Fix result of Farbar Recovery Scan Tool (x64) Version: 31-07-2017 Ran by Gulek (04-08-2017 23:11:59) Run:2 Running from C:\Users\Gulek\Desktop\Nowy folder Loaded Profiles: Gulek (Available Profiles: Gulek & DefaultAppPool) Boot Mode: Normal ============================================== fixlist content: ***************** GroupPolicy: Restriction - Chrome <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION FF Extension: (TLS 1.3 A/B Test Experiment) - C:\Users\Gulek\AppData\Roaming\Mozilla\Firefox\Profiles\1o4ouu3w.default\features\{15baf91d-a17b-4d41-925f-35e3c1bcda3c}\tls13-comparison-all-v1@mozilla.org.xpi [2017-05-24] CHR HomePage: ChromeDefaultData -> hxxp://www.istartsurf.com/?type=sy&ts=1432298350&z=1b7e14261a30cda3757f9dbg7zdcboaoatbbcc1w9m&from=smt&uid=ST1000LM014-SSHD-8GB_W380XD11XXXXW380XD11 CHR StartupUrls: ChromeDefaultData -> "hxxp://www.trotux.com/?z=get_error&from=ftp&uid=ST1000LM014-SSHD-8GB_W380XD11XXXXW380XD11&type=hp" CHR Extension: (?ookies Control) - C:\Users\Gulek\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp [2017-07-03] CHR Extension: (The love Test) - C:\Users\Gulek\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\niddbagogphmdkofeehlhjhkmojepllo [2017-07-24] 2017-08-04 22:30 - 2017-05-25 18:58 - 000000000 ____D C:\AdwCleaner 2016-10-17 20:57 - 2005-01-21 08:53 - 000045056 ____R () C:\Program Files (x86)\SetAttrib.exe 2016-11-27 20:08 - 2016-11-27 20:08 - 000000016 _____ () C:\ProgramData\mntemp ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File Task: {17B1F6C1-8101-41EC-A72B-DDD8DC253172} - System32\Tasks\{4ECA4A72-D6D0-4123-837F-F3A21564487D} => C:\Users\Gulek\Downloads\musicmatch-jukebox_musicmatch_jukebox_10.0.4033_anglais_10317.exe [2016-10-17] () Task: {61211D26-6F92-47A6-A702-1FB50A167B8A} - System32\Tasks\SafeZone scheduled Autoupdate 1468416524 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe Task: {644584BB-D0A4-42E4-9B23-BCA6A76D50AB} - System32\Tasks\{E1A7E98C-25A7-4AB3-A29D-6B8A079109B8} => C:\Program Files (x86)\Electronic Arts\Bitwa o �r�dziemie II\lotrbfme2.exe Task: {68973E8E-FBB8-470D-9C02-B010884FCC4F} - System32\Tasks\{98194FD4-A78B-47CE-9BD0-ACFB042C1CE3} => C:\Users\Gulek\Desktop\Cheat\srvany.exe [2017-07-29] () Task: {7E2ACC38-0679-4493-9DB0-F49377DC5895} - System32\Tasks\{CB63789E-7808-41E2-9F00-1BA9E3B0485A} => C:\Windows\system32\pcalua.exe -a "C:\Users\Gulek\Desktop\The walking dead S05\Age Of Empire-II+ Expansion [Direct Play]\SETUPREG.EXE" -d "C:\Users\Gulek\Desktop\The walking dead S05\Age Of Empire-II+ Expansion [Direct Play]" Task: {9B36D8DE-1F78-41D6-A509-B002B8739074} - System32\Tasks\{27F646E0-DE6D-4588-ABE5-38482EF1EB3F} => C:\Users\Gulek\Downloads\musicmatch-jukebox_musicmatch_jukebox_10.0.4033_anglais_10317.exe [2016-10-17] () Task: {D0820DEF-BFC9-4B6B-91ED-8D26218FAD03} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe Task: {FC4E67EC-C5AD-48BE-B3D7-EDED9E3FB1B5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe Task: {FE7BC502-F432-4736-867A-4E2802A01F72} - System32\Tasks\{297807CF-5759-4F86-AA6C-B1B9D588807E} => C:\Users\Gulek\Downloads\MP10Setup.exe [2016-10-17] (Microsoft Corporation) EmptyTemp: ***************** C:\Windows\system32\GroupPolicy\Machine => moved successfully C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully HKLM\SOFTWARE\Policies\Google => key removed successfully HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully C:\Users\Gulek\AppData\Roaming\Mozilla\Firefox\Profiles\1o4ouu3w.default\features\{15baf91d-a17b-4d41-925f-35e3c1bcda3c}\tls13-comparison-all-v1@mozilla.org.xpi => moved successfully Chrome HomePage => removed successfully Chrome StartupUrls => removed successfully CHR Extension: (?ookies Control) - C:\Users\Gulek\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfkpefbllpconnkfpdgagkifmflckkdp [2017-07-03] => Error: No automatic fix found for this entry. CHR Extension: (The love Test) - C:\Users\Gulek\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\niddbagogphmdkofeehlhjhkmojepllo [2017-07-24] => Error: No automatic fix found for this entry. C:\AdwCleaner => moved successfully C:\Program Files (x86)\SetAttrib.exe => moved successfully C:\ProgramData\mntemp => moved successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => key removed successfully HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => key removed successfully HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17B1F6C1-8101-41EC-A72B-DDD8DC253172} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17B1F6C1-8101-41EC-A72B-DDD8DC253172} => key removed successfully C:\Windows\System32\Tasks\{4ECA4A72-D6D0-4123-837F-F3A21564487D} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4ECA4A72-D6D0-4123-837F-F3A21564487D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{61211D26-6F92-47A6-A702-1FB50A167B8A} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{61211D26-6F92-47A6-A702-1FB50A167B8A} => key removed successfully C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1468416524 => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SafeZone scheduled Autoupdate 1468416524 => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{644584BB-D0A4-42E4-9B23-BCA6A76D50AB} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{644584BB-D0A4-42E4-9B23-BCA6A76D50AB} => key removed successfully C:\Windows\System32\Tasks\{E1A7E98C-25A7-4AB3-A29D-6B8A079109B8} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E1A7E98C-25A7-4AB3-A29D-6B8A079109B8} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68973E8E-FBB8-470D-9C02-B010884FCC4F} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68973E8E-FBB8-470D-9C02-B010884FCC4F} => key removed successfully C:\Windows\System32\Tasks\{98194FD4-A78B-47CE-9BD0-ACFB042C1CE3} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{98194FD4-A78B-47CE-9BD0-ACFB042C1CE3} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7E2ACC38-0679-4493-9DB0-F49377DC5895} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E2ACC38-0679-4493-9DB0-F49377DC5895} => key removed successfully C:\Windows\System32\Tasks\{CB63789E-7808-41E2-9F00-1BA9E3B0485A} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CB63789E-7808-41E2-9F00-1BA9E3B0485A} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B36D8DE-1F78-41D6-A509-B002B8739074} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B36D8DE-1F78-41D6-A509-B002B8739074} => key removed successfully C:\Windows\System32\Tasks\{27F646E0-DE6D-4588-ABE5-38482EF1EB3F} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{27F646E0-DE6D-4588-ABE5-38482EF1EB3F} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D0820DEF-BFC9-4B6B-91ED-8D26218FAD03} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0820DEF-BFC9-4B6B-91ED-8D26218FAD03} => key removed successfully C:\Windows\System32\Tasks\AVAST Software\Avast settings backup => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{FC4E67EC-C5AD-48BE-B3D7-EDED9E3FB1B5} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC4E67EC-C5AD-48BE-B3D7-EDED9E3FB1B5} => key removed successfully C:\Windows\System32\Tasks\Avast Emergency Update => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Emergency Update => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FE7BC502-F432-4736-867A-4E2802A01F72} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE7BC502-F432-4736-867A-4E2802A01F72} => key removed successfully C:\Windows\System32\Tasks\{297807CF-5759-4F86-AA6C-B1B9D588807E} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{297807CF-5759-4F86-AA6C-B1B9D588807E} => key removed successfully =========== EmptyTemp: ========== BITS transfer queue => 0 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 60706048 B Java, Flash, Steam htmlcache => 310665356 B Windows/system/drivers => 189777387 B Edge => 0 B Chrome => 8597657 B Firefox => 19100596 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 128 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 0 B Gulek => 165554530 B UpdatusUser => 0 B DefaultAppPool => 0 B RecycleBin => 28179532 B EmptyTemp: => 746.3 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 23:12:06 ====