Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Scan Tool (x64) Version:25-05-2016 01
- Ran by Asher (2016-05-27 16:58:59) Run:1
- Running from C:\Users\Asher\Desktop
- Loaded Profiles: Asher (Available Profiles: Asher)
- Boot Mode: Normal
- ==============================================
- fixlist content:
- *****************
- start
- CreateRestorePoint:
- CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
- ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => No File
- AppInit_DLLs-x32: ȉ慖 => No File
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\...\Run: [LowRiskFileTypes] => .exe
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\...\Run: [WindowHost] => C:\Users\Asher\WindowHost\WindowHost.exe [12800 2016-05-04] (Microsoft)
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\...\Run: [WSecurity] => C:\Users\Asher\z15-Windows\WSecurity.exe [504320 2016-05-05] (Microsoft)
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\...\MountPoints2: {de16adc7-71be-11e3-8e32-806e6f6e6963} - D:\Run.exe
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\...\Run: [Dropbox Update] => C:\Users\Asher\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-17] (Dropbox, Inc.)
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\...\Run: [AdobeBridge] => [X]
- HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Asher\Documents\DCSCMIN\IMDCSC.exe
- HKLM\...\Run: [WINCOMDGR] => "C:\Program Files (x86)\browseextension\wincom_DGR.exe"
- S2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [X] <==== ATTENTION
- Task: {CDABA79E-F24A-44E2-BF7E-9A89DFB2E01C} - System32\Tasks\Browser Updater Task(Core) => C:\Program Files (x86)\QQBrowser\Update\CE5D008F42E46D5AEEEACB733278BDE4\Update\BrowserUpdate.exe [2016-04-25] (Tencent) <==== ATTENTION
- Task: {ED2C7209-EB50-4EE2-A180-AC86FEC5DB38} - System32\Tasks\{BA083669-37CF-41E3-B59C-B9FF0680D5CE} => pcalua.exe -a "C:\Users\Asher\Desktop\Downloads\vcs_cnt (1).exe" -d C:\Users\Asher\Desktop\Downloads
- MSCONFIG\startupreg: Roamingpayload.jar => C:\Users\Asher\Roamingpayload.jar
- CloseProcesses:
- EmptyTemp:
- Hosts:
- *****************
- Restore point was successfully created.
- "HKLM\SOFTWARE\Policies\Google" => key removed successfully
- "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay" => key removed successfully
- HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => key not found.
- "ȉ慖" => Value data removed successfully.
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LowRiskFileTypes => value removed successfully
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WindowHost => value removed successfully
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WSecurity => value removed successfully
- "HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{de16adc7-71be-11e3-8e32-806e6f6e6963}" => key removed successfully
- HKCR\CLSID\{de16adc7-71be-11e3-8e32-806e6f6e6963} => key not found.
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Dropbox Update => value removed successfully
- HKU\S-1-5-21-4141800521-2421496077-3257765511-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => value restored successfully
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\WINCOMDGR => value removed successfully
- winzipersvc => service removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CDABA79E-F24A-44E2-BF7E-9A89DFB2E01C}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CDABA79E-F24A-44E2-BF7E-9A89DFB2E01C}" => key removed successfully
- C:\Windows\System32\Tasks\Browser Updater Task(Core) => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Browser Updater Task(Core)" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED2C7209-EB50-4EE2-A180-AC86FEC5DB38}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED2C7209-EB50-4EE2-A180-AC86FEC5DB38}" => key removed successfully
- C:\Windows\System32\Tasks\{BA083669-37CF-41E3-B59C-B9FF0680D5CE} => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BA083669-37CF-41E3-B59C-B9FF0680D5CE}" => key removed successfully
- MSCONFIG\startupreg: Roamingpayload.jar => C:\Users\Asher\Roamingpayload.jar => Error: No automatic fix found for this entry.
- Processes closed successfully.
- C:\Windows\System32\Drivers\etc\hosts => moved successfully
- Hosts restored successfully.
- EmptyTemp: => 12.5 GB temporary data Removed.
- The system needed a reboot.
- ==== End of Fixlog 17:13:05 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement