Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by Edyta (2016-04-06 19:33:56) Run:1 Running from C:\Users\Edyta\Downloads Loaded Profiles: Edyta (Available Profiles: Edyta & Administrator) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1ADB0VXfVBdFElXTwh0IVdcBEszVEdQNA== HKU\S-1-5-21-4279228227-215742994-1318027649-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1ADB0VXfVBdFElXTwh0IVdcBEszVEdQNA== SearchScopes: HKLM -> DefaultScope {A9A9ECA3-DEA4-482B-AD43-46692B227404} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKLM -> {A9A9ECA3-DEA4-482B-AD43-46692B227404} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> DefaultScope {5B31877C-3856-4258-9A5F-AC0CDA29EF5D} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> OldSearch URL = SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> {5B31877C-3856-4258-9A5F-AC0CDA29EF5D} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTSEcFME0FCFwEURNNfW5ZD10UU3dWMkpM&q={searchTerms} SearchScopes: HKU\S-1-5-21-4279228227-215742994-1318027649-1001 -> {A9A9ECA3-DEA4-482B-AD43-46692B227404} URL = CHR RestoreOnStartup: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA==" CHR StartupUrls: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRghCeQsLUwwSQhgVIgsKTA1IFA0OeAtdABRAFwZCd1paBFhBFQMFIk0FA1oDB0VXfV5bFElXTwh0IVdcBEszVEdQNA==" CHR DefaultSearchURL: Default -> hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfVgBUwpDFFZAbQ9aUwtcFQwWeBQAU1wQDAQVc1gPAlsUQAUXdh9aFQQTQkcFME0FBloEURNNfW5ZD10UU3dWMkpM&q={searchTerms} CHR DefaultSearchKeyword: Default -> searchinterneat-a.akamaihd.net CHR DefaultNewTabURL: Default -> hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHFQacgoKVFoSDANBcgsVVQBEGRgbclxZTAhHElQUI1tdAAlFFxNBNARaAktXUUEeJ1pNER8fHGJCLl1dE3sEU0ZX DeleteKey: HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I DeleteKey: HKCU\Software\dobreprogramy Task: {00983364-EC4D-4640-B6BA-7F2B9679F7A3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {012DBFBE-3003-46A3-AC90-D6E1C31F873D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {08EB5D75-B8B7-431E-909D-FD30D04E62CE} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {2363E481-2A90-4F36-8E61-CE80E8072648} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {26374A49-3B60-4D71-B7A1-5A0CE67744D8} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {3C50A149-FA75-4C0B-B8EE-FC73A9A244BD} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {92C22980-DE9D-41C1-B184-07025C64A105} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {A2A08ECD-4D0B-467B-98F8-011E6E0FA4E5} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {AE668968-11DC-4F1E-B6E1-A99C45ACBDEF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {C0749BAC-A607-43DA-A670-0D614A99E853} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION Task: {DEC0DFB6-7790-4859-A6BC-BE69CE76D148} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION Task: {F6F96355-145B-4D26-A0C8-6B1DE674BB17} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION C:\Program Files (x86)\Mozilla Firefox C:\Program Files (x86)\Wander Burst C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511 C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511 C:\ProgramData\Mozilla C:\Users\Edyta\AppData\Local\Mozilla C:\Users\Edyta\AppData\Roaming\Mozilla C:\Users\Edyta\Desktop\Maciej\EPSON Scan.lnk EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-4279228227-215742994-1318027649-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A9A9ECA3-DEA4-482B-AD43-46692B227404}" => key removed successfully HKCR\CLSID\{A9A9ECA3-DEA4-482B-AD43-46692B227404} => key not found. HKU\S-1-5-21-4279228227-215742994-1318027649-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\S-1-5-21-4279228227-215742994-1318027649-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => key removed successfully HKCR\CLSID\OldSearch => key not found. "HKU\S-1-5-21-4279228227-215742994-1318027649-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5B31877C-3856-4258-9A5F-AC0CDA29EF5D}" => key removed successfully HKCR\CLSID\{5B31877C-3856-4258-9A5F-AC0CDA29EF5D} => key not found. "HKU\S-1-5-21-4279228227-215742994-1318027649-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A9A9ECA3-DEA4-482B-AD43-46692B227404}" => key removed successfully HKCR\CLSID\{A9A9ECA3-DEA4-482B-AD43-46692B227404} => key not found. Chrome RestoreOnStartup => removed successfully Chrome StartupUrls => removed successfully Chrome DefaultSearchURL => removed successfully Chrome DefaultSearchKeyword => removed successfully Chrome DefaultNewTabURL => removed successfully HKCU\Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1I => key not found. HKCU\Software\dobreprogramy => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{00983364-EC4D-4640-B6BA-7F2B9679F7A3}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00983364-EC4D-4640-B6BA-7F2B9679F7A3}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{012DBFBE-3003-46A3-AC90-D6E1C31F873D}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{012DBFBE-3003-46A3-AC90-D6E1C31F873D}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{08EB5D75-B8B7-431E-909D-FD30D04E62CE}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08EB5D75-B8B7-431E-909D-FD30D04E62CE}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2363E481-2A90-4F36-8E61-CE80E8072648}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2363E481-2A90-4F36-8E61-CE80E8072648}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26374A49-3B60-4D71-B7A1-5A0CE67744D8}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26374A49-3B60-4D71-B7A1-5A0CE67744D8}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C50A149-FA75-4C0B-B8EE-FC73A9A244BD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C50A149-FA75-4C0B-B8EE-FC73A9A244BD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{92C22980-DE9D-41C1-B184-07025C64A105}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92C22980-DE9D-41C1-B184-07025C64A105}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A2A08ECD-4D0B-467B-98F8-011E6E0FA4E5}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A2A08ECD-4D0B-467B-98F8-011E6E0FA4E5}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AE668968-11DC-4F1E-B6E1-A99C45ACBDEF}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE668968-11DC-4F1E-B6E1-A99C45ACBDEF}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C0749BAC-A607-43DA-A670-0D614A99E853}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0749BAC-A607-43DA-A670-0D614A99E853}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DEC0DFB6-7790-4859-A6BC-BE69CE76D148}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEC0DFB6-7790-4859-A6BC-BE69CE76D148}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F6F96355-145B-4D26-A0C8-6B1DE674BB17}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6F96355-145B-4D26-A0C8-6B1DE674BB17}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully "C:\Program Files (x86)\Mozilla Firefox" => not found. "C:\Program Files (x86)\Wander Burst" => not found. "C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511" => not found. "C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511" => not found. "C:\ProgramData\Mozilla" => not found. C:\Users\Edyta\AppData\Local\Mozilla => moved successfully C:\Users\Edyta\AppData\Roaming\Mozilla => moved successfully C:\Users\Edyta\Desktop\Maciej\EPSON Scan.lnk => moved successfully EmptyTemp: => 214.4 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 19:35:38 ====