Fix result of Farbar Recovery Scan Tool (x64) Version: 20-09-2016 Ran by king (21-09-2016 06:29:48) Run:1 Running from C:\Users\king\Favorites\Desktop Loaded Profiles: king (Available Profiles: king) Boot Mode: Normal ============================================== fixlist content: ***************** start CloseProcesses: CreateRestorePoint: HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-1625786293-3034445564-3463336212-1005\...\Run: [Uhvxmedia] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\king\AppData\Local\UZTmedia\jdkreswm.dll SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = SearchScopes: HKU\S-1-5-21-1625786293-3034445564-3463336212-1005 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Toolbar: HKU\S-1-5-21-1625786293-3034445564-3463336212-1005 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-1625786293-3034445564-3463336212-1005 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File U3 aspnet_state; no ImagePath U0 aswVmm; no ImagePath U3 wpcsvc; no ImagePath C:\Users\king\AppData\Local\Temp\libeay32.dll C:\Users\king\AppData\Local\Temp\msvcr120.dll C:\Users\king\AppData\Local\Temp\ReimagePackage.exe C:\Users\king\AppData\Local\Temp\sqlite3.dll Task: {4446B304-D925-4C9F-A78A-5A222BF84362} - \{5C6C9C26-CFB5-D4D0-C3D5-581E178441BD} -> No File <==== ATTENTION Task: {3B7CD8CF-A7D8-4CC7-8706-0BB36A0A4651} - \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan -> No File <==== ATTENTION Task: {4446B304-D925-4C9F-A78A-5A222BF84362} - \{5C6C9C26-CFB5-D4D0-C3D5-581E178441BD} -> No File <==== ATTENTION Task: {559092ED-7528-444E-B075-1279EDFEF146} - \Opera scheduled Autoupdate 1474196915 -> No File <==== ATTENTION Task: {98F65DA3-01C5-4785-8A16-FA62F3B0DB1E} - \Microsoft\Windows\Windows Defender\Windows Defender Cleanup -> No File <==== ATTENTION Task: {9F017B09-409B-4D18-AC9F-4D006E76CB18} - \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance -> No File <==== ATTENTION Task: {AC4E6F65-9073-44AE-A8AF-639B2D563369} - \Opera_helper -> No File <==== ATTENTION Task: {AFD4A8A3-508B-4785-8271-CDEBAEED3F46} - \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION Task: {CEDB1A65-BE1B-4CBE-A52E-A83CFCF06426} - \Microsoft\Windows\Windows Defender\Windows Defender Verification -> No File <==== ATTENTION Task: {FA625267-66E0-464A-AE95-8754007E78AD} - \Microsoft\Windows\UpdateOrchestrator\Reboot -> No File <==== ATTENTION AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1 [112] AlternateDataStreams: C:\Users\king\Cookies:d0wOdhpneRmBk4tAQngb1d7nO [2090] AlternateDataStreams: C:\Users\king\Cookies:L7zqKFQXY8uUyTLGtpb6nz2 [2336] 2016-09-19 20:00 - 2016-09-19 20:01 - 00604960 _____ (Reimage) C:\Users\king\Downloads\ReimageRepair (1).exe 2016-09-19 19:45 - 2016-09-19 19:48 - 00604928 _____ (Reimage) C:\Users\king\Downloads\ReimageRepair.exe 2016-09-18 19:02 - 2016-09-18 21:55 - 00000000 ____D C:\ProgramData\AVAST Software CMD: bitsadmin /reset /allusers RemoveProxy: Emptytemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully HKU\S-1-5-21-1625786293-3034445564-3463336212-1005\Software\Microsoft\Windows\CurrentVersion\Run\\Uhvxmedia => value removed successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKU\S-1-5-21-1625786293-3034445564-3463336212-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully HKU\S-1-5-21-1625786293-3034445564-3463336212-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value removed successfully HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => key not found. HKU\S-1-5-21-1625786293-3034445564-3463336212-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. aspnet_state => service removed successfully aswVmm => service removed successfully wpcsvc => service removed successfully C:\Users\king\AppData\Local\Temp\libeay32.dll => moved successfully C:\Users\king\AppData\Local\Temp\msvcr120.dll => moved successfully C:\Users\king\AppData\Local\Temp\ReimagePackage.exe => moved successfully C:\Users\king\AppData\Local\Temp\sqlite3.dll => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4446B304-D925-4C9F-A78A-5A222BF84362}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4446B304-D925-4C9F-A78A-5A222BF84362}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5C6C9C26-CFB5-D4D0-C3D5-581E178441BD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3B7CD8CF-A7D8-4CC7-8706-0BB36A0A4651}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B7CD8CF-A7D8-4CC7-8706-0BB36A0A4651}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4446B304-D925-4C9F-A78A-5A222BF84362} => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5C6C9C26-CFB5-D4D0-C3D5-581E178441BD} => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{559092ED-7528-444E-B075-1279EDFEF146}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{559092ED-7528-444E-B075-1279EDFEF146}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1474196915" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{98F65DA3-01C5-4785-8A16-FA62F3B0DB1E}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{98F65DA3-01C5-4785-8A16-FA62F3B0DB1E}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F017B09-409B-4D18-AC9F-4D006E76CB18}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F017B09-409B-4D18-AC9F-4D006E76CB18}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E6F65-9073-44AE-A8AF-639B2D563369}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E6F65-9073-44AE-A8AF-639B2D563369}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera_helper" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AFD4A8A3-508B-4785-8271-CDEBAEED3F46}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AFD4A8A3-508B-4785-8271-CDEBAEED3F46}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEDB1A65-BE1B-4CBE-A52E-A83CFCF06426}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEDB1A65-BE1B-4CBE-A52E-A83CFCF06426}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Verification" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA625267-66E0-464A-AE95-8754007E78AD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA625267-66E0-464A-AE95-8754007E78AD}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot" => key removed successfully C:\ProgramData\TEMP => ":D1B5B4F1" ADS removed successfully. "C:\Users\king\Cookies" => ":d0wOdhpneRmBk4tAQngb1d7nO" ADS not found. "C:\Users\king\Cookies" => ":L7zqKFQXY8uUyTLGtpb6nz2" ADS not found. C:\Users\king\Downloads\ReimageRepair (1).exe => moved successfully C:\Users\king\Downloads\ReimageRepair.exe => moved successfully C:\ProgramData\AVAST Software => moved successfully ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.8.10586 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. Unable to cancel {75146919-829A-408B-AD95-387145814710}. Unable to cancel {4647B5EE-9740-45EF-B79F-73623995432D}. {C42B82B8-5F11-45BE-A409-89AAC08A8F66} canceled. 1 out of 3 jobs canceled. ========= End of CMD: ========= ========= RemoveProxy: ========= HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully HKU\S-1-5-21-1625786293-3034445564-3463336212-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\S-1-5-21-1625786293-3034445564-3463336212-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully ========= End of RemoveProxy: ========= =========== EmptyTemp: ========== BITS transfer queue => 32768 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 287283800 B Java, Flash, Steam htmlcache => 69035259 B Windows/system/drivers => 207583464 B Edge => 24700882 B Chrome => 50984100 B Firefox => 366225172 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 16674 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 128 B LocalService => 107696 B NetworkService => 20363118 B king => 19812620 B RecycleBin => 614930869 B EmptyTemp: => 1.5 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 06:33:38 ====