Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by SYSTEM (2016-03-12 16:42:31) Run:7 Running from g:\ Boot Mode: Recovery ============================================== fixlist content: ***************** Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X] HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$70fcdb70c5b8d46645f03adef7c0c75c\n. <==== ATTENTION HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1 HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1 HKU\Default\...\Policies\Explorer: [NoDesktopCleanupWizard] 1 HKU\Default User\...\Policies\Explorer: [NoDesktopCleanupWizard] 1 BootExecute: autocheck autochk * lsdelete S2 Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2152720 2015-04-05] (Lavasoft Limited) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe [293128 2016-02-05] (McAfee, Inc.) S2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{70fcdb70-c5b8-d466-45f0-3adef7c0c75c}\ \...\ﯹ๛\{70fcdb70-c5b8-d466-45f0-3adef7c0c75c}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess) S3 ecxncijc; \??\C:\Windows\system32\drivers\ngiodriver_x64 [X] S3 epmnvwyv; \??\C:\Windows\system32\drivers\ngiodriver_x64 [X] S2 MSSQL$DDNI; no ImagePath S2 Oasis2Service; no ImagePath CMD: dir /a /s C:\found.006 CMD: dir /a C:\Windows\System32\Tasks ***************** "HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon" => key removed successfully HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => value restored successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\AllowLegacyWebView => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\AllowUnhashedWebView => value removed successfully HKU\Default\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktopCleanupWizard => value removed successfully HKU\Default User\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktopCleanupWizard => value not found. hklm\System\ControlSet001\Control\Session Manager\\BootExecute => value restored successfully Lavasoft Ad-Aware Service => service removed successfully McComponentHostService => service removed successfully *etadpug => service removed successfully ecxncijc => service removed successfully epmnvwyv => service removed successfully MSSQL$DDNI => service removed successfully Oasis2Service => service removed successfully ========= dir /a /s C:\found.006 ========= Volume in drive C has no label. Volume Serial Number is 84BC-F95D Directory of C:\found.006 03/03/2016 03:04 PM