Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-11-2014 01 Ran by Administrator at 2014-11-08 09:35:59 Run:1 Running from C:\Users\Administrator\Desktop Loaded Profile: Administrator (Available profiles: Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [] => [X] HKLM-x32\...\runonceex: [] => [X] HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] fastprox.dll ATTENTION! ====> ZeroAccess? HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://groovorio.com...=1544403511&ir= HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKCU - {47E40571-6518-4AC0-A11C-318BBA8AE641} URL = Toolbar: HKCU - No Name - {00000000-0000-0000-0000-000000000000} - No File Handler: linkscanner - No CLSID Value - Handler-x32: linkscanner - No CLSID Value - CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2014-05-17] CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fopdddcinljmpmioaklghcalngfhbaen [2014-02-25] CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod [2013-12-13] CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla [2012-11-11] CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2012-11-11] CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd [2014-02-06] CHR Extension: (No Name) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnfegheljpcijmdgonkecjpcaopjlpac [2013-02-01] 2014-10-26 19:04 - 2014-10-26 19:04 - 00000000 _____ () C:\autoexec.bat C:\$Recycle.Bin\S-1-5-18\$b12dd0ee5c02ba0f692fdb04412864d8 C:\$Recycle.Bin\S-1-5-21-2014975827-1299050775-2003155660-500\$b12dd0ee5c02ba0f692fdb04412864d8 C:\Users\Administrator\g2ax_customer_downloadhelper_win32_x86.exe C:\Users\Administrator\jagex_cl_runescape_LIVE.dat C:\Users\Administrator\random.dat C:\Users\Public\AlexaNSISPlugin.3372.dll EmptyTemp: CMD: bitsadmin /reset /allusers ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\runonceex\\ => value deleted successfully. HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{47E40571-6518-4AC0-A11C-318BBA8AE641}" => Key deleted successfully. "HKCR\CLSID\{47E40571-6518-4AC0-A11C-318BBA8AE641}" => Key not found. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0000-0000-0000-000000000000} => value deleted successfully. "HKCR\CLSID\{00000000-0000-0000-0000-000000000000}" => Key not found. "HKCR\PROTOCOLS\Handler\linkscanner" => Key deleted successfully. "HKCR\Wow6432Node\PROTOCOLS\Handler\linkscanner" => Key not found. C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd => Moved successfully. C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fopdddcinljmpmioaklghcalngfhbaen => Moved successfully. C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod => Moved successfully. C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla => Moved successfully. C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof => Moved successfully. C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd => Moved successfully. C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnfegheljpcijmdgonkecjpcaopjlpac => Moved successfully. C:\autoexec.bat => Moved successfully. C:\$Recycle.Bin\S-1-5-18\$b12dd0ee5c02ba0f692fdb04412864d8 => Moved successfully. C:\$Recycle.Bin\S-1-5-21-2014975827-1299050775-2003155660-500\$b12dd0ee5c02ba0f692fdb04412864d8 => Moved successfully. C:\Users\Administrator\g2ax_customer_downloadhelper_win32_x86.exe => Moved successfully. C:\Users\Administrator\jagex_cl_runescape_LIVE.dat => Moved successfully. C:\Users\Administrator\random.dat => Moved successfully. C:\Users\Public\AlexaNSISPlugin.3372.dll => Moved successfully. ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.5.7601 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. 0 out of 0 jobs canceled. ========= End of CMD: ========= EmptyTemp: => Removed 411.5 MB temporary data. The system needed a reboot. ==== End of Fixlog ====