Fix result of Farbar Recovery Scan Tool (x64) Version: 02-11-2017 Ran by Arkadius13 (11-11-2017 15:42:54) Run:2 Running from C:\Users\Arkadius13\Desktop\FRST64 Loaded Profiles: Arkadius13 (Available Profiles: Arkadius13) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: Task: {39476EE7-407E-4B71-8ADA-B0E8C35A8AD2} - System32\Tasks\WinThruster64-Arkadius13-Notification => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION Task: {87668741-C5C8-462E-96E5-ABE3CC249C79} - System32\Tasks\WinThruster64-Arkadius13-Startup => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION Task: C:\Windows\Tasks\WinThruster64-Arkadius13-Notification.job => C:\Program Files\Solvusoft\WinThruster\Sync.exe <==== ATTENTION Task: C:\Windows\Tasks\WinThruster64-Arkadius13-Startup.job => C:\Program Files\Solvusoft\WinThruster\WinThruster64.exe <==== ATTENTION C:\Program Files\Solvusoft HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-1244120915-4039251266-820905754-1000\...\Run: [AdobeBridge] => [X] S2 WsDrvInst; C:\Program Files (x86)\Wondershare\Wondershare dr.fone toolkit for Android\Library\DriverInstaller\DriverInstall.exe [X] U1 aswbdisk; no ImagePath S3 MSICDSetup; \??\E:\CDriver64.sys [X] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\GamerOSD\ASUS GamerOSD.lnk C:\Users\Arkadius13\Documents\lit\Start Tor Browser.lnk C:\Users\Arkadius13\Desktop\PROCODER\Tor Browser\Start Tor Browser.lnk C:\Users\Arkadius13\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Program Files\Common Files\System" CMD: dir /a "C:\Program Files (x86)\Common Files\System" CMD: dir /a C:\ProgramData CMD: dir /a C:\Users\Arkadius13\AppData\Local CMD: dir /a C:\Users\Arkadius13\AppData\LocalLow CMD: dir /a C:\Users\Arkadius13\AppData\Roaming Powershell: wevtutil el | Foreach-Object {wevtutil cl "$_"} EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{39476EE7-407E-4B71-8ADA-B0E8C35A8AD2} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39476EE7-407E-4B71-8ADA-B0E8C35A8AD2} => key removed successfully C:\Windows\System32\Tasks\WinThruster64-Arkadius13-Notification => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinThruster64-Arkadius13-Notification => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{87668741-C5C8-462E-96E5-ABE3CC249C79} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87668741-C5C8-462E-96E5-ABE3CC249C79} => key removed successfully C:\Windows\System32\Tasks\WinThruster64-Arkadius13-Startup => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinThruster64-Arkadius13-Startup => key removed successfully C:\Windows\Tasks\WinThruster64-Arkadius13-Notification.job => moved successfully C:\Windows\Tasks\WinThruster64-Arkadius13-Startup.job => moved successfully "C:\Program Files\Solvusoft" => not found. HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key not found. HKU\S-1-5-21-1244120915-4039251266-820905754-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully WsDrvInst => service not found. HKLM\System\CurrentControlSet\Services\aswbdisk => key removed successfully aswbdisk => service removed successfully HKLM\System\CurrentControlSet\Services\MSICDSetup => key removed successfully MSICDSetup => service removed successfully "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\GamerOSD\ASUS GamerOSD.lnk" => not found. C:\Users\Arkadius13\Documents\lit\Start Tor Browser.lnk => moved successfully "C:\Users\Arkadius13\Desktop\PROCODER\Tor Browser\Start Tor Browser.lnk" => not found. "C:\Users\Arkadius13\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk" => not found. ========= dir /a "C:\Program Files" ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\Program Files 2017-11-11 10:02 . 2017-11-11 10:02 .. 2017-09-24 06:48 Adobe 2017-10-28 23:47 Android 2017-09-22 14:42 ATI 2017-09-24 07:19 ATI Technologies 2017-09-18 23:01 BitComet 2017-10-26 23:46 CCleaner 2017-11-11 09:52 Common Files 2009-07-14 05:54 174 desktop.ini 2017-11-10 20:57 DVD Maker 2017-10-27 00:59 Git 2017-10-11 15:31 Internet Explorer 2017-10-18 18:37 Java 2011-04-12 09:28 Microsoft Games 2016-05-15 21:31 Microsoft.NET 2017-10-30 13:18 Mozilla Firefox 2017-09-20 13:58 MPC-HC 2009-07-14 06:32 MSBuild 2009-07-14 06:32 Reference Assemblies 2017-10-29 08:32 SmartFTP Client 2017-11-05 20:12 Sublime Text 3 2017-09-24 11:34 Topaz Labs 2009-07-14 06:09 Uninstall Information 2017-11-10 20:57 Windows Defender 2017-11-10 20:57 Windows Mail 2017-11-10 20:57 Windows Media Player 2009-07-14 06:32 Windows NT 2017-11-10 20:57 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2017-11-10 20:57 Windows Sidebar 2017-11-08 02:43 WinRAR 1 File(s) 174 bytes 31 Dir(s) 238ÿ893ÿ211ÿ648 bytes free ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)" ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\Program Files (x86) 2017-11-10 21:35 . 2017-11-10 21:35 .. 2017-10-27 00:17 Adobe 2017-09-24 07:19 AMD APP 2017-09-24 07:19 AMD AVT 2017-09-24 07:18 ATI Technologies 2017-11-11 09:48 AVG 2017-10-18 18:36 Common Files 2009-07-14 05:54 174 desktop.ini 2017-09-22 01:05 DVDVideoSoft 2017-10-12 19:17 FreeCodecPack 2017-10-27 06:44 GitHub Desktop Installer 2017-10-29 10:05 Google 2017-09-26 14:27 InstallShield Installation Information 2017-10-11 15:31 Internet Explorer 2017-09-20 17:01 K-Lite Codec Pack 2017-10-23 05:50 Malwarebytes Anti-Exploit 2017-09-20 19:25 Microsoft.NET 2017-11-01 16:45 Mozilla Maintenance Service 2009-07-14 06:32 MSBuild 2017-09-26 09:20 MSI Afterburner 2017-09-22 14:52 My Company Name 2017-09-24 08:56 NapiProjekt 2017-10-01 09:30 pazera-software 2009-07-14 06:32 Reference Assemblies 2017-10-25 06:07 Skillbrains 2017-09-18 15:05 Skype 2017-09-24 11:35 Topaz Labs 2009-07-14 05:57 Uninstall Information 2017-09-22 08:01 Winamp 2017-09-22 07:41 Winamp Detect 2017-11-10 20:57 Windows Defender 2017-11-10 20:57 Windows Mail 2017-11-10 20:57 Windows Media Player 2009-07-14 06:32 Windows NT 2017-11-10 20:57 Windows Photo Viewer 2010-11-21 04:31 Windows Portable Devices 2017-11-10 20:57 Windows Sidebar 2017-10-30 17:38 WordPress.com 1 File(s) 174 bytes 38 Dir(s) 238ÿ893ÿ211ÿ648 bytes free ========= End of CMD: ========= ========= dir /a "C:\Program Files\Common Files\System" ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\Program Files\Common Files\System 2017-11-10 20:57 . 2017-11-10 20:57 .. 2017-11-10 20:57 ado 2009-07-14 02:40 29ÿ184 DirectDB.dll 2011-04-12 09:17 en-US 2017-11-10 20:57 msadc 2017-11-10 20:57 Ole DB 2017-11-10 20:57 pl-PL 2016-05-15 13:13 886ÿ784 wab32.dll 2009-07-14 02:33 1ÿ098ÿ752 wab32res.dll 3 File(s) 2ÿ014ÿ720 bytes 7 Dir(s) 238ÿ894ÿ252ÿ032 bytes free ========= End of CMD: ========= ========= dir /a "C:\Program Files (x86)\Common Files\System" ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\Program Files (x86)\Common Files\System 2017-11-10 20:57 . 2017-11-10 20:57 .. 2017-11-10 20:57 ado 2009-07-14 02:15 24ÿ064 DirectDB.dll 2011-04-12 09:17 en-US 2017-11-10 20:57 msadc 2017-11-10 20:57 Ole DB 2017-11-10 20:57 pl-PL 2016-05-15 13:13 708ÿ608 wab32.dll 2009-07-14 02:11 1ÿ098ÿ752 wab32res.dll 3 File(s) 1ÿ831ÿ424 bytes 7 Dir(s) 238ÿ885ÿ773ÿ312 bytes free ========= End of CMD: ========= ========= dir /a C:\ProgramData ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\ProgramData 2017-11-10 14:43 . 2017-11-10 14:43 .. 2017-09-24 08:45 Adobe 2017-09-24 07:24 AMD 2009-07-14 06:08 Application Data [C:\ProgramData] 2017-09-24 07:19 ATI 2017-11-11 10:02 AVAST Software 2017-11-11 09:47 Avg 2017-09-20 18:59 Common Files 2009-07-14 06:08 Desktop [C:\Users\Public\Desktop] 2017-09-22 01:05 DigitalWave.ApplicationUpdater_files 2009-07-14 06:08 Documents [C:\Users\Public\Documents] 2009-07-14 06:08 Favorites [C:\Users\Public\Favorites] 2017-10-27 00:59 Git 2017-11-11 02:54 Malwarebytes Anti-Exploit 2017-11-11 14:57 MFAData 2017-11-08 02:38 Microsoft 2017-10-18 18:41 Oracle 2017-10-29 08:31 Package Cache 2017-09-24 05:21 regid.1986-12.com.adobe 2017-10-29 08:32 regid.2006-08.com.smartftp 2017-09-18 15:05 Skype 2009-07-14 06:08 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 2009-07-14 06:08 Templates [C:\ProgramData\Microsoft\Windows\Templates] 2017-10-02 12:31 Wondershare 0 File(s) 0 bytes 25 Dir(s) 238ÿ885ÿ769ÿ216 bytes free ========= End of CMD: ========= ========= dir /a C:\Users\Arkadius13\AppData\Local ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\Users\Arkadius13\AppData\Local 2017-11-11 08:23 . 2017-11-11 08:23 .. 2017-10-29 10:05 Adobe 2017-11-11 08:23 1ÿ496 Adobe Zapisz dla Internetu 13.0 Prefs 2017-09-24 07:24 AMD 2017-10-29 06:13 Android 2017-09-18 14:50 Application Data [C:\Users\Arkadius13\AppData\Local] 2017-09-18 14:55 Apps 2017-09-22 14:45 ATI 2017-10-27 07:02 atom 2017-11-08 02:43 AVAST Software 2017-11-11 09:52 Avg 2017-11-11 09:48 AvgSetupLog 2017-09-22 07:08 CEF 2017-11-10 21:25 Deployment 2017-11-10 21:20 Diagnostics 2017-10-25 03:46 58 DonationCoder_ScreenshotCaptor_InstallInfo.dat 2017-11-10 05:27 58ÿ832 GDIPFONTCACHEV1.DAT 2017-10-27 06:48 GitHubDesktop 2017-11-10 21:24 Google 2017-09-18 14:50 History [C:\Users\Arkadius13\AppData\Local\Microsoft\Windows\History] 2017-11-11 14:27 9ÿ818ÿ330 IconCache.db 2017-10-26 16:58 IIIQF 2017-11-06 14:48 LiveReload 2017-09-20 19:00 MFAData 2017-11-08 02:38 Microsoft 2017-10-11 18:05 Mozilla 2017-09-24 11:34 PackageAware 2017-09-20 13:15 Programs 2017-10-27 07:02 SquirrelTemp 2017-11-06 14:39 Sublime Text 3 2017-11-11 15:17 Temp 2017-09-18 14:50 Temporary Internet Files [C:\Users\Arkadius13\AppData\Local\Microsoft\Windows\Temporary Internet Files] 2017-11-01 12:20 Thunderbird 2017-09-24 13:10 Topaz Labs 2017-10-25 06:07 3 updater.log 2017-10-25 06:07 425 UserProducts.xml 2017-10-01 09:31 VirtualStore 6 File(s) 9ÿ879ÿ144 bytes 32 Dir(s) 238ÿ885ÿ769ÿ216 bytes free ========= End of CMD: ========= ========= dir /a C:\Users\Arkadius13\AppData\LocalLow ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\Users\Arkadius13\AppData\LocalLow 2017-11-01 18:36 . 2017-11-01 18:36 .. 2017-09-22 07:08 Adobe 2017-11-01 16:51 Microsoft 2017-11-01 17:00 Mozilla 2017-10-18 18:35 Oracle 2017-09-22 07:44 Sun 0 File(s) 0 bytes 7 Dir(s) 238ÿ885ÿ769ÿ216 bytes free ========= End of CMD: ========= ========= dir /a C:\Users\Arkadius13\AppData\Roaming ========= Volume in drive C has no label. Volume Serial Number is 204A-BB5B Directory of C:\Users\Arkadius13\AppData\Roaming 2017-11-11 10:02 . 2017-11-11 10:02 .. 2017-10-29 03:20 Adobe 2017-09-22 14:45 ATI 2017-10-27 20:49 Atom 2017-09-26 10:26 AVG 2017-11-11 15:41 BitComet 2017-09-23 06:36 DonationCoder 2017-09-22 12:47 DVDVideoSoft 2017-10-26 23:09 gcloud 2017-10-27 20:50 GitHub Desktop 2017-09-18 23:00 Google 2017-10-01 01:20 HMYGSetting 2017-09-18 14:51 Identities 2017-11-07 07:39 LiveReload 2017-09-20 13:17 Macromedia 2011-04-12 09:28 Media Center Programs 2017-11-10 03:41 Microsoft 2017-10-11 18:01 Mozilla 2017-09-20 13:58 MPC-HC 2017-09-20 13:17 NapiProjekt 2017-11-11 08:21 132 Preferencje formatu PNG CS6 firmy Adobe 2017-10-31 15:02 Skype 2017-10-29 20:23 SmartFTP 2017-09-24 07:00 StageManager.BD092818F67280F4B42B04877600987F0111B594.1 2017-11-06 06:15 Sublime Text 3 2017-09-22 07:44 Sun 2017-11-11 08:35 Telegram Desktop 2017-11-01 12:13 Thunderbird 2017-09-26 10:25 TuneUp Software 2017-09-22 09:47 Winamp 2017-09-18 15:17 WinRAR 2017-11-08 02:52 Wondershare 2017-10-30 21:06 WordPress.com 1 File(s) 132 bytes 33 Dir(s) 238ÿ885ÿ769ÿ216 bytes free ========= End of CMD: ========= ========= wevtutil el | Foreach-Object {wevtutil cl "$_"} ========= ========= End of Powershell: ========= =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 28744458 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 353975 B Edge => 0 B Chrome => 42019629 B Firefox => 346151270 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 128 B systemprofile32 => 430 B LocalService => 0 B NetworkService => 0 B Arkadius13 => 11278186 B RecycleBin => 546 B EmptyTemp: => 416.7 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 15:44:52 ====