Fix result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01 Ran by Właściciel (2015-08-06 14:41:24) Run:1 Running from C:\Documents and Settings\Właściciel\Moje dokumenty\Pobrane Loaded Profiles: Właściciel (Available Profiles: Właściciel) Boot Mode: Normal ============================================== fixlist content: ***************** C:\Program Files\FFFFFFFF-1438788731-FFFF-FFFF-FFFFFFFFFFFF HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f FF Extension: No Name - C:\Documents and Settings\W [not found] FF Extension: No Name - C:\Documents and Settings\W [not found] R2 comyninu; C:\Program Files\FFFFFFFF-1438788731-FFFF-FFFF-FFFFFFFFFFFF\hnss88.tmp [161792 2015-08-05] () [File not signed] R2 hyverumu; C:\Program Files\FFFFFFFF-1438788731-FFFF-FFFF-FFFFFFFFFFFF\jnsy7F.tmp [209920 2015-08-05] () [File not signed] R2 xymunype; C:\Program Files\FFFFFFFF-1438788731-FFFF-FFFF-FFFFFFFFFFFF\knst70.tmpfs [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] 2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Documents and Settings\Właściciel\Dane aplikacji\gsgM2rKhmvUAvKNu6Pz 2015-04-20 16:05 - 2015-04-20 16:05 - 1246720 _____ () C:\Documents and Settings\Właściciel\Dane aplikacji\gsgM2rKhmvUAvKNu6Pz.exe 2015-08-05 17:37 - 2015-08-05 17:37 - 0333506 _____ (AnySend.com) C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\nsn3F.tmp CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0002E005-0000-0000-C000-000000000046}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\InprocServer32 -> no filepath Task: C:\WINDOWS\Tasks\CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}.job => C:\DOCUME~1\WACICI~1\USTAWI~1\Temp\cis1D.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\gsgM2rKhmvUAvKNu6Pz.job => C:\Documents and Settings\Waciciel\Dane aplikacji\gsgM2rKhmvUAvKNu6Pz.exe EmptyTemp: ***************** "C:\Program Files\FFFFFFFF-1438788731-FFFF-FFFF-FFFFFFFFFFFF" folder move: Could not move "C:\Program Files\FFFFFFFF-1438788731-FFFF-FFFF-FFFFFFFFFFFF" => Scheduled to move on reboot. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => value removed successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukończona pomyślnie ========= End of Reg: ========= C:\Documents and Settings\W => not found. C:\Documents and Settings\W => not found. comyninu => Service stopped successfully. comyninu => service removed successfully. hyverumu => Service stopped successfully. hyverumu => service removed successfully. xymunype => Service stopped successfully. xymunype => service removed successfully. massfilter => service removed successfully. ZTEusbmdm6k => service removed successfully. ZTEusbnmea => service removed successfully. ZTEusbser6k => service removed successfully. C:\Documents and Settings\Właściciel\Dane aplikacji\gsgM2rKhmvUAvKNu6Pz => moved successfully. Could not move "C:\Documents and Settings\Właściciel\Dane aplikacji\gsgM2rKhmvUAvKNu6Pz.exe" => Scheduled to move on reboot. C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\nsn3F.tmp => moved successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020420-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020421-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020422-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020423-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020424-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{00020425-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0002E005-0000-0000-C000-000000000046}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}" => key removed successfully. "HKU\S-1-5-21-854245398-1454471165-682003330-1003_Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}" => key removed successfully. C:\WINDOWS\Tasks\CIS_{15198508-521A-4D69-8E5B-B94A6CCFF805}.job => moved successfully. Could not move "C:\WINDOWS\Tasks\gsgM2rKhmvUAvKNu6Pz.job" => Scheduled to move on reboot. EmptyTemp: => 538.8 MB temporary data Removed. ==== End of Fixlog 14:42:07 ====