Fix result of Farbar Recovery Scan Tool (x64) Version:17-08-2015 Ran by Wioleta (2015-08-19 01:48:25) Run:1 Running from C:\Users\Wioleta\Desktop Loaded Profiles: Wioleta (Available Profiles: Wioleta) Boot Mode: Normal ============================================== fixlist content: ***************** Task: {002CF15D-DD0F-47F7-9926-F207192A1C84} - System32\Tasks\StPrsSW => C:\Users\Wioleta\AppData\Roaming\StPrsSW\stprss.exe C:\Users\Wioleta\AppData\Roaming\StPrsSW HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\Software\Classes\.exe: exefile => <===== ATTENTION HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\Software\Classes\exefile: <===== ATTENTION S0 is3srv; SySWOW64\drivers\is3srv64.sys [X] S0 szkg5; SySWOW64\drivers\szkg64.sys [X] GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CustomCLSID: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Wioleta\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Wioleta\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Wioleta\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Wioleta\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Wioleta\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Wioleta\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Wioleta\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-is__alt__ddc_dsssyc_bd_com HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-is__alt__ddc_dsssyc_bd_com SearchScopes: HKU\S-1-5-21-3281234712-2478978767-3473656501-1001 -> DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = FF NewTab: hxxp://search.yahoo.com/?fr=hp-ddc-bd-tab&type=bl-bfr-is__alt__ddc_dsssyctab_bd_com FF SelectedSearchEngine: Yahoo Search! FF Homepage: hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bl-bfr-is__alt__ddc_dsssyc_bd_com FF Keyword.URL: hxxp://search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bfr-is__alt__ddc_dss_bd_com&p={searchTerms} C:\Users\Wioleta\Downloads\yet_another_cleaner_sk_7449892.exe C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56 C:\ProgramData\MakeMarkerFile.exe C:\Users\EasySurvey\EasySurvey.exe EmptyTemp: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{002CF15D-DD0F-47F7-9926-F207192A1C84}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{002CF15D-DD0F-47F7-9926-F207192A1C84}" => key removed successfully C:\WINDOWS\System32\Tasks\StPrsSW => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\StPrsSW" => key removed successfully C:\Users\Wioleta\AppData\Roaming\StPrsSW => moved successfully. "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\Software\Classes\exefile" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\Software\Classes\.exe" => key removed successfully HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\Software\Classes\exefile => key not found. is3srv => service removed successfully szkg5 => service removed successfully C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully. C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Policies\Google" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => key removed successfully "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully "HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-3281234712-2478978767-3473656501-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully Firefox "newtab" removed successfully Firefox SelectedSearchEngine removed successfully Firefox "homepage" removed successfully Firefox "Keyword.URL" removed successfully C:\Users\Wioleta\Downloads\yet_another_cleaner_sk_7449892.exe => moved successfully. C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56 => moved successfully. C:\ProgramData\MakeMarkerFile.exe => moved successfully. C:\Users\EasySurvey\EasySurvey.exe => moved successfully. EmptyTemp: => 227.8 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 01:48:42 ====