Fix result of Farbar Recovery Scan Tool (x64) Version:28-07-2015 Ran by Wiktor (2015-07-30 11:47:09) Run:1 Running from E:\Pobrane Loaded Profiles: Wiktor & UpdatusUser (Available Profiles: Wiktor & UpdatusUser) Boot Mode: Normal ============================================== fixlist content: ***************** C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack\Uninstall.lnk Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com?ty...c6b9e3mcqat6q5e HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com?ty...c6b9e3mcqat6q5e HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com?ty...c6b9e3mcqat6q5e HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com?ty...c6b9e3mcqat6q5e HKU\S-1-5-21-1486898360-476355479-2976473103-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com?ty...c6b9e3mcqat6q5e HKU\S-1-5-21-1486898360-476355479-2976473103-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com?ty...c6b9e3mcqat6q5e SearchScopes: HKU\S-1-5-21-1486898360-476355479-2976473103-1001 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://www.v9.com/we...q={searchTerms} SearchScopes: HKU\S-1-5-21-1486898360-476355479-2976473103-1001 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://www.v9.com/we...q={searchTerms} C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Developers Guidelines.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\License.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Release Notes.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Themes Creator.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Uninstall Themes Creator.lnk Task: {0A171B73-F00D-4E3A-AEC1-0A0BDE1055A9} - System32\Tasks\{ED86320F-D09F-49D3-AD5F-1E39EC25332E} => pcalua.exe -a C:\Users\Wiktor\Documents\Downloads\11CT2776682_BrotherSoft_Extreme.exe -d C:\Users\Wiktor\Documents\Downloads Task: {0BD5E6D8-7DD2-42AC-BD5F-AA927C575869} - System32\Tasks\{44966230-F6A6-4FE9-BB36-3A7AF2F2165F} => pcalua.exe -a C:\Users\Wiktor\winlogon.exe -d C:\Windows\system32 Task: {22F8771F-7885-4564-A176-161E8BAB8851} - System32\Tasks\{7B07745A-B478-48FC-8AFB-7CC2645A3049} => pcalua.exe -a "F:\PESEdit_2013_Patch_1.1 (Pespatchs.com)\Installer.exe" -d "F:\PESEdit_2013_Patch_1.1 (Pespatchs.com)" Task: {35B9A77C-CF3C-43D8-A45E-FAF9C8F2A737} - System32\Tasks\{CE35536D-B3F9-4824-A8C8-D3880D630574} => pcalua.exe -a C:\Users\Wiktor\Desktop\Nero-9.4.12.3_free.exe -d C:\Users\Wiktor\Desktop Task: {A919C4C2-ECB2-4845-9CE7-A489E726E3AD} - System32\Tasks\{FE502414-8EA7-4954-9588-0B0D47928667} => pcalua.exe -a D:\Autorun.exe -d D:\ Task: {F053F6A0-D4FB-47C3-AAB2-52BEE8A8581A} - System32\Tasks\task8564579 => C:\Windows\Temp\_ex-08.exe <==== ATTENTION Task: {F1352F4D-22DB-4C33-9623-DD6B39B2003B} - System32\Tasks\systems => C:\Users\Wiktor\AppData\Roaming\giuo.exe C:\Users\Wiktor\AppData\Roaming\giuo.exe Task: {FA07CE1F-6F2C-4CD8-9BCD-C837BA705F99} - System32\Tasks\{E47A1EB0-47E5-46ED-9B75-B5386FAC8BC5} => pcalua.exe -a E:\Gry\NFS\setup.exe -d E:\Gry\NFS FF SelectedSearchEngine: delta-homes EmptyTemp: ***************** C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 - Codec Pack\Uninstall.lnk => moved successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value removed successfully HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value removed successfully HKU\S-1-5-21-1486898360-476355479-2976473103-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-1486898360-476355479-2976473103-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-1486898360-476355479-2976473103-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\S-1-5-21-1486898360-476355479-2976473103-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => key removed successfully HKCR\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => key not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Developers Guidelines.lnk => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\License.lnk => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Release Notes.lnk => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Themes Creator.lnk => moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony Ericsson\Themes Creator\Uninstall Themes Creator.lnk => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0A171B73-F00D-4E3A-AEC1-0A0BDE1055A9}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0A171B73-F00D-4E3A-AEC1-0A0BDE1055A9}" => key removed successfully C:\Windows\System32\Tasks\{ED86320F-D09F-49D3-AD5F-1E39EC25332E} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{ED86320F-D09F-49D3-AD5F-1E39EC25332E}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0BD5E6D8-7DD2-42AC-BD5F-AA927C575869}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BD5E6D8-7DD2-42AC-BD5F-AA927C575869}" => key removed successfully C:\Windows\System32\Tasks\{44966230-F6A6-4FE9-BB36-3A7AF2F2165F} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{44966230-F6A6-4FE9-BB36-3A7AF2F2165F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{22F8771F-7885-4564-A176-161E8BAB8851}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{22F8771F-7885-4564-A176-161E8BAB8851}" => key removed successfully C:\Windows\System32\Tasks\{7B07745A-B478-48FC-8AFB-7CC2645A3049} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7B07745A-B478-48FC-8AFB-7CC2645A3049}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{35B9A77C-CF3C-43D8-A45E-FAF9C8F2A737}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35B9A77C-CF3C-43D8-A45E-FAF9C8F2A737}" => key removed successfully C:\Windows\System32\Tasks\{CE35536D-B3F9-4824-A8C8-D3880D630574} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CE35536D-B3F9-4824-A8C8-D3880D630574}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A919C4C2-ECB2-4845-9CE7-A489E726E3AD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A919C4C2-ECB2-4845-9CE7-A489E726E3AD}" => key removed successfully C:\Windows\System32\Tasks\{FE502414-8EA7-4954-9588-0B0D47928667} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FE502414-8EA7-4954-9588-0B0D47928667}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F053F6A0-D4FB-47C3-AAB2-52BEE8A8581A}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F053F6A0-D4FB-47C3-AAB2-52BEE8A8581A}" => key removed successfully C:\Windows\System32\Tasks\task8564579 => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\task8564579" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F1352F4D-22DB-4C33-9623-DD6B39B2003B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1352F4D-22DB-4C33-9623-DD6B39B2003B}" => key removed successfully C:\Windows\System32\Tasks\systems => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\systems" => key removed successfully "C:\Users\Wiktor\AppData\Roaming\giuo.exe" => File/Folder not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA07CE1F-6F2C-4CD8-9BCD-C837BA705F99}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA07CE1F-6F2C-4CD8-9BCD-C837BA705F99}" => key removed successfully C:\Windows\System32\Tasks\{E47A1EB0-47E5-46ED-9B75-B5386FAC8BC5} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E47A1EB0-47E5-46ED-9B75-B5386FAC8BC5}" => key removed successfully Firefox SelectedSearchEngine removed successfully EmptyTemp: => 5.7 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 11:48:42 ====