Fix result of Farbar Recovery Scan Tool (x64) Version:30-07-2015 Ran by Roland (2015-08-01 13:28:17) Run:1 Running from G:\PROGRAMY Loaded Profiles: Roland (Available Profiles: Roland) Boot Mode: Normal ============================================== fixlist content: ***************** IFEO\adwcleaner_4.207.exe: [Debugger] svchost.exe IFEO\adwcleaner_4.208.exe: [Debugger] svchost.exe IFEO\AnVir.exe: [Debugger] svchost.exe IFEO\AutoLogger.exe: [Debugger] svchost.exe IFEO\CCleaner64.exe: [Debugger] svchost.exe IFEO\FRST.exe: [Debugger] svchost.exe IFEO\FRST64.exe: [Debugger] svchost.exe IFEO\RegWorks.exe: [Debugger] svchost.exe IFEO\RSITx64.exe: [Debugger] svchost.exe Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f S0 ulkfbuht; C:\Windows\SysWOW64\drivers\krts.sys C:\Windows\SysWOW64\drivers\krts.sys IFEO\regedit.exe: [Debugger] svchost.exe S0 yddg; C:\Windows\SysWOW64\drivers\fbmnvb.sys [61440 2015-03-09] () [File not signed] C:\Windows\SysWOW64\drivers\fbmnvb.sys EmptyTemp: ***************** "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\adwcleaner_4.207.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\adwcleaner_4.208.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AnVir.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AutoLogger.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\CCleaner64.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FRST.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\FRST64.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\RegWorks.exe" => key removed successfully "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\RSITx64.exe" => key removed successfully ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ulkfbuht => service removed successfully C:\Windows\SysWOW64\drivers\krts.sys => moved successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\regedit.exe => key not found. yddg => service removed successfully C:\Windows\SysWOW64\drivers\fbmnvb.sys => moved successfully. EmptyTemp: => 70.3 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 13:28:22 ====