Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-10-2014 Ran by Torunscy at 2014-10-18 20:16:22 Run:1 Running from C:\Users\Torunscy\Downloads Loaded Profile: Torunscy (Available profiles: Torunscy & Dzieci) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM-x32\...\Run: [] => [X] HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S3 STHDA; system32\DRIVERS\stwrt64.sys [X] C:\ProgramData\Malwarebytes C:\ProgramData\Thunder Network C:\ProgramData\Xunlei DeleteKey: HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes DeleteKey: HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes CMD: del /q C:\Users\Torunscy\Downloads\adwcleaner*.exe CMD: sc config "PLAY ONLINE. RunOuc" start= demand EmptyTemp: ***************** Processes closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. catchme => Service deleted successfully. MBAMSwissArmy => Service deleted successfully. STHDA => Service deleted successfully. C:\ProgramData\Malwarebytes => Moved successfully. C:\ProgramData\Thunder Network => Moved successfully. C:\ProgramData\Xunlei => Moved successfully. HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes => Key Deleted successfully. HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes => Key Deleted successfully. HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes => Key Deleted successfully. ========= del /q C:\Users\Torunscy\Downloads\adwcleaner*.exe ========= ========= End of CMD: ========= ========= sc config "PLAY ONLINE. RunOuc" start= demand ========= [SC] ChangeServiceConfig SUCCESS ========= End of CMD: ========= EmptyTemp: => Removed 379.6 MB temporary data. The system needed a reboot. ==== End of Fixlog ====