Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-04-2015
- Ran by minh at 2015-04-21 07:42:42 Run:1
- Running from C:\Users\minh\Desktop
- Loaded Profiles: minh (Available profiles: minh)
- Boot Mode: Normal
- ==============================================
- Content of fixlist:
- *****************
- Start
- CreateRestorePoint:
- CloseProcesses:
- HKLM-x32\...\Run: [] => [X]
- Winlogon\Notify\igfxcui: igfxdev.dll [X]
- CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
- HKU\S-1-5-21-2449617907-3497520671-1790711468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
- HKU\S-1-5-21-2449617907-3497520671-1790711468-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
- SearchScopes: HKU\S-1-5-21-2449617907-3497520671-1790711468-1000 -> {1A5454B2-9035-4B86-941A-29DC183D68AD} URL =
- FF Plugin: @microsoft.com/GENUINE -> disabled No File
- FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
- S3 catchme; \??\C:\ComboFix\catchme.sys [X]
- C:\Users\minh\AppData\Roaming\appdataFr3.bin
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
- CMD: netsh advfirewall reset
- CMD: netsh advfirewall set allprofiles state on
- CMD: ipconfig /flushdns
- EmptyTemp:
- Hosts:
- End
- *****************
- Restore point was successfully created.
- Processes closed successfully.
- HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
- "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" => Key deleted successfully.
- "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
- "HKU\S-1-5-21-2449617907-3497520671-1790711468-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page => value deleted successfully.
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Search Page => value deleted successfully.
- HKU\S-1-5-21-2449617907-3497520671-1790711468-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
- "HKU\S-1-5-21-2449617907-3497520671-1790711468-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1A5454B2-9035-4B86-941A-29DC183D68AD}" => Key deleted successfully.
- HKCR\CLSID\{1A5454B2-9035-4B86-941A-29DC183D68AD} => Key not found.
- "HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
- "HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
- catchme => Service deleted successfully.
- C:\Users\minh\AppData\Roaming\appdataFr3.bin => Moved successfully.
- "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart" => Key deleted successfully.
- "HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys" => Key deleted successfully.
- "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart" => Key deleted successfully.
- "HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys" => Key deleted successfully.
- ========= netsh advfirewall reset =========
- Ok.
- ========= End of CMD: =========
- ========= netsh advfirewall set allprofiles state on =========
- Ok.
- ========= End of CMD: =========
- ========= ipconfig /flushdns =========
- Windows IP Configuration
- Successfully flushed the DNS Resolver Cache.
- ========= End of CMD: =========
- C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
- Hosts was reset successfully.
- EmptyTemp: => Removed 973.5 MB temporary data.
- The system needed a reboot.
- ==== End of Fixlog 07:43:12 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement