Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Scan Tool (x64) Version:10-10-2015
- Ran by Conner (2015-10-11 00:06:43) Run:1
- Running from C:\Users\Conner\Desktop
- Loaded Profiles: Conner (Available Profiles: Conner)
- Boot Mode: Normal
- ==============================================
- fixlist content:
- *****************
- Start
- CreateRestorePoint:
- CloseProcesses:
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\...\MountPoints2: E - E:\VZW_Software_upgrade_assistant.exe
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\...\MountPoints2: {21a21992-c165-11e3-99db-806e6f6e6963} - D:\DVDSetup.exe
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\...\MountPoints2: {67eaf584-c176-11e3-8324-448a5b6115ed} - E:\VZW_Software_upgrade_assistant.exe
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\...\MountPoints2: {8006f6be-c14f-11e3-9a42-806e6f6e6963} - D:\setup.exe
- HKU\S-1-5-18\...\Run: [GoogleChromeAutoLaunch_4158A702DE94E8F002D78386467F1B31] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-09-23] (Google Inc.)
- AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => No File
- C:\PROGRA~2\SearchProtect
- ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
- GroupPolicy: Restriction - Chrome <======= ATTENTION
- CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
- ProxyServer: [S-1-5-21-3144416939-2421594402-137492813-1000] => http=127.0.0.1:13001
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NS&pvid=22.1.0.9
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NS&pvid=22.5.4.24
- HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NS&pvid=22.5.4.24
- HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NS&pvid=22.5.4.24
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbQlzfY2uPTYeQjAjEDkq4w6O7BEwWot70sldsFqghGWL_tj4X1RI0uLGuNl10eybAY8lI3ovdCrXU4hCuCvAdktNCK4mjcvDpGxupo6jXe0AZ8pjfTxMiBTRENnR-doO3X4i7fJ1T01FGmgHtVpHFSpdEUqKqC384l8zxf0QGMpK-I4XA,,&q={searchTerms}
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NS&pvid=22.5.4.24
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://search.conduit.com/?gd=&ctid=ct3325286&octid=eb_original_ctid&isid=m60087815-f195-473b-a527-aa1b6dbe5c9c&searchsource=55&cui=&um=5&up=sp32f94329-5101-47ed-9722-9918b8e6314c&sspv=
- SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=100&itype=a&ver=15005&tm=315&src=ds&p={searchTerms}
- SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbQlzfY2uPTYeQjAjEDkq4w6O7BEwWot70sldsFqghGWL_tj4X1RI0uLGuNl10eybAY8lI3ovdCrXU4hCuCvAdktNCK4mjcvDpGxupo6jXe0AZ8pjfTxMiBTRENnR-doO3X4i7fJ1T01FGmgHtVpHFSpdEUqKqC384l8zxf0QGMpK-I4Ww,,&q={searchTerms}
- SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbQlzfY2uPTYeQjAjEDkq4w6O7BEwWot70sldsFqghGWL_tj4X1RI0uLGuNl10eybAY8lI3ovdCrXU4hCuCvAdktNCK4mjcvDpGxupo6jXe0AZ8pjfTxMiBTRENnR-doO3X4i7fJ1T01FGmgHtVpHFSpdEUqKqC384l8zxf0QGMpK-I4Ww,,&q={searchTerms}
- SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=100&itype=a&ver=15005&tm=315&src=ds&p={searchTerms}
- SearchScopes: HKU\S-1-5-21-3144416939-2421594402-137492813-1000 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbQlzfY2uPTYeQjAjEDkq4w6O7BEwWot70sldsFqghGWL_tj4X1RI0uLGuNl10eybAY8lI3ovdCrXU4hCuCvAdktNCK4mjcvDpGxupo6jXe0AZ8pjfTxMiBTRENnR-doO3X4i7fJ1T01FGmgHtVpHFSpdEUqKqC384l8zxf0QGMpK-I4XA,,&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-3144416939-2421594402-137492813-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbQlzfY2uPTYeQjAjEDkq4w6O7BEwWot70sldsFqghGWL_tj4X1RI0uLGuNl10eybAY8lI3ovdCrXU4hCuCvAdktNCK4mjcvDpGxupo6jXe0AZ8pjfTxMiBTRENnR-doO3X4i7fJ1T01FGmgHtVpHFSpdEUqKqC384l8zxf0QGMpK-I4XA,,&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-3144416939-2421594402-137492813-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=100&itype=a&ver=15005&tm=315&src=ds&p={searchTerms}
- BHO: MediaPlayerplus -> {11111111-1111-1111-1111-110511421146} -> C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll [2014-04-12] (Freeven)
- BHO: Quiknowledge -> {323C6E6D-1621-470F-8A52-4FDEC4E75E40} -> C:\Program Files\Quiknowledge\IE\QuiknowledgeClientIE.dll No File
- C:\Program Files (x86)\MediaPlayerplus
- C:\Program Files\Quiknowledge
- BHO-x32: PriceGong - Price Comparison -> {1631550F-191D-4826-B069-D9439253D926} -> C:\Program Files (x86)\PriceGong\2.6.11\PriceGongIE.dll No File
- C:\Program Files (x86)\PriceGong
- BHO-x32: No Name -> {59A062A1-5ECA-4a1a-BC44-B2A9283A8ACB} -> No File
- BHO-x32: Re-Markable -> {A62BF774-18B1-2C80-0363-9AD7072BB9A8} -> C:\Program Files (x86)\Re-Markable-soft\171.dll No File
- C:\Program Files (x86)\Re-Markable-soft
- Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
- Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
- Toolbar: HKU\S-1-5-21-3144416939-2421594402-137492813-1000 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
- Toolbar: HKU\S-1-5-21-3144416939-2421594402-137492813-1000 -> No Name - {4F524A2D-5637-4300-76A7-7A786E7484D7} - No File
- FF HKU\S-1-5-21-3144416939-2421594402-137492813-1000\...\Firefox\Extensions: [{C8A7850F-CCA1-ACD7-8CAF-562C883D9F80}] - C:\Program Files (x86)\Re-Markable-soft\171.xpi => not found
- C:\Program Files (x86)\Re-Markable-soft
- S2 3010859aeca4507.exe; C:\Users\Conner\AppData\Local\62b7abbdd1dd891801818168dbf983f4\3010859aeca4507.exe [X]
- C:\Users\Conner\AppData\Local\62b7abbdd1dd891801818168dbf983f4
- S2 77854be4be65e07afcf61541e60bdd79.exe; C:\Users\Conner\AppData\Local\77854be4be65e07afcf61541e60bdd79\77854be4be65e07afcf61541e60bdd79.exe [X]
- C:\Users\Conner\AppData\Local\77854be4be65e07afcf61541e60bdd79
- S2 935163118729163.exe; C:\Users\Conner\AppData\Local\f16100ccb3472d157d90c1d3816fad92\935163118729163.exe [X]
- C:\Users\Conner\AppData\Local\f16100ccb3472d157d90c1d3816fad92
- S2 a37af3405cfe910.exe; C:\Users\Conner\AppData\Local\db7b2d584efdc2710cd94ae4f27c8abb\a37af3405cfe910.exe [X]
- C:\Users\Conner\AppData\Local\db7b2d584efdc2710cd94ae4f27c8abb
- S2 ASUSWireless; "C:\Program Files (x86)\ASUS\PCE-N53 WLAN Card Utilities\Common\ASUSService.exe" [X]
- S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [X] <==== ATTENTION
- C:\Program Files (x86)\MyPC Backup
- S4 ControlProgramSchema.exe; C:\Users\Conner\AppData\Local\ArchiveCursorSDK\ArchiveCursorSDK.exe [X]
- C:\Users\Conner\AppData\Local\ArchiveCursorSDK
- S2 ee3327228c51020.exe; C:\Users\Conner\AppData\Local\48274b3ff1ca2ff16f2077c894bea374\ee3327228c51020.exe [X]
- C:\Users\Conner\AppData\Local\48274b3ff1ca2ff16f2077c894bea374
- S2 EncondingRepositoryThumbnail.exe; C:\Users\Conner\AppData\Local\e2fad099f894dd30b50f090b0ab6e51b\EncondingRepositoryThumbnail.exe [X]
- C:\Users\Conner\AppData\Local\e2fad099f894dd30b50f090b0ab6e51b
- S2 FirmwareMBRRegister.exe; C:\Users\Conner\AppData\Local\FirmwareMBRRegister\FirmwareMBRRegister.exe [X]
- C:\Users\Conner\AppData\Local\FirmwareMBRRegister
- S2 InteractivePrivacyWizard.exe; C:\Users\Conner\AppData\Local\InteractivePrivacyWizard\InteractivePrivacyWizard.exe [X]
- C:\Users\Conner\AppData\Local\InteractivePrivacyWizard
- S2 PirritDesktop; C:\Users\Conner\AppData\Local\PirritSuggestor\PirritService.exe [X]
- C:\Users\Conner\AppData\Local\PirritSuggestor
- S2 RalinkRegistryWriter; "C:\Program Files (x86)\ASUS\PCE-N53 WLAN Card Utilities\Common\RaRegistry.exe" [X]
- S2 Re-Markable; C:\Program Files (x86)\Re-Markable Corp\Re-Markable158.exe [X]
- C:\Program Files (x86)\Re-Markable Corp
- S2 schemathumbnailapi.exe; C:\Users\Conner\AppData\Local\schemathumbnailapi\schemathumbnailapi.exe [X]
- C:\Users\Conner\AppData\Local\schemathumbnailapi
- S2 sharewareracengnGUI.exe; C:\Users\Conner\AppData\Local\sharewareracengnGUI\sharewareracengnGUI.exe [X]
- C:\Users\Conner\AppData\Local\sharewareracengnGUI
- S2 SystemkService; C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe [X]
- C:\Program Files (x86)\Settings Manager
- S2 wbsvc; "C:\Program Files\WebBar\wbsvc.exe" --service [X]
- C:\Program Files\WebBar
- S3 cocippsz; C:\Windows\System32\Drivers\cocippsz.sys [423240 2014-04-13] (AVAST Software)
- C:\Windows\System32\Drivers\cocippsz.sys
- S3 qjsliszn; C:\Windows\System32\Drivers\qjsliszn.sys [421704 2014-04-13] (AVAST Software)
- C:\Windows\System32\Drivers\qjsliszn.sys
- S3 xnribqit; C:\Windows\System32\Drivers\xnribqit.sys [423240 2014-05-01] (AVAST Software)
- C:\Windows\System32\Drivers\xnribqit.sys
- S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
- S1 F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg [X]
- S1 F06DEFF2-5B9C-490D-910F-35D3A91196223; \??\C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc3.cfg [X]
- S3 MSICDSetup; \??\D:\CDriver64.sys [X]
- S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
- S1 qknfd; system32\drivers\qknfd.sys [X]
- S3 RgFltX64; \??\C:\Users\Conner\AppData\Local\ArchiveCursorSDK\RgFltX64.sys [X]
- C:\Windows\system32\drivers\EagleX64.sys
- C:\Program Files (x86)\Settings Manager
- D:\CDriver64.sys
- D:\NTIOLib_X64.sys
- C:\Windows\system32\drivers\qknfd.sys
- C:\Users\Conner\AppData\Local\ArchiveCursorSDK
- 2015-10-07 21:52 - 2015-10-07 21:52 - 00000000 _____ C:\Users\Conner\AppData\Local\{27916B05-7DEB-416D-A6FB-15A028FF5413}
- 2015-10-09 01:00 - 2014-07-21 02:08 - 00000000 ____D C:\ProgramData\CLickFaorSaaLe
- 2015-10-09 02:24 - 2015-10-09 02:24 - 0745721 _____ ( ) C:\Program Files (x86)\popappsetup.exe
- 2014-04-11 06:25 - 2014-04-11 06:25 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
- C:\Users\Conner\AppData\Local\Temp\devcon64.exe
- C:\Users\Conner\AppData\Local\Temp\NGM.exe
- C:\Users\Conner\AppData\Local\Temp\NGMDll.dll
- C:\Users\Conner\AppData\Local\Temp\NGMResource.dll
- Task: {0B90153C-C19B-418C-9243-7C9CAB9A6B8C} - System32\Tasks\WebBarUpdateTask => C:\Program Files\WebBar\wbsvc.exe <==== ATTENTION
- C:\Program Files\WebBar
- Task: {1874B5F8-3ECD-4DB9-8843-37223A5609A4} - \Driver Support-RTMRules -> No File <==== ATTENTION
- Task: {218AB6D6-F7E5-461E-83B5-77D17C12BAA1} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
- C:\Program Files (x86)\AnyProtectEx
- Task: {64C8E43D-8A41-4783-9E2C-7B3E9BB48DF6} - System32\Tasks\PCHelpers1st => C:\Program Files (x86)\Optimizer Elite Max\Optimizer Elite Max.exe <==== ATTENTION
- C:\Program Files (x86)\Optimizer Elite Max
- Task: {89E798B5-145B-4195-8B58-6E7E979210F0} - \Driver Support-RTMUpdater -> No File <==== ATTENTION
- Task: {8D1FB70F-1E26-40E3-AB3D-14471A10364B} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
- Task: {8F6F5446-3A1D-44F3-A9C7-671B8D3EAA5B} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
- Task: {AAF7CA21-4831-487F-BF95-91361E8BCABA} - \CIMT_S-1-5-21-3144416939-2421594402-137492813-1000 -> No File <==== ATTENTION
- Task: {B80C02E1-D12A-49FB-98B6-1085050AB2E0} - System32\Tasks\WebBarLaunchTask => C:\Program Files\WebBar\wbsvc.exe <==== ATTENTION
- Task: {BBC62ECE-B32E-4C83-9F57-C600DE6B57C9} - \ConsumerInputUpdateTaskMachineUA -> No File <==== ATTENTION
- Task: {D8C633FA-0662-4A6F-8663-18C21CB6094A} - \RocketTab -> No File <==== ATTENTION
- Task: {DDF3D2CA-2CA5-44FD-A57E-CA7F91CE988C} - System32\Tasks\PCHelpers_period => C:\Program Files (x86)\Optimizer Elite Max\Optimizer Elite Max.exe <==== ATTENTION
- Task: {DE70D878-C38D-4E6C-85A4-F8C375EED3BF} - \Driver Support-RTMScanRunOnce -> No File <==== ATTENTION
- Task: {F8C75149-55A3-4F87-9384-EC1E3F6CB5E2} - \ConsumerInputUpdateTaskMachineCore -> No File <==== ATTENTION
- Task: {FAD30E96-3A9D-4F9B-A746-61CA7F15218B} - \Driver Support-RTMScan -> No File <==== ATTENTION
- Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
- Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
- Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
- Task: C:\Windows\Tasks\PCHelpers1st.job => C:\Program Files (x86)\Optimizer Elite Max\Optimizer Elite Max.exe <==== ATTENTION
- Task: C:\Windows\Tasks\PCHelpers_period.job => C:\Program Files (x86)\Optimizer Elite Max\Optimizer Elite Max.exe <==== ATTENTION
- AlternateDataStreams: C:\ProgramData\TEMP:373E1720
- cmd: ipconfig /flushdns
- cmd: netsh advfirewall reset
- cmd: netsh advfirewall set allprofiles state on
- Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
- Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
- Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
- Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
- CMD: bitsadmin /reset /allusers
- RemoveProxy:
- EmptyTemp:
- Reboot:
- end
- *****************
- Restore point was successfully created.
- Processes closed successfully.
- "HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E" => key removed successfully
- "HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{21a21992-c165-11e3-99db-806e6f6e6963}" => key removed successfully
- HKCR\CLSID\{21a21992-c165-11e3-99db-806e6f6e6963} => key not found.
- "HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{67eaf584-c176-11e3-8324-448a5b6115ed}" => key removed successfully
- HKCR\CLSID\{67eaf584-c176-11e3-8324-448a5b6115ed} => key not found.
- "HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8006f6be-c14f-11e3-9a42-806e6f6e6963}" => key removed successfully
- HKCR\CLSID\{8006f6be-c14f-11e3-9a42-806e6f6e6963} => key not found.
- HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_4158A702DE94E8F002D78386467F1B31 => value removed successfully
- "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value data removed successfully.
- "C:\PROGRA~2\SearchProtect" => File/Folder not found.
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
- HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
- C:\Windows\system32\GroupPolicy\Machine => moved successfully
- C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
- C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
- "HKLM\SOFTWARE\Policies\Google" => key removed successfully
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
- HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
- HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
- HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value removed successfully
- "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}" => key removed successfully
- HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} => key not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => key removed successfully
- HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => key not found.
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}" => key removed successfully
- HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} => key not found.
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
- "HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => key removed successfully
- HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5} => key not found.
- "HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}" => key removed successfully
- HKCR\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} => key not found.
- "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511421146}" => key removed successfully
- "HKCR\CLSID\{11111111-1111-1111-1111-110511421146}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{323C6E6D-1621-470F-8A52-4FDEC4E75E40}" => key removed successfully
- "HKCR\CLSID\{323C6E6D-1621-470F-8A52-4FDEC4E75E40}" => key removed successfully
- C:\Program Files (x86)\MediaPlayerplus => moved successfully
- "C:\Program Files\Quiknowledge" => File/Folder not found.
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}" => key removed successfully
- "HKCR\Wow6432Node\CLSID\{1631550F-191D-4826-B069-D9439253D926}" => key removed successfully
- "C:\Program Files (x86)\PriceGong" => File/Folder not found.
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59A062A1-5ECA-4a1a-BC44-B2A9283A8ACB}" => key removed successfully
- HKCR\Wow6432Node\CLSID\{59A062A1-5ECA-4a1a-BC44-B2A9283A8ACB} => key not found.
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A62BF774-18B1-2C80-0363-9AD7072BB9A8}" => key removed successfully
- "HKCR\Wow6432Node\CLSID\{A62BF774-18B1-2C80-0363-9AD7072BB9A8}" => key removed successfully
- "C:\Program Files (x86)\Re-Markable-soft" => File/Folder not found.
- HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value removed successfully
- "HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => key removed successfully
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value removed successfully
- "HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => key removed successfully
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => value removed successfully
- HKCR\CLSID\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => key not found.
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4F524A2D-5637-4300-76A7-7A786E7484D7} => value removed successfully
- HKCR\CLSID\{4F524A2D-5637-4300-76A7-7A786E7484D7} => key not found.
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\Software\Mozilla\Firefox\Extensions\\{C8A7850F-CCA1-ACD7-8CAF-562C883D9F80} => value removed successfully
- "C:\Program Files (x86)\Re-Markable-soft" => File/Folder not found.
- 3010859aeca4507.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\62b7abbdd1dd891801818168dbf983f4" => File/Folder not found.
- 77854be4be65e07afcf61541e60bdd79.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\77854be4be65e07afcf61541e60bdd79" => File/Folder not found.
- 935163118729163.exe => service removed successfully
- C:\Users\Conner\AppData\Local\f16100ccb3472d157d90c1d3816fad92 => moved successfully
- a37af3405cfe910.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\db7b2d584efdc2710cd94ae4f27c8abb" => File/Folder not found.
- ASUSWireless => service removed successfully
- BackupStack => service removed successfully
- "C:\Program Files (x86)\MyPC Backup" => File/Folder not found.
- ControlProgramSchema.exe => service removed successfully
- C:\Users\Conner\AppData\Local\ArchiveCursorSDK => moved successfully
- ee3327228c51020.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\48274b3ff1ca2ff16f2077c894bea374" => File/Folder not found.
- EncondingRepositoryThumbnail.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\e2fad099f894dd30b50f090b0ab6e51b" => File/Folder not found.
- FirmwareMBRRegister.exe => service removed successfully
- C:\Users\Conner\AppData\Local\FirmwareMBRRegister => moved successfully
- InteractivePrivacyWizard.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\InteractivePrivacyWizard" => File/Folder not found.
- PirritDesktop => service removed successfully
- "C:\Users\Conner\AppData\Local\PirritSuggestor" => File/Folder not found.
- RalinkRegistryWriter => service removed successfully
- Re-Markable => service removed successfully
- "C:\Program Files (x86)\Re-Markable Corp" => File/Folder not found.
- schemathumbnailapi.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\schemathumbnailapi" => File/Folder not found.
- sharewareracengnGUI.exe => service removed successfully
- "C:\Users\Conner\AppData\Local\sharewareracengnGUI" => File/Folder not found.
- SystemkService => service removed successfully
- C:\Program Files (x86)\Settings Manager => moved successfully
- wbsvc => service removed successfully
- "C:\Program Files\WebBar" => File/Folder not found.
- cocippsz => service removed successfully
- C:\Windows\System32\Drivers\cocippsz.sys => moved successfully
- qjsliszn => service removed successfully
- C:\Windows\System32\Drivers\qjsliszn.sys => moved successfully
- xnribqit => service removed successfully
- C:\Windows\System32\Drivers\xnribqit.sys => moved successfully
- EagleX64 => service removed successfully
- F06DEFF2-5B9C-490D-910F-35D3A91196222 => service removed successfully
- F06DEFF2-5B9C-490D-910F-35D3A91196223 => service removed successfully
- MSICDSetup => service removed successfully
- NTIOLib_1_0_C => service removed successfully
- qknfd => service removed successfully
- RgFltX64 => service removed successfully
- "C:\Windows\system32\drivers\EagleX64.sys" => File/Folder not found.
- "C:\Program Files (x86)\Settings Manager" => File/Folder not found.
- "D:\CDriver64.sys" => File/Folder not found.
- "D:\NTIOLib_X64.sys" => File/Folder not found.
- "C:\Windows\system32\drivers\qknfd.sys" => File/Folder not found.
- "C:\Users\Conner\AppData\Local\ArchiveCursorSDK" => File/Folder not found.
- C:\Users\Conner\AppData\Local\{27916B05-7DEB-416D-A6FB-15A028FF5413} => moved successfully
- C:\ProgramData\CLickFaorSaaLe => moved successfully
- C:\Program Files (x86)\popappsetup.exe => moved successfully
- C:\ProgramData\DP45977C.lfl => moved successfully
- C:\Users\Conner\AppData\Local\Temp\devcon64.exe => moved successfully
- "C:\Users\Conner\AppData\Local\Temp\NGM.exe" => File/Folder not found.
- "C:\Users\Conner\AppData\Local\Temp\NGMDll.dll" => File/Folder not found.
- "C:\Users\Conner\AppData\Local\Temp\NGMResource.dll" => File/Folder not found.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0B90153C-C19B-418C-9243-7C9CAB9A6B8C}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0B90153C-C19B-418C-9243-7C9CAB9A6B8C}" => key removed successfully
- C:\Windows\System32\Tasks\WebBarUpdateTask => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarUpdateTask" => key removed successfully
- "C:\Program Files\WebBar" => File/Folder not found.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1874B5F8-3ECD-4DB9-8843-37223A5609A4}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1874B5F8-3ECD-4DB9-8843-37223A5609A4}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMRules" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{218AB6D6-F7E5-461E-83B5-77D17C12BAA1}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{218AB6D6-F7E5-461E-83B5-77D17C12BAA1}" => key removed successfully
- C:\Windows\System32\Tasks\APSnotifierPP2 => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => key removed successfully
- "C:\Program Files (x86)\AnyProtectEx" => File/Folder not found.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{64C8E43D-8A41-4783-9E2C-7B3E9BB48DF6}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{64C8E43D-8A41-4783-9E2C-7B3E9BB48DF6}" => key removed successfully
- C:\Windows\System32\Tasks\PCHelpers1st => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCHelpers1st" => key removed successfully
- "C:\Program Files (x86)\Optimizer Elite Max" => File/Folder not found.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89E798B5-145B-4195-8B58-6E7E979210F0}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89E798B5-145B-4195-8B58-6E7E979210F0}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMUpdater" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D1FB70F-1E26-40E3-AB3D-14471A10364B}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D1FB70F-1E26-40E3-AB3D-14471A10364B}" => key removed successfully
- C:\Windows\System32\Tasks\APSnotifierPP3 => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F6F5446-3A1D-44F3-A9C7-671B8D3EAA5B}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F6F5446-3A1D-44F3-A9C7-671B8D3EAA5B}" => key removed successfully
- C:\Windows\System32\Tasks\APSnotifierPP1 => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AAF7CA21-4831-487F-BF95-91361E8BCABA}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AAF7CA21-4831-487F-BF95-91361E8BCABA}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_S-1-5-21-3144416939-2421594402-137492813-1000" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B80C02E1-D12A-49FB-98B6-1085050AB2E0}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B80C02E1-D12A-49FB-98B6-1085050AB2E0}" => key removed successfully
- C:\Windows\System32\Tasks\WebBarLaunchTask => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarLaunchTask" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BBC62ECE-B32E-4C83-9F57-C600DE6B57C9}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BBC62ECE-B32E-4C83-9F57-C600DE6B57C9}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineUA" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D8C633FA-0662-4A6F-8663-18C21CB6094A}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8C633FA-0662-4A6F-8663-18C21CB6094A}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RocketTab" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DDF3D2CA-2CA5-44FD-A57E-CA7F91CE988C}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DDF3D2CA-2CA5-44FD-A57E-CA7F91CE988C}" => key removed successfully
- C:\Windows\System32\Tasks\PCHelpers_period => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCHelpers_period" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE70D878-C38D-4E6C-85A4-F8C375EED3BF}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE70D878-C38D-4E6C-85A4-F8C375EED3BF}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMScanRunOnce" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F8C75149-55A3-4F87-9384-EC1E3F6CB5E2}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8C75149-55A3-4F87-9384-EC1E3F6CB5E2}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineCore" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FAD30E96-3A9D-4F9B-A746-61CA7F15218B}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FAD30E96-3A9D-4F9B-A746-61CA7F15218B}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMScan" => key removed successfully
- C:\Windows\Tasks\APSnotifierPP1.job => moved successfully
- C:\Windows\Tasks\APSnotifierPP2.job => moved successfully
- C:\Windows\Tasks\APSnotifierPP3.job => moved successfully
- C:\Windows\Tasks\PCHelpers1st.job => moved successfully
- C:\Windows\Tasks\PCHelpers_period.job => moved successfully
- C:\ProgramData\TEMP => ":373E1720" ADS removed successfully.
- ========= ipconfig /flushdns =========
- Windows IP Configuration
- Successfully flushed the DNS Resolver Cache.
- ========= End of CMD: =========
- ========= netsh advfirewall reset =========
- Ok.
- ========= End of CMD: =========
- ========= netsh advfirewall set allprofiles state on =========
- Ok.
- ========= End of CMD: =========
- ========= Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= bitsadmin /reset /allusers =========
- BITSADMIN version 3.0 [ 7.5.7601 ]
- BITS administration utility.
- (C) Copyright 2000-2006 Microsoft Corp.
- BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
- Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
- {D3790546-BCA5-49E7-802A-F6551AF0FD5E} canceled.
- {16D872A2-E65E-4A6F-B186-4BD94BB3D64D} canceled.
- {704A6908-6D50-494C-8AF8-11E89A5CAFEF} canceled.
- {6E75B27C-DFBE-4C21-AB4A-EFDC4FF19390} canceled.
- {5D34E991-EA0D-4F0C-BFDE-87E61A88D311} canceled.
- 5 out of 5 jobs canceled.
- ========= End of CMD: =========
- ========= RemoveProxy: =========
- HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
- HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
- HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
- HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
- HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
- HKU\S-1-5-21-3144416939-2421594402-137492813-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
- ========= End of RemoveProxy: =========
- EmptyTemp: => 860.1 MB temporary data Removed.
- The system needed a reboot.
- ==== End of Fixlog 00:07:45 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement