Re: Virusy, YT downloader CINEMA ADS
Napsal: 11 črc 2015 14:08
Fix result of Farbar Recovery Scan Tool (x64) Version:11-07-2015
Ran by Ady at 2015-07-11 15:02:39 Run:1
Running from C:\Users\Ady\Desktop
Loaded Profiles: Ady (Available Profiles: Ady)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\...\Run: [GoogleChromeAutoLaunch_627D03071ECD4E853ACE01A77156EF11] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-07] (Google Inc.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
2015-07-09 18:33 - 2015-07-09 18:09 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-09 18:13 - 2015-07-09 18:44 - 00007716 _____ C:\zoek-results.log
2015-07-09 18:09 - 2015-07-09 18:30 - 00000000 ____D C:\zoek_backup
2015-07-09 18:08 - 2015-07-09 18:09 - 01308672 _____ C:\Users\Ady\Downloads\zoek.exe
2015-07-09 17:54 - 2015-07-09 18:01 - 00000000 ____D C:\AdwCleaner
2015-07-09 17:52 - 2015-07-09 17:53 - 02244096 _____ C:\Users\Ady\Downloads\adwcleaner_4.207.exe
2015-07-09 17:18 - 2015-07-10 20:00 - 00018154 _____ C:\Users\Ady\Desktop\FRST.txt
2015-07-09 17:17 - 2015-07-09 17:17 - 00055533 _____ C:\Users\Ady\Desktop\FRST3.txt
2015-07-09 17:16 - 2015-07-09 17:17 - 00028240 _____ C:\Users\Ady\Desktop\Addition.txt
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateP2GShortCut => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_627D03071ECD4E853ACE01A77156EF11 => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
C:\Windows\zoek-delete.exe => moved successfully.
C:\zoek-results.log => moved successfully.
C:\zoek_backup => moved successfully.
C:\Users\Ady\Downloads\zoek.exe => moved successfully.
C:\AdwCleaner => moved successfully.
C:\Users\Ady\Downloads\adwcleaner_4.207.exe => moved successfully.
C:\Users\Ady\Desktop\FRST.txt => moved successfully.
C:\Users\Ady\Desktop\FRST3.txt => moved successfully.
C:\Users\Ady\Desktop\Addition.txt => moved successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 775.6 MB temporary data Removed.
The system needed a reboot..
==== End of Fixlog 15:03:25 ====
Ran by Ady at 2015-07-11 15:02:39 Run:1
Running from C:\Users\Ady\Desktop
Loaded Profiles: Ady (Available Profiles: Ady)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\...\Run: [GoogleChromeAutoLaunch_627D03071ECD4E853ACE01A77156EF11] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-07] (Google Inc.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
2015-07-09 18:33 - 2015-07-09 18:09 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-09 18:13 - 2015-07-09 18:44 - 00007716 _____ C:\zoek-results.log
2015-07-09 18:09 - 2015-07-09 18:30 - 00000000 ____D C:\zoek_backup
2015-07-09 18:08 - 2015-07-09 18:09 - 01308672 _____ C:\Users\Ady\Downloads\zoek.exe
2015-07-09 17:54 - 2015-07-09 18:01 - 00000000 ____D C:\AdwCleaner
2015-07-09 17:52 - 2015-07-09 17:53 - 02244096 _____ C:\Users\Ady\Downloads\adwcleaner_4.207.exe
2015-07-09 17:18 - 2015-07-10 20:00 - 00018154 _____ C:\Users\Ady\Desktop\FRST.txt
2015-07-09 17:17 - 2015-07-09 17:17 - 00055533 _____ C:\Users\Ady\Desktop\FRST3.txt
2015-07-09 17:16 - 2015-07-09 17:17 - 00028240 _____ C:\Users\Ady\Desktop\Addition.txt
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateP2GShortCut => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_627D03071ECD4E853ACE01A77156EF11 => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-4267633423-2763059481-3757242003-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
C:\Windows\zoek-delete.exe => moved successfully.
C:\zoek-results.log => moved successfully.
C:\zoek_backup => moved successfully.
C:\Users\Ady\Downloads\zoek.exe => moved successfully.
C:\AdwCleaner => moved successfully.
C:\Users\Ady\Downloads\adwcleaner_4.207.exe => moved successfully.
C:\Users\Ady\Desktop\FRST.txt => moved successfully.
C:\Users\Ady\Desktop\FRST3.txt => moved successfully.
C:\Users\Ady\Desktop\Addition.txt => moved successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 775.6 MB temporary data Removed.
The system needed a reboot..
==== End of Fixlog 15:03:25 ====