Fix result of Farbar Recovery Scan Tool (x64) Version:27-01-2016 Ran by Rockfor (2016-02-06 12:34:43) Run:2 Running from C:\Users\Rockfor\Downloads\logi Loaded Profiles: Rockfor (Available Profiles: Rockfor & Guest) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: Task: {00BBB5EE-BE39-48C6-B20D-7C6E65B0CC16} - System32\Tasks\RockforMotetsMinistryV2 => Rundll32.exe BrookedOveranalyzing.dll,main 7 1 <==== ATTENTION Task: {0DB87349-7245-4A18-9B4E-03D395513065} - \Optimize Start Menu Cache Files-S-1-5-21-2412946247-1837993513-3895125520-1001 -> No File <==== ATTENTION Task: {8DC877D7-632E-4F4E-81D9-B28364F24B9B} - System32\Tasks\Plugin Logo => Rundll32.exe "C:\Users\Rockfor\AppData\Local\Plugin Logo\zBin\PluginLogo.dll",#3 <==== ATTENTION Task: {BCC1142A-E663-4F54-94D6-A810059915FF} - \WPD\SqmUpload_S-1-5-21-2412946247-1837993513-3895125520-1001 -> No File <==== ATTENTION Task: {D0964EBB-7367-4CF1-8160-876F30F7949B} - System32\Tasks\AsrKM => C:\Program Files (x86)\ASRock Utility\Key Master\AsrKM.exe S3 AIDA64Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme\kerneld.x64 [X] S3 cpuz138; \??\C:\Users\Rockfor\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\Run: [Fatal1tySTU] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\RunOnce: [AsrOMG_Day0] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\RunOnce: [AsrOMG_Day1] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\RunOnce: [AsrOMG_Day2] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\RunOnce: [AsrOMG_Day3] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\RunOnce: [AsrOMG_Day4] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\RunOnce: [AsrOMG_Day5] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\RunOnce: [AsrOMG_Day6] => [X] HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\MountPoints2: {3bc1d1b6-4922-11e5-826b-faec7023c987} - "H:\setup.exe" HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\...\MountPoints2: {d29070fb-5157-11e5-826c-e77552244ed3} - "E:\Startme.exe" HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy RemoveDirectory: C:\AdwCleaner RemoveDirectory: C:\Users\Rockfor\AppData\Local\MotetsMinistry C:\Users\Rockfor\Desktop\Continue Preferred Filter Tweaker for Windows 7 installation.lnk EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{00BBB5EE-BE39-48C6-B20D-7C6E65B0CC16}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00BBB5EE-BE39-48C6-B20D-7C6E65B0CC16}" => key removed successfully C:\Windows\System32\Tasks\RockforMotetsMinistryV2 => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RockforMotetsMinistryV2" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0DB87349-7245-4A18-9B4E-03D395513065}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0DB87349-7245-4A18-9B4E-03D395513065}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimize Start Menu Cache Files-S-1-5-21-2412946247-1837993513-3895125520-1001" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8DC877D7-632E-4F4E-81D9-B28364F24B9B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8DC877D7-632E-4F4E-81D9-B28364F24B9B}" => key removed successfully C:\Windows\System32\Tasks\Plugin Logo => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plugin Logo" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BCC1142A-E663-4F54-94D6-A810059915FF}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCC1142A-E663-4F54-94D6-A810059915FF}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-2412946247-1837993513-3895125520-1001" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D0964EBB-7367-4CF1-8160-876F30F7949B}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0964EBB-7367-4CF1-8160-876F30F7949B}" => key removed successfully C:\Windows\System32\Tasks\AsrKM => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AsrKM" => key removed successfully AIDA64Driver => service removed successfully cpuz138 => service removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Fatal1tySTU => value removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day0 => value removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day1 => value removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day2 => value removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day3 => value removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day4 => value removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day5 => value removed successfully HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day6 => value removed successfully "HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3bc1d1b6-4922-11e5-826b-faec7023c987}" => key removed successfully HKCR\CLSID\{3bc1d1b6-4922-11e5-826b-faec7023c987} => key not found. "HKU\S-1-5-21-2412946247-1837993513-3895125520-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d29070fb-5157-11e5-826c-e77552244ed3}" => key removed successfully HKCR\CLSID\{d29070fb-5157-11e5-826c-e77552244ed3} => key not found. HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => key removed successfully HKCU\Software\dobreprogramy => key not found. "C:\AdwCleaner" => removed successfully. "C:\Users\Rockfor\AppData\Local\MotetsMinistry" => removed successfully. C:\Users\Rockfor\Desktop\Continue Preferred Filter Tweaker for Windows 7 installation.lnk => moved successfully EmptyTemp: => 779.5 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 12:34:53 ====