Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-11-2014 Ran by monika at 2014-11-21 17:52:37 Run:3 Running from C:\Users\monika\Desktop Loaded Profile: monika (Available profiles: monika) Boot Mode: Normal ============================================== Content of fixlist: ***************** start C:\Windows\System32\mfevtps.exe C:\FRST\Quarantine\C\Program Files\Common Files\mcafee\AMCore\mcshield.exe.xBAD C:\FRST\Quarantine\C\Program Files\Common Files\mcafee\systemcore\mfefire.exe.xBAD C:\FRST\Quarantine\C\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe.xBAD SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2229077904-2083171248-1993139908-1001 -> DefaultScope {5114F51F-7F0E-4E0A-A14C-66EAA2E3D6AA} URL = SearchScopes: HKU\S-1-5-21-2229077904-2083171248-1993139908-1001 -> {5114F51F-7F0E-4E0A-A14C-66EAA2E3D6AA} URL = FF SearchPlugin: C:\Users\monika\AppData\Roaming\Mozilla\Firefox\Profiles\8y4attb6.default\searchplugins\babylon.xml S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.) R2 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] U2 McNaiAnn; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] R2 mcpltsvc; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] R2 McProxy; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [X] R2 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [X] R2 MSK80Service; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.) R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.) S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => McAfee HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp 2014-11-21 16:37 - 2014-03-06 08:42 - 00000000 ____D () C:\ProgramData\McAfee 2014-11-20 13:39 - 2014-03-06 08:42 - 00000000 ____D () C:\Program Files\mcafee 2014-11-17 19:58 - 2014-03-06 08:42 - 00000000 ____D () C:\Program Files\Common Files\mcafee AV: McAfee Anti-Virus et Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} AS: McAfee Anti-Virus et Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} FW: Pare-feu McAfee (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} end ***************** C:\Windows\System32\mfevtps.exe => Moved successfully. C:\FRST\Quarantine\C\Program Files\Common Files\mcafee\AMCore\mcshield.exe.xBAD => Moved successfully. C:\FRST\Quarantine\C\Program Files\Common Files\mcafee\systemcore\mfefire.exe.xBAD => Moved successfully. C:\FRST\Quarantine\C\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe.xBAD => Moved successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. HKU\S-1-5-21-2229077904-2083171248-1993139908-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-2229077904-2083171248-1993139908-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5114F51F-7F0E-4E0A-A14C-66EAA2E3D6AA}" => Key deleted successfully. "HKCR\CLSID\{5114F51F-7F0E-4E0A-A14C-66EAA2E3D6AA}" => Key not found. C:\Users\monika\AppData\Roaming\Mozilla\Firefox\Profiles\8y4attb6.default\searchplugins\babylon.xml => Moved successfully. McODS => Service deleted successfully. mfevtp => Unable to stop service mfevtp => Service deleted successfully. McMPFSvc => Unable to stop service McMPFSvc => Service deleted successfully. McNaiAnn => Service deleted successfully. mcpltsvc => Unable to stop service mcpltsvc => Service deleted successfully. McProxy => Unable to stop service McProxy => Service deleted successfully. mfecore => Unable to stop service mfecore => Service deleted successfully. mfefire => Unable to stop service mfefire => Service deleted successfully. MSK80Service => Unable to stop service MSK80Service => Service deleted successfully. mfeapfk => Service deleted successfully. mfeavfk => Unable to stop service mfeavfk => Service deleted successfully. mfeelamk => Service deleted successfully. mfefirek => Unable to stop service mfefirek => Service deleted successfully. mfehidk => Unable to stop service mfehidk => Service deleted successfully. mfencbdc => Unable to stop service mfencbdc => Service deleted successfully. mfencrk => Service deleted successfully. mfewfpk => Unable to stop service mfewfpk => Service deleted successfully. "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\MCODS " => Key not found. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => Error: No automatic fix found for this entry. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => Error: No automatic fix found for this entry. "C:\ProgramData\McAfee" directory move: Could not move "C:\ProgramData\McAfee\msk\MSKWMDB.dat" => Scheduled to move on reboot. Could not move "C:\ProgramData\McAfee\msk\SettingsDB.dat" => Scheduled to move on reboot. Could not move "C:\ProgramData\McAfee\msc\McUsers.dat" => Scheduled to move on reboot. Could not move "C:\ProgramData\McAfee\MPS\nomon\sacore\sacore.db" => Scheduled to move on reboot. C:\ProgramData\McAfee\MPF\mpf.dat => Moved successfully. C:\ProgramData\McAfee\MPF\mpf.dat.TMP => Moved successfully. C:\ProgramData\McAfee\MCLOGS\PLATFORM\McSvHost\McSvHost000.log => Moved successfully. C:\ProgramData\McAfee\MCLOGS\PLATFORM\mcagent\mcagent000.log => Moved successfully. C:\ProgramData\McAfee\MCLOGS\MISP\OOBESVC\McSvHost\McSvHost000.log => Moved successfully. C:\ProgramData\McAfee\MCLOGS\MISP\McSvHost\McSvHost000.log => Moved successfully. Could not move "C:\ProgramData\McAfee" directory. => Scheduled to move on reboot. C:\Program Files\mcafee => Moved successfully. "C:\Program Files\Common Files\mcafee" directory move: Could not move "C:\Program Files\Common Files\mcafee\AMCore\EM\EMSystemWideDataStore_00.PTF" => Scheduled to move on reboot. C:\Program Files\Common Files\mcafee\AMContent\content\avengine\min\7625.0\minclean.dat => Moved successfully. C:\Program Files\Common Files\mcafee\AMContent\content\avengine\min\7625.0\minnames.dat => Moved successfully. C:\Program Files\Common Files\mcafee\AMContent\content\avengine\min\7625.0\minscan.dat => Moved successfully. C:\Program Files\Common Files\mcafee\AMContent\content\amcore\content\1.13.186.1\amcontent.dat => Moved successfully. C:\Program Files\Common Files\mcafee\AMContent\content\amcore\contain\1044.0\amcontain.dat => Moved successfully. Could not move "C:\Program Files\Common Files\mcafee" directory. => Scheduled to move on reboot. AV: McAfee Anti-Virus et Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892} => The item is protected. Make sure the software is uninstalled and its services is removed. AS: McAfee Anti-Virus et Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F} => The item is protected. Make sure the software is uninstalled and its services is removed. FW: Pare-feu McAfee (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9} => The item is protected. Make sure the software is uninstalled and its services is removed. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-11-21 17:57:06)<= C:\ProgramData\McAfee\msk\MSKWMDB.dat => Is moved successfully. C:\ProgramData\McAfee\msk\SettingsDB.dat => Is moved successfully. C:\ProgramData\McAfee\msc\McUsers.dat => Is moved successfully. C:\ProgramData\McAfee\MPS\nomon\sacore\sacore.db => Is moved successfully. C:\ProgramData\McAfee => Is moved successfully. C:\Program Files\Common Files\mcafee\AMCore\EM\EMSystemWideDataStore_00.PTF => Is moved successfully. C:\Program Files\Common Files\mcafee => Is moved successfully. ==== End of Fixlog ====