Fix result of Farbar Recovery Scan Tool (x64) Version: 21-05-2015 Ran by Mariusz at 2015-05-21 18:37:32 Run:1 Running from C:\Users\Mariusz\Downloads Loaded Profiles: Mariusz (Available profiles: Mariusz) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: IFEO\caupdt.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\ChangeIcon.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwb3uic.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbadgen.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbcfg.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbckver.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbcopwr.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbcossl.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbcotrc.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbdsk.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbenv.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbinarp.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbinhlp.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbinsii.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbinww.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwblmsrv.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwblog.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwblogon.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbmptrc.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbnltbl.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbODBCreg.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbopaoc.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbopcon.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbping.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbprops.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbrminf.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbsreg.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbsvd.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbsvd64.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbsvget.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbsvstr.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbtf.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbtfdft.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbtftstfmt.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbuisxe.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbunfed.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbunnav.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbvlog.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbwlwiz.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\cwbzztrc.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\DriverBooster.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\ez2.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\ezcheck.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\ezstart.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\InstStat.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\IObitDownloader.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\lstjbl.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\lstjob.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\lstmsg.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\lstprt.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\lstsplf.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\MakeSFX.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\Promote.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\rfrompcb.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\rtopcb.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\rxferpcb.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\Scheduler.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\SetupHlp.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\srvview.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\strapp.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\wrkmsg.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\wrkprt.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\wrksplf.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\wrkusrj.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe IFEO\_isdel.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare 8\AutoReactivator.exe HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-2883962111-3297607759-932671933-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm HKU\S-1-5-21-2883962111-3297607759-932671933-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2883962111-3297607759-932671933-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch S3 catchme; No ImagePath R3 cpuz137; No ImagePath Task: {203A2F4A-BF7E-4F4B-9ABF-24E2AE7F18C0} - \Driver Booster SkipUAC (SYSTEM) No Task File <==== ATTENTION EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\caupdt.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ChangeIcon.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwb3uic.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbadgen.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbcfg.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbckver.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbcopwr.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbcossl.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbcotrc.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbdsk.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbenv.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbinarp.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbinhlp.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbinsii.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbinww.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwblmsrv.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwblog.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwblogon.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbmptrc.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbnltbl.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbODBCreg.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbopaoc.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbopcon.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbping.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbprops.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbrminf.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbsreg.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbsvd.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbsvd64.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbsvget.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbsvstr.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbtf.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbtfdft.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbtftstfmt.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbuisxe.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbunfed.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbunnav.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbvlog.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbwlwiz.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\cwbzztrc.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\DriverBooster.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ez2.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ezcheck.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ezstart.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\InstStat.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\IObitDownloader.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\lstjbl.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\lstjob.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\lstmsg.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\lstprt.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\lstsplf.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MakeSFX.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Promote.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rfrompcb.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rtopcb.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rxferpcb.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Scheduler.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SetupHlp.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\srvview.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\strapp.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wrkmsg.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wrkprt.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wrksplf.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wrkusrj.exe" => Key Deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\_isdel.exe" => Key Deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key Deleted successfully. "HKU\S-1-5-21-2883962111-3297607759-932671933-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key Deleted successfully. HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value Deleted successfully. HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => value Deleted successfully. HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page => value Deleted successfully. HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Search Page => value Deleted successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value Deleted successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => value Deleted successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Search Page => value Deleted successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Search Bar => value Deleted successfully. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value Deleted successfully. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => value Deleted successfully. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Search Page => value Deleted successfully. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Search Bar => value Deleted successfully. HKU\S-1-5-21-2883962111-3297607759-932671933-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKU\S-1-5-21-2883962111-3297607759-932671933-1000\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. catchme => Service Deleted successfully. cpuz137 => Service stopped successfully. cpuz137 => Service Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{203A2F4A-BF7E-4F4B-9ABF-24E2AE7F18C0}" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{203A2F4A-BF7E-4F4B-9ABF-24E2AE7F18C0}" => Key Deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (SYSTEM)" => Key Deleted successfully. EmptyTemp: => Removed 62.5 MB temporary data. The system needed a reboot. ==== End of Fixlog 18:38:02 ====