Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Scan Tool (x64) Version: 08-10-2017
- Ran by BODIONGAN (10-10-2017 22:35:09) Run:2
- Running from C:\Users\BODIONGAN\Dropbox\Desktop\solution
- Loaded Profiles: BODIONGAN (Available Profiles: BODIONGAN & ed)
- Boot Mode: Normal
- ==============================================
- fixlist content:
- *****************
- CloseProcesses:
- CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
- CHR DefaultSearchKeyword: Default -> Yahoo
- CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
- CHR Extension: (Movies Toolbar) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajhegnoacmkmglfacmbbhpoadcdkh [2017-05-23] [UpdateUrl: hxxp://apnmedia.ask.com/media/toolbar/everest/partners/SVI2-DTX/YY/update.xml] <==== ATTENTION
- CHR Extension: (Movies Toolbar) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aaaajhegnoacmkmglfacmbbhpoadcdkh [2016-10-06] [UpdateUrl: hxxp://apnmedia.ask.com/media/toolbar/everest/partners/SVI2-DTX/YY/update.xml] <==== ATTENTION
- CHR Extension: (Yahoo Web) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\eedgghdcpmmmilkmfpnklknlenbiolec [2016-10-06]
- CHR Extension: (Yahoo Web) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\npdicihegicnhaangkdmcgbjceoemeoo [2016-10-06]
- CHR HKLM\...\Chrome\Extension: [noajmlkipclmeolfcnflkjhijkigpfjh] - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx <not found>
- CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma.crx <not found>
- CHR HKLM-x32\...\Chrome\Extension: [aaaajhegnoacmkmglfacmbbhpoadcdkh] - C:\Users\BODIONGAN\AppData\Local\savevidmoviestoolbarha\GC\toolbar.crx [2013-08-29]
- CHR HKLM-x32\...\Chrome\Extension: [eedgghdcpmmmilkmfpnklknlenbiolec] - hxxps://clients2.google.com/service/update2/crx
- CHR HKLM-x32\...\Chrome\Extension: [noajmlkipclmeolfcnflkjhijkigpfjh] - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh.crx <not found>
- FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
- FF HKLM-x32\...\Firefox\Extensions: [detgdp@gmail.com] - C:\Users\BODIONGAN\AppData\Roaming\Mozilla\Firefox\Profiles\jhkwzk4n.default\extensions\detgdp@gmail.com => not found
- FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
- BHO: DownnloaD keeeeperi -> {EEB8706C-601F-C069-799C-BF02A7AF8031} -> No File
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://ph.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
- SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2405} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=0&systemid=405&v=u11205-241&apn_uid=2130223631114446&apn_dtid=BND405&o=APN10647&apn_ptnrs=AG8&q={searchTerms}
- SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=25&systemid=406&v=a13251-241&apn_uid=2130223631114446&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
- SearchScopes: HKLM-x32 -> DefaultScope value is missing
- SearchScopes: HKU\S-1-5-21-1980599891-4258201064-1316590169-1000 -> DefaultScope {85A60A59-D3D8-468F-B598-FB4393789EF4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKU\S-1-5-21-1980599891-4258201064-1316590169-1000 -> {85A60A59-D3D8-468F-B598-FB4393789EF4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
- SearchScopes: HKU\S-1-5-21-1980599891-4258201064-1316590169-1000 -> {89871ED8-082F-4EF9-8DBB-A6C86040DEAA} URL = hxxps://ph.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\...\MountPoints2: I - I:\Setup.exe /s
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\...\MountPoints2: {17879d87-d974-11e6-83db-00acc484b9fa} - D:\Setup.exe /s
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\...\MountPoints2: {17879daf-d974-11e6-83db-00acc484b9fa} - I:\Setup.exe /s
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\...\MountPoints2: {c8bae772-44ff-11e3-a83b-f46d04d9d562} - I:\Autorun.exe
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\...\MountPoints2: {cb3fc0f2-6018-11e4-81c0-f46d04d9d562} - D:\AutoRun.exe
- FirewallRules: [{10309980-C7C1-4512-A1A5-7A3E08351338}] => (Allow) C:\Users\BODIONGAN\AppData\Local\Torch\Plugins\Hola\hola_plugin_x64.exe
- FirewallRules: [{D37DDD03-A589-4890-B78E-7570BB15C2B9}] => (Allow) C:\Users\BODIONGAN\AppData\Local\iLivid\iLivid.exe
- Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-10-04]
- ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe (McAfee, Inc.)
- FirewallRules: [{F8D1576A-0897-4EF6-B543-B01359367812}] => (Allow) C:\Users\BODIONGAN\AppData\Local\iLivid\iLivid.exe
- EmptyTemp:
- *****************
- Processes closed successfully.
- Chrome DefaultSearchURL => removed successfully
- Chrome DefaultSearchKeyword => removed successfully
- Chrome DefaultSuggestURL => removed successfully
- CHR Extension: (Movies Toolbar) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajhegnoacmkmglfacmbbhpoadcdkh [2017-05-23] [UpdateUrl: hxxp://apnmedia.ask.com/media/toolbar/everest/partners/SVI2-DTX/YY/update.xml] <==== ATTENTION => Error: No automatic fix found for this entry.
- CHR Extension: (Movies Toolbar) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aaaajhegnoacmkmglfacmbbhpoadcdkh [2016-10-06] [UpdateUrl: hxxp://apnmedia.ask.com/media/toolbar/everest/partners/SVI2-DTX/YY/update.xml] <==== ATTENTION => Error: No automatic fix found for this entry.
- CHR Extension: (Yahoo Web) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\eedgghdcpmmmilkmfpnklknlenbiolec [2016-10-06] => Error: No automatic fix found for this entry.
- CHR Extension: (Yahoo Web) - C:\Users\BODIONGAN\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\npdicihegicnhaangkdmcgbjceoemeoo [2016-10-06] => Error: No automatic fix found for this entry.
- HKLM\SOFTWARE\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh => key removed successfully
- HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma => key removed successfully
- HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\aaaajhegnoacmkmglfacmbbhpoadcdkh => key removed successfully
- C:\Users\BODIONGAN\AppData\Local\savevidmoviestoolbarha\GC\toolbar.crx => moved successfully
- HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eedgghdcpmmmilkmfpnklknlenbiolec => key removed successfully
- HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\noajmlkipclmeolfcnflkjhijkigpfjh => key removed successfully
- HKLM\Software\Mozilla\Thunderbird\Extensions\\eplgTb@eset.com => value removed successfully
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\detgdp@gmail.com => value removed successfully
- HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\eplgTb@eset.com => value removed successfully
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEB8706C-601F-C069-799C-BF02A7AF8031} => key removed successfully
- HKLM\Software\Classes\CLSID\{EEB8706C-601F-C069-799C-BF02A7AF8031} => key removed successfully
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key removed successfully
- HKLM\Software\Classes\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405} => key removed successfully
- HKLM\Software\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405} => key not found.
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => key removed successfully
- HKLM\Software\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} => key not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{85A60A59-D3D8-468F-B598-FB4393789EF4} => key removed successfully
- HKLM\Software\Classes\CLSID\{85A60A59-D3D8-468F-B598-FB4393789EF4} => key not found.
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{89871ED8-082F-4EF9-8DBB-A6C86040DEAA} => key removed successfully
- HKLM\Software\Classes\CLSID\{89871ED8-082F-4EF9-8DBB-A6C86040DEAA} => key not found.
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I => key removed successfully
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{17879d87-d974-11e6-83db-00acc484b9fa} => key removed successfully
- HKLM\Software\Classes\CLSID\{17879d87-d974-11e6-83db-00acc484b9fa} => key not found.
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{17879daf-d974-11e6-83db-00acc484b9fa} => key removed successfully
- HKLM\Software\Classes\CLSID\{17879daf-d974-11e6-83db-00acc484b9fa} => key not found.
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c8bae772-44ff-11e3-a83b-f46d04d9d562} => key removed successfully
- HKLM\Software\Classes\CLSID\{c8bae772-44ff-11e3-a83b-f46d04d9d562} => key not found.
- HKU\S-1-5-21-1980599891-4258201064-1316590169-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb3fc0f2-6018-11e4-81c0-f46d04d9d562} => key removed successfully
- HKLM\Software\Classes\CLSID\{cb3fc0f2-6018-11e4-81c0-f46d04d9d562} => key not found.
- HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{10309980-C7C1-4512-A1A5-7A3E08351338} => value removed successfully
- HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D37DDD03-A589-4890-B78E-7570BB15C2B9} => value removed successfully
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk => moved successfully
- C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe => moved successfully
- HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F8D1576A-0897-4EF6-B543-B01359367812} => value removed successfully
- =========== EmptyTemp: ==========
- BITS transfer queue => 8388608 B
- DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 14390148 B
- Java, Flash, Steam htmlcache => 343 B
- Windows/system/drivers => 3844 B
- Edge => 0 B
- Chrome => 190448406 B
- Firefox => 0 B
- Opera => 0 B
- Temp, IE cache, history, cookies, recent:
- Users => 0 B
- Default => 0 B
- Public => 0 B
- ProgramData => 0 B
- systemprofile => 0 B
- systemprofile32 => 0 B
- LocalService => 0 B
- NetworkService => 5314 B
- BODIONGAN => 11620164 B
- weeee => 0 B
- ed => 0 B
- RecycleBin => 303104 B
- EmptyTemp: => 214.7 MB temporary data Removed.
- ================================
- The system needed a reboot.
- ==== End of Fixlog 22:35:36 ====
Add Comment
Please, Sign In to add comment