Fix result of Farbar Recovery Scan Tool (x64) Version:09-06-2016 Ran by Marek (2016-06-10 09:48:27) Run:3 Running from C:\Users\Marek\Desktop Loaded Profiles: Marek (Available Profiles: Marek & Administrator) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: S2 AdobeARMservice; "c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [X] Task: {F4246F33-17F0-4637-910E-1C34412DE3C0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated) SearchScopes: HKU\S-1-5-21-3377222215-263577021-991360115-1001 -> DefaultScope {AD627D66-48D3-45B5-B45D-AAED37AAE370} URL = BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll => No File DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f C:\ProgramData\*.* C:\ProgramData\Adobe C:\ProgramData\McAfee C:\ProgramData\Soluto C:\ProgramData\Sun C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR C:\Users\Marek\AppData\Local\Adobe C:\Users\Marek\AppData\Local\Dropbox C:\Users\Marek\AppData\Local\Temp\Low C:\Users\Marek\AppData\Roaming\*.* C:\Users\Marek\AppData\Roaming\Adobe C:\Users\Marek\AppData\Roaming\Dropbox C:\Users\Marek\AppData\Roaming\Mozilla C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR C:\Users\Marek\Desktop\Adobe Reader XI.lnk C:\Users\Marek\Desktop\Adobe - skrót.lnk C:\Users\Public\Desktop\Skype.lnk C:\WINDOWS\SysWOW64\deployJava1.dll EmptyTemp: ***************** Processes closed successfully. AdobeARMservice => service not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4246F33-17F0-4637-910E-1C34412DE3C0} => key not found. C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task => key not found. HKU\S-1-5-21-3377222215-263577021-991360115-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found. HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => key removed successfully ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= =========== "C:\ProgramData\*.*" ========== C:\ProgramData\!1BEBA2CC2C7D.bmp => moved successfully C:\ProgramData\!1BEBA2CC2C7D.cfg => moved successfully C:\ProgramData\!1BEBA2CC2C7D.html => moved successfully C:\ProgramData\DP45977C.lfl => moved successfully C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc => moved successfully ========= End -> "C:\ProgramData\*.*" ======== C:\ProgramData\Adobe => moved successfully C:\ProgramData\McAfee => moved successfully C:\ProgramData\Soluto => moved successfully C:\ProgramData\Sun => moved successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk => moved successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR => moved successfully C:\Users\Marek\AppData\Local\Adobe => moved successfully C:\Users\Marek\AppData\Local\Dropbox => moved successfully C:\Users\Marek\AppData\Local\Temp\Low => moved successfully =========== "C:\Users\Marek\AppData\Roaming\*.*" ========== C:\Users\Marek\AppData\Roaming\agent.dat => moved successfully C:\Users\Marek\AppData\Roaming\Installer.dat => moved successfully C:\Users\Marek\AppData\Roaming\Main.dat => moved successfully ========= End -> "C:\Users\Marek\AppData\Roaming\*.*" ======== C:\Users\Marek\AppData\Roaming\Adobe => moved successfully C:\Users\Marek\AppData\Roaming\Dropbox => moved successfully C:\Users\Marek\AppData\Roaming\Mozilla => moved successfully C:\Users\Marek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR => moved successfully C:\Users\Marek\Desktop\Adobe Reader XI.lnk => moved successfully C:\Users\Marek\Desktop\Adobe - skrót.lnk => moved successfully C:\Users\Public\Desktop\Skype.lnk => moved successfully C:\WINDOWS\SysWOW64\deployJava1.dll => moved successfully EmptyTemp: => 120.7 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 09:48:29 ====