Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-12-2014 Ran by Jakub at 2014-12-11 04:53:58 Run:6 Running from C:\Users\Jakub\logi Loaded Profile: Jakub (Available profiles: Jakub) Boot Mode: Normal ============================================== Content of fixlist: ***************** DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeAAMUpdater-1.0 Fallback-Kuba-Jakub DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OpenCandyHelperRunAsStandardUser1767F952F09F40CC960B82F4E2A664A1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OpenCandyHelperRunOnceF581672855574E97B6BAF2E5A2F9E8D1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D2 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D3 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D4 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D5 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D6 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D7 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera N DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT N DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT T DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT W1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT W2 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WMON1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTHUR1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTUE1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW1 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW2 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WWED1 C:\Windows\System32\Tasks\Safer-Networking CMD: type C:\Windows\System32\Tasks\{994C53C9-931B-4C78-AE49-3C455E0FC0BC} CMD: type C:\Windows\System32\Tasks\{BBD97430-1226-45F2-9E5A-C360CA072323} Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2E5628F-0AB1-43F1-AD7B-DC28612AAAD2}" /s Reg: reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E97F28D-3CB0-4203-8615-17647A9DB38A}" /s ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeAAMUpdater-1.0 Fallback-Kuba-Jakub => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OpenCandyHelperRunAsStandardUser1767F952F09F40CC960B82F4E2A664A1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OpenCandyHelperRunOnceF581672855574E97B6BAF2E5A2F9E8D1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D2 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D3 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D4 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D5 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D6 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera D7 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera N => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking => Failed to delete key at first attempt (Error: C0000121), see next line. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking => Key Deleted Successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT N => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT T => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT W1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT W2 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WMON1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTHUR1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WTUE1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW1 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WW2 => Key Deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WOT WWED1 => Key Deleted successfully. C:\Windows\System32\Tasks\Safer-Networking => Moved successfully. ========= type C:\Windows\System32\Tasks\{994C53C9-931B-4C78-AE49-3C455E0FC0BC} ========= true IgnoreNew false true true false false PT10M PT1H true false true true false false false PT72H 7 C:\Windows\system32\pcalua.exe -a "C:\Users\Jakub\Desktop\Liga Polska Manager 2005 Nowa Edycja\Dodatki\DodatekByBartek.exe" -d "C:\Users\Jakub\Desktop\Liga Polska Manager 2005 Nowa Edycja\Dodatki" Kuba\Jakub InteractiveToken LeastPrivilege ========= End of CMD: ========= ========= type C:\Windows\System32\Tasks\{BBD97430-1226-45F2-9E5A-C360CA072323} ========= true IgnoreNew false true true false false PT10M PT1H true false true true false false false PT72H 7 C:\Windows\system32\pcalua.exe -a "C:\FILMY\ESET.Smart.Security_6.0.306.7_32.64bit.PL-mara\64bit\Fix + Klucze\box, mara-fix v1.6\Eset fix\Eset fix.exe" -d "C:\FILMY\ESET.Smart.Security_6.0.306.7_32.64bit.PL-mara\64bit\Fix + Klucze\box, mara-fix v1.6\Eset fix" Kuba\Jakub InteractiveToken LeastPrivilege ========= End of CMD: ========= ========= reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2E5628F-0AB1-43F1-AD7B-DC28612AAAD2}" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2E5628F-0AB1-43F1-AD7B-DC28612AAAD2} Path REG_SZ \{994C53C9-931B-4C78-AE49-3C455E0FC0BC} Hash REG_BINARY F69CC07439AFBB6C95FDC9C15EA5F7DA97CF36EBA56CA9B751E9AD2F59C0F999 Schema REG_DWORD 0x10002 Triggers REG_BINARY 1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF282141424848484885725F2E484848480048484848484848004848484848484801000000484848481C00000048484848010500000000000515000000853EB325F9F5C92ED2556B84E90300004848484816000000484848484B007500620061005C004A0061006B0075006200000048482C0000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000484848488888000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000011CF0101000000000000000000000000000000 Actions REG_BINARY 01006666000000003C00000043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C007000630061006C00750061002E006500780065004A0100002D0061002000220043003A005C00550073006500720073005C004A0061006B00750062005C004400650073006B0074006F0070005C004C00690067006100200050006F006C0073006B00610020004D0061006E0061006700650072002000320030003000350020004E006F0077006100200045006400790063006A0061005C0044006F006400610074006B0069005C0044006F0064006100740065006B0042007900420061007200740065006B002E00650078006500220020002D0064002000220043003A005C00550073006500720073005C004A0061006B00750062005C004400650073006B0074006F0070005C004C00690067006100200050006F006C0073006B00610020004D0061006E0061006700650072002000320030003000350020004E006F0077006100200045006400790063006A0061005C0044006F006400610074006B006900220000000000 DynamicInfo REG_BINARY 030000006CBBBF59F911CF01000000000000000000000000000000000000000000000000 ========= End of Reg: ========= ========= reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E97F28D-3CB0-4203-8615-17647A9DB38A}" /s ========= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E97F28D-3CB0-4203-8615-17647A9DB38A} Path REG_SZ \{BBD97430-1226-45F2-9E5A-C360CA072323} Hash REG_BINARY 44C7CE420F2AF4388834772F5F88E28F4FD43AB4E658E8CBDB0EB4227EB662B3 Schema REG_DWORD 0x10002 Triggers REG_BINARY 1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF2821414248484848FC667FE5484848480048484848484848004848484848484801000000484848481C00000048484848010500000000000515000000853EB325F9F5C92ED2556B84E90300004848484816000000484848484B007500620061005C004A0061006B0075006200000048482C0000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000484848488888000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000DFCE0101000000000000000000000000000000 Actions REG_BINARY 01006666000000003C00000043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C007000630061006C00750061002E00650078006500C80100002D0061002000220043003A005C00460049004C004D0059005C0045005300450054002E0053006D006100720074002E00530065006300750072006900740079005F0036002E0030002E003300300036002E0037005F00330032002E00360034006200690074002E0050004C002D006D006100720061005C00360034006200690074005C0046006900780020002B0020004B006C00750063007A0065005C0062006F0078002C0020006D006100720061002D006600690078002000760031002E0036005C00450073006500740020006600690078005C00450073006500740020006600690078002E00650078006500220020002D0064002000220043003A005C00460049004C004D0059005C0045005300450054002E0053006D006100720074002E00530065006300750072006900740079005F0036002E0030002E003300300036002E0037005F00330032002E00360034006200690074002E0050004C002D006D006100720061005C00360034006200690074005C0046006900780020002B0020004B006C00750063007A0065005C0062006F0078002C0020006D006100720061002D006600690078002000760031002E0036005C0045007300650074002000660069007800220000000000 DynamicInfo REG_BINARY 030000007A9790AB7ADFCE01000000000000000000000000000000000000000000000000 ========= End of Reg: ========= ==== End of Fixlog ====