Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-04-2015 02
Ran by šalomoun at 2015-04-24 16:58:54 Run:3
Running from C:\Users\šalomoun\Desktop
Loaded Profiles: šalomoun (Available profiles: šalomoun & Administrator & Guest)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:
Task: {1AF93DCD-097F-4F12-9083-AAA7B646D112} - System32\Tasks\{D5187969-78CA-4E24-BEB6-B6EB4B8944D7} => pcalua.exe -a "C:\Program Files\InstallShield Installation Information\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}\setup.exe" -c -runfromtemp -l0x0005 -removeonly
Task: {77ECFDCA-1BF7-4AE6-AE52-5B8243C7CB03} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-06-15] ()
C:\Windows\AutoKMS
Task: {5346D01D-93E4-44DA-A62E-34244C3DEFA6} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files\IObit\Game Booster 3\AutoUpdate.exe
C:\Program Files\IObit
Task: {FACF9D81-755A-46E7-81CE-941CF8D7AF32} - \Microsoft\Windows Defender\MP Scheduled Scan No Task File <==== ATTENTION
C:\Windows\Tasks\*.job
HKLM\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-03-30] (LogMeIn Inc.)
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-1830440610-1908763506-3238583907-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-1830440610-1908763506-3238583907-1000\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2012-10-31] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-29] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-29] (Google Inc.)
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
S3 catchme; \??\C:\Users\ALOMOU~1\AppData\Local\Temp\catchme.sys [X]
S1 MpKsl87f5419b; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{23AC6BDE-3662-44B8-B9FD-35012108D678}\MpKsl87f5419b.sys [X]
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1AF93DCD-097F-4F12-9083-AAA7B646D112}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1AF93DCD-097F-4F12-9083-AAA7B646D112}" => Key deleted successfully.
C:\Windows\System32\Tasks\{D5187969-78CA-4E24-BEB6-B6EB4B8944D7} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D5187969-78CA-4E24-BEB6-B6EB4B8944D7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{77ECFDCA-1BF7-4AE6-AE52-5B8243C7CB03}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77ECFDCA-1BF7-4AE6-AE52-5B8243C7CB03}" => Key deleted successfully.
C:\Windows\System32\Tasks\AutoKMS => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => Key deleted successfully.
C:\Windows\AutoKMS => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5346D01D-93E4-44DA-A62E-34244C3DEFA6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5346D01D-93E4-44DA-A62E-34244C3DEFA6}" => Key deleted successfully.
C:\Windows\System32\Tasks\Game_Booster_AutoUpdate => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Game_Booster_AutoUpdate" => Key deleted successfully.
"C:\Program Files\IObit" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FACF9D81-755A-46E7-81CE-941CF8D7AF32}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FACF9D81-755A-46E7-81CE-941CF8D7AF32}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan" => Key deleted successfully.
C:\Windows\Tasks\*.job => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\LogMeIn Hamachi Ui => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\RestrictRun => value deleted successfully.
"HKU\S-1-5-21-1830440610-1908763506-3238583907-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Search Page => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page => value deleted successfully.
HKU\S-1-5-21-1830440610-1908763506-3238583907-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
"HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0" => Key deleted successfully.
C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll => Moved successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0" => Key deleted successfully.
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) not found.
"HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully.
C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll => Moved successfully.
"HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully.
C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll not found.
C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} => not found.
catchme => Service deleted successfully.
MpKsl87f5419b => Service deleted successfully.
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
Unable to cancel {AE7570CA-01D1-4732-B2C4-65E0CC079AA8}.
Unable to cancel {DB3FFF9C-C6AA-40F0-90DE-82834EB64511}.
0 out of 2 jobs canceled.
========= End of CMD: =========
========= netsh winsock reset catalog =========
Katalog Winsock byl �sp��n� resetov�n.
K dokon�en� resetov�n� je nutn� restartovat po��ta�.
========= End of CMD: =========
EmptyTemp: => Removed 830.7 MB temporary data.
The system needed a reboot.
==== End of Fixlog 16:59:40 ====