Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-09-2014 Ran by SZEF at 2014-09-10 23:44:30 Run:1 Running from C:\Users\SZEF\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses:S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-08-26] (globalUpdate) [File not signed]S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-08-26] (globalUpdate) [File not signed]R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-08-26] (Cherished Technololgy LIMITED)R2 servervo; C:\Users\SZEF\AppData\Roaming\VOPackage\VOsrv.exe [71680 2014-08-26] () [File not signed]R2 Update WebSpades; C:\Program Files (x86)\WebSpades\updateWebSpades.exe [323360 2014-09-07] ()R2 Util WebSpades; C:\Program Files (x86)\WebSpades\bin\utilWebSpades.exe [323360 2014-09-07] ()R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [528896 2014-08-26] (Fuyu LIMITED) [File not signed]S2 trntv; C:\Users\SZEF\AppData\Roaming\TornTV.com\TornTVSvc.exe [X]R1 {ed7eb956-75ed-460d-8f69-29a93b07afd1}w64; C:\Windows\System32\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}w64.sys [61120 2014-08-25] (StdLib)S3 ASUSProcObsrv; \??\E:\I386\AsPrOb64.sys [X]Task: {0136126B-1C88-4AB4-A15F-9396EA45897E} - System32\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-2 => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-2.exe <==== ATTENTIONTask: {1F08394A-E80B-42D3-97AD-67CB95D3D6B7} - System32\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-5_user => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-5.exe <==== ATTENTIONTask: {21BFAE22-7AD5-4DB1-8672-D127308B98D8} - System32\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-1 => C:\Program Files (x86)\TheTorntv V10\TheTorntv V10-codedownloader.exe <==== ATTENTIONTask: {228F48F8-5F3C-468E-9557-43123570495B} - System32\Tasks\BlockAndSurf Update => C:\Program Files (x86)\ver5BlockAndSurf\N0BlockAndSurfB54.exe <==== ATTENTIONTask: {250BAB48-BD6E-4A0D-99D1-F88769A0A7B0} - System32\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-11 => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-11.exe <==== ATTENTIONTask: {47A5108A-7EAC-4D76-B01B-BC7ADB1C883D} - System32\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-3 => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-3.exe <==== ATTENTIONTask: {4AD625DB-350F-4BD5-87A7-5D613043725E} - System32\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-4 => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-4.exe <==== ATTENTIONTask: {864DE72C-9554-41A7-876A-08CD7DDE5BFF} - System32\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-5 => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-5.exe <==== ATTENTIONTask: {9222458E-B4C4-4751-A3DB-C2FF63AC6F5B} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-26] (globalUpdate) <==== ATTENTIONTask: {98F9D86E-7D3A-48B7-A6C9-5ECA78F00F78} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-26] (globalUpdate) <==== ATTENTIONTask: {B65A03E7-B6A9-46C0-9484-52932C1179B6} - System32\Tasks\9f3778b9-5e3c-4bcc-9650-0df564f358ad => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-4.exe <==== ATTENTIONTask: C:\Windows\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-1.job => C:\Program Files (x86)\TheTorntv V10\TheTorntv V10-codedownloader.exe <==== ATTENTIONTask: C:\Windows\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-11.job => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-11.exe <==== ATTENTIONTask: C:\Windows\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-2.job => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-2.exe <==== ATTENTIONTask: C:\Windows\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-3.job => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-3.exe <==== ATTENTIONTask: C:\Windows\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-4.job => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-4.exe <==== ATTENTIONTask: C:\Windows\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-5.job => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-5.exe <==== ATTENTIONTask: C:\Windows\Tasks\3df4ae78-cb14-43a9-9da2-ecaae484d736-5_user.job => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-5.exe <==== ATTENTIONTask: C:\Windows\Tasks\9f3778b9-5e3c-4bcc-9650-0df564f358ad.job => C:\Program Files (x86)\TheTorntv V10\3df4ae78-cb14-43a9-9da2-ecaae484d736-4.exe <==== ATTENTIONTask: C:\Windows\Tasks\BlockAndSurf Update.job => C:\Program Files (x86)\ver5BlockAndSurf\N0BlockAndSurfB54.exe <==== ATTENTIONTask: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTIONTask: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTIONHKU\S-1-5-21-3915100798-2594843860-4059984336-1000\...\Run: [TornTv Downloader] => C:\Users\SZEF\AppData\Roaming\TornTV.com\Torntv Downloader.exe /c=startupStartup: C:\Users\SZEF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnkGroupPolicy: Group Policy on Chrome detected <======= ATTENTIONShortcutWithArgument: C:\Users\SZEF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVShortcutWithArgument: C:\Users\SZEF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVShortcutWithArgument: C:\Users\SZEF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVShortcutWithArgument: C:\Users\SZEF\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://istart.webssearches.com/?type=sc&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVHKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFV&q={searchTerms}HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVHKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVHKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFV&q={searchTerms}StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVSearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFV&q={searchTerms}SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFV&q={searchTerms}SearchScopes: HKLM-x32 - DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFV&q={searchTerms}SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFV&q={searchTerms}BHO: No Name -> {11111111-1111-1111-1111-110611331111} -> No FileBHO: BlockAndSurf -> {B4D7DCE9-70A4-6253-F5E3-52BD99EF69C2} -> C:\Program Files (x86)\ver5BlockAndSurf\178_x64.dll ()BHO-x32: No Name -> {11111111-1111-1111-1111-110611331111} -> No FileBHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No FileFF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\SZEF\AppData\Roaming\Mozilla\Firefox\Profiles\95ouojc5.default\extensions\faststartff@gmail.comFF HKCU\...\Firefox\Extensions: [{706D7F0F-33E2-8C65-3E51-0956792D987E}] - C:\Program Files (x86)\ver5BlockAndSurf\178.xpiFF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://istart.webssearches.com/?type=sc&ts=1409013418&from=ild&uid=ST9320325AS_S2WJNPFVXXXXS2WJNPFVC:\Program Files (x86)\globalUpdateC:\Program Files (x86)\SiteLookupC:\Users\SZEF\AppData\Local\globalUpdateC:\Users\SZEF\AppData\Roaming\SimilarAddonC:\Windows\system32\Drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}w64.sysC:\Windows\SysWOW64\GroupPolicy\GPT.INIFolder: C:\Users\SZEF\AppData\Roaming\Opera Software\Opera Stable\ExtensionsCMD: type "C:\Users\SZEF\AppData\Roaming\Opera Software\Opera Stable\Preferences"Reg: reg query "HKLM\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command" /s ***************** Processes closed successfully. The system needed a reboot. ==== End of Fixlog ====