Fix result of Farbar Recovery Scan Tool (x64) Version:14-08-2015 01 Ran by Tomek (2015-08-15 20:14:25) Run:1 Running from C:\Users\Tomek\Downloads Loaded Profiles: Tomek & Tom (Available Profiles: Tomek & Tom) Boot Mode: Normal ============================================== fixlist content: ***************** C:\Users\Tomek\AppData\Roaming\pwo12 Task: {0AD00364-AB38-4A60-9F2D-8E9F4C9B0D08} - System32\Tasks\{264467C9-B393-4976-916C-6B2D4E32B292} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe" Task: {0B754755-3B1D-478E-A089-F0A824C186BD} - \ShopperProJSUpd -> No File <==== ATTENTION Task: {0F726A6C-A261-4765-B1E9-A108F6E139BB} - \SPBIW_UpdateTask_Time_313431323531373631332d5b374a5a6c6c23322a345541 -> No File <==== ATTENTION Task: {1308C2C9-EAEB-42D1-9B3F-BCC77C575504} - \Installer_sense -> No File <==== ATTENTION Task: {52C9C22A-68FF-4085-AEEA-025073FEA568} - \Installer_iwebar -> No File <==== ATTENTION Task: {9FE2A07B-AED1-4538-A947-EAEA4D404933} - \ShopperPro -> No File <==== ATTENTION Task: {F5D6764D-38D4-434A-AC5C-5A1173106FC2} - \SPDriver -> No File <==== ATTENTION HKU\S-1-5-21-3940539798-2983024366-2410409241-1000\...\Run: [pwo12] => C:\Users\Tomek\AppData\Roaming\pwo12\audiogd.exe [9255846 2015-08-13] () GroupPolicyScripts: Group Policy detected <======= ATTENTION GroupPolicyScripts\User: Group Policy detected <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3940539798-2983024366-2410409241-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] C:\Users\Tomek\AppData\Local\Ethash C:\Users\Tomek\AppData\Local\CEF C:\Users\Tomek\AppData\Roaming\pwo6 EmptyTemp: ***************** "C:\Users\Tomek\AppData\Roaming\pwo12" folder move: Could not move "C:\Users\Tomek\AppData\Roaming\pwo12" => Scheduled to move on reboot. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0AD00364-AB38-4A60-9F2D-8E9F4C9B0D08}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0AD00364-AB38-4A60-9F2D-8E9F4C9B0D08}" => key removed successfully C:\Windows\System32\Tasks\{264467C9-B393-4976-916C-6B2D4E32B292} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{264467C9-B393-4976-916C-6B2D4E32B292}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0B754755-3B1D-478E-A089-F0A824C186BD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0B754755-3B1D-478E-A089-F0A824C186BD}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0F726A6C-A261-4765-B1E9-A108F6E139BB}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F726A6C-A261-4765-B1E9-A108F6E139BB}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_313431323531373631332d5b374a5a6c6c23322a345541 => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1308C2C9-EAEB-42D1-9B3F-BCC77C575504}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1308C2C9-EAEB-42D1-9B3F-BCC77C575504}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_sense" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{52C9C22A-68FF-4085-AEEA-025073FEA568}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52C9C22A-68FF-4085-AEEA-025073FEA568}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Installer_iwebar => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9FE2A07B-AED1-4538-A947-EAEA4D404933}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9FE2A07B-AED1-4538-A947-EAEA4D404933}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F5D6764D-38D4-434A-AC5C-5A1173106FC2}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5D6764D-38D4-434A-AC5C-5A1173106FC2}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver => key not found. HKU\S-1-5-21-3940539798-2983024366-2410409241-1000\Software\Microsoft\Windows\CurrentVersion\Run\\pwo12 => value removed successfully C:\Windows\system32\GroupPolicy\Machine => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. C:\Windows\system32\GroupPolicy\User => moved successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully "HKU\S-1-5-21-3940539798-2983024366-2410409241-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully MozillaMaintenance => service removed successfully EagleX64 => service removed successfully gdrv => service removed successfully "C:\Users\Tomek\AppData\Local\Ethash" folder move: Could not move "C:\Users\Tomek\AppData\Local\Ethash" => Scheduled to move on reboot. C:\Users\Tomek\AppData\Local\CEF => moved successfully. C:\Users\Tomek\AppData\Roaming\pwo6 => moved successfully. EmptyTemp: => 2.7 GB temporary data Removed. Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-08-15 20:26:40)<= C:\Users\Tomek\AppData\Roaming\pwo12 => Is moved successfully C:\Users\Tomek\AppData\Local\Ethash => Is moved successfully ==== End of Fixlog 20:26:40 ====