Fix result of Farbar Recovery Scan Tool (x64) Version:17-12-2015 Ran by Evenix (2015-12-17 21:37:07) Run:1 Running from C:\Users\Evenix\Desktop Loaded Profiles: Evenix (Available Profiles: Evenix) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: Task: {7AD1B008-CA85-4200-8A74-3059CB2D2F59} - System32\Tasks\{E0DC0DF8-36E7-48CC-866F-32CBB3FCBB12} => Iexplore.exe hxxp://ui.skype.com/ui/0/7.6.0.103/pl/abandoninstall?source=lightinstaller&page=tsInstall Task: {F942C242-D309-4D8E-B6A4-02F56EF1DC06} - System32\Tasks\{B221FAC5-B5C2-4414-AE50-680F251D3579} => Chrome.exe hxxp://ui.skype.com/ui/0/7.6.0.105/pl/abandoninstall?page=tsProgressBar U0 qrlpsmcl; C:\Windows\System32\drivers\jproxcgw.sys [79064 2015-12-17] (Malwarebytes) C:\Windows\System32\drivers\jproxcgw.sys S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] SearchScopes: HKU\S-1-5-21-1644087666-2204009049-2821983492-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f Reg: reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f CMD: netsh advfirewall reset C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ KillDisk 9.2 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Origin Error Reporter.lnk C:\Users\Evenix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shortcut to ShredIt Documentation.lnk C:\Users\Evenix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk C:\Users\Evenix\AppData\Roaming\Microsoft\Word\Katedra304882790885201834\Katedra.docx.lnk C:\Users\Evenix\Desktop\New folder (6)\New folder (8)\*.lnk EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7AD1B008-CA85-4200-8A74-3059CB2D2F59}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AD1B008-CA85-4200-8A74-3059CB2D2F59}" => key removed successfully C:\Windows\System32\Tasks\{E0DC0DF8-36E7-48CC-866F-32CBB3FCBB12} => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E0DC0DF8-36E7-48CC-866F-32CBB3FCBB12}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F942C242-D309-4D8E-B6A4-02F56EF1DC06}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F942C242-D309-4D8E-B6A4-02F56EF1DC06}" => key removed successfully C:\Windows\System32\Tasks\{B221FAC5-B5C2-4414-AE50-680F251D3579} => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B221FAC5-B5C2-4414-AE50-680F251D3579}" => key removed successfully qrlpsmcl => service not found. "C:\Windows\System32\drivers\jproxcgw.sys" => not found. EagleX64 => service removed successfully HKU\S-1-5-21-1644087666-2204009049-2821983492-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /ve /t REG_SZ /d Bing /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v URL /t REG_SZ /d "http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v DisplayName /t REG_SZ /d "@ieframe.dll,-12512" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Active@ KillDisk 9.2 => moved successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin\Origin Error Reporter.lnk => moved successfully C:\Users\Evenix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shortcut to ShredIt Documentation.lnk => moved successfully C:\Users\Evenix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk => moved successfully C:\Users\Evenix\AppData\Roaming\Microsoft\Word\Katedra304882790885201834\Katedra.docx.lnk => moved successfully =========== "C:\Users\Evenix\Desktop\New folder (6)\New folder (8)\*.lnk" ========== not found ========= End -> "C:\Users\Evenix\Desktop\New folder (6)\New folder (8)\*.lnk" ======== EmptyTemp: => 216.2 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 21:37:11 ====