Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Scan Tool (x64) Version:29-11-2015
- Ran by Dimitris (2015-11-30 18:54:11) Run:1
- Running from C:\Users\Dimitris\Desktop
- Loaded Profiles: Dimitris (Available Profiles: Dimitris & Chrisa & DefaultAppPool)
- Boot Mode: Normal
- ==============================================
- fixlist content:
- *****************
- start
- CreateRestorePoint:
- CloseProcesses:
- CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
- HKU\S-1-5-21-4193550190-2721119157-2499064272-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
- HKU\S-1-5-21-4193550190-2721119157-2499064272-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [232960 2015-10-30] (Microsoft Corporation)
- HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
- SearchScopes: HKLM -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL =
- SearchScopes: HKLM -> OldSearch URL = hxxp://www.google.com/search?q={searchTerms}
- SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
- SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
- SearchScopes: HKU\S-1-5-21-4193550190-2721119157-2499064272-1000 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL =
- SearchScopes: HKU\S-1-5-21-4193550190-2721119157-2499064272-1000 -> OldSearch URL = hxxps://www.google.com/search?q={searchTerms}
- SearchScopes: HKU\S-1-5-21-4193550190-2721119157-2499064272-1000 -> {EDA4D357-355E-4C76-B3F2-45100A0B9B6C} URL = hxxps://www.google.com/search?q={searchTerms}
- BHO: No Name -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> No File
- BHO: No Name -> {11111111-1111-1111-1111-110411851159} -> No File
- CHR RestoreOnStartup: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggbeQgIWAkUGRgWcltdTA0TFgcOIVoKWBQVQwYXeQ5bBAxAQw0FIk0FA1oDB0V?XfV5bFElXTwhuL1dZE1oZZ1xNJA=="
- CHR StartupUrls: Default -> "hxxp://www.google.gr/"
- CHR DefaultSearchURL: Default -> hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQEBUAlIEVAbbQwKA1xcFVcUchRZAgtIDFFBcw0BVloUFARBeB9aFQQTQkc?FME0FBloEURNNfXRXD1gDQl1lKVdc&q={searchTerms}
- CHR DefaultSearchKeyword: Default -> searchinterneat-a.akamaihd.net
- CHR DefaultNewTabURL: Default -> hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHA0acQkBUVxJDAARIlwVVVtGExhCIwsBTF0TEgEad1pdVAgTGRNBNARaAktXUUE?eJ1pNER8fHHhMLlhKAlE3SFtH
- 2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Dimitris\AppData\Roaming\KZYWOTH
- 2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Dimitris\AppData\Roaming\NQTL
- Task: {002E43F3-566D-440C-BAF8-9F5C414F0DE4} - System32\Tasks\060184C3-9766-46a0-B258-F4518A0B2633 => Cscript.exe "C:\ProgramData\Baidu Security\Duplicaterecord.js" <==== ATTENTION
- Task: {162F35DF-1DDD-4B95-B79C-CED2BAE9E050} - System32\Tasks\KZYWOTH => C:\Users\Dimitris\AppData\Roaming\KZYWOTH.exe <==== ATTENTION
- Task: {1FDD5AF4-B2B7-4904-AD0B-D88CA0487B5D} - System32\Tasks\NQTL => C:\Users\Dimitris\AppData\Roaming\NQTL.exe <==== ATTENTION
- Task: {41FA8F66-B839-419E-A47A-FE32D5CBAC9E} - \SPBIW_UpdateTask_Time_3731373031333335312d414a34413734452a786c5a5a -> No File <==== ATTENTION
- Task: C:\WINDOWS\Tasks\KZYWOTH.job => C:\Users\Dimitris\AppData\Roaming\KZYWOTH.exe <==== ATTENTION
- Task: C:\WINDOWS\Tasks\NQTL.job => C:\Users\Dimitris\AppData\Roaming\NQTL.exe <==== ATTENTION
- AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
- EmptyTemp:
- end
- *****************
- Restore point was successfully created.
- Processes closed successfully.
- "HKLM\SOFTWARE\Policies\Google" => key removed successfully
- HKU\S-1-5-21-4193550190-2721119157-2499064272-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value removed successfully
- HKU\S-1-5-21-4193550190-2721119157-2499064272-1000\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully
- "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => key removed successfully
- HKCR\CLSID\OldSearch => key not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}" => key removed successfully
- HKCR\Wow6432Node\CLSID\{0191A6B0-1154-4C22-9182-23A95BBE92D9} => key not found.
- HKU\S-1-5-21-4193550190-2721119157-2499064272-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
- "HKU\S-1-5-21-4193550190-2721119157-2499064272-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => key removed successfully
- HKCR\CLSID\OldSearch => key not found.
- "HKU\S-1-5-21-4193550190-2721119157-2499064272-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EDA4D357-355E-4C76-B3F2-45100A0B9B6C}" => key removed successfully
- HKCR\CLSID\{EDA4D357-355E-4C76-B3F2-45100A0B9B6C} => key not found.
- "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => key removed successfully
- HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814} => key not found.
- "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}" => key removed successfully
- HKCR\CLSID\{11111111-1111-1111-1111-110411851159} => key not found.
- Chrome RestoreOnStartup => removed successfully
- Chrome StartupUrls => removed successfully
- Chrome DefaultSearchURL => removed successfully
- Chrome DefaultSearchKeyword => removed successfully
- Chrome DefaultNewTabURL => removed successfully
- C:\Users\Dimitris\AppData\Roaming\KZYWOTH => moved successfully
- C:\Users\Dimitris\AppData\Roaming\NQTL => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{002E43F3-566D-440C-BAF8-9F5C414F0DE4}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{002E43F3-566D-440C-BAF8-9F5C414F0DE4}" => key removed successfully
- C:\WINDOWS\System32\Tasks\060184C3-9766-46a0-B258-F4518A0B2633 => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\060184C3-9766-46a0-B258-F4518A0B2633" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{162F35DF-1DDD-4B95-B79C-CED2BAE9E050}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{162F35DF-1DDD-4B95-B79C-CED2BAE9E050}" => key removed successfully
- C:\WINDOWS\System32\Tasks\KZYWOTH => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KZYWOTH" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1FDD5AF4-B2B7-4904-AD0B-D88CA0487B5D}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1FDD5AF4-B2B7-4904-AD0B-D88CA0487B5D}" => key removed successfully
- C:\WINDOWS\System32\Tasks\NQTL => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NQTL" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41FA8F66-B839-419E-A47A-FE32D5CBAC9E}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41FA8F66-B839-419E-A47A-FE32D5CBAC9E}" => key removed successfully
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3731373031333335312d414a34413734452a786c5a5a => key not found.
- C:\WINDOWS\Tasks\KZYWOTH.job => moved successfully
- C:\WINDOWS\Tasks\NQTL.job => moved successfully
- C:\ProgramData\TEMP => ":56E2E879" ADS removed successfully.
- EmptyTemp: => 60.3 MB temporary data Removed.
- The system needed a reboot.
- ==== End of Fixlog 18:54:53 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement