Fix result of Farbar Recovery Scan Tool (x64) Version: 29-09-2017 Ran by raf (30-09-2017 21:00:26) Run:1 Running from C:\Users\raf\Desktop Loaded Profiles: raf (Available Profiles: raf) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: CloseProcesses: Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction ShellExecuteHooks: No Name - {FD2052F8-9EBE-11E6-B429-64006A5CFC23} - -> No File GroupPolicy: Restriction - Chrome FF ProfilePath: C:\Users\raf\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\fpbra1ko.default\Profiles\fpbra1ko.default [not found] FF Extension: (MEGA) - C:\Users\raf\AppData\Roaming\Mozilla\Firefox\Profiles\fpbra1ko.default\Extensions\firefox@mega.co.nz.xpi [2017-09-28] FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] CHR HomePage: ChromeDefaultData -> hxxp://www.trotux.com/?z=6487ea2abf45c22433c2b00g2z2mebdb3e9z8t3o8z&from=isr&uid=WDCXWD5000LPVX-22V0TT0_WD-WX41A23C3374C3374&type=hp CHR StartupUrls: ChromeDefaultData -> "hxxp://www.trotux.com/?z=6487ea2abf45c22433c2b00g2z2mebdb3e9z8t3o8z&from=isr&uid=WDCXWD5000LPVX-22V0TT0_WD-WX41A23C3374C3374&type=hp" CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.trotux.com/search/?q={searchTerms}&z=6487ea2abf45c22433c2b00g2z2mebdb3e9z8t3o8z&from=isr&uid=WDCXWD5000LPVX-22V0TT0_WD-WX41A23C3374C3374&type=sp CHR DefaultSearchKeyword: ChromeDefaultData -> trotux CHR Profile: C:\Users\raf\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-09-30] S1 fgdsqezj; \??\C:\Windows\system32\drivers\fgdsqezj.sys [X] S1 fgsuyqxp; \??\C:\Windows\system32\drivers\fgsuyqxp.sys [X] S1 fppopxbt; \??\C:\Windows\system32\drivers\fppopxbt.sys [X] S1 kufboaaa; \??\C:\Windows\system32\drivers\kufboaaa.sys [X] S1 labqchln; \??\C:\Windows\system32\drivers\labqchln.sys [X] S1 mmsfqjmn; \??\C:\Windows\system32\drivers\mmsfqjmn.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] 2017-09-30 16:11 - 2017-09-30 16:11 - 000000000 ____D C:\ProgramData\SWCUTemp ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File ShortcutWithArgument: C:\Users\raf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=ChromeDefaultData AlternateDataStreams: C:\ProgramData\TEMP:6B50FDB5 [119] EmptyTemp: ***************** Restore point was successfully created. Processes closed successfully. HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon => key removed successfully HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{FD2052F8-9EBE-11E6-B429-64006A5CFC23} => value removed successfully HKLM\Software\Classes\CLSID\{FD2052F8-9EBE-11E6-B429-64006A5CFC23} => key not found. C:\Windows\system32\GroupPolicy\Machine => moved successfully C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully C:\Users\raf\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\fpbra1ko.default\Profiles\fpbra1ko.default => path removed successfully C:\Users\raf\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\fpbra1ko.default\Profiles\fpbra1ko.default => path removed successfully C:\Users\raf\AppData\Roaming\Mozilla\Firefox\Profiles\fpbra1ko.default\Extensions\firefox@mega.co.nz.xpi => moved successfully HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully Chrome HomePage => removed successfully Chrome StartupUrls => removed successfully Chrome DefaultSearchURL => removed successfully Chrome DefaultSearchKeyword => removed successfully C:\Users\raf\AppData\Local\Google\Chrome\User Data\ChromeDefaultData => moved successfully HKLM\System\CurrentControlSet\Services\fgdsqezj => key removed successfully fgdsqezj => service removed successfully HKLM\System\CurrentControlSet\Services\fgsuyqxp => key removed successfully fgsuyqxp => service removed successfully HKLM\System\CurrentControlSet\Services\fppopxbt => key removed successfully fppopxbt => service removed successfully HKLM\System\CurrentControlSet\Services\kufboaaa => key removed successfully kufboaaa => service removed successfully HKLM\System\CurrentControlSet\Services\labqchln => key removed successfully labqchln => service removed successfully HKLM\System\CurrentControlSet\Services\mmsfqjmn => key removed successfully mmsfqjmn => service removed successfully HKLM\System\CurrentControlSet\Services\Synth3dVsc => key removed successfully Synth3dVsc => service removed successfully HKLM\System\CurrentControlSet\Services\tsusbhub => key removed successfully tsusbhub => service removed successfully HKLM\System\CurrentControlSet\Services\VGPU => key removed successfully VGPU => service removed successfully C:\ProgramData\SWCUTemp => moved successfully HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => key removed successfully HKLM\Software\Classes\CLSID\{B298D29A-A6ED-11DE-BA8C-A68E55D89593} => key not found. C:\Users\raf\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\360c22b137d62ce9\Google Chrome.lnk => Shortcut argument removed successfully. C:\ProgramData\TEMP => ":6B50FDB5" ADS removed successfully. =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 24009918 B Java, Flash, Steam htmlcache => 370347730 B Windows/system/drivers => 1227221 B Edge => 0 B Chrome => 0 B Firefox => 427808811 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 58840887 B systemprofile32 => 186918542 B LocalService => 66228 B NetworkService => 62307291 B raf => 9101350 B UpdatusUser => 0 B UpdatusUser => 0 B RecycleBin => 162578 B EmptyTemp: => 1.1 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 21:01:23 ====