Fix result of Farbar Recovery Scan Tool (x64) Version:11-07-2015 Ran by euro at 2015-07-12 13:39:39 Run:1 Running from C:\Users\euro\Desktop Loaded Profiles: euro (Available Profiles: euro) Boot Mode: Normal ============================================== fixlist content: ***************** Task: {7E0A1E98-510E-4204-BB29-93948B324787} - System32\Tasks\{82B159F4-CCC1-4B9C-ADE4-30B77CE13099} => pcalua.exe -a C:\Users\euro\AppData\Local\Temp\st926.tmp\uninstall.exe -d C:\Windows\system32 -c -install -s -ptid=wpm05083 -s Task: {35B3727B-42F8-407A-804C-70D4BA57B341} - System32\Tasks\{8EBCBF27-15A4-479E-A438-A6D421A5FF5A} => pcalua.exe -a C:\Users\euro\AppData\Local\Temp\Temp1_Audio_Realtek_v6.0.1.5628_XP.zip\04_Audio\5628_PG259_R194_UAAV10a-5013\Setup.exe C: PROGRAM Files (x86)\MiuiTab C:\Program Files (x86)\WordAnchor_1.10.0.20 Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsur...5MZTXX42OEC5MZT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsur...5MZTXX42OEC5MZT HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsur...5MZTXX42OEC5MZT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsur...5MZTXX42OEC5MZT HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com?ty...c7q8gftdt7bbgdq HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com?ty...c7q8gftdt7bbgdq HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com?ty...c7q8gftdt7bbgdq HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com?ty...c7q8gftdt7bbgdq HKU\S-1-5-21-3046815239-261040755-881543829-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsur...5MZTXX42OEC5MZT HKU\S-1-5-21-3046815239-261040755-881543829-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsur...5MZTXX42OEC5MZT SearchScopes: HKU\S-1-5-21-3046815239-261040755-881543829-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-3046815239-261040755-881543829-1000 -> OldSearch URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-3046815239-261040755-881543829-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-3046815239-261040755-881543829-1000 -> {1A2E0390-8654-4DBC-BEEA-F7AE98810725} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-3046815239-261040755-881543829-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-3046815239-261040755-881543829-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.istartsur...q={searchTerms} SearchScopes: HKU\S-1-5-21-3046815239-261040755-881543829-1000 -> {szukaj.gazeta.pl} URL = http://www.istartsur...q={searchTerms} OPR Extension: (Dynamo Combo) - C:\Users\euro\AppData ROAMING\Opera Software\Opera Stable\Extensions\cgohmfhlbipbcmmpdonacmkpibfghppn [2015-05-20] R2 IHProtect Service; C:\Program Files (x86)\MiuiTab\ProtectService.exe [125112 2015-06-24] (XTab system) R2 wasvc_1.10.0.20; C:\Program Files (x86)\WordAnchor_1.10.0.20\Service\wasvc.exe [300120 2015-07-06] (WA) S2 Update Dynamo Combo; "C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe" [X] S2 Util Dynamo Combo; "C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe" [X] C:\Program Files (x86)\Dynamo Combo R1 wafd_vt_1_10_0_20; C:\Windows\System32\drivers\wafd_vt_1_10_0_20.sys [61312 2015-07-06] (WA) S3 cpuz135; \??\C:\Users\euro\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X] EmptyTemp: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7E0A1E98-510E-4204-BB29-93948B324787}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E0A1E98-510E-4204-BB29-93948B324787}" => key removed successfully C:\Windows\System32\Tasks\{82B159F4-CCC1-4B9C-ADE4-30B77CE13099} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{82B159F4-CCC1-4B9C-ADE4-30B77CE13099}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{35B3727B-42F8-407A-804C-70D4BA57B341}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35B3727B-42F8-407A-804C-70D4BA57B341}" => key removed successfully C:\Windows\System32\Tasks\{8EBCBF27-15A4-479E-A438-A6D421A5FF5A} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8EBCBF27-15A4-479E-A438-A6D421A5FF5A}" => key removed successfully C: PROGRAM Files (x86)\MiuiTab => Error: No automatic fix found for this entry. "C:\Program Files (x86)\WordAnchor_1.10.0.20" => File/Folder not found. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= C:\Windows\system32\GroupPolicy\Machine => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Policies\Google" => key removed successfully "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully "HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value removed successfully HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value removed successfully HKU\S-1-5-21-3046815239-261040755-881543829-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-3046815239-261040755-881543829-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => key removed successfully HKCR\CLSID\OldSearch => key not found. "HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. "HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1A2E0390-8654-4DBC-BEEA-F7AE98810725}" => key removed successfully HKCR\CLSID\{1A2E0390-8654-4DBC-BEEA-F7AE98810725} => key not found. "HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => key removed successfully HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. "HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => key removed successfully HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found. "HKU\S-1-5-21-3046815239-261040755-881543829-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{szukaj.gazeta.pl}" => key removed successfully HKCR\CLSID\{szukaj.gazeta.pl} => key not found. C:\Users\euro\AppData ROAMING\Opera Software\Opera Stable\Extensions\cgohmfhlbipbcmmpdonacmkpibfghppn folder not found. IHProtect Service => Service stopped successfully. IHProtect Service => Service removed successfully wasvc_1.10.0.20 => Service not found. Update Dynamo Combo => Service removed successfully Util Dynamo Combo => Service removed successfully "C:\Program Files (x86)\Dynamo Combo" => File/Folder not found. wafd_vt_1_10_0_20 => Unable to stop service. wafd_vt_1_10_0_20 => Service removed successfully cpuz135 => Service removed successfully EmptyTemp: => 1 GB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 13:40:21 ====