Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by Jurek at 2015-06-25 16:11:15 Run:1 Running from C:\Users\Jurek\Desktop Loaded Profiles: Jurek (Available Profiles: UpdatusUser & Jurek) Boot Mode: Normal ============================================== fixlist content: ***************** C:\Users\Jurek\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe R2 VSSS; C:\Users\Jurek\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1 HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-21-3202079706-1851762946-1585998374-1002\...\Run: [] => [X] HKU\S-1-5-21-3202079706-1851762946-1585998374-1002\...\Run: [BackgroundContainerV2] => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Jurek\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun HKU\S-1-5-21-3202079706-1851762946-1585998374-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> URLSearchHook: [S-1-5-21-3202079706-1851762946-1585998374-1002] ATTENTION ==> Default URLSearchHook is missing BHO: Hotspot Shield Class -> {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll No File BHO-x32: uTorrentControl2 Toolbar -> {687578b9-7132-4a7a-80e4-30ee31099e03} -> C:\Users\Jurek\AppData\LocalLow\uTorrentControl2\prxtbuTo2.dll [2014-09-23] (ClientConnect Ltd.) Toolbar: HKLM-x32 - uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Users\Jurek\AppData\LocalLow\uTorrentControl2\prxtbuTo2.dll FF SearchPlugin: C:\Users\Jurek\AppData\Roaming\Mozilla\Firefox\Profiles\2tv9h9un.default\searchplugins\conduit.xml [2012-06-07] 2015-06-24 16:34 - 2015-06-24 16:34 - 01415680 _____ (wj32) C:\Program Files\JNKU9C0V.exe 2015-06-24 16:34 - 2015-06-24 16:34 - 01415680 _____ (wj32) C:\Program Files\DSVZEHL0.exe 2015-06-24 16:33 - 2015-06-24 16:33 - 01415680 _____ (wj32) C:\Program Files\S6K0KY8G.exe 2015-06-24 16:33 - 2015-06-24 16:33 - 01415680 _____ (wj32) C:\Program Files\GVADSWVK.exe 2015-06-24 16:33 - 2015-06-24 16:33 - 01415680 _____ (wj32) C:\Program Files\FIX1GJNK.exe 2015-06-24 16:33 - 2015-06-24 16:33 - 01415680 _____ (wj32) C:\Program Files\DN1LV9T3.exe 2015-06-24 16:33 - 2015-06-24 16:33 - 01415680 _____ (wj32) C:\Program Files\BEHTWY14.exe 2015-06-24 16:33 - 2015-06-24 16:33 - 01415680 _____ (wj32) C:\Program Files\7AEHW037.exe 2015-06-24 16:32 - 2015-06-24 16:32 - 01415680 _____ (wj32) C:\Program Files\A0M7TK5R.exe 2015-06-24 15:48 - 2015-06-24 15:48 - 01415680 _____ (wj32) C:\Program Files\TE0MCYJ5.exe 2015-06-24 15:48 - 2015-06-24 15:48 - 01415680 _____ (wj32) C:\Program Files\JM158C5T.exe 2015-06-24 15:48 - 2015-06-24 15:48 - 01415680 _____ (wj32) C:\Program Files\GFSOKXWR.exe 2015-06-24 15:48 - 2015-06-24 15:48 - 01415680 _____ (wj32) C:\Program Files\BIMKU15J.exe 2015-06-24 15:48 - 2015-06-24 15:48 - 01415680 _____ (wj32) C:\Program Files\59D6DHLD.exe 2015-06-24 15:32 - 2015-06-24 15:32 - 01415680 _____ (wj32) C:\Program Files\LSW0704W.exe 2015-06-24 15:32 - 2015-06-24 15:32 - 01415680 _____ (wj32) C:\Program Files\LSW04X1T.exe 2015-06-24 15:32 - 2015-06-24 15:32 - 01415680 _____ (wj32) C:\Program Files\IM1GJY2H.exe 2015-06-24 15:32 - 2015-06-24 15:32 - 01415680 _____ (wj32) C:\Program Files\HL037APK.exe 2015-06-24 15:32 - 2015-06-24 15:32 - 01415680 _____ (wj32) C:\Program Files\DHOHLPWA.exe C:\found.00* C:\ProgramData\msequ.exe EmptyTemp: ***************** "C:\Users\Jurek\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe" => File/Folder not found. VSSS => Service removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully HKU\S-1-5-21-3202079706-1851762946-1585998374-1002\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully HKU\S-1-5-21-3202079706-1851762946-1585998374-1002\Software\Microsoft\Windows\CurrentVersion\Run\\BackgroundContainerV2 => value removed successfully HKU\S-1-5-21-3202079706-1851762946-1585998374-1002\Control Panel\Desktop\\SCRNSAVE.EXE => value not found. HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully Could not restore Default URLSearchHook. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}" => key removed successfully "HKCR\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{687578b9-7132-4a7a-80e4-30ee31099e03}" => key removed successfully "HKCR\Wow6432Node\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}" => key removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{687578b9-7132-4a7a-80e4-30ee31099e03} => value removed successfully "HKCR\Wow6432Node\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}" => key removed successfully C:\Users\Jurek\AppData\Roaming\Mozilla\Firefox\Profiles\2tv9h9un.default\searchplugins\conduit.xml => moved successfully. C:\Program Files\JNKU9C0V.exe => moved successfully. C:\Program Files\DSVZEHL0.exe => moved successfully. C:\Program Files\S6K0KY8G.exe => moved successfully. C:\Program Files\GVADSWVK.exe => moved successfully. C:\Program Files\FIX1GJNK.exe => moved successfully. C:\Program Files\DN1LV9T3.exe => moved successfully. C:\Program Files\BEHTWY14.exe => moved successfully. C:\Program Files\7AEHW037.exe => moved successfully. C:\Program Files\A0M7TK5R.exe => moved successfully. C:\Program Files\TE0MCYJ5.exe => moved successfully. C:\Program Files\JM158C5T.exe => moved successfully. C:\Program Files\GFSOKXWR.exe => moved successfully. C:\Program Files\BIMKU15J.exe => moved successfully. C:\Program Files\59D6DHLD.exe => moved successfully. C:\Program Files\LSW0704W.exe => moved successfully. C:\Program Files\LSW04X1T.exe => moved successfully. C:\Program Files\IM1GJY2H.exe => moved successfully. C:\Program Files\HL037APK.exe => moved successfully. C:\Program Files\DHOHLPWA.exe => moved successfully. "C:\found.00*" folder move: Could not move "C:\found.00*" folder => Scheduled to move on reboot. Could not move "C:\ProgramData\msequ.exe" => Scheduled to move on reboot. EmptyTemp: => 3.9 GB temporary data Removed. Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-06-25 16:17:23)<= "C:\found.00*" => Could not move C:\ProgramData\msequ.exe => Is moved successfully ==== End of Fixlog 16:17:23 ====