Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 18-02-2015 01 Ran by dom at 2015-02-20 09:32:38 Run:3 Running from C:\Users\dom\Desktop Loaded Profiles: dom (Available profiles: dom) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X] S3 dcdbas; system32\DRIVERS\dcdbas32.sys [X] Task: {1DE39C38-69FB-4786-A03F-CC9A9FE57F75} - System32\Tasks\{7255226E-3E75-4C90-B3ED-8BA7072D468F} => pcalua.exe -a C:\Users\dom\Downloads\GFX_Win7_15.12.75.4.1930_PV_Intel.exe -d C:\Users\dom\Downloads Task: {2159DDD7-DAD7-411D-BC0B-BD620B4923E0} - System32\Tasks\{4C4C9318-B8D5-4268-AC75-3ABD4C870EE8} => pcalua.exe -a "C:\Users\dom\Downloads\Audio_Realtek_Asus_September_2014\Windows 7, 8, 8.1 ? Vista\Setup.exe" -d "C:\Users\dom\Downloads\Audio_Realtek_Asus_September_2014\Windows 7, 8, 8.1 ? Vista" Task: {2E2478E2-A0BE-4BED-9AC2-AB6833026E02} - System32\Tasks\{D6E604CB-A3AF-45EF-A63B-3DAF7CFEA9D4} => pcalua.exe -a C:\Users\dom\Downloads\CrystalLauncher-Installer.exe -d C:\Users\dom\Downloads Task: {36A292ED-5870-4294-88B6-D8A3A4E84CB1} - System32\Tasks\{B5DCB01F-B59E-4510-A43F-E27FF3411572} => pcalua.exe -a "C:\Program Files\YouTube Accelerator\YTAUninstall.exe" HKU\S-1-5-21-3115265202-861073304-1815682740-1000\...\MountPoints2: {e27e6af8-5e5e-11e4-a306-6c71d9bc607c} - F:\sources\sperr32.exe x64 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com C:\$360Section C:\Program Files\360 C:\ProgramData\360Quarant C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk C:\Users\dom\AppData\Roaming\OJP C:\Users\dom\AppData\Roaming\XTZSVL C:\Users\dom\Downloads\*(*)-dp*.exe C:\Users\dom\Downloads\AdwCleaner*.exe C:\Windows\Tasks\360Disabled Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f C:\ProgramData\TEMP EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. BAPIDRV => Service deleted successfully. dcdbas => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1DE39C38-69FB-4786-A03F-CC9A9FE57F75}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DE39C38-69FB-4786-A03F-CC9A9FE57F75}" => Key deleted successfully. C:\Windows\System32\Tasks\{7255226E-3E75-4C90-B3ED-8BA7072D468F} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7255226E-3E75-4C90-B3ED-8BA7072D468F}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2159DDD7-DAD7-411D-BC0B-BD620B4923E0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2159DDD7-DAD7-411D-BC0B-BD620B4923E0}" => Key deleted successfully. C:\Windows\System32\Tasks\{4C4C9318-B8D5-4268-AC75-3ABD4C870EE8} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4C4C9318-B8D5-4268-AC75-3ABD4C870EE8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2E2478E2-A0BE-4BED-9AC2-AB6833026E02}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E2478E2-A0BE-4BED-9AC2-AB6833026E02}" => Key deleted successfully. C:\Windows\System32\Tasks\{D6E604CB-A3AF-45EF-A63B-3DAF7CFEA9D4} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D6E604CB-A3AF-45EF-A63B-3DAF7CFEA9D4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36A292ED-5870-4294-88B6-D8A3A4E84CB1}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36A292ED-5870-4294-88B6-D8A3A4E84CB1}" => Key deleted successfully. C:\Windows\System32\Tasks\{B5DCB01F-B59E-4510-A43F-E27FF3411572} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B5DCB01F-B59E-4510-A43F-E27FF3411572}" => Key deleted successfully. "HKU\S-1-5-21-3115265202-861073304-1815682740-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e27e6af8-5e5e-11e4-a306-6c71d9bc607c}" => Key deleted successfully. HKCR\CLSID\{e27e6af8-5e5e-11e4-a306-6c71d9bc607c} => Key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. C:\$360Section => Moved successfully. C:\Program Files\360 => Moved successfully. C:\ProgramData\360Quarant => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Moved successfully. C:\Users\dom\AppData\Roaming\OJP => Moved successfully. C:\Users\dom\AppData\Roaming\XTZSVL => Moved successfully. C:\Users\dom\Downloads\*(*)-dp*.exe => Moved successfully. C:\Users\dom\Downloads\AdwCleaner*.exe => Moved successfully. C:\Windows\Tasks\360Disabled => Moved successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= C:\ProgramData\TEMP => Moved successfully. EmptyTemp: => Removed 68.5 MB temporary data. The system needed a reboot. ==== End of Fixlog 09:33:16 ====