Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-01-2015 Ran by Tommy at 2015-01-10 18:16:22 Run:1 Running from C:\Users\Tommy\Desktop Loaded Profile: Tommy (Available profiles: Tommy) Boot Mode: Normal ============================================== Content of fixlist: ***************** CreateRestorePoint: HKU\S-1-5-21-393944708-137268486-1877606601-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 243 more characters). <==== Poweliks! SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: No Name -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> No File 2014-12-23 16:15 - 2014-12-23 16:15 - 00000064 _____ () C:\Users\Tommy\AppData\Local\9086ed19628b63613bd1dcaad423885c CustomCLSID: HKU\S-1-5-21-393944708-137268486-1877606601-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 251 more characters). <==== Poweliks? EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Restore point was successfully created. "HKU\S-1-5-21-393944708-137268486-1877606601-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key Deleted Successfully. "HKU\S-1-5-21-393944708-137268486-1877606601-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" => Key deleted successfully. HKCR\Wow6432Node\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} => Key not found. C:\Users\Tommy\AppData\Local\9086ed19628b63613bd1dcaad423885c => Moved successfully. HKU\S-1-5-21-393944708-137268486-1877606601-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} => Key not found. ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.5.7601 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. {8DA5AB9D-DD52-4213-9484-3BFD92F0AE41} canceled. {BFA093F1-0543-49E3-92C8-8F604EC63A0C} canceled. {17BEFB5D-85C8-4214-AC84-66A24D95C472} canceled. {9AD32EDC-D897-48CB-9D45-B3EE94A97F12} canceled. {FDED44FB-FE1E-404A-B854-8A85627E05D0} canceled. {6B6AF47B-5ED9-4F76-A921-99810C9A749D} canceled. {5FDAB6C4-EFDD-4CA8-B8B1-C572DFD6F9F5} canceled. {5823AE6A-FC7C-4638-AFAD-C8BE871D3B8E} canceled. {EEED5C0E-1E22-4750-932E-F06899D6BFB8} canceled. {F81A3F64-8AFB-4A11-8A62-E270A9DA07A2} canceled. 10 out of 10 jobs canceled. ========= End of CMD: ========= EmptyTemp: => Removed 40.9 GB temporary data. The system needed a reboot. ==== End of Fixlog 21:40:11 ====