Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by SYSTEM (2016-03-12 16:42:31) Run:7 Running from g:\ Boot Mode: Recovery ============================================== fixlist content: ***************** Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X] HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$70fcdb70c5b8d46645f03adef7c0c75c\n. <==== ATTENTION HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1 HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1 HKU\Default\...\Policies\Explorer: [NoDesktopCleanupWizard] 1 HKU\Default User\...\Policies\Explorer: [NoDesktopCleanupWizard] 1 BootExecute: autocheck autochk * lsdelete S2 Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2152720 2015-04-05] (Lavasoft Limited) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe [293128 2016-02-05] (McAfee, Inc.) S2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{70fcdb70-c5b8-d466-45f0-3adef7c0c75c}\ \...\ﯹ๛\{70fcdb70-c5b8-d466-45f0-3adef7c0c75c}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess) S3 ecxncijc; \??\C:\Windows\system32\drivers\ngiodriver_x64 [X] S3 epmnvwyv; \??\C:\Windows\system32\drivers\ngiodriver_x64 [X] S2 MSSQL$DDNI; no ImagePath S2 Oasis2Service; no ImagePath CMD: dir /a /s C:\found.006 CMD: dir /a C:\Windows\System32\Tasks ***************** "HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon" => key removed successfully HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => value restored successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\AllowLegacyWebView => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\AllowUnhashedWebView => value removed successfully HKU\Default\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktopCleanupWizard => value removed successfully HKU\Default User\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktopCleanupWizard => value not found. hklm\System\ControlSet001\Control\Session Manager\\BootExecute => value restored successfully Lavasoft Ad-Aware Service => service removed successfully McComponentHostService => service removed successfully *etadpug => service removed successfully ecxncijc => service removed successfully epmnvwyv => service removed successfully MSSQL$DDNI => service removed successfully Oasis2Service => service removed successfully ========= dir /a /s C:\found.006 ========= Volume in drive C has no label. Volume Serial Number is 84BC-F95D Directory of C:\found.006 03/03/2016 03:04 PM . 03/03/2016 03:04 PM .. 09/10/2015 11:51 PM 196,608 file0000.chk 02/28/2016 06:15 PM 3,622 file0001.chk 2 File(s) 200,230 bytes Total Files Listed: 2 File(s) 200,230 bytes 2 Dir(s) 128,020,713,472 bytes free ========= End of CMD: ========= ========= dir /a C:\Windows\System32\Tasks ========= Volume in drive C has no label. Volume Serial Number is 84BC-F95D Directory of C:\Windows\System32\Tasks 03/12/2016 06:55 AM . 03/12/2016 06:55 AM .. 08/17/2011 03:14 PM 2,812 59c65a60 08/17/2011 03:14 PM 2,812 6abb4b60 12/22/2015 12:53 AM 3,886 Adobe Acrobat Update Task 02/10/2016 01:26 AM 3,768 Adobe Flash Player Updater 03/03/2016 02:54 PM AVAST Software 02/28/2016 06:23 PM 4,182 avast! Emergency Update 06/10/2013 11:31 AM 2,854 AVG-Secure-Search-Update_JUNE2013_HP_rmv 06/03/2013 03:20 AM 2,854 AVG-Secure-Search-Update_JUNE2013_TB_rmv 08/17/2011 03:14 PM 2,812 b771fe00 08/18/2011 03:17 AM 2,778 ca77cd80 02/03/2016 10:01 PM 3,642 GoogleUpdateTaskMachineCore 02/03/2016 10:01 PM 3,894 GoogleUpdateTaskMachineUA 02/03/2016 10:00 PM 3,482 GoogleUpdateTaskUserS-1-5-21-1798455190-986609235-2888039337-1001Core 02/03/2016 10:00 PM 3,878 GoogleUpdateTaskUserS-1-5-21-1798455190-986609235-2888039337-1001UA 11/16/2011 12:20 PM Microsoft 11/20/2010 05:58 PM OfficeSoftwareProtectionPlatform 02/28/2016 03:06 AM 3,052 SafeZone scheduled Autoupdate 1455187739 08/30/2012 09:19 PM SONY 03/03/2016 02:54 PM Sony Corporation 05/10/2011 09:21 PM Symantec 05/17/2013 01:40 AM 2,802 task669556 08/25/2011 04:05 PM 3,154 thpm331580783402690592 09/22/2012 05:36 PM 3,204 VAIO Care 09/22/2012 05:36 PM 3,284 VAIO Care Support 11/17/2012 06:46 PM 2,664 VaudiXUpdaterTask{F2A09392-928B-4B6C-8529-C725BE4B293E} 09/22/2012 05:36 PM 4,312 VCOneClick 12/02/2011 06:23 PM 3,102 win402b40 01/19/2012 02:07 PM WPD 09/02/2012 06:52 PM 3,314 {07B13964-78B2-41E7-BB80-8EF3B8126A67} 09/22/2013 12:49 AM 3,212 {F992848E-4F81-4169-9D4A-69A86BE7A1E4} 23 File(s) 75,754 bytes 9 Dir(s) 128,020,713,472 bytes free ========= End of CMD: ========= ==== End of Fixlog 16:42:33 ====