Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-07-2014 01
- Ran by PAUL at 2014-07-25 22:17:26 Run:3
- Running from C:\Users\PAUL\Desktop\Mailware
- Boot Mode: Normal
- ==============================================
- Content of fixlist:
- *****************
- () C:\Windows\System32\mstcntrs.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- HKLM-x32\...\Run: [] => [X]
- GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
- SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
- SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.google.de/search?q={searchTerms}&hl=de&gl=de&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
- SearchScopes: HKLM-x32 - DefaultScope value is missing.
- SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- BHO: DownloadProtect Extension -> {C654F3FE-8E84-4BB7-87CF-8D9171FC3C73} -> C:\Program Files\{CAC9EFB5-4F70-4EDE-A049-A412D9A1075B}\{87EDDB32-D7FA-4FDB-A735-B25763682037}.bin (Download Protect)
- C:\Program Files\{CAC9EFB5-4F70-4EDE-A049-A412D9A1075B}\{87EDDB32-D7FA-4FDB-A735-B25763682037}.bin
- BHO-x32: DownloadProtect Extension -> {C654F3FE-8E84-4BB7-87CF-8D9171FC3C73} -> C:\Program Files (x86)\{7253BAE9-9C31-4697-89ED-1A8C78DC192E}\{CEDCB182-6F48-496A-B42D-6AE9F0BBD095}.bin (Download Protect)
- C:\Program Files (x86)\{7253BAE9-9C31-4697-89ED-1A8C78DC192E}\{CEDCB182-6F48-496A-B42D-6AE9F0BBD095}.bin (Download Protect)
- FF Plugin: @microsoft.com/GENUINE - disabled No File
- FF HKLM-x32\...\Firefox\Extensions: [{5960B094-9894-4CB6-8555-77E5440285A3}] - C:\Windows\Installer\{0D055583-FA89-496D-8684-C63CC7004BF5}\{5960B094-9894-4CB6-8555-77E5440285A3}.xpi
- FF Extension: Download Protect - C:\Windows\Installer\{0D055583-FA89-496D-8684-C63CC7004BF5}\{5960B094-9894-4CB6-8555-77E5440285A3}.xpi [2014-07-25]
- C:\Windows\Installer\{0D055583-FA89-496D-8684-C63CC7004BF5}\{5960B094-9894-4CB6-8555-77E5440285A3}.xpi [2014-07-25]
- CHR Extension: (Download Protect) - C:\Users\PAUL\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjhjoemoechogmnomaebajbikjbicafe [2014-07-25]
- CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
- R2 SebrchProtocolHost; C:\Windows\system32\mstcntrs.exe [118784 2013-12-23] () [File not signed]
- 2014-07-25 19:02 - 2014-07-25 19:02 - 00000000 ____D () C:\Program Files\{CAC9EFB5-4F70-4EDE-A049-A412D9A1075B}
- 2014-07-25 19:02 - 2014-07-25 19:02 - 00000000 ____D () C:\Program Files (x86)\{7253BAE9-9C31-4697-89ED-1A8C78DC192E}
- 2014-07-25 17:31 - 2014-07-25 19:00 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- 2014-07-25 17:31 - 2014-07-25 18:36 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Users\PAUL\AppData\Local\Temp\avgnt.exe
- C:\Users\PAUL\AppData\Local\Temp\ICReinstall_COMPUTER_BILD-Download-Manager_fuer_mp3tagv258setup.exe
- C:\Users\PAUL\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
- C:\Users\PAUL\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
- C:\Users\PAUL\AppData\Local\Temp\QuickStores_Unlocker.exe
- Task: {051C2A8A-F99C-442B-9BF1-3C2DF77BDADF} - System32\Tasks\{2A0BDC3A-94D2-4A9A-B4E1-527FC0D712A8} => Chrome.exe
- Task: {2AB67FC4-35BC-45CA-A462-F56EAA1F0F4C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-24] (Google Inc.)
- Task: {2D41049D-A1C5-4379-A7E0-BF3F5936F632} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000Core => C:\Users\PAUL\AppData\Local\Google\Update\GoogleUpdate.exe [2013-11-09] (Google Inc.)
- Task: {4A414945-AB07-4987-8A8C-CFFFF47390DE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-24] (Google Inc.)
- Task: {4ED13A86-7A6C-4DAF-B59A-595B4ABE889C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000UA => C:\Users\PAUL\AppData\Local\Google\Update\GoogleUpdate.exe [2013-11-09] (Google Inc.)
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000Core.job => C:\Users\PAUL\AppData\Local\Google\Update\GoogleUpdate.exe
- Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000UA.job => C:\Users\PAUL\AppData\Local\Google\Update\GoogleUpdate.exe
- 2013-12-23 21:32 - 2013-12-23 21:32 - 00118784 _____ () C:\Windows\system32\mstcntrs.exe
- AlternateDataStreams: C:\ProgramData\Temp:AD022376
- *****************
- [1528] C:\Windows\System32\mstcntrs.exe => Process closed successfully.
- [4380] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => Process closed successfully.
- [5508] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => Process closed successfully.
- [5508] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => Process closed successfully.
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => No running process found
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => No running process found
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe => No running process found
- HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
- C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
- C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
- "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
- "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
- HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}" => Key deleted successfully.
- "HKCR\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}" => Key deleted successfully.
- "C:\Program Files\{CAC9EFB5-4F70-4EDE-A049-A412D9A1075B}\{87EDDB32-D7FA-4FDB-A735-B25763682037}.bin" => File/Directory not found.
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}" => Key deleted successfully.
- "HKCR\Wow6432Node\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}" => Key deleted successfully.
- "C:\Program Files (x86)\{7253BAE9-9C31-4697-89ED-1A8C78DC192E}\{CEDCB182-6F48-496A-B42D-6AE9F0BBD095}.bin (Download Protect)" => File/Directory not found.
- "HKLM\Software\MozillaPlugins\FF Plugin: @microsoft.com/GENUINE - disabled No File" => Key not found.
- "FF Plugin: @microsoft.com/GENUINE - disabled No File" => not found.
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{5960B094-9894-4CB6-8555-77E5440285A3} => Value not found.
- C:\Windows\Installer\{0D055583-FA89-496D-8684-C63CC7004BF5}\{5960B094-9894-4CB6-8555-77E5440285A3}.xpi not found.
- "C:\Windows\Installer\{0D055583-FA89-496D-8684-C63CC7004BF5}\{5960B094-9894-4CB6-8555-77E5440285A3}.xpi [2014-07-25]" => File/Directory not found.
- C:\Users\PAUL\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjhjoemoechogmnomaebajbikjbicafe directory not found.
- "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
- SebrchProtocolHost => Service deleted successfully.
- "C:\Program Files\{CAC9EFB5-4F70-4EDE-A049-A412D9A1075B}" => File/Directory not found.
- "C:\Program Files (x86)\{7253BAE9-9C31-4697-89ED-1A8C78DC192E}" => File/Directory not found.
- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
- C:\Users\PAUL\AppData\Local\Temp\avgnt.exe => Moved successfully.
- C:\Users\PAUL\AppData\Local\Temp\ICReinstall_COMPUTER_BILD-Download-Manager_fuer_mp3tagv258setup.exe => Moved successfully.
- C:\Users\PAUL\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe => Moved successfully.
- C:\Users\PAUL\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe => Moved successfully.
- C:\Users\PAUL\AppData\Local\Temp\QuickStores_Unlocker.exe => Moved successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{051C2A8A-F99C-442B-9BF1-3C2DF77BDADF}" => Key deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{051C2A8A-F99C-442B-9BF1-3C2DF77BDADF}" => Key deleted successfully.
- C:\Windows\System32\Tasks\{2A0BDC3A-94D2-4A9A-B4E1-527FC0D712A8} => Moved successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2A0BDC3A-94D2-4A9A-B4E1-527FC0D712A8}" => Key deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AB67FC4-35BC-45CA-A462-F56EAA1F0F4C}" => Key not found.
- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2D41049D-A1C5-4379-A7E0-BF3F5936F632}" => Key deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D41049D-A1C5-4379-A7E0-BF3F5936F632}" => Key deleted successfully.
- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000Core => Moved successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000Core" => Key deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A414945-AB07-4987-8A8C-CFFFF47390DE}" => Key not found.
- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4ED13A86-7A6C-4DAF-B59A-595B4ABE889C}" => Key deleted successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4ED13A86-7A6C-4DAF-B59A-595B4ABE889C}" => Key deleted successfully.
- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000UA => Moved successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000UA" => Key deleted successfully.
- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job not found.
- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job not found.
- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000Core.job => Moved successfully.
- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-880213145-57001013-3768279162-1000UA.job => Moved successfully.
- C:\Windows\system32\mstcntrs.exe => Moved successfully.
- C:\ProgramData\Temp => ":AD022376" ADS removed successfully.
- The system needed a reboot.
- ==== End of Fixlog ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement