Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Fix result of Farbar Recovery Scan Tool (x64) Version:07-02-2016
- Ran by user (2016-02-12 23:50:35) Run:1
- Running from C:\Users\user\Downloads
- Loaded Profiles: user (Available Profiles: user & BvSsh_VirtualUsers & Gurtna011)
- Boot Mode: Normal
- ==============================================
- fixlist content:
- *****************
- start
- CreateRestorePoint:
- CloseProcesses:
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\...\Run: [302a3f59a0bda767f51d068b3f4568a5] => C:\Users\user\AppData\Local\Temp\svchost.exe [135168 2016-01-26] (Evil Company) <===== ATTENTION
- C:\Users\user\AppData\Local\Temp\svchost.exe
- Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\302a3f59a0bda767f51d068b3f4568a5.exe [2016-01-25] (Evil Company)
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\...\Policies\system: [LogonHoursAction] 2
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\...\MountPoints2: {256d7995-9e7c-11e5-815c-005056c00008} - F:\autorun.exe
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\...\MountPoints2: {256d7998-9e7c-11e5-815c-005056c00008} - G:\MAXON-Start.exe
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\...\MountPoints2: {400daf09-7f0e-11e5-809e-005056c00008} - E:\LG_PC_Programs.exe
- AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [249104 2016-01-14] (Client Connect LTD)
- AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [221456 2016-01-14] (Client Connect LTD)
- GroupPolicy: Restriction - Chrome <======= ATTENTION
- GroupPolicyUsers\S-1-5-21-1292048591-1437342970-2306004842-1005\User: Restriction <======= ATTENTION
- CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY&q={searchTerms}
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.yoursites123.com/web/?type=ds&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY&q={searchTerms}
- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY&q={searchTerms}
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY&q={searchTerms}
- HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3McXDvdSN6JAXeL5DbU_ODcLUTwSUWTaxZImUxxNdscwO55MTP5WPcno3sf4KNr4NX9YHKeoy8lA4LmWZ0I_QU78NbQivcj_YhZjm3BP7-2IxurlG0ZKCJeUKYpsoBrRNVVPN6jSCEyxTlFlFkNnpkakFumC&q={searchTerms}
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=55&CUI=&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&D=020116&SSPV=
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3McXDvdSN6JAXeL5DbU_ODcLUTwSUWTaxZImUxxNdscwO55MTP5WPcno3sf4KNr4NX9YHKeoy8lA4LmWZ0I_QU78NbQivcj_YhZjm3BP7-2IxurlG0ZKCJeUKYpsoBrRNVVPN6jSCEyxTlFlFkNnpkakFumC&q={searchTerms}
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3McXDvdSN6JAXeL5DbU_ODcLUTwSUWTaxZImUxxNdscwO55MTP5WPcno3sf4KNr4NX9YHKeoy8lA4LmWZ0I_QU78NbQivcj_YhZjm3BP7-2IxurlG0ZKCJeUKYpsoBrRNVVPN6jSCEyxTlFlFkNnpkakFumC&q={searchTerms}
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://v9.com/?type=hp&ts=1450675887&from=mych123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg
- SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
- SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY&q={searchTerms}
- SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450675887&from=zzgbkk123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg&q={searchTerms}
- SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3McXDvdSN6JAXeL5DbU_ODcLUTwSUWTaxZImUxxNdscwO55MTP5WPcno3sf4KNr4NX9YHKeoy8lA4LmWZ0I_QU78NbQivcj_YhZjm3BP7-2IxurlG0ZKCJeUKYpsoBrRNVVPN6jSCEyxTlFlFkNnpkakFumC&q={searchTerms}
- SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.yoursites123.com/web/?type=ds&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY&q={searchTerms}
- SearchScopes: HKLM-x32 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450675887&from=zzgbkk123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-1292048591-1437342970-2306004842-1000 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450675887&from=zzgbkk123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-1292048591-1437342970-2306004842-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=58&CUI=&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&D=020116&q={searchTerms}&SSPV=
- SearchScopes: HKU\S-1-5-21-1292048591-1437342970-2306004842-1000 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://v9.com/web?type=ds&ts=1450675887&from=zzgbkk123&uid=st3500418as_9vmdw0byxxxx9vmdw0by&z=ff2f3f500e4aabd74543086g5z0wfedqdm8w0batcg&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-1292048591-1437342970-2306004842-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/search?fr=vmn&type=vmn__webcompa__1_0__ya__ch_WCYID10099_swoc_campaign_151102__yaie&p={searchTerms}
- SearchScopes: HKU\S-1-5-21-1292048591-1437342970-2306004842-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3McXDvdSN6JAXeL5DbU_ODcLUTwSUWTaxZImUxxNdscwO55MTP5WPcno3sf4KNr4NX9YHKeoy8lA4LmWZ0I_QU78NbQivcj_YhZjm3BP7-2IxurlG0ZKCJeUKYpsoBrRNVVPN6jSCEyxTlFlFkNnpkakFumC&q={searchTerms}
- Toolbar: HKU\S-1-5-21-1292048591-1437342970-2306004842-1000 -> No Name - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - No File
- StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=69&CUI=&SSPV=&Lay=1&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&D=020116
- FF DefaultSearchEngine: yoursites123
- FF SelectedSearchEngine: Trovi
- FF Homepage: hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=55&CUI=&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&D=020116&SSPV=
- FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\findit.xml [2015-11-17]
- FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\trovi.xml [2016-02-02]
- FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\v9-.xml [2016-01-02]
- FF SearchPlugin: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\yoursites123.xml [2016-01-08]
- FF Extension: xRocket Toolbar - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\Extensions\arthurj8283@gmail.com [2015-12-21] [not signed]
- FF Extension: Default NewTab - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\Extensions\default_newtabff@gmail.com [2015-12-10] [not signed]
- FF Extension: YahooToolsProtected - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\Extensions\yahooprotected@gmail.com [2015-12-10] [not signed]
- FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\extensions\default_newtabff@gmail.com
- FF HKLM-x32\...\Firefox\Extensions: [yahooprotected@gmail.com] - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\extensions\yahooprotected@gmail.com
- FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\extensions\arthurj8283@gmail.com
- CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=55&CUI=&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&D=020116&SSPV=
- CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=55&CUI=&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&D=020116&SSPV="
- CHR DefaultSearchURL: Default -> hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=58&CUI=&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&D=020116&q={searchTerms}&SSPV=
- CHR DefaultSearchKeyword: Default -> trovi.search
- CHR DefaultNewTabURL: Default -> hxxps://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M6E481ED3-311B-4EDD-8AB3-FB165B13D669&SearchSource=69&CUI=&SSPV=&lay=5&p=cnts&UM=8&UP=SPB230D308-0707-42C8-8A60-8DA6B18C0CD7&SAT=CNTS&D=020116
- CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}&SSPV=
- CHR Extension: (Extutil) - C:\Users\user\AppData\Local\Temp\D8ADFCCA-EE7E-442C-9999-C4D14FEF360B [2016-02-02]
- CHR Extension: (Managera) - C:\Users\user\AppData\Local\Temp\39fdaae5-8e0e-493c-88ec-e05c3be06e42 [2016-02-02]
- OPR Extension: (Outrageous Deal) - C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\djmlpekfpipkpbipnanenhngngapmhal [2015-11-03]
- OPR Extension: (Monarch Find) - C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\jnnippojjelolbkfkaclaopllmbfoomp [2015-11-01]
- R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3246864 2016-01-14] (Client Connect LTD)
- R2 WdMan; C:\ProgramData\ZWdMZ\WdMan.exe [326656 2016-01-08] (TU-Funs LIMITED) [File not signed]
- C:\ProgramData\ZWdMZ
- 2016-02-02 01:21 - 2016-02-02 01:21 - 00003456 _____ C:\Windows\System32\Tasks\bvxvbxxvaa
- 2016-02-02 01:20 - 2016-02-02 10:07 - 00000000 ____D C:\Users\user\AppData\Local\bvxvbxxvaa
- 2016-02-02 01:20 - 2016-02-02 01:21 - 00000000 ____D C:\Users\user\AppData\Local\SearchProtect
- 2016-02-02 01:20 - 2016-02-02 01:20 - 00000000 ____D C:\Program Files (x86)\SearchProtect
- C:\Users\user\AppData\Local\Temp\bitool.dll
- C:\Users\user\AppData\Local\Temp\Crack Setup__11652_i1841842341_il6.exe
- C:\Users\user\AppData\Local\Temp\cres.dll
- C:\Users\user\AppData\Local\Temp\cshell.dll
- C:\Users\user\AppData\Local\Temp\ICReinstall_KeygenBitvise55HS3rv.exe
- C:\Users\user\AppData\Local\Temp\nGyN5z8T4Esc4ZoDj2nsN4DyL8i4biervHd.exe
- C:\Users\user\AppData\Local\Temp\OZlfHXt8eXLw3EDGtluUjjB3FzUldKyBQx1.exe
- C:\Users\user\AppData\Local\Temp\R2RTOOL.dll
- C:\Users\user\AppData\Local\Temp\sfamcc00001.dll
- C:\Users\user\AppData\Local\Temp\sfextra.dll
- C:\Users\user\AppData\Local\Temp\sp-downloader.exe
- C:\Users\user\AppData\Local\Temp\sres.dll
- C:\Users\user\AppData\Local\Temp\svchost.exe
- Task: {21245C2D-784F-46EE-A9C0-785EE2D6B919} - System32\Tasks\u3ngamib => C:\Program Files\Common Files\s3bxrxon\fe6372brqoho3.exe <==== ATTENTION
- C:\Program Files\Common Files\s3bxrxon
- Task: {9C683581-1C5B-4FE2-ADD5-DF2557871DA0} - System32\Tasks\productdqw => C:\Windows\system32\config\systemprofile\AppData\Local\Volplus <==== ATTENTION
- Task: {F8BE0199-7333-4179-A772-C37B3F8DAC8D} - System32\Tasks\bvxvbxxvaa => C:\Users\user\AppData\Local\bvxvbxxvaa\bvxvbxxvaa.exe [2016-01-14] () <==== ATTENTION
- C:\Users\user\AppData\Local\bvxvbxxvaa
- Task: {E79FFC5B-38B2-48E4-979A-15DC18538AD6} - System32\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5 => C:\Program Files (x86)\CinemaPlus-3.2cV25.10\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5.exe [2015-10-31] (Cinema PlusV25.10) <==== ATTENTION
- Task: {EDA94171-95D1-4EDF-A9BA-B584701EC9F9} - System32\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5_user => C:\Program Files (x86)\SavePass 1.1\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5.exe <==== ATTENTION
- Task: {8CBEF160-9C44-4F87-90CF-0B92F1F02162} - System32\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5_user => C:\Program Files (x86)\CinemaPlus-3.2cV25.10\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5.exe [2015-10-31] (Cinema PlusV25.10) <==== ATTENTION
- C:\Program Files (x86)\CinemaPlus-3.2cV25.10
- Task: {9C683581-1C5B-4FE2-ADD5-DF2557871DA0} - System32\Tasks\productdqw => C:\Windows\system32\config\systemprofile\AppData\Local\Volplus <==== ATTENTION
- Task: {3995C6CD-CCED-4B48-B19E-10ED921B0170} - System32\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5 => C:\Program Files (x86)\SavePass 1.1\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5.exe <==== ATTENTION
- C:\Program Files (x86)\SavePass 1.1
- Task: C:\Windows\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5.job => C:\Program Files (x86)\SavePass 1.1\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5.exe <==== ATTENTION
- Task: C:\Windows\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5_user.job => C:\Program Files (x86)\SavePass 1.1\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5.exe <==== ATTENTION
- Task: C:\Windows\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5.job => C:\Program Files (x86)\CinemaPlus-3.2cV25.10\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5.exe <==== ATTENTION
- Task: C:\Windows\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV25.10\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5.exe <==== ATTENTION
- ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.yoursites123.com/?type=sc&ts=1449716162&z=54345151c7aa277865c8e44g0zbz5t3mdg9q4g8w6t&from=ient07021&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursites123.com/?type=sc&ts=1452234073&z=3408d1426191634786098a7gdz5w9o1o0c9zde7m2o&from=wpm01073&uid=ST3500418AS_9VMDW0BYXXXX9VMDW0BY
- AlternateDataStreams: C:\ProgramData\Reprise:jhqduwvxlctbqqijsf`usjbm`bfpfh
- AlternateDataStreams: C:\Users\user\Cookies:yRhqZuwxxcIjxCPPqx1pr2YVv
- AlternateDataStreams: C:\Users\user\AppData\Local\Temporary Internet Files:0ZX3q4jcXEBCwVhDLgj8QN
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Classes\.exe: exefile => <===== ATTENTION
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Classes\exefile: <===== ATTENTION
- Hosts:
- EmptyTemp:
- end
- *****************
- Restore point was successfully created.
- Processes closed successfully.
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Windows\CurrentVersion\Run\\302a3f59a0bda767f51d068b3f4568a5 => value removed successfully
- C:\Users\user\AppData\Local\Temp\svchost.exe => moved successfully
- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\302a3f59a0bda767f51d068b3f4568a5.exe => moved successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => value removed successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => value removed successfully
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{256d7995-9e7c-11e5-815c-005056c00008}" => key removed successfully
- HKCR\CLSID\{256d7995-9e7c-11e5-815c-005056c00008} => key not found.
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{256d7998-9e7c-11e5-815c-005056c00008}" => key removed successfully
- HKCR\CLSID\{256d7998-9e7c-11e5-815c-005056c00008} => key not found.
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{400daf09-7f0e-11e5-809e-005056c00008}" => key removed successfully
- HKCR\CLSID\{400daf09-7f0e-11e5-809e-005056c00008} => key not found.
- "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll" => Value data not found.
- "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value data not found.
- C:\Windows\system32\GroupPolicy\Machine => moved successfully
- C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
- C:\Windows\system32\GroupPolicyUsers\S-1-5-21-1292048591-1437342970-2306004842-1005\User => moved successfully
- "HKLM\SOFTWARE\Policies\Google" => key removed successfully
- HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
- HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
- HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
- HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
- HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
- HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value removed successfully
- HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
- HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value removed successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => value removed successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
- HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
- HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => key removed successfully
- HKCR\Wow6432Node\CLSID\ielnksrch => key not found.
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
- HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
- "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => key removed successfully
- HKCR\Wow6432Node\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => key not found.
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => key removed successfully
- HKCR\CLSID\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found.
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}" => key removed successfully
- HKCR\CLSID\{425ED333-6083-428a-92C9-0CFC28B9D1BF} => key not found.
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C0C3A6C6-03BC-4195-8FCB-AEA091301353}" => key removed successfully
- HKCR\CLSID\{C0C3A6C6-03BC-4195-8FCB-AEA091301353} => key not found.
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => key removed successfully
- HKCR\CLSID\{ielnksrch} => key not found.
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A13C2648-91D4-4BF3-BC6D-0079707C4389} => value removed successfully
- "HKCR\CLSID\{A13C2648-91D4-4BF3-BC6D-0079707C4389}" => key removed successfully
- HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
- Firefox "newtab" removed successfully
- Firefox DefaultSearchEngine removed successfully
- Firefox SelectedSearchEngine removed successfully
- Firefox "homepage" removed successfully
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\findit.xml => moved successfully
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\trovi.xml => moved successfully
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\v9-.xml => moved successfully
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\searchplugins\yoursites123.xml => moved successfully
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\Extensions\arthurj8283@gmail.com => moved successfully
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\Extensions\default_newtabff@gmail.com => moved successfully
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6op4yo6f.default\Extensions\yahooprotected@gmail.com => moved successfully
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\default_newtabff@gmail.com => value removed successfully
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\yahooprotected@gmail.com => value removed successfully
- HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\arthurj8283@gmail.com => value removed successfully
- Chrome HomePage => removed successfully
- Chrome StartupUrls => removed successfully
- Chrome DefaultSearchURL => removed successfully
- Chrome DefaultSearchKeyword => removed successfully
- Chrome DefaultNewTabURL => removed successfully
- Chrome DefaultSuggestURL => removed successfully
- C:\Users\user\AppData\Local\Temp\D8ADFCCA-EE7E-442C-9999-C4D14FEF360B => moved successfully
- C:\Users\user\AppData\Local\Temp\39fdaae5-8e0e-493c-88ec-e05c3be06e42 => moved successfully
- C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\djmlpekfpipkpbipnanenhngngapmhal => moved successfully
- C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Extensions\jnnippojjelolbkfkaclaopllmbfoomp => moved successfully
- CltMngSvc => service not found.
- WdMan => service removed successfully
- C:\ProgramData\ZWdMZ => moved successfully
- "C:\Windows\System32\Tasks\bvxvbxxvaa" => not found.
- "C:\Users\user\AppData\Local\bvxvbxxvaa" => not found.
- "C:\Users\user\AppData\Local\SearchProtect" => not found.
- "C:\Program Files (x86)\SearchProtect" => not found.
- C:\Users\user\AppData\Local\Temp\bitool.dll => moved successfully
- C:\Users\user\AppData\Local\Temp\Crack Setup__11652_i1841842341_il6.exe => moved successfully
- C:\Users\user\AppData\Local\Temp\cres.dll => moved successfully
- C:\Users\user\AppData\Local\Temp\cshell.dll => moved successfully
- C:\Users\user\AppData\Local\Temp\ICReinstall_KeygenBitvise55HS3rv.exe => moved successfully
- C:\Users\user\AppData\Local\Temp\nGyN5z8T4Esc4ZoDj2nsN4DyL8i4biervHd.exe => moved successfully
- C:\Users\user\AppData\Local\Temp\OZlfHXt8eXLw3EDGtluUjjB3FzUldKyBQx1.exe => moved successfully
- C:\Users\user\AppData\Local\Temp\R2RTOOL.dll => moved successfully
- C:\Users\user\AppData\Local\Temp\sfamcc00001.dll => moved successfully
- C:\Users\user\AppData\Local\Temp\sfextra.dll => moved successfully
- C:\Users\user\AppData\Local\Temp\sp-downloader.exe => moved successfully
- C:\Users\user\AppData\Local\Temp\sres.dll => moved successfully
- "C:\Users\user\AppData\Local\Temp\svchost.exe" => not found.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{21245C2D-784F-46EE-A9C0-785EE2D6B919}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21245C2D-784F-46EE-A9C0-785EE2D6B919}" => key removed successfully
- C:\Windows\System32\Tasks\u3ngamib => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\u3ngamib" => key removed successfully
- C:\Program Files\Common Files\s3bxrxon => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9C683581-1C5B-4FE2-ADD5-DF2557871DA0}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C683581-1C5B-4FE2-ADD5-DF2557871DA0}" => key removed successfully
- C:\Windows\System32\Tasks\productdqw => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\productdqw" => key removed successfully
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8BE0199-7333-4179-A772-C37B3F8DAC8D} => key not found.
- C:\Windows\System32\Tasks\bvxvbxxvaa => not found.
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbxxvaa => key not found.
- "C:\Users\user\AppData\Local\bvxvbxxvaa" => not found.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E79FFC5B-38B2-48E4-979A-15DC18538AD6}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E79FFC5B-38B2-48E4-979A-15DC18538AD6}" => key removed successfully
- C:\Windows\System32\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5 => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EDA94171-95D1-4EDF-A9BA-B584701EC9F9}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EDA94171-95D1-4EDF-A9BA-B584701EC9F9}" => key removed successfully
- C:\Windows\System32\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5_user => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5_user" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8CBEF160-9C44-4F87-90CF-0B92F1F02162}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CBEF160-9C44-4F87-90CF-0B92F1F02162}" => key removed successfully
- C:\Windows\System32\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5_user => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5_user" => key removed successfully
- C:\Program Files (x86)\CinemaPlus-3.2cV25.10 => moved successfully
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C683581-1C5B-4FE2-ADD5-DF2557871DA0} => key not found.
- C:\Windows\System32\Tasks\productdqw => not found.
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\productdqw => key not found.
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3995C6CD-CCED-4B48-B19E-10ED921B0170}" => key removed successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3995C6CD-CCED-4B48-B19E-10ED921B0170}" => key removed successfully
- C:\Windows\System32\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5 => moved successfully
- "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5" => key removed successfully
- "C:\Program Files (x86)\SavePass 1.1" => not found.
- C:\Windows\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5.job => moved successfully
- C:\Windows\Tasks\06947da4-c300-4fc0-9ccc-4d861fbfb68d-5_user.job => moved successfully
- C:\Windows\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5.job => moved successfully
- C:\Windows\Tasks\08d47c20-5df0-42b6-a3b0-f77cb968d1a2-5_user.job => moved successfully
- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk => Shortcut argument removed successfully.
- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Shortcut argument removed successfully.
- C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => Shortcut argument restored successfully
- C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => Shortcut argument removed successfully.
- C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => Shortcut argument removed successfully.
- C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => Shortcut argument removed successfully.
- C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera.lnk => Shortcut argument removed successfully.
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Shortcut argument removed successfully.
- C:\Users\Public\Desktop\Google Chrome.lnk => Shortcut argument removed successfully.
- C:\ProgramData\Reprise => ":jhqduwvxlctbqqijsf`usjbm`bfpfh" ADS removed successfully.
- "C:\Users\user\Cookies" => ":yRhqZuwxxcIjxCPPqx1pr2YVv" ADS not found.
- "C:\Users\user\AppData\Local\Temporary Internet Files" => ":0ZX3q4jcXEBCwVhDLgj8QN" ADS not found.
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Classes\exefile" => key removed successfully
- "HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Classes\.exe" => key removed successfully
- HKU\S-1-5-21-1292048591-1437342970-2306004842-1000\Software\Classes\exefile => key not found.
- C:\Windows\System32\Drivers\etc\hosts => moved successfully
- Hosts restored successfully.
- EmptyTemp: => 51.6 GB temporary data Removed.
- The system needed a reboot.
- ==== End of Fixlog 00:01:06 ====
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement