Fix result of Farbar Recovery Scan Tool (x64) Version:13-06-2015 Ran by muun at 2015-06-17 09:43:09 Run:1 Running from C:\Users\muun\Desktop\naprawa' Loaded Profiles: UpdatusUser & muun (Available Profiles: UpdatusUser & muun & Praca) Boot Mode: Normal ============================================== fixlist content: ***************** Task: {48EE59A3-FB46-4249-87FA-6E9BD25AE0FD} - System32\Tasks\ShopperPro => C:\Program Files (x86)\ShopperPro\ShopperPro.exe <==== ATTENTION C:\Program Files (x86)\ShopperPro Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f Task: {4EBE2BE3-889F-4E44-956E-E7A1DAD7BF36} - \Apps Hat-firefoxinstaller No Task File <==== ATTENTION Task: {83093923-CDD1-422D-AA77-448FCAB1BD9C} - System32\Tasks\YTAUpdate => C:\PROGRA~2\YOUTUB~1\Updater.exe <==== ATTENTION C:\PROGRA~2\YOUTUB~1 Task: {AE1EB6D9-80F8-4CF3-A74D-1F64BF6D737F} - System32\Tasks\YTAUpdate_logon => C:\PROGRA~2\YOUTUB~1\Updater.exe <==== ATTENTION Task: {B36EF78B-A44C-4C0D-9CA5-AFE0F6912779} - \Apps Hat-updater No Task File <==== ATTENTION Task: {D93390BA-93BC-42A7-9DEC-D5D3030D06CF} - \Apps Hat-enabler No Task File <==== ATTENTION Task: {E525B31D-DF6E-4FDD-94CF-10EBE0999315} - \Apps Hat-codedownloader No Task File <==== ATTENTION Task: {F20071DF-D0B8-49C2-9DA9-7D774D8EC99A} - System32\Tasks\SPDriver => C:\Program Files (x86)\ShopperPro\JSDriver\1.35.1.155\jsdrv.exe <==== ATTENTION Task: {F778928A-5D16-421A-88A5-36F64228EDA7} - System32\Tasks\ShopperProJSUpd => C:\Program Files (x86)\ShopperPro\updater.exe <==== ATTENTION C:\Users\UpdatusUser\Desktop\ARAR.lnk C:\Users\Praca\Desktop\ARAR.lnk HKLM\...\Run: [] => [X] GroupPolicyUsers\S-1-5-21-543189089-2044631228-4276830283-1000\User: Group Policy Restriction detected <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-543189089-2044631228-4276830283-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = Toolbar: HKU\S-1-5-21-543189089-2044631228-4276830283-1002 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File S3 ADSMService; No ImagePath S2 Nero BackItUp Scheduler 4.0; No ImagePath S2 YouTubeAcceleratorService; No ImagePath EmptyTemp: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{48EE59A3-FB46-4249-87FA-6E9BD25AE0FD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{48EE59A3-FB46-4249-87FA-6E9BD25AE0FD}" => key removed successfully C:\Windows\System32\Tasks\ShopperPro => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro" => key removed successfully "C:\Program Files (x86)\ShopperPro" => File/Folder not found. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mystartsearch uninstall" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4EBE2BE3-889F-4E44-956E-E7A1DAD7BF36}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4EBE2BE3-889F-4E44-956E-E7A1DAD7BF36}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apps Hat-firefoxinstaller" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{83093923-CDD1-422D-AA77-448FCAB1BD9C}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83093923-CDD1-422D-AA77-448FCAB1BD9C}" => key removed successfully C:\Windows\System32\Tasks\YTAUpdate => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTAUpdate" => key removed successfully "C:\PROGRA~2\YOUTUB~1" => File/Folder not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AE1EB6D9-80F8-4CF3-A74D-1F64BF6D737F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE1EB6D9-80F8-4CF3-A74D-1F64BF6D737F}" => key removed successfully C:\Windows\System32\Tasks\YTAUpdate_logon => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTAUpdate_logon" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B36EF78B-A44C-4C0D-9CA5-AFE0F6912779}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B36EF78B-A44C-4C0D-9CA5-AFE0F6912779}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apps Hat-updater" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D93390BA-93BC-42A7-9DEC-D5D3030D06CF}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D93390BA-93BC-42A7-9DEC-D5D3030D06CF}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apps Hat-enabler" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E525B31D-DF6E-4FDD-94CF-10EBE0999315}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E525B31D-DF6E-4FDD-94CF-10EBE0999315}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apps Hat-codedownloader" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F20071DF-D0B8-49C2-9DA9-7D774D8EC99A}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F20071DF-D0B8-49C2-9DA9-7D774D8EC99A}" => key removed successfully C:\Windows\System32\Tasks\SPDriver => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F778928A-5D16-421A-88A5-36F64228EDA7}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F778928A-5D16-421A-88A5-36F64228EDA7}" => key removed successfully C:\Windows\System32\Tasks\ShopperProJSUpd => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd" => key removed successfully C:\Users\UpdatusUser\Desktop\ARAR.lnk => moved successfully. C:\Users\Praca\Desktop\ARAR.lnk => moved successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully C:\Windows\system32\GroupPolicyUsers\S-1-5-21-543189089-2044631228-4276830283-1000\User => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully "HKU\S-1-5-21-543189089-2044631228-4276830283-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKU\S-1-5-21-543189089-2044631228-4276830283-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value removed successfully HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => key not found. ADSMService => Service removed successfully Nero BackItUp Scheduler 4.0 => Service removed successfully YouTubeAcceleratorService => Service removed successfully EmptyTemp: => 2.7 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 09:52:10 ====