Fix result of Farbar Recovery Scan Tool (x64) Version:21-06-2015 01 Ran by Matti24a at 2015-06-24 10:58:58 Run:2 Running from D:\download Loaded Profiles: Matti24a (Available Profiles: Matti24a) Boot Mode: Normal ============================================== fixlist content: ***************** HKU\S-1-5-21-2962128431-3766831332-2638231919-1000\...\CurrentVersion\Windows: [Load] C:\ProgramData\msbxucljo.exe <===== ATTENTION C:\ProgramData\msbxucljo.exe C:\Program Files\A09WD3KS.exe Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1 HKLM\...\Policies\Explorer: [HideSCAHealth] 1 BHO-x32: No Name -> {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} -> No File R3 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X] S3 usb6xxxk; \??\C:\Windows\system32\drivers\usb6xxxkl.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] EmptyTemp: ***************** HKU\S-1-5-21-2962128431-3766831332-2638231919-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => value restored successfully Could not move "C:\ProgramData\msbxucljo.exe" => Scheduled to move on reboot. C:\Program Files\A09WD3KS.exe => moved successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}" => key removed successfully HKCR\Wow6432Node\CLSID\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616} => key not found. KProcessHacker2 => Service stopped successfully. KProcessHacker2 => Service removed successfully usb6xxxk => Service removed successfully VBoxNetFlt => Service removed successfully vmci => Service removed successfully VMnetAdapter => Service removed successfully EmptyTemp: => 455.6 MB temporary data Removed. Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-06-24 11:00:30)<= C:\ProgramData\msbxucljo.exe => Is moved successfully ==== End of Fixlog 11:00:30 ====