Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015 Ran by user at 2015-01-29 18:57:29 Run:1 Running from C:\Users\user\Downloads Loaded Profiles: user (Available profiles: user) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-04-23] (StdLib) S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [9856 2012-01-23] (Padus, Inc.) [File not signed] S3 MSICDSetup; \??\E:\CDriver64.sys [X] ShellIconOverlayIdentifiers: [GGDriveOverlay1] -> {E68D0A50-3C40-4712-B90D-DCFA93FF2534} => No File ShellIconOverlayIdentifiers: [GGDriveOverlay2] -> {E68D0A51-3C40-4712-B90D-DCFA93FF2534} => No File ShellIconOverlayIdentifiers: [GGDriveOverlay3] -> {E68D0A52-3C40-4712-B90D-DCFA93FF2534} => No File ShellIconOverlayIdentifiers: [GGDriveOverlay4] -> {E68D0A53-3C40-4712-B90D-DCFA93FF2534} => No File CustomCLSID: HKU\S-1-5-21-3017187921-1793405025-1133042684-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\user\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File Task: {2494FFA9-AA52-441B-AD78-20DB48F80F94} - System32\Tasks\{0B80D1CC-9FEF-4950-80AE-AA526DE04C2D} => Firefox.exe http://ui.skype.com/ui/0/5.5.0.124.259/pl/abandoninstall?source=lightinstaller&page=tsProblems&LastError=12007&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled Task: {376B1C9A-B922-407C-9477-207FA811552D} - System32\Tasks\{9A087C6C-6323-4476-B2A6-45E105FC527C} => pcalua.exe -a "C:\Program Files (x86)\Sense\Uninstall.exe" -c /fromcontrolpanel=1 Task: {6B6095B9-1E27-4AF6-800D-252250D38ABA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-02] (Google Inc.) Task: {789B5B86-C6D2-4553-8800-2E369A1D0499} - System32\Tasks\{426E5C90-584F-4CC2-ABBC-B2A1A1C39449} => pcalua.exe -a C:\Users\user\Desktop\l3codecx.exe -d C:\Users\user\Desktop Task: {97150842-6A18-400E-9932-CBBE296908E2} - System32\Tasks\{5D1EAD23-C157-44A8-985A-EC065628FFB2} => Firefox.exe http://ui.skype.com/ui/0/6.6.0.106/pl/abandoninstall?page=tsMain Task: {AB9B71AA-7A0E-48CA-80C1-DCD1E470DD01} - System32\Tasks\Sense-enabler => C:\Program Files (x86)\Sense\Sense-enabler.exe [2014-02-26] (Object Browser) <==== ATTENTION Task: {B6D789C0-4767-4933-9776-C412A0DACE14} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-02] (Google Inc.) Task: {FF68E047-06C1-420D-8BED-B7DFAE85EE94} - System32\Tasks\{B828FEC2-E17B-40B8-9793-1FA7C996A0C3} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe" Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Sense-enabler.job => C:\Program Files (x86)\Sense\Sense-enabler.exe <==== ATTENTION FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = SearchScopes: HKU\S-1-5-21-3017187921-1793405025-1133042684-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} SearchScopes: HKU\S-1-5-21-3017187921-1793405025-1133042684-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.v9.com/web/?q={searchTerms} Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File C:\Program Files (x86)\Google C:\Program Files (x86)\Mozilla Firefox\plugins C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dee2 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall C:\ProgramData\Temp C:\Users\user\AppData\Roaming\LiveSupport.exe_log.txt C:\Users\user\AppData\Roaming\regsvr32.exe_log.txt C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MX Skype Recorder C:\Windows\System32\drivers\wStLib64.sys C:\Windows\SysWOW64\drivers\pfc.sys CMD: sc config c2cautoupdatesvc start= demand CMD: sc config c2cpnrsvc start= demand CMD: sc config NvNetworkService start= demand CMD: sc config NvStreamSvc start= demand CMD: sc config WinDefend start= demand EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. wStLib64 => Unable to stop service wStLib64 => Service deleted successfully. pfc => Service deleted successfully. MSICDSetup => Service deleted successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay1" => Key deleted successfully. HKCR\CLSID\{E68D0A50-3C40-4712-B90D-DCFA93FF2534} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay2" => Key deleted successfully. HKCR\CLSID\{E68D0A51-3C40-4712-B90D-DCFA93FF2534} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay3" => Key deleted successfully. HKCR\CLSID\{E68D0A52-3C40-4712-B90D-DCFA93FF2534} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GGDriveOverlay4" => Key deleted successfully. HKCR\CLSID\{E68D0A53-3C40-4712-B90D-DCFA93FF2534} => Key not found. "HKU\S-1-5-21-3017187921-1793405025-1133042684-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2494FFA9-AA52-441B-AD78-20DB48F80F94}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2494FFA9-AA52-441B-AD78-20DB48F80F94}" => Key deleted successfully. C:\Windows\System32\Tasks\{0B80D1CC-9FEF-4950-80AE-AA526DE04C2D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0B80D1CC-9FEF-4950-80AE-AA526DE04C2D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{376B1C9A-B922-407C-9477-207FA811552D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{376B1C9A-B922-407C-9477-207FA811552D}" => Key deleted successfully. C:\Windows\System32\Tasks\{9A087C6C-6323-4476-B2A6-45E105FC527C} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9A087C6C-6323-4476-B2A6-45E105FC527C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6B6095B9-1E27-4AF6-800D-252250D38ABA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6B6095B9-1E27-4AF6-800D-252250D38ABA}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{789B5B86-C6D2-4553-8800-2E369A1D0499}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{789B5B86-C6D2-4553-8800-2E369A1D0499}" => Key deleted successfully. C:\Windows\System32\Tasks\{426E5C90-584F-4CC2-ABBC-B2A1A1C39449} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{426E5C90-584F-4CC2-ABBC-B2A1A1C39449}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{97150842-6A18-400E-9932-CBBE296908E2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97150842-6A18-400E-9932-CBBE296908E2}" => Key deleted successfully. C:\Windows\System32\Tasks\{5D1EAD23-C157-44A8-985A-EC065628FFB2} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5D1EAD23-C157-44A8-985A-EC065628FFB2}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AB9B71AA-7A0E-48CA-80C1-DCD1E470DD01}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB9B71AA-7A0E-48CA-80C1-DCD1E470DD01}" => Key deleted successfully. C:\Windows\System32\Tasks\Sense-enabler => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sense-enabler" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B6D789C0-4767-4933-9776-C412A0DACE14}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B6D789C0-4767-4933-9776-C412A0DACE14}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FF68E047-06C1-420D-8BED-B7DFAE85EE94}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF68E047-06C1-420D-8BED-B7DFAE85EE94}" => Key deleted successfully. C:\Windows\System32\Tasks\{B828FEC2-E17B-40B8-9793-1FA7C996A0C3} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B828FEC2-E17B-40B8-9793-1FA7C996A0C3}" => Key deleted successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully. C:\Windows\Tasks\Sense-enabler.job => Moved successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully. C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll => Moved successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully. C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll not found. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKU\S-1-5-21-3017187921-1793405025-1133042684-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-3017187921-1793405025-1133042684-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully. "HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully. HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. C:\Program Files (x86)\Google => Moved successfully. C:\Program Files (x86)\Mozilla Firefox\plugins => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dee2 => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall => Moved successfully. C:\ProgramData\Temp => Moved successfully. C:\Users\user\AppData\Roaming\LiveSupport.exe_log.txt => Moved successfully. C:\Users\user\AppData\Roaming\regsvr32.exe_log.txt => Moved successfully. C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox => Moved successfully. C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MX Skype Recorder => Moved successfully. C:\Windows\System32\drivers\wStLib64.sys => Moved successfully. C:\Windows\SysWOW64\drivers\pfc.sys => Moved successfully. ========= sc config c2cautoupdatesvc start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config c2cpnrsvc start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config NvNetworkService start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config NvStreamSvc start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config WinDefend start= demand ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= EmptyTemp: => Removed 1.4 GB temporary data. The system needed a reboot. ==== End of Fixlog 18:58:02 ====