
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-01-2015
Ran by acer at 2015-01-20 22:04:13 Run:1
Running from C:\Users\acer\Downloads
Loaded Profiles: acer (Available profiles: acer)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [825864 2009-09-24] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3265205095-3385449152-526931692-1000\...\MountPoints2: {5173c07c-1bce-11e3-b501-60eb692dc10c} - F:\HTC_Sync_Manager_PC.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
R2 ujopqrpsggkjpn; c:\windows\SysWOW64\ztpfzeq.exe [76800 2014-05-15] (LIMITED) [File not signed]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
2015-01-20 20:02 - 2015-01-20 20:03 - 00012278 _____ () C:\Users\acer\Downloads\FRST.txt
2015-01-20 19:59 - 2015-01-20 19:59 - 01118208 _____ (Farbar) C:\Users\acer\Downloads\FRST.exe
2015-01-20 19:37 - 2015-01-20 19:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2015-01-20 19:18 - 2015-01-20 19:39 - 00012605 _____ () C:\zoek-results.log
2015-01-20 19:17 - 2015-01-20 19:33 - 00000000 ____D () C:\zoek_backup
2015-01-20 19:13 - 2015-01-20 19:38 - 00000868 _____ () C:\Windows\PFRO.log
2015-01-20 19:11 - 2015-01-20 19:11 - 01295360 _____ () C:\Users\acer\Downloads\zoek.exe
2015-01-20 19:09 - 2015-01-20 19:12 - 00000000 ____D () C:\AdwCleaner
2015-01-20 19:09 - 2015-01-20 19:09 - 02186752 _____ () C:\Users\acer\Downloads\adwcleaner_4.108.exe
2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\rsit
2015-01-20 18:20 - 2015-01-20 18:20 - 00000000 ____D () C:\Program Files (x86)\trend micro
2015-01-20 18:19 - 2015-01-20 18:19 - 01107968 _____ () C:\Users\acer\Downloads\RSIT.exe
2015-01-20 16:48 - 2015-01-20 16:49 - 05317104 _____ (Piriform Ltd) C:\Users\acer\Downloads\ccsetup501.exe
Task: {0755206E-2304-45DD-94B9-A927D1AE024F} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION
Task: {173E6FE9-9AB0-427A-BB61-0315465F5462} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:8927A071
AlternateDataStreams: C:\ProgramData\TEMP:93EB7685
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LManager => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully.
"HKU\S-1-5-21-3265205095-3385449152-526931692-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5173c07c-1bce-11e3-b501-60eb692dc10c}" => Key deleted successfully.
HKCR\CLSID\{5173c07c-1bce-11e3-b501-60eb692dc10c} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => Key deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => Moved successfully.
ujopqrpsggkjpn => Unable to stop service
ujopqrpsggkjpn => Service deleted successfully.
RtsUIR => Service deleted successfully.
USBCCID => Service deleted successfully.
C:\Users\acer\Downloads\FRST.txt => Moved successfully.
C:\Users\acer\Downloads\FRST.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Users\acer\Downloads\zoek.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\acer\Downloads\adwcleaner_4.108.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files (x86)\trend micro => Moved successfully.
C:\Users\acer\Downloads\RSIT.exe => Moved successfully.
C:\Users\acer\Downloads\ccsetup501.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{0755206E-2304-45DD-94B9-A927D1AE024F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0755206E-2304-45DD-94B9-A927D1AE024F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{173E6FE9-9AB0-427A-BB61-0315465F5462}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{173E6FE9-9AB0-427A-BB61-0315465F5462}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate" => Key deleted successfully.
C:\ProgramData\TEMP => ":8927A071" ADS removed successfully.
C:\ProgramData\TEMP => ":93EB7685" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 40.5 MB temporary data.
The system needed a reboot.
==== End of Fixlog 22:04:24 ====