Fix result of Farbar Recovery Scan Tool (x64) Version:20-07-2015 Ran by Lloyd at 2015-07-21 13:31:36 Run:1 Running from C:\Users\Lloyd\Downloads Loaded Profiles: Lloyd (Available Profiles: Lloyd) Boot Mode: Normal ============================================== fixlist content: ***************** HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3125439737-3418779363-418148557-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Handler: AutorunsDisabled - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll [2011-02-08] (AVG Technologies CZ, s.r.o.) Handler-x32: AutorunsDisabled - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll [2011-02-08] (AVG Technologies CZ, s.r.o.) FF HKLM-x32\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - C:\Program Files (x86)\AVG\AVG10\Firefox4 FF Extension: AVG Safe Search - C:\Program Files (x86)\AVG\AVG10\Firefox4 [2011-03-30] CHR HKLM-x32\...\Chrome\Extension: [jmfkcklnlgedgbglfkkgedjfmejoahla] - C:\Program Files (x86)\AVG\AVG10\Chrome\safesearch.crx [2011-09-09] 2015-07-08 18:23 - 2015-07-08 18:23 - 00000000 ___HD C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} AV: AVG Anti-Virus Free Edition 2011 (Disabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} AS: AVG Anti-Virus Free Edition 2011 (Disabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} AVG 2011 (Version: 10.0.1434 - AVG Technologies) Hidden FirewallRules: [{7D490D38-C701-4954-A80B-607320021C1F}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe FirewallRules: [{859F2274-5E6D-40BD-A470-393AB8BF55D6}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe FirewallRules: [{C4D44525-BF02-44B0-A3C1-3D4CB76B3E0D}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgdiagex.exe FirewallRules: [{730AF223-2BC3-4B1A-BF1C-071CEF246253}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgdiagex.exe FirewallRules: [{5C0C2130-FFFF-47F4-A124-AB01E7BA1FB8}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgnsa.exe FirewallRules: [{CC4B3BCD-BCA7-407F-ABBB-D0D6849DCEAF}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgnsa.exe FirewallRules: [{E854422F-D26C-4ABF-B942-3DFD52524FF9}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgemca.exe FirewallRules: [{F6AE95A1-9E45-4D78-978F-1B00E5FD5A24}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgemca.exe Task: {3282B8BB-A4BF-469B-B504-E275BF6C1EAD} - System32\Tasks\{718D57E4-E434-4EA1-A0F5-3C46351CB713} => pcalua.exe -a E:\DetectVista.exe -d E:\ Task: {A39EFFB5-254F-4C61-80CD-0AB6C293E55C} - System32\Tasks\{5FE8B9C2-361B-437F-9809-C1F3D7A8D90A} => pcalua.exe -a E:\SETUP.EXE -d E:\ C:\Users\All Users\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} EmptyTemp: ***************** "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully "HKU\S-1-5-21-3125439737-3418779363-418148557-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKCR\PROTOCOLS\Handler\AutorunsDisabled" => key removed successfully "HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}" => key removed successfully HKCR\Wow6432Node\PROTOCOLS\Handler\AutorunsDisabled => key not found. "HKCR\Wow6432Node\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}" => key removed successfully HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4} => value removed successfully C:\Program Files (x86)\AVG\AVG10\Firefox4 => moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla" => key removed successfully C:\Program Files (x86)\AVG\AVG10\Chrome\safesearch.crx => moved successfully. "C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}" folder move: Could not move "C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}" folder => Scheduled to move on reboot. AV: AVG Anti-Virus Free Edition 2011 (Disabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} => The item is protected. Make sure the software is uninstalled and its services is removed. AS: AVG Anti-Virus Free Edition 2011 (Disabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} => The item is protected. Make sure the software is uninstalled and its services is removed. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CCC0CFD7-24B3-4E5A-8863-28769C4BCE54}\\SystemComponent => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7D490D38-C701-4954-A80B-607320021C1F} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{859F2274-5E6D-40BD-A470-393AB8BF55D6} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C4D44525-BF02-44B0-A3C1-3D4CB76B3E0D} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{730AF223-2BC3-4B1A-BF1C-071CEF246253} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5C0C2130-FFFF-47F4-A124-AB01E7BA1FB8} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CC4B3BCD-BCA7-407F-ABBB-D0D6849DCEAF} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E854422F-D26C-4ABF-B942-3DFD52524FF9} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F6AE95A1-9E45-4D78-978F-1B00E5FD5A24} => value removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3282B8BB-A4BF-469B-B504-E275BF6C1EAD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3282B8BB-A4BF-469B-B504-E275BF6C1EAD}" => key removed successfully C:\Windows\System32\Tasks\{718D57E4-E434-4EA1-A0F5-3C46351CB713} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{718D57E4-E434-4EA1-A0F5-3C46351CB713}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A39EFFB5-254F-4C61-80CD-0AB6C293E55C}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A39EFFB5-254F-4C61-80CD-0AB6C293E55C}" => key removed successfully C:\Windows\System32\Tasks\{5FE8B9C2-361B-437F-9809-C1F3D7A8D90A} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5FE8B9C2-361B-437F-9809-C1F3D7A8D90A}" => key removed successfully "C:\Users\All Users\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}" folder move: Could not move "C:\Users\All Users\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}" folder => Scheduled to move on reboot. EmptyTemp: => 815.4 MB temporary data Removed. Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-07-21 13:33:29)<= C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} => Is moved successfully C:\Users\All Users\{9A88E103-A20A-4EA5-8636-C73B709A5BF8} => Is moved successfully ==== End of Fixlog 13:33:29 ====