Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-10-2014 01 Ran by Lenovo at 2014-10-28 20:15:28 Run:1 Running from C:\Users\Lenovo\Desktop Loaded Profile: Lenovo (Available profiles: Lenovo) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: Task: {11F34C68-E5FD-4B80-92A6-0E2B1010B8CE} - System32\Tasks\Opera scheduled Autoupdate 1412344377 => C:\Program Files\Opera\launcher.exe Task: {A99455B1-188B-4BD6-B907-7787C10EA73A} - System32\Tasks\Microsoft\windows\DiskDiagnostic\DiskDiagnostic => C:\Program Files\DiskDiagnostic\DiskDiagnostic.exe [2014-10-03] () Task: {B4F2DD13-905A-480E-8A3B-D9166ADE882D} - \Driver Pro Schedule No Task File <==== ATTENTION Task: {CED5A85F-E68F-4DA0-B5B3-501DE0AFEF1F} - System32\Tasks\Loca\Loca\Loca => C:\Program Files\Loca\bin\LocaProxy.exe [2014-10-20] () Task: {DA9A1342-205E-4025-9E96-201EA968CD43} - \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-HashDiagnostic No Task File <==== ATTENTION HKU\S-1-5-21-4144906793-159945770-2030462716-1000\...\MountPoints2: {fe7d3415-4df2-11e4-976e-b870f448ed3f} - F:\Startme.exe HKU\S-1-5-18\...\Run: [Bitdefender Wallet Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" HKU\S-1-5-18\...\Run: [Bitdefender Wallet] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard HKU\S-1-5-18\...\Run: [Bitdefender Wallet Application Agent] => "C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe" S1 BdfNdisf; \??\c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [X] ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:8080;https=127.0.0.1:8080 Folder: C:\Program Files\DiskDiagnostic C:\Program Files\Common Files\Bitdefender C:\Program Files\DiskDiagnostic C:\Program Files\Loca C:\ProgramData\cryptoDrvUpdate.exe C:\ProgramData\*.bdinstall.bin C:\Users\Lenovo\AppData\Temp C:\Users\Lenovo\AppData\Roaming\driver C:\Users\Lenovo\AppData\Roaming\Mozilla C:\Users\Lenovo\AppData\Roaming\QuickScan C:\Windows\system32\sqlite3.dll C:\Windows\system32\Tasks\Loca Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Driver Pro" /f Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\InstallerLauncher" /f EmptyTemp: ***************** Processes closed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{11F34C68-E5FD-4B80-92A6-0E2B1010B8CE}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11F34C68-E5FD-4B80-92A6-0E2B1010B8CE}" => Key deleted successfully. C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1412344377 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1412344377" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A99455B1-188B-4BD6-B907-7787C10EA73A}" => Key not found. C:\Windows\System32\Tasks\Microsoft\windows\DiskDiagnostic\DiskDiagnostic => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\windows\DiskDiagnostic\DiskDiagnostic" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4F2DD13-905A-480E-8A3B-D9166ADE882D}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Pro Schedule" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CED5A85F-E68F-4DA0-B5B3-501DE0AFEF1F}" => Key not found. C:\Windows\System32\Tasks\Loca\Loca\Loca => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Loca\Loca\Loca" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA9A1342-205E-4025-9E96-201EA968CD43}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA9A1342-205E-4025-9E96-201EA968CD43}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-HashDiagnostic" => Key deleted successfully. "HKU\S-1-5-21-4144906793-159945770-2030462716-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe7d3415-4df2-11e4-976e-b870f448ed3f}" => Key deleted successfully. "HKCR\CLSID\{fe7d3415-4df2-11e4-976e-b870f448ed3f}" => Key not found. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Bitdefender Wallet Agent => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Bitdefender Wallet => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Bitdefender Wallet Application Agent => value deleted successfully. BdfNdisf => Service deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. ========================= Folder: C:\Program Files\DiskDiagnostic ======================== 2014-10-03 10:00 - 2014-10-03 10:00 - 0333312 _____ () C:\Program Files\DiskDiagnostic\DiskDiagnostic.exe ====== End of Folder: ====== C:\Program Files\Common Files\Bitdefender => Moved successfully. C:\Program Files\DiskDiagnostic => Moved successfully. C:\Program Files\Loca => Moved successfully. C:\ProgramData\cryptoDrvUpdate.exe => Moved successfully. C:\ProgramData\*.bdinstall.bin => Moved successfully. C:\Users\Lenovo\AppData\Temp => Moved successfully. C:\Users\Lenovo\AppData\Roaming\driver => Moved successfully. C:\Users\Lenovo\AppData\Roaming\Mozilla => Moved successfully. C:\Users\Lenovo\AppData\Roaming\QuickScan => Moved successfully. C:\Windows\system32\sqlite3.dll => Moved successfully. C:\Windows\system32\Tasks\Loca => Moved successfully. ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Driver Pro" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\InstallerLauncher" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 871.2 MB temporary data. The system needed a reboot. ==== End of Fixlog ====