Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-04-2015 01 Ran by Jim at 2015-04-19 12:12:25 Run:1 Running from C:\Users\Jim\Desktop Loaded Profiles: Jim (Available profiles: Jim) Boot Mode: Normal ============================================== Content of fixlist: ***************** CreateRestorePoint: HKU\S-1-5-21-1853225634-1185179328-766844407-1000\...\Run: [Google Update] => C:\Users\Jim\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-12-01] (Google Inc.) AppInit_DLLs: C:\Windows\katrack.dll => C:\Windows\katrack.dll File Not Found AppInit_DLLs: KATRACK.DLL => KATRACK.DLL File Not Found AppInit_DLLs: C:\Windows\katrack.dll => C:\Windows\katrack.dll File Not Found AppInit_DLLs: C:\Windows\katrack.dll => C:\Windows\katrack.dll File Not Found AppInit_DLLs: C:\Windows\katrk64.dll => C:\Windows\katrk64.dll File Not Found AppInit_DLLs: KATRK64.DLL => KATRK64.DLL File Not Found AppInit_DLLs-x32: C:\Windows\katrack.dll => "C:\Windows\katrack.dll" File Not Found AppInit_DLLs-x32: C:\Windows\katrack.dll => "C:\Windows\katrack.dll" File Not Found AppInit_DLLs-x32: C:\Windows\katrack.dll => "C:\Windows\katrack.dll" File Not Found AppInit_DLLs-x32: KATRACK.DLL => "KATRACK.DLL" File Not Found CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1853225634-1185179328-766844407-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION Toolbar: HKU\S-1-5-21-1853225634-1185179328-766844407-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.) FF Plugin HKU\S-1-5-21-1853225634-1185179328-766844407-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Jim\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin HKU\S-1-5-21-1853225634-1185179328-766844407-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Jim\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "https://www.google.com/" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.669\_platform_specific\win_x86\widevinecdmadapter.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Jim\AppData\Local\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Jim\AppData\Local\Google\Chrome\Application\42.0.2311.90\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Jim\AppData\Local\Google\Chrome\Application\42.0.2311.90\pdf.dll No File CHR Plugin: (Adobe Create PDF) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj\11.0.7.52_0\plugin/npWCChromeExtnStub.dll No File CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.670.1) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File CHR Plugin: (Java™ Platform SE 7 U67) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: ( Wacom Dynamic Link Library) - C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Jim\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File CHR Profile: C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Adblock Plus) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-09-25] CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014-03-28] CHR Extension: (Blur) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2014-11-18] CHR Extension: (Dashlane) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2014-02-04] CHR Extension: (LastPass: Free Password Manager) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2013-06-21] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-11] CHR Extension: (Google Wallet) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Dashlane Search) - C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnimjdijgakingbgempmgkdgfhmmogah [2014-07-29] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2012-09-23] StartMenuInternet: Google Chrome.3QA2LMI57PR7SKSX3U3K6BDIZY - C:\Users\Jim\AppData\Local\Google\Chrome\Application\chrome.exe 2015-04-18 00:23 - 2015-04-18 00:23 - 00000000 ____D () C:\ProgramData\6467019769728057092 2015-04-18 00:20 - 2015-04-18 01:13 - 00000000 ____D () C:\ProgramData\{19079dab-850b-e1b9-1907-79dab85076ae} 2015-03-26 10:02 - 2015-03-26 10:02 - 00000000 __SHD () C:\Users\Jim\AppData\Local\EmieBrowserModeList 2015-04-19 10:55 - 2013-07-18 14:09 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-19 10:54 - 2014-12-25 13:30 - 00001272 ____H () C:\Windows\Tasks\{3A1B2112-3617-4D99-BF54-7AB8F9D18F97}.job 2015-04-19 10:50 - 2012-12-01 19:06 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853225634-1185179328-766844407-1000UA.job 2015-04-18 17:41 - 2012-12-01 19:06 - 00000848 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853225634-1185179328-766844407-1000Core.job C:\Windows\Tasks\{3A1B2112-3617-4D99-BF54-7AB8F9D18F97}.job C:\Users\Jim\AppData\Local\Google Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Restore point was successfully created. HKU\S-1-5-21-1853225634-1185179328-766844407-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully. "C:\Windows\katrack.dll" => Value Data removed successfully. "KATRACK.DLL" => Value Data removed successfully. "C:\Windows\katrack.dll" => Value Data not found. "C:\Windows\katrack.dll" => Value Data not found. "C:\Windows\katrk64.dll" => Value Data removed successfully. "KATRK64.DLL" => Value Data removed successfully. "C:\Windows\katrack.dll" => Value Data removed successfully. "C:\Windows\katrack.dll" => Value Data not found. "C:\Windows\katrack.dll" => Value Data not found. "KATRACK.DLL" => Value Data removed successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-1853225634-1185179328-766844407-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-1853225634-1185179328-766844407-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => value deleted successfully. HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Key not found. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully. C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll => Moved successfully. "HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully. C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll not found. "HKU\S-1-5-21-1853225634-1185179328-766844407-1000\Software\MozillaPlugins\@tools.google.com/Google Update;version=3" => Key deleted successfully. C:\Users\Jim\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll => Moved successfully. "HKU\S-1-5-21-1853225634-1185179328-766844407-1000\Software\MozillaPlugins\@tools.google.com/Google Update;version=9" => Key deleted successfully. C:\Users\Jim\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll not found. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSuggestURL deleted successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.669\_platform_specific\win_x86\widevinecdmadapter.dll not found. C:\Users\Jim\AppData\Local\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\Application\42.0.2311.90\ppGoogleNaClPluginChrome.dll not found. C:\Users\Jim\AppData\Local\Google\Chrome\Application\42.0.2311.90\pdf.dll not found. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj\11.0.7.52_0\plugin/npWCChromeExtnStub.dll not found. C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll => Moved successfully. C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll => Moved successfully. C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll => Moved successfully. C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll not found. C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll not found. C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll not found. C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll not found. C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll not found. C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll => Moved successfully. C:\Program Files (x86)\TabletPlugins\npwacom.dll => Moved successfully. C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll => Moved successfully. C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL => Moved successfully. C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll => Moved successfully. C:\Users\Jim\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll not found. CHR Profile: C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default => Error: No automatic fix found for this entry. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda => Moved successfully. C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnimjdijgakingbgempmgkdgfhmmogah => Moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj" => Key deleted successfully. C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. C:\ProgramData\6467019769728057092 => Moved successfully. C:\ProgramData\{19079dab-850b-e1b9-1907-79dab85076ae} => Moved successfully. C:\Users\Jim\AppData\Local\EmieBrowserModeList => Moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully. C:\Windows\Tasks\{3A1B2112-3617-4D99-BF54-7AB8F9D18F97}.job => Moved successfully. C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853225634-1185179328-766844407-1000UA.job => Moved successfully. C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1853225634-1185179328-766844407-1000Core.job => Moved successfully. "C:\Windows\Tasks\{3A1B2112-3617-4D99-BF54-7AB8F9D18F97}.job" => File/Directory not found. C:\Users\Jim\AppData\Local\Google => Moved successfully. ========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f ========= The operation completed successfully. ========= End of Reg: ========= ========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f ========= The operation completed successfully. ========= End of Reg: ========= ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. HKU\S-1-5-21-1853225634-1185179328-766844407-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\S-1-5-21-1853225634-1185179328-766844407-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. ========= End of RemoveProxy: ========= ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.5.7601 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. 0 out of 0 jobs canceled. ========= End of CMD: ========= EmptyTemp: => Removed 113.6 MB temporary data. The system needed a reboot. ==== End of Fixlog 12:12:35 ====