Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-02-2015 Ran by R at 2015-03-02 18:56:49 Run:1 Running from C:\Users\R\Downloads Loaded Profiles: R & (Available profiles: R) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: Task: {249C0560-71D5-4143-B9C6-E56CFE2BCFAA} - System32\Tasks\InstallShield Updater => Wscript.exe //nologo //E:jscript //B "C:\Users\R\AppData\Roaming\InstallShield Updater\updater.ini" Task: C:\Windows\Tasks\InstallShield Updater.job => Wscript.exeX//nologo //E:jscript //B C:\Users\R\AppData\Roaming\InstallShield Updater\updater.ini R2 Updater.exe; C:\Users\R\AppData\Roaming\InstallShield Updater\Updater.exe [36864 2014-12-15] (InstallShield) [File not signed] S3 GPU-Z; \??\C:\Users\R\AppData\Local\Temp\GPU-Z.sys [X] S3 t3; \SystemRoot\system32\drivers\t3.sys [X] ProxyServer: [HKLM-x32] => http://127.0.0.1:8080/proxy.pac AutoConfigURL: [HKLM-x32] => http://127.0.0.1:8080/proxy.pac CHR StartupUrls: Default -> "hxxp://start.qone8.com/?type=hp&ts=1382629367&from=cor&uid=HitachiXHDP725050GLA360_GEA534RJ07N65A07N65AX", "hxxp://www.nationzoom.com/?type=hp&ts=1388262092&from=ild&uid=HitachiXHTS545016B9A300_091008PB5B03QCJAJ4WGX" C:\Users\R\AppData\Roaming\InstallShield Updater Hosts: Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{249C0560-71D5-4143-B9C6-E56CFE2BCFAA}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{249C0560-71D5-4143-B9C6-E56CFE2BCFAA}" => Key deleted successfully. C:\Windows\System32\Tasks\InstallShield Updater => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\InstallShield Updater" => Key deleted successfully. C:\Windows\Tasks\InstallShield Updater.job => Moved successfully. Updater.exe => Service deleted successfully. GPU-Z => Service deleted successfully. t3 => Service deleted successfully. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found. HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value deleted successfully. Chrome StartupUrls deleted successfully. C:\Users\R\AppData\Roaming\InstallShield Updater => Moved successfully. Hosts was reset successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= The operation completed successfully. ========= End of Reg: ========= EmptyTemp: => Removed 538.6 MB temporary data. The system needed a reboot. ==== End of Fixlog 18:57:09 ====