Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-01-2014 Ran by Jessi at 2014-01-23 15:50:47 Run:1 Running from C:\Users\Jessi\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** () C:\Users\Jessi\AppData\Roaming\pwo6\svchost.exe () C:\Users\Jessi\AppData\Local\Temp\_MEI28082\bin\winlogon.exe HKLM-x32\...\Run: [] - [x] HKCU\...\Run: [pwo6] - C:\Users\Jessi\AppData\Roaming\pwo6\svchost.exe [7321472 2014-01-08] () BHO-x32: PassShow - {2d661e5b-7d7a-417c-b5b5-6479017bb314} - C:\Program Files (x86)\PassShow\150.dll () Task: {DC53E1C2-23EA-4FF6-90AA-6A88B552226D} - System32\Tasks\PassShow Update => C:\Program Files (x86)\PassShow\PsUP.exe [2014-01-06] () Task: C:\Windows\Tasks\PassShow Update.job => C:\Program Files (x86)\PassShow\PsUP.exe C:\Windows\System32\Tasks\{9D689C75-3D9F-448E-B2C1-B61E429F0D3B} C:\Users\Jessi\.android C:\Users\Jessi\daemonprocess.txt C:\Users\Jessi\AppData\Local\cache C:\Users\Jessi\AppData\Local\Temp\_MEI28082 C:\Users\Jessi\AppData\Roaming\pwo6 C:\Users\Jessi\AppData\Roaming\Smart PC Solutions ***************** [3204] C:\Users\Jessi\AppData\Roaming\pwo6\svchost.exe => Process closed successfully. [4112] C:\Users\Jessi\AppData\Local\Temp\_MEI28082\bin\winlogon.exe => Process closed successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\pwo6 => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d661e5b-7d7a-417c-b5b5-6479017bb314} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{2d661e5b-7d7a-417c-b5b5-6479017bb314} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DC53E1C2-23EA-4FF6-90AA-6A88B552226D} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC53E1C2-23EA-4FF6-90AA-6A88B552226D} => Key deleted successfully. C:\Windows\System32\Tasks\PassShow Update => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PassShow Update => Key deleted successfully. C:\Windows\Tasks\PassShow Update.job => Moved successfully. C:\Windows\System32\Tasks\{9D689C75-3D9F-448E-B2C1-B61E429F0D3B} => Moved successfully. C:\Users\Jessi\.android => Moved successfully. C:\Users\Jessi\daemonprocess.txt => Moved successfully. C:\Users\Jessi\AppData\Local\cache => Moved successfully. C:\Users\Jessi\AppData\Local\Temp\_MEI28082 => Moved successfully. C:\Users\Jessi\AppData\Roaming\pwo6 => Moved successfully. C:\Users\Jessi\AppData\Roaming\Smart PC Solutions => Moved successfully. ==== End of Fixlog ====