Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014
- Ran by Michael & Michelle at 2014-01-05 22:07:16 Run:1
- Running from C:\Users\Michael & Michelle\Desktop
- Boot Mode: Normal
- ==============================================
- Content of fixlist:
- *****************
- start
- HKLM-x32\...\Run: [] - [x]
- SearchScopes: HKLM - {397CFBAF-01FE-4A0D-950E-041F4905DC38} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
- SearchScopes: HKLM-x32 - {397CFBAF-01FE-4A0D-950E-041F4905DC38} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
- SearchScopes: HKLM-x32 - {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^UX^xdm002^YYA^us&si=CI3qz43BqrgCFeZxQgoduggANA&ptb=E299A356-501F-4300-A361-AA42ABACBC0A&ind=2013071215&n=77fd076f&psa=&st=sb&searchfor={searchTerms}
- SearchScopes: HKCU - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60347
- SearchScopes: HKCU - {397CFBAF-01FE-4A0D-950E-041F4905DC38} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
- SearchScopes: HKCU - {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^UX^xdm002^YYA^us&si=CI3qz43BqrgCFeZxQgoduggANA&ptb=E299A356-501F-4300-A361-AA42ABACBC0A&ind=2013071215&n=77fd076f&psa=&st=sb&searchfor={searchTerms}
- Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
- Toolbar: HKCU - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
- FF SearchEngineOrder.1: Ask.com
- FF Homepage: hxxp://home.mywebsearch.com/index.jhtml?ptb=766D2BED-CBDD-4BD7-B959-777AAE32C193&n=77ee6363&p2=^XP^xdm345^S03635^us&si=38885
- FF Keyword.URL: hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=E299A356-501F-4300-A361-AA42ABACBC0A&n=77fd076b&ind=2013071211&p2=^UX^xdm002^YYA^us&si=CI3qz43BqrgCFeZxQgoduggANA&searchfor=
- FF SearchPlugin: C:\Users\Michael & Michelle\AppData\Roaming\Mozilla\Firefox\Profiles\42lpyg3r.default\searchplugins\ask-web-search.xml
- FF SearchPlugin: C:\Users\Michael & Michelle\AppData\Roaming\Mozilla\Firefox\Profiles\42lpyg3r.default\searchplugins\my-web-search.xml
- FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\
- FF HKLM-x32\...\Firefox\Extensions: [64ffxtbr@TelevisionFanatic.com] - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin
- FF HKLM-x32\...\Firefox\Extensions: [gethighlightly@gethighlightly.com] - C:\Program Files (x86)\Mozilla Firefox\extensions\gethighlightly@gethighlightly.com
- FF Extension: Highlightly - C:\Program Files (x86)\Mozilla Firefox\extensions\gethighlightly@gethighlightly.com
- CHR HKLM-x32\...\Chrome\Extension: [aaaangaohdajkgeopjhpbnlpkehbhmbj] - C:\Users\Michael & Michelle\AppData\Local\APN\GoogleCRXs\aaaangaohdajkgeopjhpbnlpkehbhmbj_7.15.4.0.crx
- R1 hlnfd; C:\Windows\System32\drivers\hlnfd.sys [58256 2013-12-04] (Highlightly)
- S3 catchme; \??\C:\combofix-13.2.18.2-en\catchme.sys [x]
- 2013-12-29 17:26 - 2013-12-29 17:26 - 00000000 ____D C:\Program Files\Highlightly
- 2013-12-29 17:26 - 2013-12-29 17:26 - 00000000 ____D C:\Program Files (x86)\Highlightly
- Folder: C:\Users\Michael & Michelle\AppData\Local\nfbuvvco
- Folder: C:\Users\Michael & Michelle\AppData\Local\djboktuq
- Folder: C:\Users\Michael & Michelle\AppData\Roaming\SharedSettings.ccs
- 2013-12-18 12:17 - 2013-12-18 12:17 - 00504452 _____ C:\Users\Michael & Michelle\Downloads\ACFrOgBJXWb5zmYnnK4TYTKRM7uSUJYYo0XgNIUEUjetkGeQxfaOUqRcOzU_ciXvmlOCCBZ-pcso18do46zkjmw_vbzrxGnXuVpZM9suYeoO2L4xed4oDzm_gLfCBJM=
- 2013-12-18 12:14 - 2013-12-18 12:15 - 00504452 _____ C:\Users\Michael & Michelle\Downloads\ACFrOgAhcyXI8oKCL2OzXSRZYK6nsTVKYhUtSyXu7TGKkRKHid1GnUQMWt0bIuojVyWy91Js7USX2BBe6uaNywOZ99rvByUOsM3XFVCJm2vrXy5Ug4hQi1gie5jSfGM=(1)
- 2013-12-18 12:14 - 2013-12-18 12:14 - 00504452 _____ C:\Users\Michael & Michelle\Downloads\ACFrOgAhcyXI8oKCL2OzXSRZYK6nsTVKYhUtSyXu7TGKkRKHid1GnUQMWt0bIuojVyWy91Js7USX2BBe6uaNywOZ99rvByUOsM3XFVCJm2vrXy5Ug4hQi1gie5jSfGM=
- C:\Program Files (x86)\Ask.com
- C:\Users\Michael & Michelle\AppData\LocalLow\AskToolbar
- C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
- Reg: reg delete "HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1" /f
- Reg: reg delete "HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd" /f
- Reg: reg delete "HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888" /f
- Reg: reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF" /f
- Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}" /f
- Reg: reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}" /f
- Reg: reg delete "HKU\.DEFAULT\Software\Ask.com" /f
- Reg: reg delete "HKU\.DEFAULT\Software\AskToolbar" /f
- Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}" /f
- Reg: reg delete "HKU\S-1-5-18\Software\Ask.com" /f
- Reg: reg delete "HKU\S-1-5-18\Software\AskToolbar" /f
- Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}" /f
- C:\Users\Michael & Michelle\AppData\Local\Temp
- end
- *****************
- HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{397CFBAF-01FE-4A0D-950E-041F4905DC38} => Key deleted successfully.
- HKCR\CLSID\{397CFBAF-01FE-4A0D-950E-041F4905DC38} => Key not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{397CFBAF-01FE-4A0D-950E-041F4905DC38} => Key deleted successfully.
- HKCR\Wow6432Node\CLSID\{397CFBAF-01FE-4A0D-950E-041F4905DC38} => Key not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f} => Key deleted successfully.
- HKCR\Wow6432Node\CLSID\{b0441a0e-a49a-4e16-afc1-74ecced1921f} => Key not found.
- HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} => Key deleted successfully.
- HKCR\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} => Key not found.
- HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{397CFBAF-01FE-4A0D-950E-041F4905DC38} => Key deleted successfully.
- HKCR\CLSID\{397CFBAF-01FE-4A0D-950E-041F4905DC38} => Key not found.
- HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f} => Key deleted successfully.
- HKCR\CLSID\{b0441a0e-a49a-4e16-afc1-74ecced1921f} => Key not found.
- HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully.
- HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
- HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => Value deleted successfully.
- HKCR\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => Key not found.
- Firefox SearchEngineOrder.1 deleted successfully.
- Firefox homepage deleted successfully.
- Firefox Keyword.URL deleted successfully.
- C:\Users\Michael & Michelle\AppData\Roaming\Mozilla\Firefox\Profiles\42lpyg3r.default\searchplugins\ask-web-search.xml => Moved successfully.
- C:\Users\Michael & Michelle\AppData\Roaming\Mozilla\Firefox\Profiles\42lpyg3r.default\searchplugins\my-web-search.xml => Moved successfully.
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC} => Value deleted successfully.
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\64ffxtbr@TelevisionFanatic.com => Value deleted successfully.
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\gethighlightly@gethighlightly.com => Value deleted successfully.
- C:\Program Files (x86)\Mozilla Firefox\extensions\gethighlightly@gethighlightly.com not found.
- HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj => Key deleted successfully.
- C:\Users\Michael & Michelle\AppData\Local\APN\GoogleCRXs\aaaangaohdajkgeopjhpbnlpkehbhmbj_7.15.4.0.crx => Moved successfully.
- hlnfd => Service deleted successfully.
- catchme => Service deleted successfully.
- "C:\Program Files\Highlightly" => File/Directory not found.
- "C:\Program Files (x86)\Highlightly" => File/Directory not found.
- ========================= Folder: C:\Users\Michael & Michelle\AppData\Local\nfbuvvco ========================
- 2013-12-26 15:47 - 2013-12-26 15:47 - 0012326 _____ () C:\Users\Michael & Michelle\AppData\Local\nfbuvvco
- ====== End of Folder: ======
- ========================= Folder: C:\Users\Michael & Michelle\AppData\Local\djboktuq ========================
- 2013-12-26 15:46 - 2013-12-26 15:46 - 0067992 _____ () C:\Users\Michael & Michelle\AppData\Local\djboktuq
- ====== End of Folder: ======
- ========================= Folder: C:\Users\Michael & Michelle\AppData\Roaming\SharedSettings.ccs ========================
- 2013-12-26 15:45 - 2013-12-26 15:45 - 0000000 _____ () C:\Users\Michael & Michelle\AppData\Roaming\SharedSettings.ccs
- ====== End of Folder: ======
- C:\Users\Michael & Michelle\Downloads\ACFrOgBJXWb5zmYnnK4TYTKRM7uSUJYYo0XgNIUEUjetkGeQxfaOUqRcOzU_ciXvmlOCCBZ-pcso18do46zkjmw_vbzrxGnXuVpZM9suYeoO2L4xed4oDzm_gLfCBJM= => Moved successfully.
- C:\Users\Michael & Michelle\Downloads\ACFrOgAhcyXI8oKCL2OzXSRZYK6nsTVKYhUtSyXu7TGKkRKHid1GnUQMWt0bIuojVyWy91Js7USX2BBe6uaNywOZ99rvByUOsM3XFVCJm2vrXy5Ug4hQi1gie5jSfGM=(1) => Moved successfully.
- C:\Users\Michael & Michelle\Downloads\ACFrOgAhcyXI8oKCL2OzXSRZYK6nsTVKYhUtSyXu7TGKkRKHid1GnUQMWt0bIuojVyWy91Js7USX2BBe6uaNywOZ99rvByUOsM3XFVCJm2vrXy5Ug4hQi1gie5jSfGM= => Moved successfully.
- "C:\Program Files (x86)\Ask.com" => File/Directory not found.
- C:\Users\Michael & Michelle\AppData\LocalLow\AskToolbar => Moved successfully.
- C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} => Moved successfully.
- ========= reg delete "HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKU\.DEFAULT\Software\Ask.com" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKU\.DEFAULT\Software\AskToolbar" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}" /f =========
- The operation completed successfully.
- ========= End of Reg: =========
- ========= reg delete "HKU\S-1-5-18\Software\Ask.com" /f =========
- ERROR: The system was unable to find the specified registry key or value.
- ========= End of Reg: =========
- ========= reg delete "HKU\S-1-5-18\Software\AskToolbar" /f =========
- ERROR: The system was unable to find the specified registry key or value.
- ========= End of Reg: =========
- ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}" /f =========
- ERROR: The system was unable to find the specified registry key or value.
- ========= End of Reg: =========
- "C:\Users\Michael & Michelle\AppData\Local\Temp" directory move:
- C:\Users\Michael & Michelle\AppData\Local\Temp\895C1DD9-84CA-4A4B-B781-D9684B134BE8 => Moved successfully.
- C:\Users\Michael & Michelle\AppData\Local\Temp\AdobeARM.log => Moved successfully.
- C:\Users\Michael & Michelle\AppData\Local\Temp\clipboardcache => Moved successfully.
- C:\Users\Michael & Michelle\AppData\Local\Temp\clipboardcache-1 => Moved successfully.
- C:\Users\Michael & Michelle\AppData\Local\Temp\clipboardcache-2 => Moved successfully.
- Could not move "C:\Users\Michael & Michelle\AppData\Local\Temp\FXSAPIDebugLogFile.txt" => Scheduled to move on reboot.
- C:\Users\Michael & Michelle\AppData\Local\Temp\ntdll_dump.dll => Moved successfully.
- C:\Users\Michael & Michelle\AppData\Local\Temp\uninstall => Moved successfully.
- C:\Users\Michael & Michelle\AppData\Local\Temp\users00 => Moved successfully.
- Could not move "C:\Users\Michael & Michelle\AppData\Local\Temp" directory. => Scheduled to move on reboot.
- => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-01-05 22:11:37)<=
- "C:\Users\Michael & Michelle\AppData\Local\Temp\FXSAPIDebugLogFile.txt" => File could not move.
- "C:\Users\Michael & Michelle\AppData\Local\Temp" => Directory could not move.
- ==== End of Fixlog ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement