Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by User at 2015-04-03 11:41:00 Run:1 Running from C:\Users\User\Downloads Loaded Profiles: User (Available profiles: User) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: S2 Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [X] S3 MSICDSetup; \??\F:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] Task: {76A29440-6E1F-49B4-8EC1-4759BFC64110} - System32\Tasks\{4CEAADF1-61F5-4E9D-85D3-D72313130D3E} => pcalua.exe -a "E:\fifa\FIFA 14\ModdingWayInstaller.exe" -d "E:\fifa\FIFA 14" HKU\S-1-5-21-3088188526-2701845234-4171393175-1000\...\MountPoints2: {35f352f1-7270-11e4-a599-448a5ba0606d} - H:\setup.exe ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com C:\ProgramData\SMRResults430.dat C:\ProgramData\EmailNotifier C:\ProgramData\Microsoft\Windows\GameExplorer\{C925ED11-7102-423A-9F7E-061EFADE30C7} C:\Users\User\Programy\avast! Free Antivirus.lnk Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: ipconfig /flushdns EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. Nero BackItUp Scheduler 4.0 => Service deleted successfully. MSICDSetup => Service deleted successfully. NTIOLib_1_0_C => Service deleted successfully. VGPU => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{76A29440-6E1F-49B4-8EC1-4759BFC64110}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76A29440-6E1F-49B4-8EC1-4759BFC64110}" => Key deleted successfully. C:\Windows\System32\Tasks\{4CEAADF1-61F5-4E9D-85D3-D72313130D3E} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4CEAADF1-61F5-4E9D-85D3-D72313130D3E}" => Key deleted successfully. "HKU\S-1-5-21-3088188526-2701845234-4171393175-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{35f352f1-7270-11e4-a599-448a5ba0606d}" => Key deleted successfully. HKCR\CLSID\{35f352f1-7270-11e4-a599-448a5ba0606d} => Key not found. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully. "HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. C:\ProgramData\SMRResults430.dat => Moved successfully. C:\ProgramData\EmailNotifier => Moved successfully. C:\ProgramData\Microsoft\Windows\GameExplorer\{C925ED11-7102-423A-9F7E-061EFADE30C7} => Moved successfully. C:\Users\User\Programy\avast! Free Antivirus.lnk => Moved successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= ipconfig /flushdns ========= Konfiguracja IP systemu Windows Pomy˜lnie opr¢¾niono pami©† podr©czn¥ programu rozpoznawania nazw DNS. ========= End of CMD: ========= EmptyTemp: => Removed 2.6 GB temporary data. The system needed a reboot. ==== End of Fixlog 11:42:04 ====