Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 28-01-2015 01 Ran by ron at 2015-01-30 08:45:58 Run:3 Running from C:\FRST Loaded Profiles: ron (Available profiles: ron) Boot Mode: Normal ============================================== Content of fixlist: ***************** CreateRestorePoint: HKU\S-1-5-21-893646719-2384664811-2616046975-1000\...\Policies\Explorer: [Run] "C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate\odbcconf.exe" HKU\S-1-5-21-893646719-2384664811-2616046975-1000\...409d6c4515e9\InprocServer32: [Default-shell32] shell32.dll ATTENTION! ====> ZeroAccess? HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] fastprox.dll ATTENTION! ====> ZeroAccess? Toolbar: HKU\S-1-5-21-893646719-2384664811-2616046975-1000 -> No Name - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File Toolbar: HKU\S-1-5-21-893646719-2384664811-2616046975-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" 2015-01-28 17:33 - 2015-01-28 17:31 - 00270340 _____ (Dramatising#Featuring) C:\Windows\system32\bitsDGAE.exe 2015-01-28 09:01 - 2015-01-29 12:12 - 00000000 ___HD () C:\ProgramData\{49A0BAC7-3326-4433-9373-4AA8793ABB5C} 2015-01-29 12:16 - 2013-12-12 08:36 - 00000000 ____D () C:\ProgramData\boost_interprocess 2015-01-28 18:45 - 2012-10-22 10:15 - 00000000 ____D () C:\ProgramData\cylabuedltgjbsp 2015-01-28 15:35 - 2014-04-04 16:38 - 00000000 ____D () C:\ProgramData\2992199F9A 2013-03-01 09:05 - 2013-03-01 09:07 - 95023320 ____T () C:\ProgramData\1507992.pad 2013-12-30 13:40 - 2013-12-30 13:45 - 95025368 ____T () C:\ProgramData\3bnfrjwlc.fee 2013-12-30 13:40 - 2013-12-30 13:44 - 0000000 _____ () C:\ProgramData\3bnfrjwlc.odd 2013-03-06 11:16 - 2013-03-06 11:19 - 95023320 ____T () C:\ProgramData\4601732.pad 2013-03-13 09:37 - 2013-03-13 09:38 - 95023320 ____T () C:\ProgramData\6845498.pad 2012-10-02 16:01 - 2012-10-03 16:59 - 83023306 ____T () C:\ProgramData\avaj.pad 2013-12-30 13:40 - 2013-12-30 13:40 - 0160232 _____ (Microsoft Corporation) C:\ProgramData\clwjrfnb3.jss 2013-01-02 08:27 - 2013-01-02 08:27 - 0000000 _____ () C:\ProgramData\cmn_upld.log 2012-09-28 16:17 - 2012-10-03 12:58 - 83023306 ____T () C:\ProgramData\dapeton.pad 2013-01-02 08:55 - 2014-01-24 08:57 - 0000309 _____ () C:\ProgramData\dlea.log 2013-05-03 08:43 - 2013-08-19 13:30 - 0089010 _____ () C:\ProgramData\dleaJSW.log 2013-05-06 07:01 - 2014-01-24 08:57 - 0011273 _____ () C:\ProgramData\dleascan.log 2012-10-05 11:20 - 2012-10-05 11:21 - 83023306 ____T () C:\ProgramData\emorhc.pad 2009-11-16 09:15 - 2009-11-16 09:15 - 0000056 ____H () C:\ProgramData\ezsidmv.dat 2013-01-03 08:14 - 2013-01-18 09:09 - 0000504 _____ () C:\ProgramData\FastPics.log 2014-01-23 11:17 - 2014-01-24 08:33 - 0000000 _____ () C:\ProgramData\frmqjfj6b.odd 2012-10-02 07:24 - 2012-10-02 07:27 - 83023306 ____T () C:\ProgramData\gifnocsm.pad 2012-07-06 08:37 - 2012-07-06 08:38 - 4503728 ____T () C:\ProgramData\go_0molg.pad 2012-08-16 13:38 - 2012-08-17 07:05 - 83023306 ____T () C:\ProgramData\ism_0_llatsni.pad 2009-12-24 08:42 - 2012-12-17 08:35 - 0000980 _____ () C:\ProgramData\lxduDiagnostics.log 2009-07-22 12:48 - 2012-01-06 16:23 - 0047092 _____ () C:\ProgramData\lxduJSW.log 2013-01-02 08:27 - 2013-01-02 08:27 - 0000000 _____ () C:\ProgramData\LxWbGwLog.log 2014-03-14 14:27 - 2014-03-17 16:22 - 95027928 ____T () C:\ProgramData\qlf7lflb.fee 2014-03-27 14:55 - 2014-03-27 14:55 - 0201481 _____ () C:\ProgramData\qm7wj4hjr.gsa 2013-12-13 17:36 - 2013-12-13 18:09 - 95025368 ____T () C:\ProgramData\qwh2bnmq.fee 2013-12-13 17:36 - 2013-12-13 18:09 - 0000000 _____ () C:\ProgramData\qwh2bnmq.odd 2013-12-13 17:37 - 2013-12-13 17:53 - 0000285 _____ () C:\ProgramData\qwh2bnmq.reg 2012-08-03 08:15 - 2012-08-03 08:18 - 4503728 ____T () C:\ProgramData\ras_0oed.pad 2012-10-02 09:25 - 2012-10-02 09:25 - 83023306 ____T () C:\ProgramData\reyalpclv.pad 2014-03-27 14:56 - 2014-04-02 11:10 - 95027928 ____T () C:\ProgramData\rjh4jw7mq.bbr 2014-01-29 13:51 - 2014-01-29 13:51 - 0000000 _____ () C:\ProgramData\rllflc3v.odd 2009-07-17 15:53 - 2009-07-17 15:53 - 0252654 _____ () C:\ProgramData\SPL1C96.tmp 2012-09-26 16:48 - 2012-09-26 16:48 - 0239141 _____ () C:\ProgramData\SPL256.tmp 2009-07-16 17:48 - 2009-07-16 17:48 - 0014854 _____ () C:\ProgramData\SPL2ECB.tmp 2011-07-11 15:04 - 2011-07-11 15:04 - 0183016 _____ () C:\ProgramData\SPL2FC2.tmp 2009-11-20 08:51 - 2009-11-20 08:51 - 0529138 _____ () C:\ProgramData\SPL69EE.tmp 2009-11-20 08:53 - 2009-11-20 08:53 - 0529138 _____ () C:\ProgramData\SPL8057.tmp 2012-09-14 13:30 - 2012-09-14 13:30 - 0365310 _____ () C:\ProgramData\SPLD9B5.tmp 2009-11-20 08:54 - 2009-11-20 08:54 - 0187264 _____ () C:\ProgramData\SPLEB97.tmp 2012-09-24 11:38 - 2012-09-27 10:54 - 83023306 ____T () C:\ProgramData\sqj.pad 2012-09-21 14:40 - 2012-09-21 14:42 - 83023306 ____T () C:\ProgramData\ssrsc.pad 2012-09-21 13:23 - 2012-09-21 13:29 - 83023306 ____T () C:\ProgramData\tsohnoc.pad 2009-07-08 10:24 - 2009-07-08 10:24 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt 2013-12-20 12:39 - 2013-12-20 12:54 - 95025368 ____T () C:\ProgramData\v7jw87tr.fee 2013-12-20 12:39 - 2013-12-20 12:39 - 0000000 _____ () C:\ProgramData\v7jw87tr.odd 2012-10-01 14:32 - 2012-10-01 14:36 - 83023306 ____T () C:\ProgramData\vsloops.pad 2012-10-18 09:13 - 2012-10-18 09:14 - 83023306 ____T () C:\ProgramData\xoferif.pad 2012-07-26 09:33 - 2012-07-26 09:35 - 4503728 ____T () C:\ProgramData\z7_0ytr.pad Task: {1846B47A-65FA-4F82-93C7-FFF00E67AB24} - System32\Tasks\{10BD6702-A095-42C9-9584-28140523B5F5} => pcalua.exe -a "C:\Users\ron\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\77N3PB15\pbf4setup[1].exe" -d C:\Users\ron\Desktop HKLM\...\.exe: => <===== ATTENTION! HKU\S-1-5-21-893646719-2384664811-2616046975-1000\Software\Classes\.exe: exefile => <===== ATTENTION! C:\$Recycle.Bin\S-1-5-21-893646719-2384664811-2616046975-1000\$74dfbc209b664417a153f0d06f86a798 C:\$Recycle.Bin\S-1-5-18\$74dfbc209b664417a153f0d06f86a798 C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Restore point was successfully created. HKU\S-1-5-21-893646719-2384664811-2616046975-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\Run => Value not found. HKU\S-1-5-21-893646719-2384664811-2616046975-1000\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} => Key not found. HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully. HKU\S-1-5-21-893646719-2384664811-2616046975-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1017A80C-6F09-4548-A84D-EDD6AC9525F0} => Value not found. HKCR\CLSID\{1017A80C-6F09-4548-A84D-EDD6AC9525F0} => Key not found. HKU\S-1-5-21-893646719-2384664811-2616046975-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value not found. HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} => Key not found. HKCR\CLSID\{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} => Key not found. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} => Key not found. HKCR\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} => Key not found. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E77F23EB-E7AB-4502-8F37-247DBAF1A147} => Key not found. HKCR\CLSID\{E77F23EB-E7AB-4502-8F37-247DBAF1A147} => Key not found. Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll Winsock: Catalog5 entry 000000000005\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll "C:\Windows\system32\bitsDGAE.exe" => File/Directory not found. "C:\ProgramData\{49A0BAC7-3326-4433-9373-4AA8793ABB5C}" => File/Directory not found. "C:\ProgramData\boost_interprocess" => File/Directory not found. "C:\ProgramData\cylabuedltgjbsp" => File/Directory not found. "C:\ProgramData\2992199F9A" => File/Directory not found. "C:\ProgramData\1507992.pad" => File/Directory not found. "C:\ProgramData\3bnfrjwlc.fee" => File/Directory not found. "C:\ProgramData\3bnfrjwlc.odd" => File/Directory not found. "C:\ProgramData\4601732.pad" => File/Directory not found. "C:\ProgramData\6845498.pad" => File/Directory not found. "C:\ProgramData\avaj.pad" => File/Directory not found. "C:\ProgramData\clwjrfnb3.jss" => File/Directory not found. "C:\ProgramData\cmn_upld.log" => File/Directory not found. "C:\ProgramData\dapeton.pad" => File/Directory not found. "C:\ProgramData\dlea.log" => File/Directory not found. "C:\ProgramData\dleaJSW.log" => File/Directory not found. "C:\ProgramData\dleascan.log" => File/Directory not found. "C:\ProgramData\emorhc.pad" => File/Directory not found. "C:\ProgramData\ezsidmv.dat" => File/Directory not found. "C:\ProgramData\FastPics.log" => File/Directory not found. "C:\ProgramData\frmqjfj6b.odd" => File/Directory not found. "C:\ProgramData\gifnocsm.pad" => File/Directory not found. "C:\ProgramData\go_0molg.pad" => File/Directory not found. "C:\ProgramData\ism_0_llatsni.pad" => File/Directory not found. "C:\ProgramData\lxduDiagnostics.log" => File/Directory not found. "C:\ProgramData\lxduJSW.log" => File/Directory not found. "C:\ProgramData\LxWbGwLog.log" => File/Directory not found. "C:\ProgramData\qlf7lflb.fee" => File/Directory not found. "C:\ProgramData\qm7wj4hjr.gsa" => File/Directory not found. "C:\ProgramData\qwh2bnmq.fee" => File/Directory not found. "C:\ProgramData\qwh2bnmq.odd" => File/Directory not found. "C:\ProgramData\qwh2bnmq.reg" => File/Directory not found. "C:\ProgramData\ras_0oed.pad" => File/Directory not found. "C:\ProgramData\reyalpclv.pad" => File/Directory not found. "C:\ProgramData\rjh4jw7mq.bbr" => File/Directory not found. "C:\ProgramData\rllflc3v.odd" => File/Directory not found. "C:\ProgramData\SPL1C96.tmp" => File/Directory not found. "C:\ProgramData\SPL256.tmp" => File/Directory not found. "C:\ProgramData\SPL2ECB.tmp" => File/Directory not found. "C:\ProgramData\SPL2FC2.tmp" => File/Directory not found. "C:\ProgramData\SPL69EE.tmp" => File/Directory not found. "C:\ProgramData\SPL8057.tmp" => File/Directory not found. "C:\ProgramData\SPLD9B5.tmp" => File/Directory not found. "C:\ProgramData\SPLEB97.tmp" => File/Directory not found. "C:\ProgramData\sqj.pad" => File/Directory not found. "C:\ProgramData\ssrsc.pad" => File/Directory not found. "C:\ProgramData\tsohnoc.pad" => File/Directory not found. "C:\ProgramData\UpdaterLog.txt" => File/Directory not found. "C:\ProgramData\v7jw87tr.fee" => File/Directory not found. "C:\ProgramData\v7jw87tr.odd" => File/Directory not found. "C:\ProgramData\vsloops.pad" => File/Directory not found. "C:\ProgramData\xoferif.pad" => File/Directory not found. "C:\ProgramData\z7_0ytr.pad" => File/Directory not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1846B47A-65FA-4F82-93C7-FFF00E67AB24} => Key not found. C:\Windows\System32\Tasks\{10BD6702-A095-42C9-9584-28140523B5F5} not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{10BD6702-A095-42C9-9584-28140523B5F5} => Key not found. HKLM\Software\Classes\.exe\\Default => Value was restored successfully. HKU\S-1-5-21-893646719-2384664811-2616046975-1000\Software\Classes\.exe => Key not found. "C:\$Recycle.Bin\S-1-5-21-893646719-2384664811-2616046975-1000\$74dfbc209b664417a153f0d06f86a798" => File/Directory not found. "C:\$Recycle.Bin\S-1-5-18\$74dfbc209b664417a153f0d06f86a798" => File/Directory not found. "C:\Users\ron\AppData\Roaming\Microsoft\Windows\IEUpdate" => File/Directory not found. ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.0.6001 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. Unable to connect to BITS - 0x80070422 The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ========= End of CMD: ========= EmptyTemp: => Removed 10.5 GB temporary data. The system needed a reboot. ==== End of Fixlog 08:55:06 ====