Fix result of Farbar Recovery Scan Tool (x64) Version: 09-08-2016 Ran by Fig (2016-08-09 17:38:07) Run:1 Running from C:\Users\Fig\Desktop Loaded Profiles: Fig (Available Profiles: Fig) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: Task: {E30BE303-0ECD-48AC-881F-8D574C73610A} - System32\Tasks\Realtek HD Audio => C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\rthdcpl.exe [2016-07-23] (Realtek) S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] S3 EverestDriver; \??\F:\Potrzebne\Instalki\Programy\ewerest\kerneld.amd64 [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-1636404970-671201596-126257068-1000\...\MountPoints2: {f7e90b9f-a1b7-11e5-9a82-f0795990e8cb} - K:\Startme.exe HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = DeleteKey: HKLM\SOFTWARE\Mozilla DeleteKey: HKLM\SOFTWARE\MozillaPlugins DeleteKey: HKLM\SOFTWARE\Wow6432Node\Mozilla DeleteKey: HKLM\SOFTWARE\Wow6432Node\MozillaPlugins C:\Program Files (x86)\Temp Folder: C:\Users\Fig\AppData\Roaming\AVAST Software C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD C:\Windows\SysWOW64\*.tmp Hosts: EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E30BE303-0ECD-48AC-881F-8D574C73610A}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E30BE303-0ECD-48AC-881F-8D574C73610A}" => key removed successfully C:\Windows\System32\Tasks\Realtek HD Audio => moved successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Realtek HD Audio" => key removed successfully cpuz136 => service removed successfully EverestDriver => service removed successfully GPUZ => service removed successfully Synth3dVsc => service removed successfully tsusbhub => service removed successfully VGPU => service removed successfully HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\Sidebar => value removed successfully HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\Sidebar => value removed successfully "HKU\S-1-5-21-1636404970-671201596-126257068-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7e90b9f-a1b7-11e5-9a82-f0795990e8cb}" => key removed successfully HKCR\CLSID\{f7e90b9f-a1b7-11e5-9a82-f0795990e8cb} => key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully HKLM\SOFTWARE\Mozilla => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Mozilla => key removed successfully HKLM\SOFTWARE\MozillaPlugins => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\MozillaPlugins => key removed successfully HKLM\SOFTWARE\Wow6432Node\Mozilla => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\Mozilla => key removed successfully HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Wow6432Node\MozillaPlugins => key removed successfully C:\Program Files (x86)\Temp => moved successfully ========================= Folder: C:\Users\Fig\AppData\Roaming\AVAST Software ======================== 2015-11-07 17:25 - 2016-08-04 19:55 - 0000000 ____D () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast 2016-08-04 19:55 - 2016-08-04 19:55 - 1487697 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\remotecache.zip 2015-11-07 17:25 - 2016-08-02 19:43 - 0000000 ____D () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache 2016-06-30 16:47 - 2016-06-30 16:48 - 23389080 ____N () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache\ChromeDWriteFontCache 2015-11-07 17:25 - 2016-07-30 14:40 - 0008192 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache\Cookies 2015-11-07 17:25 - 2016-07-30 14:40 - 0000000 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache\Cookies-journal 2016-08-02 19:43 - 2016-08-08 17:25 - 0002062 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache\HTMLayout.xml 2016-06-30 16:47 - 2016-07-30 02:59 - 0131072 ____N () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache\Visited Links 2015-11-07 17:25 - 2015-11-07 17:25 - 0000000 ____D () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache\Dictionaries 2015-12-06 15:09 - 2015-12-06 15:09 - 0000000 ____D () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\Cache\Local Storage 2015-11-07 17:25 - 2015-11-07 17:25 - 0000000 ____D () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\log 2015-11-07 17:25 - 2016-07-30 02:47 - 0003252 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Avast\log\avastium.log 2016-07-23 21:07 - 2016-07-25 23:12 - 0000000 ____D () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD 2016-07-23 21:07 - 2016-07-23 21:07 - 0003282 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\config.xml 2016-07-25 23:12 - 2016-07-25 23:12 - 0094392 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\decredJunipergw256l4tc4032.bin 2016-07-23 21:07 - 2016-07-23 21:07 - 0640000 _____ (The cURL library, http://curl.haxx.se/) C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\libcurl.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 1707520 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\libeay32.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 0118784 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\libgcc_s_dw2-1.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 0279955 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\libidn-11.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 0970912 _____ (Microsoft Corporation) C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\msvcr120.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 0094300 _____ (Open Source Software community LGPL) C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\pthreadGC2.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 0055808 _____ (Open Source Software community LGPL) C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\pthreadVC2.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 1606656 _____ (Realtek) C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\rthdcpl.exe 2016-07-23 21:07 - 2016-07-23 21:07 - 0368640 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\ssleay32.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 0113166 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\zlib1.dll 2016-07-23 21:07 - 2016-07-23 21:07 - 0000000 ____D () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\kernel 2016-07-23 21:07 - 2016-07-23 21:07 - 0028658 _____ () C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD\kernel\decred.cl ====== End of Folder: ====== C:\Users\Fig\AppData\Roaming\AVAST Software\Realtek HD => moved successfully =========== "C:\Windows\SysWOW64\*.tmp" ========== C:\Windows\SysWOW64\OCL13DE.tmp => moved successfully C:\Windows\SysWOW64\tmp89BF.tmp => moved successfully C:\Windows\SysWOW64\tmp89EF.tmp => moved successfully C:\Windows\SysWOW64\tmpD03B.tmp => moved successfully C:\Windows\SysWOW64\tmpD03C.tmp => moved successfully ========= End -> "C:\Windows\SysWOW64\*.tmp" ======== C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18384609 B Java, Flash, Steam htmlcache => 61952559 B Windows/system/drivers => 5402804 B Edge => 0 B Chrome => 188416 B Firefox => 0 B Opera => 406619819 B Temp, IE cache, history, cookies, recent: Default => 66228 B Public => 0 B ProgramData => 0 B systemprofile => 58558607 B systemprofile32 => 66228 B LocalService => 66228 B NetworkService => 66228 B Fig => 13821685 B RecycleBin => 0 B EmptyTemp: => 547 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 17:38:46 ====