Fix result of Farbar Recovery Scan Tool (x64) Version:26-07-2015 Ran by DOM at 2015-07-27 14:33:15 Run:1 Running from C:\Users\DOM\Desktop Loaded Profiles: DOM (Available Profiles: DOM) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: HKLM-x32\...\Run: [fst_pl_144] => [X] ShortcutTarget: GM_DevUpdate.lnk -> C:\Program Files (x86)\USB all-in-one game controller\GM_DevUpdate.exe (No File) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKU\S-1-5-21-900956390-2900685666-1750924883-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelog.dll No File S2 Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] Task: {02740DC5-5FB6-4E11-8A36-28C2D0B17634} - System32\Tasks\{3D72BBB8-7205-4BE7-9BE5-B4ED2FE4BAB8} => pcalua.exe -a "E:\Pobrane\Warhammer 40k - Dawn of War Collection - Torrent\Warhammer 40k - Dawn of War Collection\Expansion 002 - Dark Crusade\Patches\dowdc-110-111.exe" -d "E:\Pobrane\Warhammer 40k - Dawn of War Collection - Torrent\Warhammer 40k - Dawn of War Collection\Expansion 002 - Dark Crusade\Patches" Task: {4A71BC08-79D7-4379-A03C-91D4952492E5} - System32\Tasks\{7D0AB98F-DB33-4E4E-AEE8-D4FE9490EB73} => pcalua.exe -a I:\autorun.exe -d I:\ Task: {666E8532-287A-41D7-8600-66F85AC6C96E} - System32\Tasks\{4092DEE5-7982-492A-AA47-D499B947C4B3} => pcalua.exe -a E:\Pobrane\interstate18full.exe -d E:\Pobrane Task: {66BC5E0A-41D4-4BC9-893B-5B219C9C3CD6} - System32\Tasks\{86416C65-82DA-4B6D-9F87-04AFFBECB9B9} => pcalua.exe -a "C:\Program Files (x86)\YTDownloader\YTDUninstall.exe" Task: {6C655B88-D789-459C-9C24-79E1D180FB0F} - System32\Tasks\{B03ADFF4-93D8-4831-8D9D-93F3D1A78328} => pcalua.exe -a "E:\Pobrane\C&C Generals and Zero Hour\setup.exe" -d "E:\Pobrane\C&C Generals and Zero Hour" Task: {6FF1ECA4-41C1-4DF6-9B09-E58F83DD006D} - System32\Tasks\{5CA42D02-F017-4CF8-96D4-F2B7ED642FB8} => pcalua.exe -a "E:\Gry\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe" -c uninstall=17 Task: {79900865-6C25-4647-A8C0-9C41EEAF4EFA} - System32\Tasks\{66F7CA35-D5C4-4523-9A9F-3EA10CA1392B} => pcalua.exe -a I:\autorun.exe -d I:\ Task: {8372DB52-4CEC-4E17-B814-392F0A7F9B9B} - System32\Tasks\{5AFCD57C-AE60-404D-BBF1-2618F077FCEA} => pcalua.exe -a "C:\Users\DOM\Desktop\battlefield MDT_2.75.exe" -d C:\Users\DOM\Desktop Task: {BF9BA50D-E21A-4067-8481-E1879F0550A7} - System32\Tasks\temp_4746a55b-dd69-4131-9ea9-ea086c8a5d4c-6 => C:\Program Files (x86)\Object Browser\4746a55b-dd69-4131-9ea9-ea086c8a5d4c-6.exe <==== ATTENTION Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh advfirewall reset EmptyTemp: ***************** Processes closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\fst_pl_144 => value removed successfully C:\Program Files (x86)\USB all-in-one game controller\GM_DevUpdate.exe not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value removed successfully "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => key removed successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found. HKU\S-1-5-21-900956390-2900685666-1750924883-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0" => key removed successfully "HKLM\Software\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.7.0" => key removed successfully Nero BackItUp Scheduler 4.0 => service removed successfully EagleX64 => service removed successfully ewusbnet => service removed successfully ew_hwusbdev => service removed successfully huawei_enumerator => service removed successfully hwdatacard => service removed successfully VGPU => service removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02740DC5-5FB6-4E11-8A36-28C2D0B17634}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02740DC5-5FB6-4E11-8A36-28C2D0B17634}" => key removed successfully C:\Windows\System32\Tasks\{3D72BBB8-7205-4BE7-9BE5-B4ED2FE4BAB8} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3D72BBB8-7205-4BE7-9BE5-B4ED2FE4BAB8}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4A71BC08-79D7-4379-A03C-91D4952492E5}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A71BC08-79D7-4379-A03C-91D4952492E5}" => key removed successfully C:\Windows\System32\Tasks\{7D0AB98F-DB33-4E4E-AEE8-D4FE9490EB73} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7D0AB98F-DB33-4E4E-AEE8-D4FE9490EB73}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{666E8532-287A-41D7-8600-66F85AC6C96E}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{666E8532-287A-41D7-8600-66F85AC6C96E}" => key removed successfully C:\Windows\System32\Tasks\{4092DEE5-7982-492A-AA47-D499B947C4B3} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4092DEE5-7982-492A-AA47-D499B947C4B3}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{66BC5E0A-41D4-4BC9-893B-5B219C9C3CD6}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66BC5E0A-41D4-4BC9-893B-5B219C9C3CD6}" => key removed successfully C:\Windows\System32\Tasks\{86416C65-82DA-4B6D-9F87-04AFFBECB9B9} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{86416C65-82DA-4B6D-9F87-04AFFBECB9B9}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C655B88-D789-459C-9C24-79E1D180FB0F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C655B88-D789-459C-9C24-79E1D180FB0F}" => key removed successfully C:\Windows\System32\Tasks\{B03ADFF4-93D8-4831-8D9D-93F3D1A78328} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B03ADFF4-93D8-4831-8D9D-93F3D1A78328}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6FF1ECA4-41C1-4DF6-9B09-E58F83DD006D}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FF1ECA4-41C1-4DF6-9B09-E58F83DD006D}" => key removed successfully C:\Windows\System32\Tasks\{5CA42D02-F017-4CF8-96D4-F2B7ED642FB8} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5CA42D02-F017-4CF8-96D4-F2B7ED642FB8}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{79900865-6C25-4647-A8C0-9C41EEAF4EFA}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79900865-6C25-4647-A8C0-9C41EEAF4EFA}" => key removed successfully C:\Windows\System32\Tasks\{66F7CA35-D5C4-4523-9A9F-3EA10CA1392B} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{66F7CA35-D5C4-4523-9A9F-3EA10CA1392B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8372DB52-4CEC-4E17-B814-392F0A7F9B9B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8372DB52-4CEC-4E17-B814-392F0A7F9B9B}" => key removed successfully C:\Windows\System32\Tasks\{5AFCD57C-AE60-404D-BBF1-2618F077FCEA} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5AFCD57C-AE60-404D-BBF1-2618F077FCEA}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BF9BA50D-E21A-4067-8481-E1879F0550A7}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF9BA50D-E21A-4067-8481-E1879F0550A7}" => key removed successfully C:\Windows\System32\Tasks\temp_4746a55b-dd69-4131-9ea9-ea086c8a5d4c-6 => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\temp_4746a55b-dd69-4131-9ea9-ea086c8a5d4c-6" => key removed successfully ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= EmptyTemp: => 2.6 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 14:33:52 ====