Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015 Ran by SYSTEM at 2015-04-03 14:31:52 Run:4 Running from e:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** CreateRestorePoint: HKU\S-1-5-21-893646719-2384664811-2616046975-1000\...\Command Processor: "C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate\mountvol.exe" <===== ATTENTION! Startup: C:\Users\ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mountvol.lnk ShortcutTarget: mountvol.lnk -> C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate\mountvol.exe (No File) CHR Extension: (No Name) - C:\Users\ron\AppData\Local\Google\Chrome\User Data\Default\Extensions\opfedmikikmahmpaimpfelmikhaigobp [2013-11-11] 2015-01-30 09:03 - 2015-01-30 09:03 - 00000000 ____D () C:\ProgramData\boost_interprocess 2015-01-29 18:37 - 2015-01-29 18:37 - 00000794 _____ () C:\Windows\system32\.tmp 2015-01-29 17:34 - 2015-01-29 17:36 - 00000153 _____ () C:\Users\ron\AppData\Local\svcxdcl32.dat 2015-01-29 17:32 - 2015-01-30 09:03 - 00000000 ____D () C:\ProgramData\ZebkEnope 2015-01-28 18:28 - 2015-01-28 18:59 - 00000000 ___HD () C:\48895b54 2015-01-28 18:44 - 2012-10-15 16:43 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1 Task: {11651B12-8847-4966-99D0-1D929B9151D9} - System32\Tasks\{D1BFA6FF-41A0-43C1-8066-59F23B8BCAC8} => pcalua.exe -a C:\Users\ron\AppData\Local\Temp\InstallFlashPlayer.exe -d C:\Users\ron\Desktop Task: {2FD63CB2-E0A1-45FC-AC37-CCE8E845D0AF} - System32\Tasks\{7EE89D9E-2EC9-419D-9E9E-63942478420F} => Iexplore.exe http://ui.skype.com/...;toolbaroffered Task: {4ADDFFC8-0509-4985-A7F9-96F65443DFD3} - System32\Tasks\{67CFC914-29A9-4A9A-80F9-B0A4C858A3F7} => Iexplore.exe http://ui.skype.com/...;toolbaroffered Task: {4E7F1733-CC6A-4813-B25A-7AE5D5ECEBB3} - System32\Tasks\{450EFA0A-4048-4002-9B3C-B6CCEC831CE2} => Iexplore.exe http://ui.skype.com/...temlevelpresent Task: {66DDE1DE-FB23-43BF-A0B1-0C08971B7A16} - System32\Tasks\GoogleUpdater => Rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write((new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\internet explorer\\zergling_rush")) Task: {7AB943AB-95FA-46D0-AE5E-4C146C89B1BA} - System32\Tasks\{274A29E0-5B3C-4986-B01C-BA97FA88C6AA} => Iexplore.exe http://ui.skype.com/...;toolbaroffered Task: {E7F1B31F-C9EB-4BFB-80F1-8D125868101D} - System32\Tasks\{2FF53E40-C08D-440D-83BA-3FA3BAB0540D} => pcalua.exe -a "C:\Users\ron\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SPW7MLZA\download[1].exe" -d C:\Users\ron\Desktop C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Error: Restore point can only be created in normal mode. HKU\S-1-5-21-893646719-2384664811-2616046975-1000\Software\Microsoft\Command Processor\\AutoRun => Value not found. C:\Users\ron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mountvol.lnk not found. C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate\mountvol.exe not found. CHR Extension: (No Name) - C:\Users\ron\AppData\Local\Google\Chrome\User Data\Default\Extensions\opfedmikikmahmpaimpfelmikhaigobp [2013-11-11] => Error: The entry should be fixed outside recovery mode. "C:\ProgramData\boost_interprocess" => File/Directory not found. "C:\Windows\system32\.tmp" => File/Directory not found. "C:\Users\ron\AppData\Local\svcxdcl32.dat" => File/Directory not found. "C:\ProgramData\ZebkEnope" => File/Directory not found. "C:\48895b54" => File/Directory not found. "C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1" => File/Directory not found. Task: {11651B12-8847-4966-99D0-1D929B9151D9} - System32\Tasks\{D1BFA6FF-41A0-43C1-8066-59F23B8BCAC8} => pcalua.exe -a C:\Users\ron\AppData\Local\Temp\InstallFlashPlayer.exe -d C:\Users\ron\Desktop => Error: The entry should be fixed outside recovery mode. Task: {2FD63CB2-E0A1-45FC-AC37-CCE8E845D0AF} - System32\Tasks\{7EE89D9E-2EC9-419D-9E9E-63942478420F} => Iexplore.exe http://ui.skype.com/...;toolbaroffered => Error: The entry should be fixed outside recovery mode. Task: {4ADDFFC8-0509-4985-A7F9-96F65443DFD3} - System32\Tasks\{67CFC914-29A9-4A9A-80F9-B0A4C858A3F7} => Iexplore.exe http://ui.skype.com/...;toolbaroffered => Error: The entry should be fixed outside recovery mode. Task: {4E7F1733-CC6A-4813-B25A-7AE5D5ECEBB3} - System32\Tasks\{450EFA0A-4048-4002-9B3C-B6CCEC831CE2} => Iexplore.exe http://ui.skype.com/...temlevelpresent => Error: The entry should be fixed outside recovery mode. Task: {66DDE1DE-FB23-43BF-A0B1-0C08971B7A16} - System32\Tasks\GoogleUpdater => Rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write((new%20ActiveXObject("WScript.Shell")).RegRead("HKCU\\software\\microsoft\\internet explorer\\zergling_rush")) => Error: The entry should be fixed outside recovery mode. Task: {7AB943AB-95FA-46D0-AE5E-4C146C89B1BA} - System32\Tasks\{274A29E0-5B3C-4986-B01C-BA97FA88C6AA} => Iexplore.exe http://ui.skype.com/...;toolbaroffered => Error: The entry should be fixed outside recovery mode. Task: {E7F1B31F-C9EB-4BFB-80F1-8D125868101D} - System32\Tasks\{2FF53E40-C08D-440D-83BA-3FA3BAB0540D} => pcalua.exe -a "C:\Users\ron\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SPW7MLZA\download[1].exe" -d C:\Users\ron\Desktop => Error: The entry should be fixed outside recovery mode. "C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate" => File/Directory not found. EmptyTemp: => Error: This directive works only outside recovery mode. ========= bitsadmin /reset /allusers ========= 'bitsadmin' is not recognized as an internal or external command, operable program or batch file. ========= End of CMD: ========= ==== End of Fixlog 14:31:52 ====