Fix result of Farbar Recovery Scan Tool (x64) Version:29-05-2016 02 Ran by Irek (2016-05-31 20:40:37) Run:1 Running from C:\Users\Irek\Desktop\frst Loaded Profiles: Irek (Available Profiles: Irek) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CMD: ipconfig /flushdns S3 DrvAgent64; \??\C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS [X] IE trusted site: HKU\.DEFAULT\...\localhost -> localhost IE trusted site: HKU\.DEFAULT\...\webcompanion.com -> hxxp://webcompanion.com IE trusted site: HKU\S-1-5-21-2779230792-305716697-1430175923-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2779230792-305716697-1430175923-1001\...\webcompanion.com -> hxxp://webcompanion.com Task: {47B44C56-D165-49F5-91FB-EBD84CFE7623} - System32\Tasks\Norton 360\Norton Autofix => C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\SymErr.exe Task: {836ABB64-4959-4FCA-83C2-2A3E97E4D408} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\SymErr.exe Task: {92A3839B-5D2C-4707-84E8-2B652908F0F9} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\SymErr.exe DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton 360 Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "Web Companion" /f C:\Program Files (x86)\Google C:\Program Files (x86)\Mozilla Firefox\plugins C:\Users\Irek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DriverAgent Plus.lnk C:\Windows\System32\Tasks\Norton 360 EmptyTemp: ***************** Processes closed successfully. ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= DrvAgent64 => service removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com" => key removed successfully "HKU\S-1-5-21-2779230792-305716697-1430175923-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost" => key removed successfully "HKU\S-1-5-21-2779230792-305716697-1430175923-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47B44C56-D165-49F5-91FB-EBD84CFE7623}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47B44C56-D165-49F5-91FB-EBD84CFE7623}" => key removed successfully C:\WINDOWS\System32\Tasks\Norton 360\Norton Autofix => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton 360\Norton Autofix" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{836ABB64-4959-4FCA-83C2-2A3E97E4D408}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{836ABB64-4959-4FCA-83C2-2A3E97E4D408}" => key removed successfully C:\WINDOWS\System32\Tasks\Norton 360\Norton Error Analyzer => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton 360\Norton Error Analyzer" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{92A3839B-5D2C-4707-84E8-2B652908F0F9}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92A3839B-5D2C-4707-84E8-2B652908F0F9}" => key removed successfully C:\WINDOWS\System32\Tasks\Norton 360\Norton Error Processor => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton 360\Norton Error Processor" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton 360 => key removed successfully ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run /v "Web Companion" /f ========= Operacja ukonczona pomyslnie. ========= End of Reg: ========= C:\Program Files (x86)\Google => moved successfully C:\Program Files (x86)\Mozilla Firefox\plugins => moved successfully C:\Users\Irek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DriverAgent Plus.lnk => moved successfully C:\Windows\System32\Tasks\Norton 360 => moved successfully EmptyTemp: => 27.9 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 20:40:44 ====