Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015 Ran by Konrad at 2015-04-03 09:38:01 Run:1 Running from C:\Users\Konrad\Desktop Loaded Profiles: Konrad (Available profiles: Konrad) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKU\S-1-5-21-3709328401-3719035880-1003004347-1000\...\Run: [Tok-Cirrhatus] => C:\Users\Konrad\AppData\Local\smss.exe [42619 2014-01-12] () Startup: C:\Users\Konrad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif () S3 VGPU; System32\drivers\rdvgkmd.sys [X] C:\Users\Konrad\AppData\Local\Bron.tok-12-13 C:\Users\Konrad\AppData\Local\Bron.tok-12-12 C:\Users\Konrad\AppData\Local\Bron.tok-12-11 C:\Users\Konrad\AppData\Local\Loc.Mail.Bron.Tok C:\Users\Konrad\AppData\Local\Bron.tok.A12.em.bin C:\Users\Konrad\AppData\Local\csrss.exe C:\Users\Konrad\AppData\Local\inetinfo.exe C:\Users\Konrad\AppData\Local\Kosong.Bron.Tok.txt C:\Users\Konrad\AppData\Local\lsass.exe C:\Users\Konrad\AppData\Local\services.exe C:\Users\Konrad\AppData\Local\smss.exe C:\Users\Konrad\AppData\Local\winlogon.exe C:\Users\Konrad\AppData\Roaming\Panda Security C:\Program Files\Panda Security C:\ProgramData\Panda Security Task: {4240324C-DEB4-44F1-BC17-BBF822ACBFEB} - System32\Tasks\{BDEB99CE-66AF-4138-A7BE-BB7040D87AC7} => pcalua.exe -a C:\Users\Konrad\Desktop\WinWDF\x86\InstNT.exe -d C:\Users\Konrad\Desktop\WinWDF\x86 EmptyTemp: ***************** Processes closed successfully. HKU\S-1-5-21-3709328401-3719035880-1003004347-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Tok-Cirrhatus => value deleted successfully. C:\Users\Konrad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif => Moved successfully. VGPU => Service deleted successfully. C:\Users\Konrad\AppData\Local\Bron.tok-12-13 => Moved successfully. C:\Users\Konrad\AppData\Local\Bron.tok-12-12 => Moved successfully. C:\Users\Konrad\AppData\Local\Bron.tok-12-11 => Moved successfully. C:\Users\Konrad\AppData\Local\Loc.Mail.Bron.Tok => Moved successfully. "C:\Users\Konrad\AppData\Local\Bron.tok.A12.em.bin" => File/Directory not found. C:\Users\Konrad\AppData\Local\csrss.exe => Moved successfully. C:\Users\Konrad\AppData\Local\inetinfo.exe => Moved successfully. C:\Users\Konrad\AppData\Local\Kosong.Bron.Tok.txt => Moved successfully. C:\Users\Konrad\AppData\Local\lsass.exe => Moved successfully. C:\Users\Konrad\AppData\Local\services.exe => Moved successfully. C:\Users\Konrad\AppData\Local\smss.exe => Moved successfully. C:\Users\Konrad\AppData\Local\winlogon.exe => Moved successfully. C:\Users\Konrad\AppData\Roaming\Panda Security => Moved successfully. C:\Program Files\Panda Security => Moved successfully. C:\ProgramData\Panda Security => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4240324C-DEB4-44F1-BC17-BBF822ACBFEB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4240324C-DEB4-44F1-BC17-BBF822ACBFEB}" => Key deleted successfully. C:\Windows\System32\Tasks\{BDEB99CE-66AF-4138-A7BE-BB7040D87AC7} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BDEB99CE-66AF-4138-A7BE-BB7040D87AC7}" => Key deleted successfully. EmptyTemp: => Removed 3.8 GB temporary data. The system needed a reboot. ==== End of Fixlog 09:39:33 ====