Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-01-2014 01 Ran by abc at 2014-01-30 09:49:53 Run:3 Running from C:\Users\abc\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {1395AFE3-AA8D-41F4-95E3-09B8C7FF2431} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\Sanjeev18\Standalone 8 Clock\Standalone 8 Clock.exe Task: {868574EF-5E4C-4600-9CF3-48833F598B0A} - \DealPly No Task File Task: {DF5EDB52-4131-410A-AABB-646BBF3548EF} - \Desk 365 RunAsStdUser No Task File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe FF NetworkProxy: "type", 0 FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppluginrichmediaplayer.dll () S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] C:\Users\abc\AppData\Local\WMTools Downloaded Files C:\Users\abc\AppData\Roaming\abclog.dat C:\Users\abc\AppData\Roaming\chrtmp C:\Users\abc\AppData\Roaming\F4A03908 C:\Users\abc\AppData\Roaming\WinDir C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP AlternateDataStreams: C:\ProgramData:NT AlternateDataStreams: C:\Users\All Users:NT AlternateDataStreams: C:\Users\abc\Dane aplikacji:NT AlternateDataStreams: C:\Users\abc\AppData\Roaming:NT AlternateDataStreams: C:\ProgramData\Application Data:NT AlternateDataStreams: C:\ProgramData\Dane aplikacji:NT AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT AlternateDataStreams: C:\ProgramData\TEMP:6BE50C2B Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1395AFE3-AA8D-41F4-95E3-09B8C7FF2431} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1395AFE3-AA8D-41F4-95E3-09B8C7FF2431} => Error deleting key Could not move "C:\Windows\System32\Tasks\RunAsStdUser Task" => Scheduled to move on reboot. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser Task => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{868574EF-5E4C-4600-9CF3-48833F598B0A} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{868574EF-5E4C-4600-9CF3-48833F598B0A} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DF5EDB52-4131-410A-AABB-646BBF3548EF} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF5EDB52-4131-410A-AABB-646BBF3548EF} => Error deleting key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Error deleting key HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Error setting value. Firefox Proxy settings were reset. EagleX64 => Unable to delete service C:\Users\abc\AppData\Local\WMTools Downloaded Files => Moved successfully. C:\Users\abc\AppData\Roaming\abclog.dat => Moved successfully. C:\Users\abc\AppData\Roaming\chrtmp => Moved successfully. C:\Users\abc\AppData\Roaming\F4A03908 => Moved successfully. C:\Users\abc\AppData\Roaming\WinDir => Moved successfully. "C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP" directory move: Could not move "C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP\WiseCustomCalla.dll" => Scheduled to move on reboot. Could not move "C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP" directory. => Scheduled to move on reboot. C:\ProgramData => ":NT" ADS removed successfully. "C:\Users\All Users" => ":NT" ADS not found. "C:\Users\abc\Dane aplikacji" => ":NT" ADS not found. C:\Users\abc\AppData\Roaming => ":NT" ADS removed successfully. "C:\ProgramData\Application Data" => ":NT" ADS not found. "C:\ProgramData\Dane aplikacji" => ":NT" ADS not found. C:\ProgramData\MTA San Andreas All => ":NT" ADS removed successfully. C:\ProgramData\TEMP => ":6BE50C2B" ADS removed successfully. ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes" /v DefaultScope /t REG_SZ /d {0633EE93-D776-472f-A0FF-E1416B8B2E3A} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: =========