Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-01-2014 01 Ran by admin at 2014-02-07 15:35:52 Run:1 Running from C:\Documents and Settings\admin\Pulpit\frst Boot Mode: Normal ============================================== Content of fixlist: ***************** (Huawei Technologies Co., Ltd.) C:\Documents and Settings\admin\Dane aplikacji\PLAY ONLINE\ouc.exe HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k HKCU\...\Run: [HW_OPENEYE_OUC_PLAY ONLINE] - C:\Program Files\PLAY ONLINE\UpdateDog\ouc.exe [110592 2014-01-29] (Huawei Technologies Co., Ltd.) HKCU\...\Policies\Explorer: [EditLevel] 0 HKCU\...\Policies\Explorer: [NoFileMenu] 0 HKCU\...\Policies\Explorer: [NoCommonGroups] 0 DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab S2 yksvc; %SystemRoot%\System32\yk51x86.dll [x] S3 amsint32; \??\C:\WINDOWS\system32\drivers\hqrii.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 dzfccyxf; dzfccyxf.sys [x] S3 kwjiusbz; kwjiusbz.sys [x] S2 SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [x] U3 TlntSvr; AlternateDataStreams: C:\WINDOWS\regedit.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} C:\WINDOWS\system32\Drivers\tavwssrh.sys C:\WINDOWS\system32\Drivers\dzfccyxf.sys C:\WINDOWS\system32\Drivers\kowgwmdt.sys C:\WINDOWS\System32\ckvo0.dll C:\WINDOWS\system32\ckvo.exe C:\WINDOWS\system32\EXPLORER.EXE C:\autorun.inf C:\autorun.txt C:\ckgn.exe C:\tukp.exe D:\autorun.inf D:\gyfs.pif D:\lmkokb.exe ***************** [1896] C:\Documents and Settings\admin\Dane aplikacji\PLAY ONLINE\ouc.exe => Process closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\HW_OPENEYE_OUC_PLAY ONLINE => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EditLevel => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFileMenu => Value deleted successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoCommonGroups => Value deleted successfully. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. HKCR\CLSID\{68282C51-9459-467B-95BF-3C0E89627E55} => Key deleted successfully. yksvc => Service deleted successfully. amsint32 => Service deleted successfully. catchme => Service deleted successfully. dzfccyxf => Service deleted successfully. kwjiusbz => Service deleted successfully. SSPORT => Service deleted successfully. TlntSvr => Service deleted successfully. C:\WINDOWS\regedit.exe => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS removed successfully. C:\WINDOWS\system32\Drivers\tavwssrh.sys => Moved successfully. C:\WINDOWS\system32\Drivers\dzfccyxf.sys => Moved successfully. C:\WINDOWS\system32\Drivers\kowgwmdt.sys => Moved successfully. C:\WINDOWS\System32\ckvo0.dll => Moved successfully. C:\WINDOWS\system32\ckvo.exe => Moved successfully. C:\WINDOWS\system32\EXPLORER.EXE => Moved successfully. C:\autorun.inf => Moved successfully. C:\autorun.txt => Moved successfully. C:\ckgn.exe => Moved successfully. C:\tukp.exe => Moved successfully. D:\autorun.inf => Moved successfully. D:\gyfs.pif => Moved successfully. D:\lmkokb.exe => Moved successfully. ==== End of Fixlog ====