Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
help please and thank you
Message
<blockquote data-quote="S Henson" data-source="post: 405972" data-attributes="member: 37603"><p>Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01</p><p>Ran by Sandra Henson at 2015-07-02 14:37:56 Run:2</p><p>Running from C:\Users\Sandra Henson\Desktop</p><p>Loaded Profiles: Sandra Henson (Available Profiles: Sandra Henson & sandra backup & Guest)</p><p>Boot Mode: Normal</p><p>==============================================</p><p></p><p>fixlist content:</p><p>*****************</p><p>closeprocesses:</p><p>emptytemp:</p><p>C:\Program Files (x86)\Fast Browser</p><p>GroupPolicy: Group Policy on Chrome detected <======= ATTENTION</p><p>HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://speedial.com/?f=1&a=spd_dsit...tGtByE0FyCyC0DyEyC0C0E0Bzz2Q&cr=411408616&ir=" target="_blank">http://speedial.com/?f=1&a=spd_dsit...tGtByE0FyCyC0DyEyC0C0E0Bzz2Q&cr=411408616&ir=</a></p><p>HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = <a href="http://www.safesear.ch/?type=20150614-230-ie" target="_blank">http://www.safesear.ch/?type=20150614-230-ie</a></p><p>HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}" target="_blank">http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}</a></p><p>HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://www.safesear.ch/?type=20150614-230-ie" target="_blank">http://www.safesear.ch/?type=20150614-230-ie</a></p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://yahoo/.com" target="_blank">http://yahoo/.com</a></p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}" target="_blank">http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}</a></p><p>URLSearchHook: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)</p><p>SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = <a href="http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox" target="_blank">http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox</a></p><p>SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = <a href="http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox" target="_blank">http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox</a></p><p>SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = <a href="http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF" target="_blank">http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF</a></p><p>SearchScopes: HKLM -> {31090377-0740-419E-BEFC-A56E50500D5B} URL = <a href="http://speedial.com/results.php?f=4...tGtByE0FyCyC0DyEyC0C0E0Bzz2Q&cr=411408616&ir=" target="_blank">http://speedial.com/results.php?f=4...tGtByE0FyCyC0DyEyC0C0E0Bzz2Q&cr=411408616&ir=</a></p><p>SearchScopes: HKLM -> {A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} URL = <a href="http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}" target="_blank">http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}</a></p><p>SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = <a href="http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF" target="_blank">http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF</a></p><p>SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = <a href="http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}" target="_blank">http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}</a></p><p>SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = <a href="http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}" target="_blank">http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}</a></p><p>SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = <a href="http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox" target="_blank">http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox</a></p><p>SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = <a href="http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox" target="_blank">http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox</a></p><p>SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = <a href="http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF" target="_blank">http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF</a></p><p>SearchScopes: HKLM-x32 -> {A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} URL = <a href="http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}" target="_blank">http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}</a></p><p>SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = <a href="http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}" target="_blank">http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}</a></p><p>SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = <a href="http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}" target="_blank">http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}</a></p><p>SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = <a href="http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}" target="_blank">http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}</a></p><p>SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =</p><p>SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {08E50FFB-6A26-4BFA-8998-D03FD169D2FF} URL = <a href="https://search.yahoo.com/search?p={searchTerms}&fr=chr-ygamesbar&type=yahoo_oberon_ygames_ytb" target="_blank">https://search.yahoo.com/search?p={searchTerms}&fr=chr-ygamesbar&type=yahoo_oberon_ygames_ytb</a></p><p>SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL =</p><p>SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {31090377-0740-419E-BEFC-A56E50500D5B} URL =</p><p>SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} URL =</p><p>SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL =</p><p>SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL =</p><p>SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =</p><p>CHR HKLM\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - <a href="https://clients2.google.com/service/update2/crx" target="_blank">https://clients2.google.com/service/update2/crx</a></p><p>CHR HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - <a href="https://clients2.google.com/service/update2/crx" target="_blank">https://clients2.google.com/service/update2/crx</a></p><p>CHR HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - <a href="https://clients2.google.com/service/update2/crx" target="_blank">https://clients2.google.com/service/update2/crx</a></p><p>CHR HKLM-x32\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - <a href="https://clients2.google.com/service/update2/crx" target="_blank">https://clients2.google.com/service/update2/crx</a></p><p>S1 qknfd; system32\drivers\qknfd.sys [X]</p><p>Task: {F3EE3214-C517-4569-965C-AD245A1F403F} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION</p><p>C:\Program Files (x86)\MyPC Backup</p><p>AlternateDataStreams: C:\ProgramData\Temp:00FE3B98</p><p>AlternateDataStreams: C:\ProgramData\Temp:01442FD8</p><p>AlternateDataStreams: C:\ProgramData\Temp:0EFEBFCB</p><p>AlternateDataStreams: C:\ProgramData\Temp:17FF6514</p><p>AlternateDataStreams: C:\ProgramData\Temp:1F9C3D08</p><p>AlternateDataStreams: C:\ProgramData\Temp:29BCDA07</p><p>AlternateDataStreams: C:\ProgramData\Temp:3447AB86</p><p>AlternateDataStreams: C:\ProgramData\Temp:3ABC2192</p><p>AlternateDataStreams: C:\ProgramData\Temp:3B9582E0</p><p>AlternateDataStreams: C:\ProgramData\Temp:54FDCED6</p><p>AlternateDataStreams: C:\ProgramData\Temp:5E3FBF9D</p><p>AlternateDataStreams: C:\ProgramData\Temp:69E7DEDD</p><p>AlternateDataStreams: C:\ProgramData\Temp:79363C4B</p><p>AlternateDataStreams: C:\ProgramData\Temp:7ACF38DE</p><p>AlternateDataStreams: C:\ProgramData\Temp:89952728</p><p>AlternateDataStreams: C:\ProgramData\Temp:8EB63C9D</p><p>AlternateDataStreams: C:\ProgramData\Temp:97CCC404</p><p>AlternateDataStreams: C:\ProgramData\Temp:9A995231</p><p>AlternateDataStreams: C:\ProgramData\Temp:9FF05345</p><p>AlternateDataStreams: C:\ProgramData\Temp:ACA50580</p><p>AlternateDataStreams: C:\ProgramData\Temp:B7B09D45</p><p>AlternateDataStreams: C:\ProgramData\Temp:C6B7DC67</p><p>AlternateDataStreams: C:\ProgramData\Temp:CBEB737E</p><p>AlternateDataStreams: C:\ProgramData\Temp<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite116" alt=":D" title="Big grin :D" loading="lazy" data-shortname=":D" />B0CD29E</p><p>AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D</p><p>AlternateDataStreams: C:\ProgramData\Temp:EC5BDCFF</p><p>AlternateDataStreams: C:\ProgramData\Temp:F306CF14</p><p>AlternateDataStreams: C:\ProgramData\Temp:F5D4C9D5</p><p>AlternateDataStreams: C:\ProgramData\Temp:FA62FF6E</p><p>AlternateDataStreams: C:\ProgramData\Temp:FC5FFC81</p><p></p><p>*****************</p><p></p><p>Processes closed successfully.</p><p>"C:\Program Files (x86)\Fast Browser" => File/Folder not found.</p><p>"C:\Windows\system32\GroupPolicy\Machine" => File/Folder not found.</p><p>HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully</p><p>HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully</p><p>HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully</p><p>HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully</p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully</p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully</p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} => value not found.</p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully</p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. </p><p>HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. </p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. </p><p>HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. </p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. </p><p>HKCR\CLSID\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. </p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. </p><p>HKCR\CLSID\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. </p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. </p><p>HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. </p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. </p><p>HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. </p><p>HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. </p><p>HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. </p><p>HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully</p><p>HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. </p><p>HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. </p><p>HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. </p><p>HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. </p><p>HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. </p><p>HKCR\Wow6432Node\CLSID\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. </p><p>HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. </p><p>HKCR\Wow6432Node\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. </p><p>HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. </p><p>HKCR\Wow6432Node\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. </p><p>HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. </p><p>HKCR\Wow6432Node\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. </p><p>HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.</p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{08E50FFB-6A26-4BFA-8998-D03FD169D2FF} => key not found. </p><p>HKCR\CLSID\{08E50FFB-6A26-4BFA-8998-D03FD169D2FF} => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. </p><p>HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. </p><p>HKCR\CLSID\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. </p><p>HKCR\CLSID\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. </p><p>HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. </p><p>HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. </p><p>HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. </p><p>HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd => key not found. </p><p>HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\gdfjhiclilbjdpeejgcgebmmihkkofji => key not found. </p><p>HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd => key not found. </p><p>qknfd => Service not found.</p><p>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3EE3214-C517-4569-965C-AD245A1F403F} => key not found. </p><p>C:\Windows\System32\Tasks\LaunchApp not found.</p><p>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchApp => key not found. </p><p>"C:\Program Files (x86)\MyPC Backup" => File/Folder not found.</p><p>"C:\ProgramData\Temp" => ":00FE3B98" ADS not found.</p><p>"C:\ProgramData\Temp" => ":01442FD8" ADS not found.</p><p>"C:\ProgramData\Temp" => ":0EFEBFCB" ADS not found.</p><p>"C:\ProgramData\Temp" => ":17FF6514" ADS not found.</p><p>"C:\ProgramData\Temp" => ":1F9C3D08" ADS not found.</p><p>"C:\ProgramData\Temp" => ":29BCDA07" ADS not found.</p><p>"C:\ProgramData\Temp" => ":3447AB86" ADS not found.</p><p>"C:\ProgramData\Temp" => ":3ABC2192" ADS not found.</p><p>"C:\ProgramData\Temp" => ":3B9582E0" ADS not found.</p><p>"C:\ProgramData\Temp" => ":54FDCED6" ADS not found.</p><p>"C:\ProgramData\Temp" => ":5E3FBF9D" ADS not found.</p><p>"C:\ProgramData\Temp" => ":69E7DEDD" ADS not found.</p><p>"C:\ProgramData\Temp" => ":79363C4B" ADS not found.</p><p>"C:\ProgramData\Temp" => ":7ACF38DE" ADS not found.</p><p>"C:\ProgramData\Temp" => ":89952728" ADS not found.</p><p>"C:\ProgramData\Temp" => ":8EB63C9D" ADS not found.</p><p>"C:\ProgramData\Temp" => ":97CCC404" ADS not found.</p><p>"C:\ProgramData\Temp" => ":9A995231" ADS not found.</p><p>"C:\ProgramData\Temp" => ":9FF05345" ADS not found.</p><p>"C:\ProgramData\Temp" => ":ACA50580" ADS not found.</p><p>"C:\ProgramData\Temp" => ":B7B09D45" ADS not found.</p><p>"C:\ProgramData\Temp" => ":C6B7DC67" ADS not found.</p><p>"C:\ProgramData\Temp" => ":CBEB737E" ADS not found.</p><p>"C:\ProgramData\Temp" => "<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite116" alt=":D" title="Big grin :D" loading="lazy" data-shortname=":D" />B0CD29E" ADS not found.</p><p>"C:\ProgramData\Temp" => ":E1F04E8D" ADS not found.</p><p>"C:\ProgramData\Temp" => ":EC5BDCFF" ADS not found.</p><p>"C:\ProgramData\Temp" => ":F306CF14" ADS not found.</p><p>"C:\ProgramData\Temp" => ":F5D4C9D5" ADS not found.</p><p>"C:\ProgramData\Temp" => ":FA62FF6E" ADS not found.</p><p>"C:\ProgramData\Temp" => ":FC5FFC81" ADS not found.</p><p>EmptyTemp: => 986.2 MB temporary data Removed.</p><p></p><p></p><p>The system needed a reboot.. </p><p></p><p>==== End of Fixlog 14:39:31 ====</p></blockquote><p></p>
[QUOTE="S Henson, post: 405972, member: 37603"] Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01 Ran by Sandra Henson at 2015-07-02 14:37:56 Run:2 Running from C:\Users\Sandra Henson\Desktop Loaded Profiles: Sandra Henson (Available Profiles: Sandra Henson & sandra backup & Guest) Boot Mode: Normal ============================================== fixlist content: ***************** closeprocesses: emptytemp: C:\Program Files (x86)\Fast Browser GroupPolicy: Group Policy on Chrome detected <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://speedial.com/?f=1&a=spd_dsit...tGtByE0FyCyC0DyEyC0C0E0Bzz2Q&cr=411408616&ir=[/URL] HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = [URL]http://www.safesear.ch/?type=20150614-230-ie[/URL] HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = [URL]http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}[/URL] HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = [URL]http://www.safesear.ch/?type=20150614-230-ie[/URL] HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://yahoo/.com[/URL] HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main,Search Page = [URL]http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}[/URL] URLSearchHook: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.) SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [URL]http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox[/URL] SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [URL]http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox[/URL] SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = [URL]http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF[/URL] SearchScopes: HKLM -> {31090377-0740-419E-BEFC-A56E50500D5B} URL = [URL]http://speedial.com/results.php?f=4...tGtByE0FyCyC0DyEyC0C0E0Bzz2Q&cr=411408616&ir=[/URL] SearchScopes: HKLM -> {A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} URL = [URL]http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}[/URL] SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = [URL]http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF[/URL] SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = [URL]http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}[/URL] SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = [URL]http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}[/URL] SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [URL]http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox[/URL] SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = [URL]http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox[/URL] SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = [URL]http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF[/URL] SearchScopes: HKLM-x32 -> {A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} URL = [URL]http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}[/URL] SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = [URL]http://www.safesear.ch/web/?type=20150614-230-sshome-ie-df&q={searchTerms}[/URL] SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = [URL]http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}[/URL] SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = [URL]http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}[/URL] SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {08E50FFB-6A26-4BFA-8998-D03FD169D2FF} URL = [URL]https://search.yahoo.com/search?p={searchTerms}&fr=chr-ygamesbar&type=yahoo_oberon_ygames_ytb[/URL] SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {31090377-0740-419E-BEFC-A56E50500D5B} URL = SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} URL = SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = SearchScopes: HKU\S-1-5-21-1948824698-2788543327-851348242-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = CHR HKLM\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - [URL]https://clients2.google.com/service/update2/crx[/URL] CHR HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - [URL]https://clients2.google.com/service/update2/crx[/URL] CHR HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - [URL]https://clients2.google.com/service/update2/crx[/URL] CHR HKLM-x32\...\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - [URL]https://clients2.google.com/service/update2/crx[/URL] S1 qknfd; system32\drivers\qknfd.sys [X] Task: {F3EE3214-C517-4569-965C-AD245A1F403F} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION C:\Program Files (x86)\MyPC Backup AlternateDataStreams: C:\ProgramData\Temp:00FE3B98 AlternateDataStreams: C:\ProgramData\Temp:01442FD8 AlternateDataStreams: C:\ProgramData\Temp:0EFEBFCB AlternateDataStreams: C:\ProgramData\Temp:17FF6514 AlternateDataStreams: C:\ProgramData\Temp:1F9C3D08 AlternateDataStreams: C:\ProgramData\Temp:29BCDA07 AlternateDataStreams: C:\ProgramData\Temp:3447AB86 AlternateDataStreams: C:\ProgramData\Temp:3ABC2192 AlternateDataStreams: C:\ProgramData\Temp:3B9582E0 AlternateDataStreams: C:\ProgramData\Temp:54FDCED6 AlternateDataStreams: C:\ProgramData\Temp:5E3FBF9D AlternateDataStreams: C:\ProgramData\Temp:69E7DEDD AlternateDataStreams: C:\ProgramData\Temp:79363C4B AlternateDataStreams: C:\ProgramData\Temp:7ACF38DE AlternateDataStreams: C:\ProgramData\Temp:89952728 AlternateDataStreams: C:\ProgramData\Temp:8EB63C9D AlternateDataStreams: C:\ProgramData\Temp:97CCC404 AlternateDataStreams: C:\ProgramData\Temp:9A995231 AlternateDataStreams: C:\ProgramData\Temp:9FF05345 AlternateDataStreams: C:\ProgramData\Temp:ACA50580 AlternateDataStreams: C:\ProgramData\Temp:B7B09D45 AlternateDataStreams: C:\ProgramData\Temp:C6B7DC67 AlternateDataStreams: C:\ProgramData\Temp:CBEB737E AlternateDataStreams: C:\ProgramData\Temp:DB0CD29E AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D AlternateDataStreams: C:\ProgramData\Temp:EC5BDCFF AlternateDataStreams: C:\ProgramData\Temp:F306CF14 AlternateDataStreams: C:\ProgramData\Temp:F5D4C9D5 AlternateDataStreams: C:\ProgramData\Temp:FA62FF6E AlternateDataStreams: C:\ProgramData\Temp:FC5FFC81 ***************** Processes closed successfully. "C:\Program Files (x86)\Fast Browser" => File/Folder not found. "C:\Windows\system32\GroupPolicy\Machine" => File/Folder not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-1948824698-2788543327-851348242-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} => value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. HKCR\CLSID\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. HKCR\CLSID\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. HKCR\Wow6432Node\CLSID\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. HKCR\Wow6432Node\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. HKCR\Wow6432Node\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. HKCR\Wow6432Node\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{08E50FFB-6A26-4BFA-8998-D03FD169D2FF} => key not found. HKCR\CLSID\{08E50FFB-6A26-4BFA-8998-D03FD169D2FF} => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827} => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. HKCR\CLSID\{31090377-0740-419E-BEFC-A56E50500D5B} => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. HKCR\CLSID\{A06319E2-0C7F-4144-A3D4-ADDAB6C8DF42} => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. HKCR\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. HKCR\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => key not found. HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd => key not found. HKU\S-1-5-21-1948824698-2788543327-851348242-1001\SOFTWARE\Google\Chrome\Extensions\gdfjhiclilbjdpeejgcgebmmihkkofji => key not found. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd => key not found. qknfd => Service not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3EE3214-C517-4569-965C-AD245A1F403F} => key not found. C:\Windows\System32\Tasks\LaunchApp not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchApp => key not found. "C:\Program Files (x86)\MyPC Backup" => File/Folder not found. "C:\ProgramData\Temp" => ":00FE3B98" ADS not found. "C:\ProgramData\Temp" => ":01442FD8" ADS not found. "C:\ProgramData\Temp" => ":0EFEBFCB" ADS not found. "C:\ProgramData\Temp" => ":17FF6514" ADS not found. "C:\ProgramData\Temp" => ":1F9C3D08" ADS not found. "C:\ProgramData\Temp" => ":29BCDA07" ADS not found. "C:\ProgramData\Temp" => ":3447AB86" ADS not found. "C:\ProgramData\Temp" => ":3ABC2192" ADS not found. "C:\ProgramData\Temp" => ":3B9582E0" ADS not found. "C:\ProgramData\Temp" => ":54FDCED6" ADS not found. "C:\ProgramData\Temp" => ":5E3FBF9D" ADS not found. "C:\ProgramData\Temp" => ":69E7DEDD" ADS not found. "C:\ProgramData\Temp" => ":79363C4B" ADS not found. "C:\ProgramData\Temp" => ":7ACF38DE" ADS not found. "C:\ProgramData\Temp" => ":89952728" ADS not found. "C:\ProgramData\Temp" => ":8EB63C9D" ADS not found. "C:\ProgramData\Temp" => ":97CCC404" ADS not found. "C:\ProgramData\Temp" => ":9A995231" ADS not found. "C:\ProgramData\Temp" => ":9FF05345" ADS not found. "C:\ProgramData\Temp" => ":ACA50580" ADS not found. "C:\ProgramData\Temp" => ":B7B09D45" ADS not found. "C:\ProgramData\Temp" => ":C6B7DC67" ADS not found. "C:\ProgramData\Temp" => ":CBEB737E" ADS not found. "C:\ProgramData\Temp" => ":DB0CD29E" ADS not found. "C:\ProgramData\Temp" => ":E1F04E8D" ADS not found. "C:\ProgramData\Temp" => ":EC5BDCFF" ADS not found. "C:\ProgramData\Temp" => ":F306CF14" ADS not found. "C:\ProgramData\Temp" => ":F5D4C9D5" ADS not found. "C:\ProgramData\Temp" => ":FA62FF6E" ADS not found. "C:\ProgramData\Temp" => ":FC5FFC81" ADS not found. EmptyTemp: => 986.2 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 14:39:31 ==== [/QUOTE]
Insert quotes…
Verification
Post reply
Top