﻿Fix result of Farbar Recovery Scan Tool (x64) Version: 21-05-2015
Ran by Lucie at 2015-05-22 16:20:20 Run:1
Running from C:\Users\Lucie\Desktop
Loaded Profiles: Lucie (Available profiles: Lucie)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM-x32\...\Run: [SSBkgdUpdate] => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [185896 2006-09-28] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [OpwareSE4] => C:\Program Files (x86)\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [75304 2006-10-11] (ScanSoft, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Freecorder FLV Service] => "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
KU\S-1-5-21-1277503925-3455442646-631812523-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Lucie\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Lucie\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2014-12-15] (SUPERAntiSpyware)
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\...\MountPoints2: {0e517619-0ad6-11e1-b778-6431509cb0ab} - I:\setup.exe
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\...\MountPoints2: {9460eddc-c8b9-11e0-85ef-68a3c4cc9759} - D:\AutoRun.exe
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\...\MountPoints2: {9460ee17-c8b9-11e0-85ef-6431509cb0ab} - D:\AutoRun.exe
AppInit_DLLs-x32: c:\progra~2\sn0310~1.boo => "c:\progra~2\sn0310~1.boo" File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012-10-11]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Lucie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk [2013-03-06]
Startup: C:\Users\Lucie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk [2011-10-19]
Startup: C:\Users\Lucie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration The Settlers II - 10th Anniversary.LNK [2011-11-28]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-1277503925-3455442646-631812523-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
URLSearchHook: HKU\S-1-5-21-1277503925-3455442646-631812523-1001 - (No Name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No File
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: No Name -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} ->  No File
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-1277503925-3455442646-631812523-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKU\S-1-5-21-1277503925-3455442646-631812523-1001 -> No Name - {1392B8D2-5C05-419F-A8F6-B9F15A596612} -  No File

FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Extension: ShuOpa  SmaRt - C:\Users\Lucie\AppData\Roaming\Mozilla\Firefox\Profiles\fslm82lg.default\Extensions\gj2m6h4@papatbpldzdhhf.co.uk.xpi [2014-04-29]
FF HKU\S-1-5-21-1277503925-3455442646-631812523-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF Extension: No Name - C:\Users\Lucie\AppData\Roaming\Mozilla\Firefox\Profiles\fslm82lg.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612} [not found]

CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - No Path Or update_url value

S2 funykoqo; C:\Users\Lucie\AppData\Roaming\VOPackage\nsvEF6.tmpfs [X]

C:\Program Files\McAfee Security Scan
U3 arv6lelo; C:\Windows\System32\Drivers\arv6lelo.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]

C:\Program Files (x86)\PANDORA.TV
2015-05-22 15:21 - 2015-05-22 15:21 - 00006420 _____ () C:\Users\Lucie\Desktop\AdwCleaner[S0].zip
2015-05-22 14:50 - 2015-05-22 14:50 - 00032516 _____ () C:\Users\Lucie\Desktop\AdwCleaner[S0].txt
2015-05-22 14:43 - 2015-05-22 14:43 - 02209792 _____ () C:\Users\Lucie\Desktop\adwcleaner_4.204.exe
2015-05-22 14:41 - 2015-05-22 14:47 - 00000000 ____D () C:\AdwCleaner
2015-05-22 14:41 - 2015-05-22 14:41 - 02217984 _____ () C:\Users\Lucie\Desktop\adwcleaner_4.201.exe
2015-05-22 14:14 - 2015-05-22 14:14 - 00029796 _____ () C:\Users\Lucie\Desktop\UsbFix_Report.zip
2015-05-22 14:05 - 2015-05-22 14:09 - 00040050 _____ () C:\Users\Lucie\Desktop\Addition.txt
2015-05-22 14:03 - 2015-05-22 15:45 - 00032931 _____ () C:\Users\Lucie\Desktop\FRST.txt
2015-05-22 14:01 - 2015-05-22 14:01 - 00112640 _____ (forum.viry.cz) C:\Users\Lucie\Desktop\FRSTLauncher (1).exe
2015-05-22 14:00 - 2015-05-22 14:00 - 00109563 _____ () C:\Users\Lucie\Downloads\FRSTLauncher.exe
2015-05-21 20:50 - 2015-05-21 20:49 - 00009152 _____ () C:\Users\Lucie\Desktop\UsbFix_Report.txt
2015-05-21 20:28 - 2015-05-21 20:50 - 00000000 ____D () C:\UsbFix
2015-05-21 20:28 - 2015-05-21 20:28 - 00001448 _____ () C:\Users\Lucie\Desktop\UsbFix.lnk
2015-05-21 20:27 - 2015-05-21 20:28 - 03877164 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\Lucie\Downloads\UsbFix (3).exe
2015-05-21 20:26 - 2015-05-21 20:26 - 03877164 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\Lucie\Downloads\Nepotvrzeno 201993.crdownload
2015-05-21 20:25 - 2015-05-21 20:25 - 03877164 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\Lucie\Downloads\Nepotvrzeno 477105.crdownload
2015-05-21 20:24 - 2015-05-21 20:24 - 03679316 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\Lucie\Downloads\Nepotvrzeno 389143.crdownload
2015-05-21 15:16 - 2015-05-21 15:16 - 00003106 _____ () C:\windows\System32\Tasks\{6AD83B86-FC73-490D-94E3-E44D5E551ABA}
2015-05-19 14:28 - 2015-05-19 14:28 - 00003156 _____ () C:\windows\System32\Tasks\{53B8E719-BAC5-4BC1-8D2D-6F9511DD371D}

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForC02-316B$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\HPCeeScheduleForLucie.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

FirewallRules: [{75611838-6E5D-4A3C-B3CC-E576CA0E17B2}] => (Allow) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
FirewallRules: [{CD5F5A15-B542-4E3B-A377-1822A8F7903A}] => (Allow) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe


Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SSBkgdUpdate => value Deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\OpwareSE4 => value Deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => value Deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Freecorder FLV Service => value Deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value Deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value Deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value Deleted successfully.
KU\S-1-5-21-1277503925-3455442646-631812523-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Lucie\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] () => Error: No automatic fix found for this entry.
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => value Deleted successfully.
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SUPERAntiSpyware => value Deleted successfully.
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Windows\CurrentVersion\Run\\RESTART_STICKY_NOTES => value Deleted successfully.
"HKU\S-1-5-21-1277503925-3455442646-631812523-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e517619-0ad6-11e1-b778-6431509cb0ab}" => Key Deleted successfully.
HKCR\CLSID\{0e517619-0ad6-11e1-b778-6431509cb0ab} => Key not found. 
"HKU\S-1-5-21-1277503925-3455442646-631812523-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9460eddc-c8b9-11e0-85ef-68a3c4cc9759}" => Key Deleted successfully.
HKCR\CLSID\{9460eddc-c8b9-11e0-85ef-68a3c4cc9759} => Key not found. 
"HKU\S-1-5-21-1277503925-3455442646-631812523-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9460ee17-c8b9-11e0-85ef-6431509cb0ab}" => Key Deleted successfully.
HKCR\CLSID\{9460ee17-c8b9-11e0-85ef-6431509cb0ab} => Key not found. 
"c:\progra~2\sn0310~1.boo" => Value Data removed successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk => Moved successfully.
C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe => Moved successfully.
C:\Users\Lucie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk => Moved successfully.
C:\Users\Lucie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk => Moved successfully.
C:\Users\Lucie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration The Settlers II - 10th Anniversary.LNK => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key Deleted successfully.
"HKU\S-1-5-21-1277503925-3455442646-631812523-1001\SOFTWARE\Policies\Google" => Key Deleted successfully.
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{1392b8d2-5c05-419f-a8f6-b9f15a596612} => value Deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}" => Key Deleted successfully.
HKCR\Wow6432Node\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key not found. 
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value Deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value Deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value Deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}" => Key Deleted successfully.
HKCR\Wow6432Node\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value Deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key Deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value Deleted successfully.
HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => Key not found. 
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value Deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found. 
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} => value Deleted successfully.
HKCR\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612} => Key not found. 
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key Deleted successfully.
"HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect" => Key Deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key Deleted successfully.
C:\Users\Lucie\AppData\Roaming\Mozilla\Firefox\Profiles\fslm82lg.default\Extensions\gj2m6h4@papatbpldzdhhf.co.uk.xpi => Moved successfully.
HKU\S-1-5-21-1277503925-3455442646-631812523-1001\Software\Mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8} => value Deleted successfully.
C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => Moved successfully.
C:\Users\Lucie\AppData\Roaming\Mozilla\Firefox\Profiles\fslm82lg.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612} not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk" => Key Deleted successfully.
funykoqo => Service Deleted successfully.
C:\Program Files\McAfee Security Scan => Moved successfully.
arv6lelo => Service Deleted successfully.
Huawei => Service Deleted successfully.
hwdatacard => Service Deleted successfully.
hwusbdev => Service Deleted successfully.
"C:\Program Files (x86)\PANDORA.TV" => File/Directory not found.
C:\Users\Lucie\Desktop\AdwCleaner[S0].zip => Moved successfully.
C:\Users\Lucie\Desktop\AdwCleaner[S0].txt => Moved successfully.
C:\Users\Lucie\Desktop\adwcleaner_4.204.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Lucie\Desktop\adwcleaner_4.201.exe => Moved successfully.
C:\Users\Lucie\Desktop\UsbFix_Report.zip => Moved successfully.
C:\Users\Lucie\Desktop\Addition.txt => Moved successfully.
C:\Users\Lucie\Desktop\FRST.txt => Moved successfully.
C:\Users\Lucie\Desktop\FRSTLauncher (1).exe => Moved successfully.
C:\Users\Lucie\Downloads\FRSTLauncher.exe => Moved successfully.
C:\Users\Lucie\Desktop\UsbFix_Report.txt => Moved successfully.
C:\UsbFix => Moved successfully.
C:\Users\Lucie\Desktop\UsbFix.lnk => Moved successfully.
C:\Users\Lucie\Downloads\UsbFix (3).exe => Moved successfully.
C:\Users\Lucie\Downloads\Nepotvrzeno 201993.crdownload => Moved successfully.
C:\Users\Lucie\Downloads\Nepotvrzeno 477105.crdownload => Moved successfully.
C:\Users\Lucie\Downloads\Nepotvrzeno 389143.crdownload => Moved successfully.
C:\windows\System32\Tasks\{6AD83B86-FC73-490D-94E3-E44D5E551ABA} => Moved successfully.
C:\windows\System32\Tasks\{53B8E719-BAC5-4BC1-8D2D-6F9511DD371D} => Moved successfully.
C:\windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\windows\Tasks\HPCeeScheduleForC02-316B$.job => Moved successfully.
C:\windows\Tasks\HPCeeScheduleForLucie.job => Moved successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{75611838-6E5D-4A3C-B3CC-E576CA0E17B2} => value Deleted successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CD5F5A15-B542-4E3B-A377-1822A8F7903A} => value Deleted successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 5.6 GB temporary data.


The system needed a reboot. 

==== End of Fixlog 16:25:06 ====