Fix result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by Jožin (2017-01-16 21:42:01) Run:1
Running from C:\Users\Jožin\Downloads
Loaded Profiles: Jožin (Available Profiles: Jožin)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
HKLM-x32\...\Run: [TaskTray] => [X]
HKU\S-1-5-21-3695787775-2199685802-2270573759-1001\...\Run: [] => [X]
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
SearchScopes: HKU\S-1-5-21-3695787775-2199685802-2270573759-1001 -> {C3BBCD0B-9234-4d36-9151-EC49EE32FCE3} URL = hxxp://
www.baidu.com/s?wd={searchTerms}&tn=280 ... g&ie=utf-8
S2 MLPTDR_Q; \??\C:\WINDOWS\system32\ [0 ] () <==== ATTENTION (zero byte File/Folder)
S2 MLPTDR_Q; \??\C:\WINDOWS\SysWOW64\ [0 ] () <==== ATTENTION (zero byte File/Folder)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\System32\Tasks\270051v3a62h24
C:\Users\Jožin\Downloads\Gw2Setup-64.tmp
C:\Users\Jožin\Downloads\Gw2.tmp
C:\ProgramData\AutoKMS
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3695787775-2199685802-2270573759-1001UA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3695787775-2199685802-2270573759-1001Core
C:\Users\Jožin\AppData\Local\Temp
Task: {18568618-1602-4C22-B187-ADD8B1426DE4} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {230A7B43-5BE5-4280-B4EC-5A396DEE4FE0} - \Microsoft\Windows\Setup\GWXTriggers\Logon-URT -> No File <==== ATTENTION
Task: {2B255218-3894-4EA4-8CBC-54A1250E6384} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {3EB76D62-AC9E-40D3-99E8-DBDEF1993EF2} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {5DA3774E-9AB8-4942-981A-834D171B697B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {88475055-51BE-4A33-8040-91F00EE0EFF7} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe
Task: {8E03D9E7-FF6F-453A-80FD-D04F540EFD53} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
C:\Windows\AutoKMS.exe
Task: {9268EA3E-8B80-43A4-A653-4AD925A2765A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B0A9C29C-EF03-4C1E-BB51-66E1FFF8D153} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {C0103F76-FE8A-4D3C-AC96-269561BF2F99} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {C4223E00-9121-49A5-AC5D-DCA044A1A249} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {EFE804FC-EBE2-4646-A54D-074CC22FB914} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
C:\WINDOWS\TEMP\gB5B2.tmp.exe
C:\WINDOWS\TEMP\g66C7.tmp
AlternateDataStreams: C:\Program Files\Barvy:Win32App_1
AlternateDataStreams: C:\Program Files\Bonjour:Win32App_1
AlternateDataStreams: C:\Program Files\CCleaner:Win32App_1
AlternateDataStreams: C:\Program Files\DigitalPersona:Win32App_1
AlternateDataStreams: C:\Program Files\Hewlett-Packard:Win32App_1
AlternateDataStreams: C:\Program Files\IDT:Win32App_1
AlternateDataStreams: C:\Program Files\iTunes:Win32App_1
AlternateDataStreams: C:\Program Files\JabRef:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Office:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App_1
AlternateDataStreams: C:\Program Files\PlayReady:Win32App_1
AlternateDataStreams: C:\Program Files\SmartFTP Client:Win32App_1
AlternateDataStreams: C:\Program Files\Validity Sensors, Inc:Win32App_1
AlternateDataStreams: C:\Program Files\WinHTTrack:Win32App_1
AlternateDataStreams: C:\Program Files\WinRAR:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Adobe:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Audacity:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\AVerMedia:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Bonjour:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\DigitalPersona:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Freemake:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Intel Driver Update Utility:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Lame For Audacity:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\LAV Filters:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Malware:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft Expression:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft Visual Studio 8:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\MSBuild:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Recovery Toolbox for Word:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Stellar Phoenix Word Repair:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\TeamViewer:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\DESIGNER:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App_1
AlternateDataStreams: C:\ProgramData\Nero:Win32App_1
AlternateDataStreams: C:\ProgramData\regid.2006-08.com.smartftp:Win32App_1
AlternateDataStreams: C:\ProgramData\Temp:810B9F0D
AlternateDataStreams: C:\ProgramData\Temp:9A78FF1A
AlternateDataStreams: C:\Users\Jožin\AppData\Local\Degoo:Win32App_1
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\TaskTray => value removed successfully
HKU\S-1-5-21-3695787775-2199685802-2270573759-1001\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
"HKU\S-1-5-21-3695787775-2199685802-2270573759-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C3BBCD0B-9234-4d36-9151-EC49EE32FCE3}" => key removed successfully
HKCR\CLSID\{C3BBCD0B-9234-4d36-9151-EC49EE32FCE3} => key not found.
MLPTDR_Q => service removed successfully
MLPTDR_Q => service not found.
idsvc => service removed successfully
wpcsvc => service removed successfully
C:\WINDOWS\System32\Tasks\270051v3a62h24 => moved successfully
C:\Users\Jožin\Downloads\Gw2Setup-64.tmp => moved successfully
C:\Users\Jožin\Downloads\Gw2.tmp => moved successfully
C:\ProgramData\AutoKMS => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3695787775-2199685802-2270573759-1001UA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3695787775-2199685802-2270573759-1001Core => moved successfully
"C:\Users\Jožin\AppData\Local\Temp" folder move:
Could not move "C:\Users\Jožin\AppData\Local\Temp" => Scheduled to move on reboot.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{18568618-1602-4C22-B187-ADD8B1426DE4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18568618-1602-4C22-B187-ADD8B1426DE4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{230A7B43-5BE5-4280-B4EC-5A396DEE4FE0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{230A7B43-5BE5-4280-B4EC-5A396DEE4FE0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-URT" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2B255218-3894-4EA4-8CBC-54A1250E6384}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B255218-3894-4EA4-8CBC-54A1250E6384}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3EB76D62-AC9E-40D3-99E8-DBDEF1993EF2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3EB76D62-AC9E-40D3-99E8-DBDEF1993EF2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5DA3774E-9AB8-4942-981A-834D171B697B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5DA3774E-9AB8-4942-981A-834D171B697B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{88475055-51BE-4A33-8040-91F00EE0EFF7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88475055-51BE-4A33-8040-91F00EE0EFF7}" => key removed successfully
C:\WINDOWS\System32\Tasks\AutoKMS => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8E03D9E7-FF6F-453A-80FD-D04F540EFD53}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E03D9E7-FF6F-453A-80FD-D04F540EFD53}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"C:\Windows\AutoKMS.exe" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9268EA3E-8B80-43A4-A653-4AD925A2765A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9268EA3E-8B80-43A4-A653-4AD925A2765A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B0A9C29C-EF03-4C1E-BB51-66E1FFF8D153}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0A9C29C-EF03-4C1E-BB51-66E1FFF8D153}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C0103F76-FE8A-4D3C-AC96-269561BF2F99}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0103F76-FE8A-4D3C-AC96-269561BF2F99}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4223E00-9121-49A5-AC5D-DCA044A1A249}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4223E00-9121-49A5-AC5D-DCA044A1A249}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EFE804FC-EBE2-4646-A54D-074CC22FB914}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFE804FC-EBE2-4646-A54D-074CC22FB914}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"C:\WINDOWS\TEMP\gB5B2.tmp.exe" => File/Folder not found.
"C:\WINDOWS\TEMP\g66C7.tmp" => File/Folder not found.
C:\Program Files\Barvy => ":Win32App_1" ADS removed successfully.
C:\Program Files\Bonjour => ":Win32App_1" ADS removed successfully.
C:\Program Files\CCleaner => ":Win32App_1" ADS removed successfully.
C:\Program Files\DigitalPersona => ":Win32App_1" ADS removed successfully.
C:\Program Files\Hewlett-Packard => ":Win32App_1" ADS removed successfully.
C:\Program Files\IDT => ":Win32App_1" ADS removed successfully.
C:\Program Files\iTunes => ":Win32App_1" ADS removed successfully.
C:\Program Files\JabRef => ":Win32App_1" ADS removed successfully.
C:\Program Files\Microsoft Office => ":Win32App_1" ADS removed successfully.
C:\Program Files\Microsoft Silverlight => ":Win32App_1" ADS removed successfully.
C:\Program Files\PlayReady => ":Win32App_1" ADS removed successfully.
C:\Program Files\SmartFTP Client => ":Win32App_1" ADS removed successfully.
C:\Program Files\Validity Sensors, Inc => ":Win32App_1" ADS removed successfully.
C:\Program Files\WinHTTrack => ":Win32App_1" ADS removed successfully.
C:\Program Files\WinRAR => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Adobe => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Apple Software Update => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Audacity => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\AVerMedia => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Bonjour => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\DigitalPersona => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Freemake => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Intel Driver Update Utility => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Lame For Audacity => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\LAV Filters => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Malwarebytes Anti-Malware => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Microsoft Expression => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Microsoft Visual Studio 8 => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\MSBuild => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\QuickTime => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Recovery Toolbox for Word => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Stellar Phoenix Word Repair => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\TeamViewer => ":Win32App_1" ADS removed successfully.
C:\Program Files\Common Files\DESIGNER => ":Win32App_1" ADS removed successfully.
C:\Program Files\Common Files\microsoft shared => ":Win32App_1" ADS removed successfully.
C:\ProgramData\Nero => ":Win32App_1" ADS removed successfully.
C:\ProgramData\regid.2006-08.com.smartftp => ":Win32App_1" ADS removed successfully.
C:\ProgramData\Temp => ":810B9F0D" ADS removed successfully.
C:\ProgramData\Temp => ":9A78FF1A" ADS removed successfully.
C:\Users\Jožin\AppData\Local\Degoo => ":Win32App_1" ADS removed successfully.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2017-01-16 22:21:29)
C:\Users\Jožin\AppData\Local\Temp => moved successfully
==== End of Fixlog 22:21:31 ====