Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by kubar (16-03-2017 18:25:41) Run:1
Running from C:\Users\kubar\Desktop
Loaded Profiles: kubar (Available Profiles: defaultuser0 & kubar)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\S-1-5-21-495495518-1249904075-3165854488-1001\...\MountPoints2: {f626bf78-eef9-11e6-8230-c48e8f8122ca} - "F:\setup.exe"
IFEO\taskmgr.exe: [Debugger]
ShellExecuteHooks: No Name - {7F7806D8-DE44-11E6-82D2-64006A5CFC23} - C:\Users\kubar\AppData\Roaming\Kaphghibapy\Grefaph.dll -> No File
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-495495518-1249904075-3165854488-1001 -> {B79D4439-0DF3-4135-AE13-9C9E4387437C} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=H2Azamobl20603AU,2f18c99d-2ca8-46e1-b5e7-db88961a4ba2,
Edge HomeButtonPage: HKU\S-1-5-21-495495518-1249904075-3165854488-1001 -> hxxp://
www.amisites.com/?type=hp&ts=148 ... 339DS339DS
CHR HomePage: ChromeDefaultData -> hxxp://
www.luckysearch123.com?type=hp&t ... 6e7g2bdtat
CHR StartupUrls: ChromeDefaultData -> "hxxp://
www.luckysearch123.com?type=hp&ts=14894 ... 6e7g2bdtat"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://
www.luckysearch123.com/search.ph ... g2bdtat&q={searchTerms}
CHR DefaultSearchKeyword: ChromeDefaultData -> luck
CHR Profile: C:\Users\kubar\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-03-15] <==== ATTENTION
HKU\S-1-5-21-495495518-1249904075-3165854488-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Cansuck\Application\chrome.exe (Google Inc.) <==== ATTENTION
S2 Themes; C:\Windows\system32\themeservice.dll [70656 2016-07-16] (Microsoft Corporation) [DependOnService: iThemes5]<==== ATTENTION
S2 WinSnare; C:\Users\kubar\AppData\Roaming\WinSnare\WinSnare.dll [779776 2017-02-08] (InterSect Alliance Pty Ltd) [File not signed] <==== ATTENTION
S2 CansuckSU; "C:\Users\kubar\AppData\Local\Temp\1\Bfinstall.exe" /i [X] <==== ATTENTION
S2 Protecultsakt; C:\Program Files (x86)\Newughikeing\PlpVerfier.dll [X]
R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [262344 2016-05-23] (Elex do Brasil Participaçoes Ltda)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [55056 2016-05-23] (Elex do Brasil Participaçoes Ltda)
S1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [110112 2016-05-23] (Elex do Brasil Participaçoes Ltda)
R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [103904 2016-05-23] (Elex do Brasil Participaçoes Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [52392 2016-05-19] (Elex do Brasil Participaçoes Ltda)
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Windows\system32\ApnDatabase.xml
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\ProgramData\smp2.exe
C:\Users\kubar\jre-8u121-windows-x64.exe
C:\Users\kubar\TLv4.0-238-64b-win.exe
Task: {03628B6C-9516-42A8-9BD7-36DC0521B475} - \SMW_UpdateTask_Time_343036333939313337342d4a375b5a5a6c783245343741 -> No File <==== ATTENTION
Task: {7C3E5C8F-611F-4F44-8E8C-43682EB9ECE7} - System32\Tasks\1280l23A15c3397 => Rundll32.exe "C:\ProgramData\1280l23A15c3397\1280l23A15c3397.dll",lAcqxFh <==== ATTENTION
Task: {FF163EA7-C9B9-4F30-B18D-2B1930733779} - System32\Tasks\SMW_P => C:\ProgramData\smp2.exe [2017-02-10] () <==== ATTENTION
EmptyTemp:
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
HKU\S-1-5-21-495495518-1249904075-3165854488-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f626bf78-eef9-11e6-8230-c48e8f8122ca} => key removed successfully
HKCR\CLSID\{f626bf78-eef9-11e6-8230-c48e8f8122ca} => key not found.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\taskmgr.exe => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{7F7806D8-DE44-11E6-82D2-64006A5CFC23} => value removed successfully
HKCR\CLSID\{7F7806D8-DE44-11E6-82D2-64006A5CFC23} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-21-495495518-1249904075-3165854488-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B79D4439-0DF3-4135-AE13-9C9E4387437C} => key could not remove, key could be protected
HKCR\CLSID\{B79D4439-0DF3-4135-AE13-9C9E4387437C} => key not found.
HKU\S-1-5-21-495495518-1249904075-3165854488-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main\\HomeButtonPage => value removed successfully
Chrome HomePage => removed successfully
Chrome StartupUrls => removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
C:\Users\kubar\AppData\Local\Google\Chrome\User Data\ChromeDefaultData => moved successfully
HKU\S-1-5-21-495495518-1249904075-3165854488-1001\SOFTWARE\Clients\StartMenuInternet\ChromeHTML => key removed successfully
HKLM\System\CurrentControlSet\Services\Themes\\DependOnService => value removed successfully
HKLM\System\CurrentControlSet\Services\WinSnare => key removed successfully
WinSnare => service removed successfully
HKLM\System\CurrentControlSet\Services\CansuckSU => key removed successfully
CansuckSU => service removed successfully
HKLM\System\CurrentControlSet\Services\Protecultsakt => key removed successfully
Protecultsakt => service removed successfully
iSafeKrnl => Unable to stop service.
HKLM\System\CurrentControlSet\Services\iSafeKrnl => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\iSafeKrnlBoot => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\iSafeKrnlKit => key could not remove, key could be protected
iSafeKrnlR3 => Unable to stop service.
HKLM\System\CurrentControlSet\Services\iSafeKrnlR3 => key could not remove, key could be protected
iSafeNetFilter => Unable to stop service.
HKLM\System\CurrentControlSet\Services\iSafeNetFilter => key could not remove, key could be protected
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\Windows\system32\ApnDatabase.xml => moved successfully
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
C:\ProgramData\smp2.exe => moved successfully
C:\Users\kubar\jre-8u121-windows-x64.exe => moved successfully
Could not move "C:\Users\kubar\TLv4.0-238-64b-win.exe" => Scheduled to move on reboot.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03628B6C-9516-42A8-9BD7-36DC0521B475} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03628B6C-9516-42A8-9BD7-36DC0521B475} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_UpdateTask_Time_343036333939313337342d4a375b5a5a6c783245343741 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7C3E5C8F-611F-4F44-8E8C-43682EB9ECE7} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C3E5C8F-611F-4F44-8E8C-43682EB9ECE7} => key removed successfully
C:\Windows\System32\Tasks\1280l23A15c3397 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1280l23A15c3397 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FF163EA7-C9B9-4F30-B18D-2B1930733779} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF163EA7-C9B9-4F30-B18D-2B1930733779} => key removed successfully
C:\Windows\System32\Tasks\SMW_P => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_P => key removed successfully
=========== EmptyTemp: ==========
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 24455321 B
Java, Flash, Steam htmlcache => 6403130 B
Windows/system/drivers => 58572572 B
Edge => 21044352 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 21190 B
NetworkService => 87380 B
defaultuser0 => 588289 B
kubar => 694820128 B
RecycleBin => 10248262064 B
EmptyTemp: => 10.3 GB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 16-03-2017 18:27:47)
C:\Users\kubar\TLv4.0-238-64b-win.exe => Is moved successfully
Result of scheduled keys to remove after reboot:
HKU\S-1-5-21-495495518-1249904075-3165854488-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B79D4439-0DF3-4135-AE13-9C9E4387437C} => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\iSafeKrnl => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\iSafeKrnlBoot => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\iSafeKrnlKit => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\iSafeKrnlR3 => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\iSafeNetFilter => key could not remove, key could be protected
==== End of Fixlog 18:27:47 ====