows\System32\Tasks\BBHJ => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BBHJ" => Key Deleted successfully. C:\Windows\Tasks\BBHJ.job => Moved successfully. C:\Windows\system32\roboot.exe => Moved successfully. EmptyTemp: => Removed 1.9 GB temporary data. The system needed a reboot. ==== End of Fixlog 16:47:31 ====