Fix result of Farbar Recovery Scan Tool (x86) Version: 27-10-2016
Ran by doma (28-10-2016 11:34:57) Run:1
Running from C:\Users\doma\Desktop
Loaded Profiles: doma (Available Profiles: doma)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
Amazon 1Button App (Version: 1.0.4 - Amazon) Hidden <==== ATTENTION
Task: {47776C4C-9014-4422-AC60-0BAFEBFBB576} - \Microsoft\Windows\Multimedia\SMupdate3 -> No File <==== ATTENTION
Task: {538B71EB-2D5A-48A2-BA7E-91C0B55187B6} - \Microsoft\Windows\Maintenance\SMupdate2 -> No File <==== ATTENTION
Task: {6094DA0F-D580-4265-ABE9-B416A61486A8} - \Driver Booster SkipUAC (doma) -> No File <==== ATTENTION
Task: {D53BF144-C674-40D8-AA3D-7A9695200A08} - System32\Tasks\{6995CDF9-BEA2-47EC-A4B9-7FF166524FA2} => pcalua.exe -a E:\SETUP.EXE -d E:\ -c /AUTORUN
Task: {DF9A677E-C7FC-4AC0-9240-BA3C8DEFA1CE} - \Driver Booster Scheduler -> No File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\System32\imageres.dll,-68 <===== ATTENTION
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com ->
www.008k.comIE restricted site: HKU\.DEFAULT\...\00hq.com ->
www.00hq.comIE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com ->
www.0scan.comIE restricted site: HKU\.DEFAULT\...\1-2005-search.com ->
www.1-2005-search.comIE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com ->
www.1-domains-registrations.comIE restricted site: HKU\.DEFAULT\...\1000gratisproben.com ->
www.1000gratisproben.comIE restricted site: HKU\.DEFAULT\...\1001namen.com ->
www.1001namen.comIE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com ->
www.100sexlinks.comIE restricted site: HKU\.DEFAULT\...\10sek.com ->
www.10sek.comIE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info ->
www.123fporn.infoIE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com ->
www.123haustiereundmehr.comIE restricted site: HKU\.DEFAULT\...\123moviedownload.com ->
www.123moviedownload.comIE restricted site: HKU\.DEFAULT\...\123simsen.com ->
www.123simsen.comIE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\008k.com ->
www.008k.comIE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\00hq.com ->
www.00hq.comIE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\0scan.com ->
www.0scan.comIE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\1-2005-search.com ->
www.1-2005-search.comIE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\1-domains-registrations.com ->
www.1-domains-registrations.comIE restricted site: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\...\1-se.com -> 1-se.com
GroupPolicy: Restriction ? <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3810265174-1972376959-2373567011-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL =
hxxp://www.google.com/search?q={searchTerms}
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
hxxp://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
FF Plugin HKU\S-1-5-21-3810265174-1972376959-2373567011-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\doma\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path\update_url>
C:\Users\doma\AppData\Local\d3d9caps.dat
C:\ProgramData\nvModes.001
C:\ProgramData\nvModes.dat
C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{54AA7C11-54B7-4BD8-84B2-85873B5C7A04}\\SystemComponent => value removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{47776C4C-9014-4422-AC60-0BAFEBFBB576}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47776C4C-9014-4422-AC60-0BAFEBFBB576}" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{538B71EB-2D5A-48A2-BA7E-91C0B55187B6}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{538B71EB-2D5A-48A2-BA7E-91C0B55187B6}" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\SMupdate2 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6094DA0F-D580-4265-ABE9-B416A61486A8}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6094DA0F-D580-4265-ABE9-B416A61486A8}" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (doma) => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D53BF144-C674-40D8-AA3D-7A9695200A08}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D53BF144-C674-40D8-AA3D-7A9695200A08}" => key removed successfully.
C:\Windows\System32\Tasks\{6995CDF9-BEA2-47EC-A4B9-7FF166524FA2} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6995CDF9-BEA2-47EC-A4B9-7FF166524FA2}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DF9A677E-C7FC-4AC0-9240-BA3C8DEFA1CE}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF9A677E-C7FC-4AC0-9240-BA3C8DEFA1CE}" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler => key not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully
HKLM\Software\Classes\cmdfile\DefaultIcon\\Default => value restored successfully
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\007guard.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008i.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008k.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\00hq.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\010402.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\032439.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0scan.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-2005-search.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-domains-registrations.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1000gratisproben.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1001namen.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\100888290cs.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\100sexlinks.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\10sek.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\12-26.net" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\12-27.net" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\123fporn.info" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\123haustiereundmehr.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\123moviedownload.com" => key removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\123simsen.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\007guard.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008i.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008k.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\00hq.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\010402.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0190-dialers.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\01i.info" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\02pmnzy5eo29bfk4.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\032439.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\05p.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\07ic5do2myz3vzpk.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\08nigbmwk43i01y6.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\093qpeuqpmz6ebfa.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0calories.net" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0cj.net" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0scan.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-2005-search.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-britney-spears-nude.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-domains-registrations.com" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-se.com" => key removed successfully.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully.
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => key removed successfully.
"HKCR\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => key removed successfully.
"HKU\S-1-5-21-3810265174-1972376959-2373567011-1000\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0" => key removed successfully.
C:\Users\doma\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll => not found.
"HKLM\SOFTWARE\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk" => key removed successfully.
C:\Users\doma\AppData\Local\d3d9caps.dat => moved successfully
C:\ProgramData\nvModes.001 => moved successfully
C:\ProgramData\nvModes.dat => moved successfully
C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log => moved successfully
C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log => moved successfully
C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log => moved successfully
C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log => moved successfully
C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log => moved successfully
C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log => moved successfully
C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log => moved successfully
C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log => moved successfully
C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log => moved successfully
=========== EmptyTemp: ==========
BITS transfer queue => 0 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10579400 B
Java, Flash, Steam htmlcache => 1923 B
Windows/system/drivers => 1158281 B
Edge => 0 B
Chrome => 32768 B
Firefox => 375446019 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 33058 B
Public => 0 B
ProgramData => 0 B
systemprofile => 1371 B
LocalService => 33125 B
NetworkService => 33125 B
doma => 19689898 B
RecycleBin => 0 B
EmptyTemp: => 388.2 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 11:35:57 ====
HP Pavilion dv6 1230ec, Win. Vista