Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-08-2014 02 Ran by abc at 2014-09-03 19:28:09 Run:5 Running from C:\Users\abc\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Users\abc\AppData\Roaming\winvap.exe () C:\Users\abc\AppData\Roaming\nvidiadisp\nvidiadisp.exe () C:\Users\abc\AppData\Roaming\c4sysmgr.exe HKU\S-1-5-21-2069616815-3132189673-721496042-1000\...\Run: [Display] => C:\Users\abc\AppData\Roaming\c4sysmgr.exe [129536 2014-09-02] () HKU\S-1-5-21-2069616815-3132189673-721496042-1000\...\Run: [Drivers] => C:\Users\abc\AppData\Roaming\c4sysmgr.exe [129536 2014-09-02] () HKU\S-1-5-21-2069616815-3132189673-721496042-1000\...\Run: [svchost] => C:\ProgramData\svchost\hemxccape.exe [38182400 2014-09-02] () HKU\S-1-5-21-2069616815-3132189673-721496042-1000\...\RunOnce: [svchost] => C:\ProgramData\svchost\hemxccape.exe [38182400 2014-09-02] () BootExecute: autocheck autochk * sdnclean64.exe Task: {868574EF-5E4C-4600-9CF3-48833F598B0A} - \DealPly No Task File <==== ATTENTION Task: {DF5EDB52-4131-410A-AABB-646BBF3548EF} - \Desk 365 RunAsStdUser No Task File <==== ATTENTION StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe FF Plugin-x32: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files (x86)\McFunSoft Video Capture Convert Burn Solution\codec\real\browser\plugins\nppl3260.dll No File FF Plugin-x32: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files (x86)\McFunSoft Video Capture Convert Burn Solution\codec\real\browser\plugins\nppl3260.dll No File FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files (x86)\McFunSoft Video Capture Convert Burn Solution\codec\real\browser\plugins\nprpjplug.dll No File FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files (x86)\McFunSoft Video Capture Convert Burn Solution\codec\real\browser\plugins\nprpjplug.dll No File S2 DisplayFusionService; "C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe" [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] C:\Program Files (x86)\mozilla firefox\plugins C:\ProgramData\svchost C:\ProgramData\TEMP C:\Users\abc\AppData\Roaming\*.exe C:\Users\abc\AppData\Roaming\3909 C:\Users\abc\AppData\Roaming\app C:\Users\abc\AppData\Roaming\Common C:\Users\abc\AppData\Roaming\nvidiadisp C:\Users\abc\AppData\Roaming\SettingsWin C:\Users\abc\AppData\Roaming\SFBot C:\Users\abc\AppData\Roaming\st1 C:\Users\abc\AppData\Roaming\Win32 C:\Windows\system32\Drivers\kjwfcn.sys C:\Windows\system32\Drivers\myeix.sys C:\Windows\system32\Drivers\xlaed.sys Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\avgua32.exe" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchProtection" /f Hosts: EmptyTemp: ***************** C:\Users\abc\AppData\Roaming\winvap.exe => No running process found C:\Users\abc\AppData\Roaming\nvidiadisp\nvidiadisp.exe => No running process found C:\Users\abc\AppData\Roaming\c4sysmgr.exe => No running process found HKU\S-1-5-21-2069616815-3132189673-721496042-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Display => Value not found. HKU\S-1-5-21-2069616815-3132189673-721496042-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Drivers => Value not found. HKU\S-1-5-21-2069616815-3132189673-721496042-1000\Software\Microsoft\Windows\CurrentVersion\Run\\svchost => Value not found. HKU\S-1-5-21-2069616815-3132189673-721496042-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\S-1-5-21-2069616815-3132189673-721496042-1000\...\RunOnce: [svchost] => C:\ProgramData\svchost\hemxccape.exe [38182400 2014-09-02] () => Value not found. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{868574EF-5E4C-4600-9CF3-48833F598B0A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{868574EF-5E4C-4600-9CF3-48833F598B0A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DF5EDB52-4131-410A-AABB-646BBF3548EF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF5EDB52-4131-410A-AABB-646BBF3548EF}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser" => Key deleted successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662" => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46" => Key not found. DisplayFusionService => Service not found. EagleX64 => Service not found. "C:\Program Files (x86)\mozilla firefox\plugins" => File/Directory not found. "C:\ProgramData\svchost" => File/Directory not found. "C:\ProgramData\TEMP" => File/Directory not found. "C:\Users\abc\AppData\Roaming\*.exe" => File/Directory not found. "C:\Users\abc\AppData\Roaming\3909" => File/Directory not found. "C:\Users\abc\AppData\Roaming\app" => File/Directory not found. "C:\Users\abc\AppData\Roaming\Common" => File/Directory not found. "C:\Users\abc\AppData\Roaming\nvidiadisp" => File/Directory not found. "C:\Users\abc\AppData\Roaming\SettingsWin" => File/Directory not found. "C:\Users\abc\AppData\Roaming\SFBot" => File/Directory not found. "C:\Users\abc\AppData\Roaming\st1" => File/Directory not found. "C:\Users\abc\AppData\Roaming\Win32" => File/Directory not found. "C:\Windows\system32\Drivers\kjwfcn.sys" => File/Directory not found. "C:\Windows\system32\Drivers\myeix.sys" => File/Directory not found. "C:\Windows\system32\Drivers\xlaed.sys" => File/Directory not found. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\avgua32.exe" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchProtection" /f ========= Bť¤D: System nie znalazˆ w rejestrze okre˜lonego klucza albo warto˜ci. ========= End of Reg: ========= C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 560.6 MB temporary data. The system needed a reboot. ==== End of Fixlog ====