Fix result of Farbar Recovery Scan Tool (x64) Version: 10-06-2019
Ran by ruda6 (10-06-2019 18:41:45) Run:3
Running from C:\Users\ruda6\Desktop
Loaded Profiles: ruda6 (Available Profiles: ruda6 & DevToolsUser)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
File: C:\Users\ruda6\Downloads\EFClock.exe
CMD: type "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
CMD: type "C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js"
CMD: type "C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg"
CMD: type "C:\Users\ruda6\AppData\Local\temp.bat"
HKU\S-1-5-21-267884743-2030251231-2907502807-1001\...\MountPoints2: {c7d85400-dbe7-11e7-8776-94e97978fbde} - "F:\WD Drive Unlock.exe" autoplay=true
HKU\S-1-5-21-267884743-2030251231-2907502807-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.bing.com/
CHR HomePage: Default -> hxxps://
www.google.cz/?gfe_rd=cr&ei=X0EGWaPSAYi ... =ssl&pli=1
CHR StartupUrls: Default -> "hxxps://
www.google.cz/?pli=1","hxxps://www.sezn ... entrum.cz/"
2019-06-09 17:21 - 2019-06-09 17:21 - 000000000 ____D C:\Users\ruda6\Desktop\FRST-OlderVersion
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\Program Files\PDFCreator\PDFCreatorShell.DLL -> No File
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========
Count : 476
Average :
Sum : 92356299
Maximum :
Minimum :
Property : Length
========= End of Powershell: =========
========================= File: C:\Users\ruda6\Downloads\EFClock.exe ========================
C:\Users\ruda6\Downloads\EFClock.exe
File not signed
MD5: F79F220F279FCD81CD521AEB240F6E05
Creation and modification date: 2019-02-03 00:23 - 2019-02-03 00:23
Size: 000458752
Attributes: ----A
Company Name: Eusing Software
Internal Name: EFClock
Original Name: EFClock.exe
Product: Eusing Clock
Description: A beautiful clock
File Version: 2.08
Product Version: 2.08
Copyright: Copyright (C) 2004 - 2018 Eusing Software
VirusTotal:
https://www.virustotal.com/file/d7394bd ... 559681642/
====== End of File: ======
========= type "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs" =========
Set objShell = CreateObject("WScript.Shell")
objShell.Run("C:\WINDOWS\system32\cmd.exe /c ""C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.bat"""), 0
Set objShell = Nothing
========= End of CMD: =========
========= type "C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js" =========
// kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js
pref("general.config.obscure_value", 0);
pref("general.config.filename", "kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg");
========= End of CMD: =========
========= type "C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg" =========
// kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg
lockPref("security.enterprise_roots.enabled", true);
========= End of CMD: =========
========= type "C:\Users\ruda6\AppData\Local\temp.bat" =========
setlocal ENABLEDELAYEDEXPANSION
Set Process=purevpn_setup
:ppp
tasklist | Find /i "%Process%.exe" || (goto Else)
:THEN
goto ppp
:ELSE
%systemdrive%
cd %programfiles%
cd purevpn
if exist purevpn.exe start purevpn.exe
cd C:\Users\ruda6\AppData\Local
del temp.bat
Exit
========= End of CMD: =========
HKU\S-1-5-21-267884743-2030251231-2907502807-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c7d85400-dbe7-11e7-8776-94e97978fbde} => removed successfully
HKLM\Software\Classes\CLSID\{c7d85400-dbe7-11e7-8776-94e97978fbde} => not found
HKU\S-1-5-21-267884743-2030251231-2907502807-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
"Chrome HomePage" => removed successfully
"Chrome StartupUrls" => removed successfully
C:\Users\ruda6\Desktop\FRST-OlderVersion => moved successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\PDFCreator.ShellContextMenu => removed successfully
HKLM\Software\Classes\CLSID\{d9cea52e-100d-4159-89ea-76e845bc13e1} => removed successfully
Could not move "C:\Windows\System32\Drivers\etc\hosts" => Scheduled to move on reboot.
=========== EmptyTemp: ==========
BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 29605538 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 539037 B
Edge => 82332156 B
Chrome => 485973 B
Firefox => 22838187 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 4940 B
LocalService => 0 B
NetworkService => 0 B
NetworkService => 0 B
ruda6 => 43184902 B
rudyk => 0 B
DevToolsUser => 0 B
RecycleBin => 33304757 B
EmptyTemp: => 212.5 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 10-06-2019 18:43:47)
C:\Windows\System32\Drivers\etc\hosts => Is moved successfully