Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01 Ran by Patryk at 2015-07-01 22:20:04 Run:1 Running from C:\Users\Patryk\Downloads Loaded Profiles: Patryk (Available Profiles: Patryk) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: HKLM-x32\...\Run: [fst_pl_127] => [X] HKLM-x32\...\Run: [mbot_pl_166] => [X] HKU\S-1-5-21-4069025438-3372814304-445969007-1000\...\Run: [CW] => [X] HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S2 SPDRIVER_1.37.0.871; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.871\jsdrv.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] Task: {15AC4286-756C-48EE-BBDA-EA44299CE78B} - System32\Tasks\{F0F4E334-8484-4A59-8126-2BE37AC47F0D} => pcalua.exe -a "C:\Users\Patryk\Downloads\NIEOFICJALNE SPOLSZCZENIE PES 2014 v.1.0.exe" -d C:\Users\Patryk\Downloads Task: {173BCA7C-65A6-482C-AFAD-A29B055E645B} - System32\Tasks\{846CD7D0-9F19-4665-958A-9D555FCA05EE} => pcalua.exe -a "E:\The SIMS 4\__Installer\vp6\vp6install.exe" -d "E:\The SIMS 4\__Installer\vp6" Task: {31D5A69B-FF98-4B2C-BE00-6F6020613F9F} - System32\Tasks\{364507E9-908D-40FD-A104-B1A28CAABAAD} => pcalua.exe -a C:\Users\Patryk\Desktop\TWEE_Upgrade.exe -d C:\Users\Patryk\Desktop Task: {32582BF6-E8FD-485D-82AD-5E92BCC939C4} - System32\Tasks\{F57630C4-D92A-42B2-8F4E-1223345B55A3} => pcalua.exe -a C:\Users\Patryk\Desktop\cenega_poland_gta4pcpatch\Content\setup.exe -d C:\Users\Patryk\Desktop\cenega_poland_gta4pcpatch\Content Task: {616516B8-6719-43E6-B993-278B246F19E6} - System32\Tasks\{31DFB57C-AB46-4BBD-AA1A-965CEA3F8910} => pcalua.exe -a C:\Users\Patryk\Desktop\mafia11-13pl.exe -d C:\Users\Patryk\Desktop Task: {673B9346-20D7-4F67-8278-303C46B0BB9E} - System32\Tasks\{7E36720A-D65D-4A25-8DC6-A01DF0B8BFB5} => pcalua.exe -a C:\Users\Patryk\AppData\Local\Temp\Temp1_YAhwl4op.zip\scc_spolszczenie_by_damagus.exe Task: {74605093-961E-46E6-B552-09DA641A78F3} - System32\Tasks\{2031F200-98B8-4C6E-BC6D-B25AA8268C38} => pcalua.exe -a C:\Users\Patryk\Downloads\vcredist_x86.exe -d C:\Users\Patryk\Downloads Task: {A3CFCCFB-7700-41FF-941B-DDFAA013872F} - System32\Tasks\{E112E6F6-9E79-4A1B-B181-44027C518EC8} => pcalua.exe -a C:\Users\Patryk\Desktop\TWEE_Polish_language_pack.exe -d C:\Users\Patryk\Desktop Task: {A7EA94BB-C6C0-4FF4-9E43-CF48D6A63F67} - System32\Tasks\{CB01D014-333F-4505-AE90-C788C6659EF2} => pcalua.exe -a "C:\Users\Patryk\Downloads\The Stanley Parable - Spolszczenie.exe" -d C:\Users\Patryk\Downloads Task: {B21B2B73-09CE-488C-9300-9CD552AF8AB6} - System32\Tasks\{AD98CCDD-141F-4755-B665-B920E880F753} => pcalua.exe -a C:\Users\Patryk\Desktop\mafia11-13pl.exe -d C:\Users\Patryk\Desktop Task: {C22806B0-5146-4867-B0AE-16AE19D95F29} - System32\Tasks\{69B41898-776C-4DB8-B1C3-A87EA60360E6} => pcalua.exe -a C:\Users\Patryk\Downloads\mafia11pl+.exe -d C:\Users\Patryk\Downloads Task: {CA30DAAB-4ADE-4C4C-B14F-8D390FACB622} - System32\Tasks\{3A214F80-46BD-4B6A-BCC5-1E801D392992} => pcalua.exe -a F:\setup.exe -d F:\ Task: {E6633D22-8DD0-448F-81A8-C0DFD4CDC4EF} - System32\Tasks\{28704245-58C1-42D9-803B-559577A5A0D4} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe" Hosts: EmptyTemp: ***************** Processes closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_127 => value removed successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mbot_pl_166 => value removed successfully HKU\S-1-5-21-4069025438-3372814304-445969007-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CW => value removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully C:\Windows\system32\GroupPolicy\Machine => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Policies\Google" => key removed successfully SPDRIVER_1.37.0.871 => Service removed successfully VGPU => Service removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15AC4286-756C-48EE-BBDA-EA44299CE78B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15AC4286-756C-48EE-BBDA-EA44299CE78B}" => key removed successfully C:\Windows\System32\Tasks\{F0F4E334-8484-4A59-8126-2BE37AC47F0D} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F0F4E334-8484-4A59-8126-2BE37AC47F0D}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{173BCA7C-65A6-482C-AFAD-A29B055E645B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{173BCA7C-65A6-482C-AFAD-A29B055E645B}" => key removed successfully C:\Windows\System32\Tasks\{846CD7D0-9F19-4665-958A-9D555FCA05EE} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{846CD7D0-9F19-4665-958A-9D555FCA05EE}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{31D5A69B-FF98-4B2C-BE00-6F6020613F9F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{31D5A69B-FF98-4B2C-BE00-6F6020613F9F}" => key removed successfully C:\Windows\System32\Tasks\{364507E9-908D-40FD-A104-B1A28CAABAAD} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{364507E9-908D-40FD-A104-B1A28CAABAAD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{32582BF6-E8FD-485D-82AD-5E92BCC939C4}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32582BF6-E8FD-485D-82AD-5E92BCC939C4}" => key removed successfully C:\Windows\System32\Tasks\{F57630C4-D92A-42B2-8F4E-1223345B55A3} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F57630C4-D92A-42B2-8F4E-1223345B55A3}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{616516B8-6719-43E6-B993-278B246F19E6}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{616516B8-6719-43E6-B993-278B246F19E6}" => key removed successfully C:\Windows\System32\Tasks\{31DFB57C-AB46-4BBD-AA1A-965CEA3F8910} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{31DFB57C-AB46-4BBD-AA1A-965CEA3F8910}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{673B9346-20D7-4F67-8278-303C46B0BB9E}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{673B9346-20D7-4F67-8278-303C46B0BB9E}" => key removed successfully C:\Windows\System32\Tasks\{7E36720A-D65D-4A25-8DC6-A01DF0B8BFB5} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7E36720A-D65D-4A25-8DC6-A01DF0B8BFB5}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{74605093-961E-46E6-B552-09DA641A78F3}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74605093-961E-46E6-B552-09DA641A78F3}" => key removed successfully C:\Windows\System32\Tasks\{2031F200-98B8-4C6E-BC6D-B25AA8268C38} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2031F200-98B8-4C6E-BC6D-B25AA8268C38}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3CFCCFB-7700-41FF-941B-DDFAA013872F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3CFCCFB-7700-41FF-941B-DDFAA013872F}" => key removed successfully C:\Windows\System32\Tasks\{E112E6F6-9E79-4A1B-B181-44027C518EC8} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E112E6F6-9E79-4A1B-B181-44027C518EC8}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7EA94BB-C6C0-4FF4-9E43-CF48D6A63F67}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7EA94BB-C6C0-4FF4-9E43-CF48D6A63F67}" => key removed successfully C:\Windows\System32\Tasks\{CB01D014-333F-4505-AE90-C788C6659EF2} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CB01D014-333F-4505-AE90-C788C6659EF2}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B21B2B73-09CE-488C-9300-9CD552AF8AB6}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B21B2B73-09CE-488C-9300-9CD552AF8AB6}" => key removed successfully C:\Windows\System32\Tasks\{AD98CCDD-141F-4755-B665-B920E880F753} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AD98CCDD-141F-4755-B665-B920E880F753}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C22806B0-5146-4867-B0AE-16AE19D95F29}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C22806B0-5146-4867-B0AE-16AE19D95F29}" => key removed successfully C:\Windows\System32\Tasks\{69B41898-776C-4DB8-B1C3-A87EA60360E6} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{69B41898-776C-4DB8-B1C3-A87EA60360E6}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA30DAAB-4ADE-4C4C-B14F-8D390FACB622}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA30DAAB-4ADE-4C4C-B14F-8D390FACB622}" => key removed successfully C:\Windows\System32\Tasks\{3A214F80-46BD-4B6A-BCC5-1E801D392992} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3A214F80-46BD-4B6A-BCC5-1E801D392992}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E6633D22-8DD0-448F-81A8-C0DFD4CDC4EF}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6633D22-8DD0-448F-81A8-C0DFD4CDC4EF}" => key removed successfully C:\Windows\System32\Tasks\{28704245-58C1-42D9-803B-559577A5A0D4} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{28704245-58C1-42D9-803B-559577A5A0D4}" => key removed successfully C:\Windows\System32\Drivers\etc\hosts => moved successfully. Hosts restored successfully. EmptyTemp: => 558.4 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 22:20:10 ====