Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-12-2014 Ran by Ken at 2014-12-13 14:03:02 Run:1 Running from C:\Users\Ken\Desktop Loaded Profile: Ken (Available profiles: Ken) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-21-886335986-3291866647-4040213550-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 243 more characters). <==== Poweliks! SearchScopes: HKU\S-1-5-21-886335986-3291866647-4040213550-1001 -> DefaultScope {93F6EAC8-8977-4DA5-8128-92F8E08EC682} URL = http://search.condui...0032492608&UM=2 SearchScopes: HKU\S-1-5-21-886335986-3291866647-4040213550-1001 -> {93F6EAC8-8977-4DA5-8128-92F8E08EC682} URL = http://search.condui...0032492608&UM=2 SearchScopes: HKU\S-1-5-21-886335986-3291866647-4040213550-1001 -> {D4580B42-CBC8-4E7D-B842-E759C7D2BEF6} URL = SearchScopes: HKU\S-1-5-21-886335986-3291866647-4040213550-1001 -> {EFC1FC54-BEA0-4C57-A78C-C17E410ADD69} URL = SearchScopes: HKLM-x32 -> DefaultScope {93F6EAC8-8977-4DA5-8128-92F8E08EC682} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File Toolbar: HKU\S-1-5-21-886335986-3291866647-4040213550-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File C:\ProgramData\obn08eg.bxx C:\ProgramData\obn08eg.fvv CustomCLSID: HKU\S-1-5-21-886335986-3291866647-4040213550-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 251 more characters). <==== Poweliks? EmptyTemp: CMD: bitsadmin /reset /allusers ***************** "HKU\S-1-5-21-886335986-3291866647-4040213550-1001\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32" => Key Deleted Successfully. "HKU\S-1-5-21-886335986-3291866647-4040213550-1001\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key deleted successfully. HKU\S-1-5-21-886335986-3291866647-4040213550-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-886335986-3291866647-4040213550-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{93F6EAC8-8977-4DA5-8128-92F8E08EC682}" => Key deleted successfully. "HKCR\CLSID\{93F6EAC8-8977-4DA5-8128-92F8E08EC682}" => Key not found. "HKU\S-1-5-21-886335986-3291866647-4040213550-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D4580B42-CBC8-4E7D-B842-E759C7D2BEF6}" => Key deleted successfully. "HKCR\CLSID\{D4580B42-CBC8-4E7D-B842-E759C7D2BEF6}" => Key not found. "HKU\S-1-5-21-886335986-3291866647-4040213550-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EFC1FC54-BEA0-4C57-A78C-C17E410ADD69}" => Key deleted successfully. "HKCR\CLSID\{EFC1FC54-BEA0-4C57-A78C-C17E410ADD69}" => Key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL => Value not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}" => Key deleted successfully. "HKCR\Wow6432Node\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}" => Key not found. HKU\S-1-5-21-886335986-3291866647-4040213550-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully. "HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}" => Key not found. C:\ProgramData\obn08eg.bxx => Moved successfully. C:\ProgramData\obn08eg.fvv => Moved successfully. "HKU\S-1-5-21-886335986-3291866647-4040213550-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}" => Key not found. ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.5.7601 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. 0 out of 0 jobs canceled. ========= End of CMD: ========= EmptyTemp: => Removed 4.9 GB temporary data. The system needed a reboot. ==== End of Fixlog ====