Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-12-2014 01 Ran by Kubix at 2014-12-07 15:31:33 Run:1 Running from C:\Users\Kubix\Downloads Loaded Profile: Kubix (Available profiles: Kubix) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: AppInit_DLLs-x32: C:\Users\Kubix\AppData\Local\DProtect\eBP.dll => "C:\Users\Kubix\AppData\Local\DProtect\eBP.dll" File Not Found AppInit_DLLs-x32: ,C:\Users\Kubix\AppData\Local\DProtect\eBPSD.dll => "C:\Users\Kubix\AppData\Local\DProtect\eBPSD.dll" File Not Found S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] Task: {00B9DDD9-2E94-43E4-B3A7-3DB37C301A83} - System32\Tasks\{70CC391B-9627-4A59-B544-F24D9BE8F219} => C:\Program Files (x86)\R.G. Mechanics\Bastion\Bastion.exe Task: {1DD9169C-92CD-47F2-895F-BDA619B4E58D} - System32\Tasks\{D817E2D9-67EE-45A1-9E93-E4A70E869B2D} => C:\Program Files (x86)\Dz Repack Team\Bioshock Infinite\Binaries\Win32\BioShockInfinite.exe Task: {462A2FFD-BEFD-4A14-B860-27B58A0CC6D3} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-10-27] () <==== ATTENTION Task: {A72F26EB-51A1-4D7A-AA09-E23632743FC7} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RCP\RegCleanPro.exe [2014-10-27] () <==== ATTENTION Task: {DE315D6E-8A73-4F87-AE32-C09FF0FAF00E} - System32\Tasks\{0E38D4F4-12AD-48CA-B4B5-DA52D430C4EB} => C:\Program Files (x86)\Dz Repack Team\Bioshock Infinite\Binaries\Win32\BioShockInfinite.exe Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RCP\RegCleanPro.exe <==== ATTENTION GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.10\\npsitesafety.dll No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\RCP C:\ProgramData\AVG Secure Search C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro C:\Users\Kubix\AppData\Local\qs.dll C:\Users\Kubix\AppData\Local\qs64.dll C:\Users\Kubix\AppData\Local\Google\Chrome C:\Users\Kubix\AppData\Roaming\apachesrvin.vbs C:\Users\Kubix\AppData\Roaming\die.bat C:\Users\Kubix\AppData\Roaming\minerd C:\Users\Kubix\AppData\Roaming\OnLive App C:\Users\Kubix\AppData\Roaming\QuickScan C:\Users\Kubix\AppData\Roaming\Systweak C:\Windows\ati.exe C:\Windows\cpu1.exe C:\Windows\cuda.exe C:\Windows\libcurl-4.dll C:\Windows\proxy.exe C:\Windows\pthread.dll C:\Windows\zlib1.dll C:\Windows\system32\roboot64.exe CMD: sc config NAUpdate start= disabled CMD: sc config NvStreamSvc start= disabled CMD: sc config NvNetworkService start= disabled Reg: reg delete HKCU\Software\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4F524A2D-5350-4500-76A7-A758B70C1200} /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. "C:\Users\Kubix\AppData\Local\DProtect\eBP.dll" => Value Data not found. ",C:\Users\Kubix\AppData\Local\DProtect\eBPSD.dll" => Value Data not found. xhunter1 => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{00B9DDD9-2E94-43E4-B3A7-3DB37C301A83}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00B9DDD9-2E94-43E4-B3A7-3DB37C301A83}" => Key deleted successfully. C:\Windows\System32\Tasks\{70CC391B-9627-4A59-B544-F24D9BE8F219} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{70CC391B-9627-4A59-B544-F24D9BE8F219}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DD9169C-92CD-47F2-895F-BDA619B4E58D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DD9169C-92CD-47F2-895F-BDA619B4E58D}" => Key deleted successfully. C:\Windows\System32\Tasks\{D817E2D9-67EE-45A1-9E93-E4A70E869B2D} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D817E2D9-67EE-45A1-9E93-E4A70E869B2D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{462A2FFD-BEFD-4A14-B860-27B58A0CC6D3}" => Key not found. C:\Windows\System32\Tasks\RegClean Pro_DEFAULT not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A72F26EB-51A1-4D7A-AA09-E23632743FC7}" => Key not found. C:\Windows\System32\Tasks\RegClean Pro_UPDATES not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE315D6E-8A73-4F87-AE32-C09FF0FAF00E}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE315D6E-8A73-4F87-AE32-C09FF0FAF00E}" => Key deleted successfully. C:\Windows\System32\Tasks\{0E38D4F4-12AD-48CA-B4B5-DA52D430C4EB} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0E38D4F4-12AD-48CA-B4B5-DA52D430C4EB}" => Key deleted successfully. C:\Windows\Tasks\RegClean Pro_DEFAULT.job not found. C:\Windows\Tasks\RegClean Pro_UPDATES.job not found. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin" => Key not found. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "C:\Program Files (x86)\RCP" => File/Directory not found. "C:\ProgramData\AVG Secure Search" => File/Directory not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro" => File/Directory not found. C:\Users\Kubix\AppData\Local\qs.dll => Moved successfully. C:\Users\Kubix\AppData\Local\qs64.dll => Moved successfully. C:\Users\Kubix\AppData\Local\Google\Chrome => Moved successfully. C:\Users\Kubix\AppData\Roaming\apachesrvin.vbs => Moved successfully. C:\Users\Kubix\AppData\Roaming\die.bat => Moved successfully. C:\Users\Kubix\AppData\Roaming\minerd => Moved successfully. C:\Users\Kubix\AppData\Roaming\OnLive App => Moved successfully. C:\Users\Kubix\AppData\Roaming\QuickScan => Moved successfully. C:\Users\Kubix\AppData\Roaming\Systweak => Moved successfully. C:\Windows\ati.exe => Moved successfully. C:\Windows\cpu1.exe => Moved successfully. C:\Windows\cuda.exe => Moved successfully. C:\Windows\libcurl-4.dll => Moved successfully. C:\Windows\proxy.exe => Moved successfully. C:\Windows\pthread.dll => Moved successfully. C:\Windows\zlib1.dll => Moved successfully. C:\Windows\system32\roboot64.exe => Moved successfully. ========= sc config NAUpdate start= disabled ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config NvStreamSvc start= disabled ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= sc config NvNetworkService start= disabled ========= [SC] ChangeServiceConfig SUKCES ========= End of CMD: ========= ========= reg delete HKCU\Software\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4F524A2D-5350-4500-76A7-A758B70C1200} /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 958.2 MB temporary data. The system needed a reboot. ==== End of Fixlog ====