Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015 Ran by Szymon at 2015-02-04 00:32:43 Run:1 Running from G:\FRTST Loaded Profiles: Szymon (Available profiles: Szymon) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [113952 2014-02-25] (Oracle Corporation) S2 VMUSBArbService; "C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe" [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cpuz136; \??\F:\TEMP\cpuz136\cpuz136_x64.sys [X] U2 V2iMount; No ImagePath S3 VBoxNetAdp; system32\DRIVERS\VBoxNetAdp.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X] S3 XFDriver64; \??\E:\Xfire_New\XFDriver64.sys [X] HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3380270715-3188171858-2067456427-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3380270715-3188171858-2067456427-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch C:\ProgramData\McAfee C:\ProgramData\TEMP C:\ProgramData\VMware C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDDlife C:\Users\Szymon\.VirtualBox C:\Windows\System32\Drivers\VBoxUSB.sys C:\Windows\SysWOW64\%TMP% Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. VBoxUSB => Service deleted successfully. VMUSBArbService => Service deleted successfully. catchme => Service deleted successfully. cpuz136 => Service deleted successfully. V2iMount => Service deleted successfully. VBoxNetAdp => Service deleted successfully. VBoxNetFlt => Service deleted successfully. vmci => Service deleted successfully. XFDriver64 => Service deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-3380270715-3188171858-2067456427-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-3380270715-3188171858-2067456427-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. C:\ProgramData\McAfee => Moved successfully. C:\ProgramData\TEMP => Moved successfully. C:\ProgramData\VMware => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDDlife => Moved successfully. C:\Users\Szymon\.VirtualBox => Moved successfully. C:\Windows\System32\Drivers\VBoxUSB.sys => Moved successfully. C:\Windows\SysWOW64\%TMP% => Moved successfully. ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= EmptyTemp: => Removed 420 MB temporary data. The system needed a reboot. ==== End of Fixlog 00:32:54 ====