Fix result of Farbar Recovery Scan Tool (x86) Version: 12-07-2015 Ran by Bartek at 2015-07-13 16:34:52 Run:1 Running from C:\Users\Bartek\Desktop Loaded Profiles: Bartek (Available Profiles: Bartek) Boot Mode: Safe Mode (minimal) ============================================== fixlist content: ***************** CloseProcesses: R1 {255a824a-3cde-4dee-9785-284605606456}Gw; C:\Windows\System32\drivers\{255a824a-3cde-4dee-9785-284605606456}Gw.sys [43200 2014-10-28] (StdLib) R1 {71841b04-1cf8-4575-bb09-affe4c54c593}Gw; C:\Windows\System32\drivers\{71841b04-1cf8-4575-bb09-affe4c54c593}Gw.sys [43152 2015-03-16] (StdLib) R1 {b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw; C:\Windows\System32\drivers\{b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw.sys [43152 2014-10-25] (StdLib) R1 {f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw; C:\Windows\System32\drivers\{f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw.sys [43152 2014-10-24] (StdLib) R1 {fc7329ef-e953-454c-8e78-ed2cf0acb2ef}Gw; C:\Windows\System32\drivers\{fc7329ef-e953-454c-8e78-ed2cf0acb2ef}Gw.sys [43200 2014-10-31] (StdLib) R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X] R2 MaintainerSvc1.20.7247763; C:\ProgramData\d2446020-ddff-402b-b064-199d2ce66b2b\maintainer.exe [128232 2015-07-13] () R2 VSSS; C:\Users\Bartek\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [100135104 2015-06-23] (Microsoft Corporation) [File not signed] <==== ATTENTION HKLM\...\RunOnce: [] => [X] HKU\S-1-5-21-3193886611-3762004184-2434545920-1000\...\CurrentVersion\Windows: [Load] C:\ProgramData\mscrzoj.exe <===== ATTENTION Task: {84655EDB-A879-4D42-A5CD-7E38AA16DC35} - System32\Tasks\DLL-files.com Fixer_UPDATES => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe Task: {FAEABC3B-9CD4-4DF9-84B4-B0C9DB948128} - System32\Tasks\{057538BB-3AA7-4662-BE43-EBFDDB1FA145} => Firefox.exe http://ui.skype.com/ui/0/7.1.59.105/pl/abandoninstall?page=tsProgressBar Task: C:\Windows\Tasks\DLL-files.com Fixer_UPDATES.job => C:\Program Files\Dll-Files.com Fixer\DLLFixer.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\*.exe C:\ProgramData\mscrzoj.exe C:\ProgramData\d2446020-ddff-402b-b064-199d2ce66b2b C:\Users\Bartek\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe C:\Windows\System32\drivers\{255a824a-3cde-4dee-9785-284605606456}Gw.sys C:\Windows\System32\drivers\{71841b04-1cf8-4575-bb09-affe4c54c593}Gw.sys C:\Windows\System32\drivers\{b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw.sys C:\Windows\System32\drivers\{f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw.sys C:\Windows\System32\drivers\{fc7329ef-e953-454c-8e78-ed2cf0acb2ef}Gw.sys H:\Removable Drive (16GB).lnk CMD: attrib /d /s -s -h H:\* CMD: netsh advfirewall reset Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f EmptyTemp: ***************** Processes closed successfully. {255a824a-3cde-4dee-9785-284605606456}Gw => Service removed successfully. {71841b04-1cf8-4575-bb09-affe4c54c593}Gw => Service removed successfully. {b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw => Service removed successfully. {f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw => Service removed successfully. {fc7329ef-e953-454c-8e78-ed2cf0acb2ef}Gw => Service removed successfully. KProcessHacker2 => Service not found. MaintainerSvc1.20.7247763 => Service removed successfully. VSSS => Service removed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => value not found. HKU\S-1-5-21-3193886611-3762004184-2434545920-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => value restored successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{84655EDB-A879-4D42-A5CD-7E38AA16DC35}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{84655EDB-A879-4D42-A5CD-7E38AA16DC35}" => key removed successfully. C:\Windows\System32\Tasks\DLL-files.com Fixer_UPDATES => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DLL-files.com Fixer_UPDATES" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FAEABC3B-9CD4-4DF9-84B4-B0C9DB948128}" => key removed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FAEABC3B-9CD4-4DF9-84B4-B0C9DB948128}" => key removed successfully. C:\Windows\System32\Tasks\{057538BB-3AA7-4662-BE43-EBFDDB1FA145} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{057538BB-3AA7-4662-BE43-EBFDDB1FA145}" => key removed successfully. C:\Windows\Tasks\DLL-files.com Fixer_UPDATES.job => moved successfully. C:\Windows\system32\GroupPolicy\Machine => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Policies\Google" => key removed successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully C:\Program Files\*.exe => moved successfully. C:\ProgramData\mscrzoj.exe => moved successfully. C:\ProgramData\d2446020-ddff-402b-b064-199d2ce66b2b => moved successfully. C:\Users\Bartek\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe => moved successfully. C:\Windows\System32\drivers\{255a824a-3cde-4dee-9785-284605606456}Gw.sys => moved successfully. C:\Windows\System32\drivers\{71841b04-1cf8-4575-bb09-affe4c54c593}Gw.sys => moved successfully. C:\Windows\System32\drivers\{b0c7827f-c845-429a-833b-c2a798fc4fc3}Gw.sys => moved successfully. C:\Windows\System32\drivers\{f5d136d7-adc2-4c84-85b2-e564334ab0bc}Gw.sys => moved successfully. C:\Windows\System32\drivers\{fc7329ef-e953-454c-8e78-ed2cf0acb2ef}Gw.sys => moved successfully. "H:\Removable Drive (16GB).lnk" => File/Folder not found. ========= attrib /d /s -s -h H:\* ========= Nie mo¾na odnale«† ˜cie¾ki - H:\. ========= End of CMD: ========= ========= netsh advfirewall reset ========= Wyst¥piˆ bˆ¥d podczas pr¢by kontaktowania si© z usˆug¥ zapory systemu Windows. Upewnij si©, ¾e usˆuga jest uruchomiona, i pon¢w ¾¥danie. ========= End of CMD: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => 5.5 GB temporary data Removed. The system needed a reboot. ==== End of Fixlog 16:35:39 ====