Fix result of Farbar Recovery Scan Tool (x64) Version:18-04-2016 Ran by user (2016-04-19 12:33:34) Run:2 Running from C:\Users\user\Desktop\av\FRST64 Loaded Profiles: user (Available Profiles: user) Boot Mode: Safe Mode (with Networking) ============================================== fixlist content: ***************** start CreateRestorePoint: BHO: Визуальные закладки -> {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} -> No File BHO-x32: No Name -> {8984B388-A5BB-4DF7-B274-77B879E179DB} -> No File BHO-x32: AlterGeoBHO Class -> {9BFBA68E-E21B-458E-AE12-FE85E903D2C1} -> C:\Program Files (x86)\AlterGeo\AlterGeo Magic Scanner\3.3.2.779\AlterGeo.BrowserPlugin.dll => No File BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll => No File BHO-x32: No Name -> {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} -> No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll No File Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll No File Toolbar: HKU\S-1-5-21-3102738836-3127478194-571303593-1001 -> No Name - {09900DE8-1DCA-443F-9243-26FF581438AF} - No File Toolbar: HKU\S-1-5-21-3102738836-3127478194-571303593-1001 -> Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File 2016-03-31 18:30 - 2016-03-12 19:02 - 00003072 _____ C:\windows\System32\Tasks\MailRuUpdater Task: {7CFDF8A6-FB04-4C8A-A173-AB41741A069F} - \Microsoft\KRBUUS\KRB Updater Utility Service -> No File <==== ATTENTION Task: {F993CCA8-6259-4C1A-82C9-E0CD1A0DCE85} - \Microsoft\KRBUUS\KRBLNKRUN -> No File <==== ATTENTION FirewallRules: [{7951B789-86C7-4A0A-AB05-79E1BEF0CC55}] => (Allow) C:\Users\user\AppData\Local\Temp\F0722_s_30803.exe FirewallRules: [{76F7BD41-4FB6-447F-9ED0-EAFFE0046DBA}] => (Allow) C:\Users\user\AppData\Local\Temp\F0722_s_30803.exe FirewallRules: [{3B8138EF-78B7-4B14-B876-0C0EEE820DBE}] => (Allow) C:\Users\user\AppData\Local\Temp\F0722_s_30803.exe FirewallRules: [{A87B025B-FEB9-46FC-8162-3C093B685F19}] => (Allow) C:\Users\user\AppData\Local\Temp\F0722_s_30803.exe FirewallRules: [{E675EED3-9D5A-4E3B-AB94-BF7F799C9BE5}] => (Allow) C:\Users\user\AppData\Local\Temp\G0722_s_70904.exe FirewallRules: [{4FDCBC57-C998-4F3C-B921-D3D561FA5B51}] => (Allow) C:\Users\user\AppData\Local\Temp\G0722_s_70904.exe FirewallRules: [{F115D377-041E-4421-A471-8EB75A60D63A}] => (Allow) C:\Users\user\AppData\Local\Temp\G0722_s_70904.exe FirewallRules: [{2E862454-C7E8-4AB8-8D27-40248F51EE91}] => (Allow) C:\Users\user\AppData\Local\Temp\G0722_s_70904.exe FirewallRules: [{14EF0AA0-48C7-4CB9-AAB3-766ADFE9EB05}] => (Allow) C:\Users\user\AppData\Local\MediaGet2\mediaget.exe FirewallRules: [{76FC8D0C-FF83-4453-9C41-D13901307B42}] => (Allow) C:\Users\user\AppData\Local\MediaGet2\mediaget.exe FirewallRules: [{C4F058BE-1A81-4F36-A980-248856BBA470}] => (Allow) C:\Program Files\UBar\ubar.exe EmptyTemp: Reboot: end ***************** Error: Restore point can only be created in normal mode. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}" => key removed successfully "HKCR\CLSID\{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8984B388-A5BB-4DF7-B274-77B879E179DB}" => key removed successfully HKCR\Wow6432Node\CLSID\{8984B388-A5BB-4DF7-B274-77B879E179DB} => key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9BFBA68E-E21B-458E-AE12-FE85E903D2C1}" => key removed successfully "HKCR\Wow6432Node\CLSID\{9BFBA68E-E21B-458E-AE12-FE85E903D2C1}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}" => key removed successfully "HKCR\Wow6432Node\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FEC983-01DB-414a-9456-AF95AC9ED7B5}" => key removed successfully HKCR\Wow6432Node\CLSID\{D5FEC983-01DB-414a-9456-AF95AC9ED7B5} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} => value removed successfully "HKCR\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}" => key removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} => value removed successfully "HKCR\Wow6432Node\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}" => key removed successfully HKU\S-1-5-21-3102738836-3127478194-571303593-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{09900DE8-1DCA-443F-9243-26FF581438AF} => value removed successfully HKCR\CLSID\{09900DE8-1DCA-443F-9243-26FF581438AF} => key not found. HKU\S-1-5-21-3102738836-3127478194-571303593-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{91397D20-1446-11D4-8AF4-0040CA1127B6} => value removed successfully "HKCR\CLSID\{91397D20-1446-11D4-8AF4-0040CA1127B6}" => key removed successfully C:\windows\System32\Tasks\MailRuUpdater => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7CFDF8A6-FB04-4C8A-A173-AB41741A069F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7CFDF8A6-FB04-4C8A-A173-AB41741A069F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\KRBUUS\KRB Updater Utility Service" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F993CCA8-6259-4C1A-82C9-E0CD1A0DCE85}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F993CCA8-6259-4C1A-82C9-E0CD1A0DCE85}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\KRBUUS\KRBLNKRUN" => key removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7951B789-86C7-4A0A-AB05-79E1BEF0CC55} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{76F7BD41-4FB6-447F-9ED0-EAFFE0046DBA} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3B8138EF-78B7-4B14-B876-0C0EEE820DBE} => value not found. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A87B025B-FEB9-46FC-8162-3C093B685F19} => value not found. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E675EED3-9D5A-4E3B-AB94-BF7F799C9BE5} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4FDCBC57-C998-4F3C-B921-D3D561FA5B51} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F115D377-041E-4421-A471-8EB75A60D63A} => value not found. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2E862454-C7E8-4AB8-8D27-40248F51EE91} => value not found. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{14EF0AA0-48C7-4CB9-AAB3-766ADFE9EB05} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{76FC8D0C-FF83-4453-9C41-D13901307B42} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C4F058BE-1A81-4F36-A980-248856BBA470} => value removed successfully EmptyTemp: => 2 GB temporary data Removed. The system needed a reboot. ==== End of Fixlog 12:35:52 ====