Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Scan Tool (x64) Version:09-08-2015
- Ran by Shinn (2015-08-11 19:52:00) Run:1
- Running from C:\Users\Shinn\Desktop
- Loaded Profiles: Shinn (Available Profiles: Shinn)
- Boot Mode: Normal
- ==============================================
- fixlist content:
- *****************
- Start
- CreateRestorePoint:
- CloseProcesses:
- HKU\S-1-5-21-3041187145-1702624955-576530130-1001\...\RunOnce: [Uninstall C:\Users\Shinn\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Shinn\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
- HKU\S-1-5-21-3041187145-1702624955-576530130-1001\...\RunOnce: [Uninstall C:\Users\Shinn\AppData\Local\Microsoft\OneDrive\17.3.5892.0626] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Shinn\AppData\Local\Microsoft\OneDrive\17.3.5892.0626"
- CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
- AutoConfigURL: [S-1-5-21-3041187145-1702624955-576530130-1001] => http://127.0.0.1:895/proxy.js
- SearchScopes: HKLM-x32 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=24432&r=2015/08/08&hid=4460734566924005976&lg=EN&cc=KR&unqvl=90
- SearchScopes: HKLM-x32 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=24432&r=2015/08/08&hid=4460734566924005976&lg=EN&cc=KR&unqvl=90
- SearchScopes: HKU\S-1-5-21-3041187145-1702624955-576530130-1001 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.hotsearches.info/?l=1&q={searchTerms}&pid=24432&r=2015/08/08&hid=4460734566924005976&lg=EN&cc=KR&unqvl=90
- FF DefaultSearchEngine: WebSearch
- FF DefaultSearchEngine,S: WebSearch
- FF DefaultSearchEngine.US: Google
- FF DefaultSearchUrl: hxxp://websearch.hotsearches.info/?pid=24432&r=2015/08/08&hid=4460734566924005976&lg=EN&cc=KR&unqvl=90&l=1&q=
- FF SearchEngineOrder.1: WebSearch
- FF SearchEngineOrder.1,S: WebSearch
- FF SelectedSearchEngine: WebSearch
- FF SelectedSearchEngine,S: WebSearch
- FF Keyword.URL: hxxp://websearch.hotsearches.info/?pid=24432&r=2015/08/08&hid=4460734566924005976&lg=EN&cc=KR&unqvl=90&l=1&q=
- FF Plugin-x32: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll [No File]
- C:\Windows\system32\npOGPPlugin.dll
- FF SearchPlugin: C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\searchplugins\WebSearch.xml [2015-08-08]
- C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\searchplugins\WebSearch.xml
- FF Extension: CutTheePRice - C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\0pC@qQ.edu [2015-08-08]
- C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\0pC@qQ.edu
- FF Extension: bestadblocker - C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\H8vDNxOc9@I.org [2015-08-08]
- C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\H8vDNxOc9@I.org
- CHR Extension: (Google Search) - C:\Users\Shinn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-13]
- C:\Users\Shinn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
- S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
- C:\Windows\SystemRoot\System32\drivers\wfpcapture.sys
- 2015-08-08 10:43 - 2015-08-08 12:45 - 00000000 ____D C:\Program Files (x86)\CutTheePRice
- 2015-08-08 10:43 - 2015-08-08 10:44 - 00000000 ____D C:\ProgramData\17097366940260626710
- 2015-08-08 10:43 - 2015-08-08 10:43 - 00000000 ____D C:\ProgramData\kfananklbdfohobgmcmaibfblmojiidg
- 2015-07-24 19:33 - 2015-03-15 16:58 - 00000000 __SHD C:\Users\Shinn\AppData\Local\EmieBrowserModeList
- 2015-07-24 19:33 - 2015-03-13 15:48 - 00000000 __SHD C:\Users\Shinn\AppData\Local\EmieUserList
- 2015-07-24 19:33 - 2015-03-13 15:48 - 00000000 __SHD C:\Users\Shinn\AppData\Local\EmieSiteList
- Task: {1579EF0F-439A-4EE0-83DE-662F4CF852FA} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
- Task: {3C011808-7620-4A1E-9651-4933825056C4} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
- Task: {5110DCDB-2993-4BD1-B51F-B0773C56F797} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
- Task: {57C1E4A3-A95D-41B5-89EF-14543984AD1C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
- Task: {6323AF09-B618-414A-9CDE-057AAB7ABC64} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
- Task: {89ED02E4-762D-4D75-AA0D-4647A74D116B} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
- Task: {A60564C3-76EB-4046-B9A6-2F42426C5F39} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
- Task: {C4925C04-5798-4454-AE9F-23E6657E744A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
- Task: {D5EF8FC5-A86A-4878-BEF6-DE85FD1DA499} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
- Task: {DAF653FB-0D0D-40D2-9465-176DCAEE23BB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
- Task: {EB1E539B-EFCA-4267-A457-4062952E2DF2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
- cmd: ipconfig /flushdns
- cmd: netsh advfirewall reset
- cmd: netsh advfirewall set allprofiles state on
- Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
- Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
- CMD: bitsadmin /reset /allusers
- RemoveProxy:
- EmptyTemp:
- Reboot:
- end
- *****************
- Restore point was successfully created.
- Processes closed successfully.
- HKU\S-1-5-21-3041187145-1702624955-576530130-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall C:\Users\Shinn\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64 => value not found.
- HKU\S-1-5-21-3041187145-1702624955-576530130-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall C:\Users\Shinn\AppData\Local\Microsoft\OneDrive\17.3.5892.0626 => value not found.
- "HKLM\SOFTWARE\Policies\Google" => key removed successfully
- HKU\S-1-5-21-3041187145-1702624955-576530130-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}" => key removed successfully
- HKCR\Wow6432Node\CLSID\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE} => key not found.
- "HKU\S-1-5-21-3041187145-1702624955-576530130-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}" => key removed successfully
- HKCR\CLSID\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE} => key not found.
- Firefox DefaultSearchEngine removed successfully
- Firefox DefaultSearchEngine,S removed successfully
- Firefox DefaultSearchEngine.US removed successfully
- Firefox DefaultSearchUrl removed successfully
- Firefox SearchEngineOrder.1 removed successfully
- Firefox SearchEngineOrder.1,S removed successfully
- Firefox SelectedSearchEngine removed successfully
- Firefox SelectedSearchEngine,S removed successfully
- Firefox "Keyword.URL" removed successfully
- "HKLM\Software\Wow6432Node\MozillaPlugins\@ogplanet.com/npOGPPlugin" => key removed successfully
- "C:\Windows\system32\npOGPPlugin.dll" => File/Folder not found.
- C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\searchplugins\WebSearch.xml => moved successfully.
- "C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\searchplugins\WebSearch.xml" => File/Folder not found.
- C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\0pC@qQ.edu => moved successfully.
- "C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\0pC@qQ.edu" => File/Folder not found.
- C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\H8vDNxOc9@I.org => moved successfully.
- "C:\Users\Shinn\AppData\Roaming\Mozilla\Firefox\Profiles\jqwy2eop.default\Extensions\H8vDNxOc9@I.org" => File/Folder not found.
- C:\Users\Shinn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf => moved successfully.
- "C:\Users\Shinn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf" => File/Folder not found.
- wfpcapture => service removed successfully
- "C:\Windows\SystemRoot\System32\drivers\wfpcapture.sys" => File/Folder not found.
- C:\Program Files (x86)\CutTheePRice => moved successfully.
- C:\ProgramData\17097366940260626710 => moved successfully.
- C:\ProgramData\kfananklbdfohobgmcmaibfblmojiidg => moved successfully.
- C:\Users\Shinn\AppData\Local\EmieBrowserModeList => moved successfully.
- C:\Users\Shinn\AppData\Local\EmieUserList => moved successfully.
- C:\Users\Shinn\AppData\Local\EmieSiteList => moved successfully.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1579EF0F-439A-4EE0-83DE-662F4CF852FA}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1579EF0F-439A-4EE0-83DE-662F4CF852FA}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C011808-7620-4A1E-9651-4933825056C4}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C011808-7620-4A1E-9651-4933825056C4}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5110DCDB-2993-4BD1-B51F-B0773C56F797}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5110DCDB-2993-4BD1-B51F-B0773C56F797}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{57C1E4A3-A95D-41B5-89EF-14543984AD1C}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57C1E4A3-A95D-41B5-89EF-14543984AD1C}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6323AF09-B618-414A-9CDE-057AAB7ABC64}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6323AF09-B618-414A-9CDE-057AAB7ABC64}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{89ED02E4-762D-4D75-AA0D-4647A74D116B}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89ED02E4-762D-4D75-AA0D-4647A74D116B}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A60564C3-76EB-4046-B9A6-2F42426C5F39}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A60564C3-76EB-4046-B9A6-2F42426C5F39}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4925C04-5798-4454-AE9F-23E6657E744A}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4925C04-5798-4454-AE9F-23E6657E744A}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D5EF8FC5-A86A-4878-BEF6-DE85FD1DA499}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D5EF8FC5-A86A-4878-BEF6-DE85FD1DA499}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DAF653FB-0D0D-40D2-9465-176DCAEE23BB}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DAF653FB-0D0D-40D2-9465-176DCAEE23BB}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB1E539B-EFCA-4267-A457-4062952E2DF2}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB1E539B-EFCA-4267-A457-4062952E2DF2}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
- ========= ipconfig /flushdns =========
- Windows IP Configuration
- Successfully flushed the DNS Resolver Cache.
- ========= End of CMD: =========
- ========= netsh advfirewall reset =========
- Ok.
- ========= End of CMD: =========
- ========= netsh advfirewall set allprofiles state on =========
- Ok.
- ========= End of CMD: =========
- ========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= bitsadmin /reset /allusers =========
- BITSADMIN version 3.0 [ 7.8.10240 ]
- BITS administration utility.
- (C) Copyright 2000-2006 Microsoft Corp.
- BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
- Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
- {B444D79D-7895-455C-8D62-3057BBBE3E10} canceled.
- {7B20FF81-F986-429A-A2B7-950FF187EB99} canceled.
- 2 out of 2 jobs canceled.
- ========= End of CMD: =========
- ========= RemoveProxy: =========
- HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
- HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
- HKU\S-1-5-21-3041187145-1702624955-576530130-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
- HKU\S-1-5-21-3041187145-1702624955-576530130-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
- ========= End of RemoveProxy: =========
- EmptyTemp: => 15.3 GB temporary data Removed.
- The system needed a reboot..
- ==== End of Fixlog 19:54:17 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement