Fix result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018
Ran by [removed] (07-11-2018 12:28:50) Run:1
Running from C:\Users\[removed]\Downloads
[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
SearchScopes: HKU\S-1-5-21-664633608-1969193544-311688193-1002 -> DefaultScope {BE7D1C27-D649-4A6B-A7E6-F9871D794584} URL =
SearchScopes: HKU\S-1-5-21-664633608-1969193544-311688193-1002 -> {634F3C65-2249-40EE-A2FD-28E653A89338} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
SearchScopes: HKU\S-1-5-21-664633608-1969193544-311688193-1002 -> {BE7D1C27-D649-4A6B-A7E6-F9871D794584} URL =
Task: {1CA3920C-7841-4586-B28D-A9B812B4B078} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {1F7DF527-B756-41CB-BB5F-ABD8917330B9} - \PCDEventLauncherTask -> No File <==== ATTENTION
Task: {3304AC6C-F703-4919-87CD-2926C79DEF1C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {64F4D052-6220-4EEB-B769-A9435F00EFBB} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {AF036088-CB0E-41AB-9F6E-F1C8BAA1B942} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {B047A7AB-9554-4F70-A48D-0D07CD7B4AB8} - \SystemToolsDailyTest -> No File <==== ATTENTION
Task: {B540F01E-666A-466F-85BD-4A64417DB8E1} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {EC4A4E9B-CA61-452F-AA5F-CAFEA706CC43} - \PCDoctorBackgroundMonitorTask -> No File <==== ATTENTION
C:\Windows\Temp\*.*
Emptytemp:
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
*****************
Processes closed successfully.
Restore point was successfully created.
"HKU\S-1-5-21-664633608-1969193544-311688193-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-664633608-1969193544-311688193-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{634F3C65-2249-40EE-A2FD-28E653A89338} => removed successfully
HKLM\Software\Classes\CLSID\{634F3C65-2249-40EE-A2FD-28E653A89338} => not found
HKU\S-1-5-21-664633608-1969193544-311688193-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BE7D1C27-D649-4A6B-A7E6-F9871D794584} => removed successfully
HKLM\Software\Classes\CLSID\{BE7D1C27-D649-4A6B-A7E6-F9871D794584} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1CA3920C-7841-4586-B28D-A9B812B4B078}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1CA3920C-7841-4586-B28D-A9B812B4B078}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1F7DF527-B756-41CB-BB5F-ABD8917330B9}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F7DF527-B756-41CB-BB5F-ABD8917330B9}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCDEventLauncherTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3304AC6C-F703-4919-87CD-2926C79DEF1C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3304AC6C-F703-4919-87CD-2926C79DEF1C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{64F4D052-6220-4EEB-B769-A9435F00EFBB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{64F4D052-6220-4EEB-B769-A9435F00EFBB}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AF036088-CB0E-41AB-9F6E-F1C8BAA1B942}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AF036088-CB0E-41AB-9F6E-F1C8BAA1B942}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B047A7AB-9554-4F70-A48D-0D07CD7B4AB8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B047A7AB-9554-4F70-A48D-0D07CD7B4AB8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SystemToolsDailyTest" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B540F01E-666A-466F-85BD-4A64417DB8E1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B540F01E-666A-466F-85BD-4A64417DB8E1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EC4A4E9B-CA61-452F-AA5F-CAFEA706CC43}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC4A4E9B-CA61-452F-AA5F-CAFEA706CC43}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCDoctorBackgroundMonitorTask" => removed successfully
=========== "C:\Windows\Temp\*.*" ==========
C:\Windows\Temp\MpCmdRun.log => moved successfully
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\SPLF9DF.tmp => moved successfully
C:\Windows\Temp\~DF9601A4722CE6E54B.TMP => moved successfully
C:\Windows\Temp\~DFB554FF067BCBB968.TMP => moved successfully
C:\Windows\Temp\~DFD3C67DBAD56EABB5.TMP => moved successfully
C:\Windows\Temp\~DFD75E5DF2390C3BFF.TMP => moved successfully
C:\Windows\Temp\~DFFEA113934FA1341E.TMP => moved successfully
========= End -> "C:\Windows\Temp\*.*" ========
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
========= netsh winsock reset all =========
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
========= End of CMD: =========
========= netsh int ipv4 reset =========
Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= netsh int ipv6 reset =========
Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
========= End of CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 9986048 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 139576653 B
Java, Flash, Steam htmlcache => 74609 B
Windows/system/drivers => 0 B
Edge => 2508995 B
Chrome => 0 B
Firefox => 20258836 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 7168 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 8128 B
LocalService => 0 B
NetworkService => 196068 B
NetworkService => 0 B
john => 437454312 B
RecycleBin => 17498222806 B
EmptyTemp: => 16.9 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 12:35:56 ====
# ——————————-
# Malwarebytes AdwCleaner 7.2.4.0
# ——————————-
# Build: 09-25-2018
# Database: 2018-11-05.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start: 11-07-2018
# Duration: 00:00:06
# OS: Windows 10 Home
# Cleaned: 9
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Program Files (x86)\Yahoo!\yset
Deleted C:\Users\john\AppData\Roaming\AdvertismentImages
Deleted C:\Users\john\AppData\Local\YSearchUtil
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKLM\Software\Wow6432Node\Classes\AppID\AmazonAppIE.dll
Deleted HKLM\SOFTWARE\Classes\AppID\AmazonAppIE.dll
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3F6D7A0BA2FDE84EB329997B1FF786D
Deleted HKLM\Software\Classes\Installer\Products\C3F6D7A0BA2FDE84EB329997B1FF786D
Deleted HKLM\Software\Classes\Installer\Features\C3F6D7A0BA2FDE84EB329997B1FF786D
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2055 octets] - [07/11/2018 21:47:47]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
RogueKiller Anti-Malware V13.0.8.0 (x64) [Nov 6 2018] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.17134) 64 bits
Started in : Normal mode
User : john [Administrator]
Started from : C:\Users\john\Desktop\RogueKiller_portable64.exe
Mode : Standard Scan, Delete – Date : 2018/11/08 00:42:58 (Duration : 01:19:37)
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[VT.Unknown (Potentially Malicious)] IDriveEBackground.exe [Pro Softnet Corporation] – %SystemDrive%\IDrive\IDriveEBackground.exe -> Killed [Tree]
[VT.Unknown (Potentially Malicious)] IDriveETray.exe [Pro Softnet Corporation] – %SystemDrive%\IDrive\IDriveETray.exe -> ERROR [0]