Fix result of Farbar Recovery Scan Tool (x64) Version: 08-08-2017 Ran by [removed] (08-08-2017 15:40:50) Run:1 Running from C:\Users\[removed]\Downloads [removed] Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: AVSDK5 (HKLM\...\{D5A6E342-907C-4CEF-96CC-FC2F4990DC9C}) (Version: 5.4.30 - CYREN Inc.) Hidden ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} => -> No File ContextMenuHandlers1-x32: [QuickShare] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} => -> No File ContextMenuHandlers1-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => -> No File ContextMenuHandlers1-x32: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => -> No File ContextMenuHandlers1-x32: [ZipItFreeContextMenu] -> {9FCB3717-B87B-421E-BB30-61769539EA23} => -> No File ContextMenuHandlers1-x32: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => -> No File ContextMenuHandlers4: [ZipItFree] -> {9FCB3717-B87B-421E-BB30-61769539EA23} => -> No File ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => -> No File ContextMenuHandlers6: [ZipItFree] -> {9FCB3717-B87B-421E-BB30-61769539EA23} => -> No File ContextMenuHandlers6: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File Task: {14F57CD1-CFEB-4005-B36E-F4840717E44B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {1621C9ED-1D6C-4023-80B9-9B0606E23586} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {3DA6EA8A-51B2-4C80-A938-9069DDA71028} - \update-S-1-5-21-4044022209-2194366084-123958388-1000 -> No File <==== ATTENTION Task: {5965114A-B5B9-423B-950B-C0B21D317C96} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {66C1BA5E-0D6A-48D1-93DC-5B02BC9A20B9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {6C4F11DB-7945-4923-8CD5-4BFFDC39EB2D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {710DC475-F5EB-4D8B-AE15-57BE32433448} - \update-sys -> No File <==== ATTENTION Task: {77C93557-7547-49E8-B0D5-FBA2CA76828B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {8196B0C5-09F7-4DA7-9797-705E9A9BE591} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {A223E981-9EF8-4300-9AA4-5D4C3D66F49D} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {AE59EC9C-C5AC-4805-BA59-2E787E6E5C45} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {C6D6E601-0232-4EAA-9705-ADE7D5EF83D8} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {DB690CDF-FE8F-4691-B8A8-69BBCAA18053} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {DE234142-6602-4FA6-B0BB-910EEB22441B} - \Driver Booster SkipUAC (Sylvia) -> No File <==== ATTENTION Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor => not found FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff => not found CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx CHR HKU\S-1-5-21-4044022209-2194366084-123958388-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx CHR HKLM-x32\...\Chrome\Extension: [gannpgaobkkhmpomoijebaigcapoeebl] - hxxps://clients2.google.com/service/update2/crx File: C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸䉬䕁⸰浴p翹 File: C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸䅬㐶⸳浴p翹 File: C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸䉬䕁⸱浴p翹 File: C:\lc\mining_proxy.exe File: C:\Program Files (x86)\GUT13E6.tmp File: C:\Program Files (x86)\GUTD4D6.tmp File: C:\Users\Sylvia\AppData\Local\a.zip Hosts: EmptyTemp: CMD: ipconfig /flushdns ***************** Restore point was successfully created. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D5A6E342-907C-4CEF-96CC-FC2F4990DC9C}\\SystemComponent => value removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => key removed successfully HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BB FlashBack 2 => key removed successfully HKLM\Software\Classes\CLSID\{A8065B9E-193F-4797-B62D-8F6321E7FCCB} => key not found. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\QuickShare => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{A8065B9E-193F-4797-B62D-8F6321E7FCCB} => key not found. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinZip => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{E0D79304-84BE-11CE-9641-444553540000} => key not found. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WondershareVideoConverterFileOpreation => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{FEB746CA-95C2-485F-B386-C30D4E56D22E} => key not found. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ZipItFreeContextMenu => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{9FCB3717-B87B-421E-BB30-61769539EA23} => key not found. HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\_Movavivc11 => key removed successfully HKLM\Software\Wow6432Node\Classes\CLSID\{1C604495-4D32-476e-8D7E-FBF50F6C80BF} => key not found. HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avast => key removed successfully HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => key removed successfully HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found. HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\WinZip => key removed successfully HKLM\Software\Classes\CLSID\{E0D79304-84BE-11CE-9641-444553540000} => key not found. HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ZipItFree => key removed successfully HKLM\Software\Classes\CLSID\{9FCB3717-B87B-421E-BB30-61769539EA23} => key not found. HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => key removed successfully HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found. HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinZip => key removed successfully HKLM\Software\Classes\CLSID\{E0D79304-84BE-11CE-9641-444553540000} => key not found. HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\ZipItFree => key removed successfully HKLM\Software\Classes\CLSID\{9FCB3717-B87B-421E-BB30-61769539EA23} => key not found. HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\_Movavivc11 => key removed successfully HKLM\Software\Classes\CLSID\{1C604495-4D32-476e-8D7E-FBF50F6C80BF} => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{14F57CD1-CFEB-4005-B36E-F4840717E44B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{14F57CD1-CFEB-4005-B36E-F4840717E44B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1621C9ED-1D6C-4023-80B9-9B0606E23586} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1621C9ED-1D6C-4023-80B9-9B0606E23586} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3DA6EA8A-51B2-4C80-A938-9069DDA71028} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DA6EA8A-51B2-4C80-A938-9069DDA71028} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\update-S-1-5-21-4044022209-2194366084-123958388-1000 => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5965114A-B5B9-423B-950B-C0B21D317C96} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5965114A-B5B9-423B-950B-C0B21D317C96} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{66C1BA5E-0D6A-48D1-93DC-5B02BC9A20B9} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66C1BA5E-0D6A-48D1-93DC-5B02BC9A20B9} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C4F11DB-7945-4923-8CD5-4BFFDC39EB2D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C4F11DB-7945-4923-8CD5-4BFFDC39EB2D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{710DC475-F5EB-4D8B-AE15-57BE32433448} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{710DC475-F5EB-4D8B-AE15-57BE32433448} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\update-sys => key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{77C93557-7547-49E8-B0D5-FBA2CA76828B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77C93557-7547-49E8-B0D5-FBA2CA76828B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8196B0C5-09F7-4DA7-9797-705E9A9BE591} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8196B0C5-09F7-4DA7-9797-705E9A9BE591} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A223E981-9EF8-4300-9AA4-5D4C3D66F49D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A223E981-9EF8-4300-9AA4-5D4C3D66F49D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AE59EC9C-C5AC-4805-BA59-2E787E6E5C45} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE59EC9C-C5AC-4805-BA59-2E787E6E5C45} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6D6E601-0232-4EAA-9705-ADE7D5EF83D8} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D6E601-0232-4EAA-9705-ADE7D5EF83D8} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB690CDF-FE8F-4691-B8A8-69BBCAA18053} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB690CDF-FE8F-4691-B8A8-69BBCAA18053} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE234142-6602-4FA6-B0BB-910EEB22441B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE234142-6602-4FA6-B0BB-910EEB22441B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Sylvia) => key removed successfully HKLM\Software\Classes\PROTOCOLS\Handler\dssrequest => key removed successfully HKLM\Software\Classes\CLSID\{5513F07E-936B-4E52-9B00-067394E91CC5} => key not found. HKLM\Software\Classes\PROTOCOLS\Handler\sacore => key removed successfully HKLM\Software\Classes\CLSID\{5513F07E-936B-4E52-9B00-067394E91CC5} => key not found. HKLM\Software\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92} => value removed successfully HKLM\Software\Mozilla\Firefox\Extensions\\[removed] => value removed successfully HKLM\SOFTWARE\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho => key removed successfully HKU\S-1-5-21-4044022209-2194366084-123958388-1000\SOFTWARE\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh => key removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho => key removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gannpgaobkkhmpomoijebaigcapoeebl => key removed successfully ========================= File: C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸䉬䕁⸰浴p翹 ======================== File not signed MD5: 89E91E7560FA97BC4D8D3E643408B19E Creation and modification date: 2017-07-19 14:17 - 2017-07-19 14:17 Size: 000000336 Attributes: ----A Company Name: Internal Name: Original Name: Product: Description: File Version: Product Version: Copyright: ====== End of File: ====== ========================= File: C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸䅬㐶⸳浴p翹 ======================== File not signed MD5: F6B6117AA68B1ECCC70CC5AD881CB472 Creation and modification date: 2017-07-19 14:17 - 2017-07-19 14:17 Size: 000000328 Attributes: ----A Company Name: Internal Name: Original Name: Product: Description: File Version: Product Version: Copyright: ====== End of File: ====== ========================= File: C:\WINDOWS\system32\㩃坜义佄南呜䵅屐浸䉬䕁⸱浴p翹 ======================== File not signed MD5: AC7196B654F79AD1C9ACA0E8D4A131EB Creation and modification date: 2017-07-19 14:17 - 2017-07-19 14:17 Size: 000000326 Attributes: ----A Company Name: Internal Name: Original Name: Product: Description: File Version: Product Version: Copyright: ====== End of File: ====== ========================= File: C:\lc\mining_proxy.exe ======================== File not signed MD5: 865D2E386549B1FCD318A20DCF99392E Creation and modification date: 2017-04-27 17:26 - 2017-04-10 13:41 Size: 005414452 Attributes: ----A Company Name: Internal Name: Original Name: mining_proxy.exe Product: stratum_mining_proxy Description: Getwork-compatible proxy for Stratum mining pools File Version: 1.5.5 Product Version: 1.5.5 Copyright: ====== End of File: ====== ========================= File: C:\Program Files (x86)\GUT13E6.tmp ======================== File not signed MD5: 02FC074F0FE7A87A8BF0C481DCC49B5E Creation and modification date: 2017-03-21 15:58 - 2017-03-21 16:09 Size: 007680000 Attributes: ----A Company Name: Internal Name: Original Name: Product: Description: File Version: Product Version: Copyright: ====== End of File: ====== ========================= File: C:\Program Files (x86)\GUTD4D6.tmp ======================== File not signed MD5: 18FC1E80A77A82EB4DBBD6FDD271D434 Creation and modification date: 2017-05-01 17:24 - 2017-05-01 17:31 Size: 007649280 Attributes: ----A Company Name: Internal Name: Original Name: Product: Description: File Version: Product Version: Copyright: ====== End of File: ====== ========================= File: C:\Users\Sylvia\AppData\Local\a.zip ======================== File not signed MD5: EA4766FDC91E0E3BD4CA28BCDA32D122 Creation and modification date: 2014-09-18 16:59 - 2014-09-18 16:59 Size: 000893239 Attributes: ----A Company Name: Internal Name: Original Name: Product: Description: File Version: Product Version: Copyright: ====== End of File: ====== C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. ========= ipconfig /flushdns ========= Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========= End of CMD: ========= =========== EmptyTemp: ========== BITS transfer queue => 9199616 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 133316850 B Java, Flash, Steam htmlcache => 523 B Windows/system/drivers => 1872240 B Edge => 35475984 B Chrome => 505915365 B Firefox => 35137345 B Opera => 112640 B Temp, IE cache, history, cookies, recent: Default => 39216 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 128 B LocalService => 5742 B NetworkService => 4735760 B Sylvia => 7881755 B Work => 1088493 B DefaultAppPool => 39216 B RecycleBin => 356932 B EmptyTemp: => 701.1 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 15:46:33 ====