Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 Ran by Furjan at 2015-06-28 19:58:24 Run:1 Running from C:\Users\Furjan\Desktop Loaded Profiles: Furjan (Available Profiles: Furjan & Emin) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: HKU\S-1-5-21-573338958-1469082045-40625102-1002\...\CurrentVersion\Windows: [Load] C:\ProgramData\msxzzrri.exe <===== ATTENTION R2 VSSS; C:\Users\Furjan\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [101288384 2015-06-26] (Microsoft Corporation) [File not signed] <==== ATTENTION R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X] Task: {5C1397E1-9015-4D19-9E2F-5DEDCB456D92} - \Optimize Start Menu Cache Files-S-1-5-21-4286360323-2242589127-2825418434-1001 No Task File <==== ATTENTION Task: {7572B40E-2997-4837-8013-19C3FA85DCB3} - \WPD\SqmUpload_S-1-5-21-4286360323-2242589127-2825418434-1001 No Task File <==== ATTENTION C:\ProgramData\msxzzrri.exe C:\Users\Furjan\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe C:\Program Files\kprocesshacker.sys RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Error: (0) Failed to create a restore point. HKU\S-1-5-21-573338958-1469082045-40625102-1002\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => value restored successfully VSSS => Unable to stop service. VSSS => Service removed successfully KProcessHacker2 => Unable to stop service. KProcessHacker2 => Service removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C1397E1-9015-4D19-9E2F-5DEDCB456D92}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C1397E1-9015-4D19-9E2F-5DEDCB456D92}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimize Start Menu Cache Files-S-1-5-21-4286360323-2242589127-2825418434-1001" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7572B40E-2997-4837-8013-19C3FA85DCB3}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7572B40E-2997-4837-8013-19C3FA85DCB3}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-4286360323-2242589127-2825418434-1001" => key removed successfully Could not move "C:\ProgramData\msxzzrri.exe" => Scheduled to move on reboot. C:\Users\Furjan\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe => moved successfully. "C:\Program Files\kprocesshacker.sys" => File/Folder not found. ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully HKU\S-1-5-21-573338958-1469082045-40625102-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\S-1-5-21-573338958-1469082045-40625102-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully ========= End of RemoveProxy: ========= ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.7.9600 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. 0 out of 0 jobs canceled. ========= End of CMD: ========= EmptyTemp: => 437.7 MB temporary data Removed. Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-06-28 20:01:22)<= C:\ProgramData\msxzzrri.exe => Is moved successfully ==== End of Fixlog 20:01:22 ====