Fix result of Farbar Recovery Scan Tool (x64) Version: 05-02-2017 Ran by boissei (08-02-2017 23:59:04) Run:1 Running from C:\Users\boissei\Downloads Loaded Profiles: boissei (Available Profiles: defaultuser0 & boissei) Boot Mode: Normal ============================================== fixlist content: ***************** HKU\S-1-5-21-3546805371-3866020912-3027837689-1001\...\Run: [Uwwvmedia] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\boissei\AppData\Local\Egjztion\sbxdupws.dll HKU\S-1-5-21-3546805371-3866020912-3027837689-1001\...\Policies\Explorer: [] HKU\S-1-5-18\...\Run: [] => 0 HKU\S-1-5-18\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\OEM\OSD\OSD.exe [146432 2016-02-25] (OEM) ShellExecuteHooks: No Name - {B7F52870-EABC-11E6-A3B1-64006A5CFC23} - C:\Users\boissei\AppData\Roaming\Valrythujaent\Faoing.dll -> No File ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => -> No File CustomCLSID: HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{FE186CB0-BEDC-11D5-9B1D-0050DA438716}\localserver32 -> "C:\Program Files\EPLAN\Platform\2.6.3\Bin\Eplan.exe" => No File ShellExecuteHooks: No Name - {B7F52870-EABC-11E6-A3B1-64006A5CFC23} - C:\Users\boissei\AppData\Roaming\Valrythujaent\Faoing.dll -> No File ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => -> No File CustomCLSID: HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\boissei\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell64.dll => No Fil (the data entry has 1 more characters). CustomCLSID: HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\boissei\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell64.dll => No Fil (the data entry has 1 more characters). CustomCLSID: HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\boissei\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell64.dll => No Fil (the data entry has 1 more characters). CustomCLSID: HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{FE186CB0-BEDC-11D5-9B1D-0050DA438716}\localserver32 -> "C:\Program Files\EPLAN\Platform\2.6.3\Bin\Eplan.exe" => No File GroupPolicy: Restriction <======= ATTENTION R3 cpuz140; C:\Users\boissei\AppData\Local\Temp\cpuz140\cpuz140_x64.sys [45888 2017-02-08] (CPUID) <==== ATTENTION S1 ucdrv; \??\C:\Program Files (x86)\UCBrowser\Security:ucdrv-x64.sys [X] <==== ATTENTION Ace Stream Media 3.1.15 (HKU\S-1-5-21-3546805371-3866020912-3027837689-1001\...\AceStream) (Version: 3.1.15 - Ace Stream Media) <==== ATTENTION Task: {24D5AB01-67DF-44D5-9DC8-0BCA0B53B6F3} - System32\Tasks\UCBrowserUpdater => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION Task: {2B313D79-0395-41B9-B17B-55C067611E4D} - System32\Tasks\UCBrowserSecureUpdater => C:\Program Files (x86)\UCBrowser\Security\uclauncher.exe <==== ATTENTION Task: {FCB2658B-4315-4722-A000-02CBFCF96229} - System32\Tasks\UCBrowserUpdaterCore => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION Task: C:\Windows\Tasks\UCBrowserUpdater.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION Task: C:\Windows\Tasks\UCBrowserUpdaterCore.job => C:\Program Files (x86)\UCBrowser\Application\update_task.exe <==== ATTENTION WMI_ActiveScriptEventConsumer_ASEC: <===== ATTENTION R3 cpuz140; C:\Users\boissei\AppData\Local\Temp\cpuz140\cpuz140_x64.sys [45888 2017-02-08] (CPUID) <==== ATTENTION 2017-01-16 14:45 - 2016-09-15 19:03 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TempSignedLicenseExchangeTask.dll 2017-01-16 01:58 - 2017-01-16 01:58 - 00000000 ___HD C:\Program Files (x86)\Temp 2017-01-27 12:14 - 2016-07-16 13:36 - 00000000 ____D C:\Windows\CbsTemp 2017-01-15 11:47 - 2016-07-16 13:47 - 00028672 _____ C:\Windows\system32\config\BCD-Template CMD: Bitsadmin /Reset /Allusers EMPTYTEMP: ***************** HKU\S-1-5-21-3546805371-3866020912-3027837689-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Uwwvmedia => value removed successfully HKU\S-1-5-21-3546805371-3866020912-3027837689-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value removed successfully HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #0 => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{B7F52870-EABC-11E6-A3B1-64006A5CFC23} => value removed successfully HKCR\CLSID\{B7F52870-EABC-11E6-A3B1-64006A5CFC23} => key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\KzShlobj => key removed successfully HKCR\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => key not found. HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{FE186CB0-BEDC-11D5-9B1D-0050DA438716} => key removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{B7F52870-EABC-11E6-A3B1-64006A5CFC23} => value not found. HKCR\CLSID\{B7F52870-EABC-11E6-A3B1-64006A5CFC23} => key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\KzShlobj => key not found. HKCR\CLSID\{AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => key not found. HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => key removed successfully HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => key removed successfully HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => key removed successfully HKU\S-1-5-21-3546805371-3866020912-3027837689-1001_Classes\CLSID\{FE186CB0-BEDC-11D5-9B1D-0050DA438716} => key not found. C:\Windows\system32\GroupPolicy\Machine => moved successfully C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully cpuz140 => Unable to stop service. HKLM\System\CurrentControlSet\Services\cpuz140 => key removed successfully cpuz140 => service removed successfully ucdrv => service not found. Ace Stream Media 3.1.15 (HKU\S-1-5-21-3546805371-3866020912-3027837689-1001\...\AceStream) (Version: 3.1.15 - Ace Stream Media) <==== ATTENTION => Error: No automatic fix found for this entry. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24D5AB01-67DF-44D5-9DC8-0BCA0B53B6F3} => key not found. C:\Windows\System32\Tasks\UCBrowserUpdater => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserUpdater => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B313D79-0395-41B9-B17B-55C067611E4D} => key not found. C:\Windows\System32\Tasks\UCBrowserSecureUpdater => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserSecureUpdater => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCB2658B-4315-4722-A000-02CBFCF96229} => key not found. C:\Windows\System32\Tasks\UCBrowserUpdaterCore => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UCBrowserUpdaterCore => key not found. C:\Windows\Tasks\UCBrowserUpdater.job => not found. C:\Windows\Tasks\UCBrowserUpdaterCore.job => not found. WMI_ActiveScriptEventConsumer_ASEC: <===== ATTENTION => removed successfully cpuz140 => service not found. C:\Windows\SysWOW64\TempSignedLicenseExchangeTask.dll => moved successfully C:\Program Files (x86)\Temp => moved successfully C:\Windows\CbsTemp => moved successfully C:\Windows\system32\config\BCD-Template => moved successfully ========= Bitsadmin /Reset /Allusers ========= BITSADMIN version 3.0 BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. {6A6F8DEF-7C7A-4833-9E32-79F85D37F5BC} canceled. 1 out of 1 jobs canceled. ========= End of CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 32768 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12668878 B Java, Flash, Steam htmlcache => 492 B Windows/system/drivers => -6882256 B Edge => 1468271 B Chrome => 0 B Firefox => 0 B Opera => 480351561 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 0 B LocalService => 0 B NetworkService => -658 B defaultuser0 => 128 B boissei => 12111671 B RecycleBin => 0 B EmptyTemp: => 476.6 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 23:59:15 ====