Fix result of Farbar Recovery Scan Tool (x64) Version: 05-03-2017 Ran by SYSTEM (05-03-2017 23:14:49) Run:1 Running from f:\ Boot Mode: Recovery ============================================== fixlist content: ***************** [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b] GroupPolicy: Restriction <======= ATTENTION S0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [0 2017-01-24] () <==== ATTENTION (zero byte File/Folder) 2016-09-27 15:13 - 2017-01-24 16:35 - 0619840 ____N () C:\Users\Tony Gomez\AppData\Local\Temp\0Kraken71ChromaDevProps.dll 2016-12-26 13:42 - 2017-01-24 16:35 - 0619616 ____N () C:\Users\Tony Gomez\AppData\Local\Temp\0ManOWarDevProps.dll HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [9926112 2016-03-10] (Malwarebytes) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) S0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [0 2017-01-24] () <==== ATTENTION (zero byte File/Folder) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) C:\Windows\System32\drivers\MBAMSwissArmy.sys ***************** [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b] => Error: No automatic fix found for this entry. C:\Windows\System32\GroupPolicy\Machine => moved successfully C:\Windows\System32\GroupPolicy\GPT.ini => moved successfully C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully HKLM\System\ControlSet001\Services\MBAMSwissArmy => key removed successfully MBAMSwissArmy => service removed successfully C:\Users\Tony Gomez\AppData\Local\Temp\0Kraken71ChromaDevProps.dll => moved successfully C:\Users\Tony Gomez\AppData\Local\Temp\0ManOWarDevProps.dll => moved successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Malwarebytes Anti-Malware => value removed successfully HKLM\System\ControlSet001\Services\MBAMScheduler => key removed successfully MBAMScheduler => service removed successfully HKLM\System\ControlSet001\Services\MBAMService => key removed successfully MBAMService => service removed successfully HKLM\System\ControlSet001\Services\MBAMProtector => key removed successfully MBAMProtector => service removed successfully MBAMScheduler => service not found. MBAMService => service not found. MBAMProtector => service not found. MBAMSwissArmy => service not found. HKLM\System\ControlSet001\Services\MBAMWebAccessControl => key removed successfully MBAMWebAccessControl => service removed successfully C:\Windows\System32\drivers\MBAMSwissArmy.sys => moved successfully ==== End of Fixlog 23:14:49 ====