Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-11-2014 Ran by SYSTEM at 2014-11-11 21:23:12 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** SubSystems: [Windows] ATTENTION! ====> ZeroAccess DeleteJunctionsIndirectory: C:\Windows\system64 HKLM-x32\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [vProt] => "C:\Program Files (x86)\AVG Secure Search\vprot.exe" HKLM-x32\...\Run: [AVG_UI] => "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY HKU\Gregor\...\Run: [AdobeBridge] => [X] HKU\Gregor\...\Run: [Urenqaagny] => C:\Users\Gregor\AppData\Roaming\Ucef\doyhz.exe S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [1820184 2014-08-12] (AVG Secure Search) S2 avgfws; "C:\Program Files (x86)\AVG\AVG2013\avgfws.exe" [X] S2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe" [X] S2 avgwd; "C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe" [X] S1 Avgfwfd; system32\DRIVERS\avgfwd6a.sys [X] S1 AVGIDSDriver; system32\DRIVERS\avgidsdrivera.sys [X] S0 AVGIDSHA; system32\DRIVERS\avgidsha.sys [X] S1 Avgldx64; system32\DRIVERS\avgldx64.sys [X] S0 Avgloga; system32\DRIVERS\avgloga.sys [X] S0 Avgmfx64; system32\DRIVERS\avgmfx64.sys [X] S0 Avgrkx64; system32\DRIVERS\avgrkx64.sys [X] S1 Avgtdia; system32\DRIVERS\avgtdia.sys [X] S1 avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [X] S2 TMAgent; No ImagePath S3 tmlwf; No ImagePath S3 tmwfp; No ImagePath C:\Users\Gregor\AppData\Local\Temp C:\Users\Gregor\AppData\Roaming\skype.ini C:\Users\Gregor\Downloads\*(*)-dp*.exe C:\Windows\assembly\GAC_32\Desktop.ini C:\Windows\assembly\GAC_64\Desktop.ini C:\Windows\assembly\temp C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job C:\Windows\Tasks\RegClean Pro_UPDATES.job C:\Windows\Tasks\RegClean Pro_DEFAULT.job C:\Windows\System32\roboot64.exe C:\Windows\System32\Tasks\RegClean Pro C:\Windows\System32\Tasks\RegClean Pro_UPDATES C:\Windows\System32\Tasks\RegClean Pro_DEFAULT ***************** HKLM\System\ControlSet001\Control\Session Manager\SubSystems\\Windows => Value was restored successfully. "C:\Windows\system64" => Deleting reparse point and unlocking started. "C:\Windows\system64" => Deleting reparse point and unlocking done. "C:\Windows\system64" => Deleting reparse point and unlocking completed. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Setwallpaper => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\vProt => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AVG_UI => value deleted successfully. HKU\Gregor\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully. HKU\Gregor\Software\Microsoft\Windows\CurrentVersion\Run\\Urenqaagny => value deleted successfully. vToolbarUpdater18.1.9 => Service deleted successfully. avgfws => Service deleted successfully. AVGIDSAgent => Service deleted successfully. avgwd => Service deleted successfully. Avgfwfd => Service deleted successfully. AVGIDSDriver => Service deleted successfully. AVGIDSHA => Service deleted successfully. Avgldx64 => Service deleted successfully. Avgloga => Service deleted successfully. Avgmfx64 => Service deleted successfully. Avgrkx64 => Service deleted successfully. Avgtdia => Service deleted successfully. avgtp => Service deleted successfully. TMAgent => Service deleted successfully. tmlwf => Service deleted successfully. tmwfp => Service deleted successfully. C:\Users\Gregor\AppData\Local\Temp => Moved successfully. C:\Users\Gregor\AppData\Roaming\skype.ini => Moved successfully. C:\Users\Gregor\Downloads\*(*)-dp*.exe => Moved successfully. C:\Windows\assembly\GAC_32\Desktop.ini => Moved successfully. C:\Windows\assembly\GAC_64\Desktop.ini => Moved successfully. C:\Windows\assembly\temp => Moved successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => Moved successfully. C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => Moved successfully. C:\Windows\Tasks\RegClean Pro_UPDATES.job => Moved successfully. C:\Windows\Tasks\RegClean Pro_DEFAULT.job => Moved successfully. C:\Windows\System32\roboot64.exe => Moved successfully. C:\Windows\System32\Tasks\RegClean Pro => Moved successfully. C:\Windows\System32\Tasks\RegClean Pro_UPDATES => Moved successfully. C:\Windows\System32\Tasks\RegClean Pro_DEFAULT => Moved successfully. ==== End of Fixlog ====