﻿Fix result of Farbar Recovery Scan Tool (x64) Version:26-07-2015
Ran by Adek at 2015-07-27 21:48:25 Run:1
Running from C:\Users\Adek\Downloads
Loaded Profiles: Adek (Available Profiles: Adek)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CustomCLSID: HKU\S-1-5-21-2164318855-3634255890-2702840794-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Adek\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2164318855-3634255890-2702840794-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Adek\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2164318855-3634255890-2702840794-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Adek\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
Task: {5C8778A9-1A6B-443E-BAEE-71F9151B9BFE} - System32\Tasks\NewsFuse => c:\programdata\{762079c1-f9c0-72cc-7620-079c1f9ce707}\8184932690931218966b.exe <==== ATTENTION
Task: {74DDDC08-A558-48A6-92CF-83AC90174555} - System32\Tasks\DigiMate => c:\programdata\{6c230f52-f2fb-553a-6c23-30f52f2f3d4b}\5208169457076591521b.exe <==== ATTENTION
Task: {CE557B29-8B5F-4724-8D22-66F059CC192C} - System32\Tasks\GameEmu => c:\programdata\{a7f88d7b-567a-ed63-a7f8-88d7b56735ed}\6934224440095694540b.exe <==== ATTENTION
Task: {DB266BAD-8E3D-4DFC-9142-265710521ECC} - System32\Tasks\PowerPad => c:\programdata\{8267d82b-6b8e-dfbe-8267-7d82b6b860ad}\5833746380576312013b.exe <==== ATTENTION
c:\programdata\{8267d82b-6b8e-dfbe-8267-7d82b6b860ad}
c:\programdata\{a7f88d7b-567a-ed63-a7f8-88d7b56735ed}
c:\programdata\{6c230f52-f2fb-553a-6c23-30f52f2f3d4b}
c:\programdata\{6c230f52-f2fb-553a-6c23-30f52f2f3d4b}
c:\programdata\{5912d5b6-63ad-7d0d-5912-2d5b663a56d9}
Task: {02FEF352-38BE-4A5B-A4C8-630403243A05} - System32\Tasks\{6E1291DF-185B-49EC-B9DE-ABB01E2C16AB} => pcalua.exe -a I:\OriginInstaller.exe -d I:\
Task: C:\Windows\Tasks\Bidaily Synchronize Task[973b].job => c:\programdata\{5912d5b6-63ad-7d0d-5912-2d5b663a56d9}\matulewska, matulewski - my logistics; j_zyk angielski dla logistykw PDF.exe <==== ATTENTION
Task: C:\Windows\Tasks\DigiMate.job => c:\programdata\{6c230f52-f2fb-553a-6c23-30f52f2f3d4b}\5208169457076591521b.exe <==== ATTENTION
Task: C:\Windows\Tasks\GameEmu.job => c:\programdata\{a7f88d7b-567a-ed63-a7f8-88d7b56735ed}\6934224440095694540b.exe <==== ATTENTION
Task: C:\Windows\Tasks\NewsFuse.job => c:\programdata\{762079c1-f9c0-72cc-7620-079c1f9ce707}\8184932690931218966b.exe <==== ATTENTION
Task: C:\Windows\Tasks\PowerPad.job => c:\programdata\{8267d82b-6b8e-dfbe-8267-7d82b6b860ad}\5833746380576312013b.exe <==== ATTENTION
c:\windows\temp\tmpjmgkfb.dll
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Browsers Protecto" /f
HKLM-x32\...\Run: [] => [X]
C:\Program Files (x86)\Browsers Protector
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-2164318855-3634255890-2702840794-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
BHO: BeestSAveiFoorYou -> {488BCC4A-A1A9-4341-B6D1-6376273D9523} -> C:\Program Files (x86)\BeestSAveiFoorYou\bG3ZXrS5gNtbBS.x64.dll [2015-07-27] ()
BHO-x32: BeestSAveiFoorYou -> {488BCC4A-A1A9-4341-B6D1-6376273D9523} -> C:\Program Files (x86)\BeestSAveiFoorYou\bG3ZXrS5gNtbBS.dll [2015-07-27] ()
C:\Program Files (x86)\BeestSAveiFoorYou
CHR HKLM-x32\...\Chrome\Extension: [bildoibdboopgomcbiplincneeicgipj] - C:\Program Files (x86)\StartSearch PLUGIN\startsplg.crx [Not Found]
StartMenuInternet: Google Chrome.JJ5VIVEZRUMP5PAWKVRTCNGMFE - C:\Users\Adek\AppData\Local\Google\Chrome\Application\chrome.exe
R2 Jumpy Fall; C:\Program Files (x86)\Jumpy Fall\Jumpy Fall.exe [8016406 2015-07-19] () [File not signed] <==== ATTENTION
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-01-23] ()
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X]
S3 XPADFL02; system32\DRIVERS\xpadfl02.sys [X]
C:\ProgramData\mpijplhgckjoigclehfmfeggpbfekfkn
C:\ProgramData\13491512564692534545
EmptyTemp:
*****************

"HKU\S-1-5-21-2164318855-3634255890-2702840794-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}" => key removed successfully
"HKU\S-1-5-21-2164318855-3634255890-2702840794-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}" => key removed successfully
"HKU\S-1-5-21-2164318855-3634255890-2702840794-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C8778A9-1A6B-443E-BAEE-71F9151B9BFE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C8778A9-1A6B-443E-BAEE-71F9151B9BFE}" => key removed successfully
C:\Windows\System32\Tasks\NewsFuse => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NewsFuse" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{74DDDC08-A558-48A6-92CF-83AC90174555}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74DDDC08-A558-48A6-92CF-83AC90174555}" => key removed successfully
C:\Windows\System32\Tasks\DigiMate => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigiMate" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE557B29-8B5F-4724-8D22-66F059CC192C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE557B29-8B5F-4724-8D22-66F059CC192C}" => key removed successfully
C:\Windows\System32\Tasks\GameEmu => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GameEmu" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB266BAD-8E3D-4DFC-9142-265710521ECC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB266BAD-8E3D-4DFC-9142-265710521ECC}" => key removed successfully
C:\Windows\System32\Tasks\PowerPad => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PowerPad" => key removed successfully
"c:\programdata\{8267d82b-6b8e-dfbe-8267-7d82b6b860ad}" => File/Folder not found.
"c:\programdata\{a7f88d7b-567a-ed63-a7f8-88d7b56735ed}" => File/Folder not found.
"c:\programdata\{6c230f52-f2fb-553a-6c23-30f52f2f3d4b}" => File/Folder not found.
"c:\programdata\{6c230f52-f2fb-553a-6c23-30f52f2f3d4b}" => File/Folder not found.
"c:\programdata\{5912d5b6-63ad-7d0d-5912-2d5b663a56d9}" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02FEF352-38BE-4A5B-A4C8-630403243A05}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02FEF352-38BE-4A5B-A4C8-630403243A05}" => key removed successfully
C:\Windows\System32\Tasks\{6E1291DF-185B-49EC-B9DE-ABB01E2C16AB} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6E1291DF-185B-49EC-B9DE-ABB01E2C16AB}" => key removed successfully
C:\Windows\Tasks\Bidaily Synchronize Task[973b].job => moved successfully.
C:\Windows\Tasks\DigiMate.job => moved successfully.
C:\Windows\Tasks\GameEmu.job => moved successfully.
C:\Windows\Tasks\NewsFuse.job => moved successfully.
C:\Windows\Tasks\PowerPad.job => moved successfully.
c:\windows\temp\tmpjmgkfb.dll => moved successfully.

========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f =========

Operacja ukoäczona pomylnie.


========= End of Reg: =========


========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f =========

Operacja ukoäczona pomylnie.


========= End of Reg: =========


========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f =========

Operacja ukoäczona pomylnie.


========= End of Reg: =========


========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Browsers Protecto" /f =========

Bť¤D: System nie znalaz w rejestrze okrelonego klucza albo wartoci.


========= End of Reg: =========

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"C:\Program Files (x86)\Browsers Protector" => File/Folder not found.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKU\S-1-5-21-2164318855-3634255890-2702840794-1000\SOFTWARE\Policies\Google" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{488BCC4A-A1A9-4341-B6D1-6376273D9523} => key not found. 
"HKCR\CLSID\{488BCC4A-A1A9-4341-B6D1-6376273D9523}" => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{488BCC4A-A1A9-4341-B6D1-6376273D9523} => key not found. 
"HKCR\Wow6432Node\CLSID\{488BCC4A-A1A9-4341-B6D1-6376273D9523}" => key removed successfully
"C:\Program Files (x86)\BeestSAveiFoorYou" => File/Folder not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bildoibdboopgomcbiplincneeicgipj" => key removed successfully
HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => value restored successfully
Jumpy Fall => Service stopped successfully.
Jumpy Fall => service removed successfully
PnkBstrA => Service stopped successfully.
PnkBstrA => service removed successfully
gupdate => service removed successfully
gupdatem => service removed successfully
DgiVecp => service removed successfully
XPADFL02 => service removed successfully
C:\ProgramData\mpijplhgckjoigclehfmfeggpbfekfkn => moved successfully.
C:\ProgramData\13491512564692534545 => moved successfully.
EmptyTemp: => 542.9 MB temporary data Removed.


The system needed a reboot.. 

==== End of Fixlog 21:48:39 ====