Fix result of Farbar Recovery Scan Tool (x64) Version: 15-06-2017 01 Ran by MerryZ (17-06-2017 21:39:23) Run:1 Running from C:\Users\MerryZ\Downloads Loaded Profiles: MerryZ (Available Profiles: MerryZ & Merry Z & Administrator & DefaultAppPool) Boot Mode: Normal ============================================== fixlist content: ***************** (Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe HKU\S-1-5-21-2720924552-1951368585-1981068937-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2720924552-1951368585-1981068937-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 GroupPolicy\User: Restriction <======= ATTENTION ProxyEnable: [S-1-5-21-2720924552-1951368585-1981068937-1000] => Proxy is enabled. Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 4.2.2.2 4.2.2.1 Tcpip\..\Interfaces\{6a56ca7a-dd21-4fc4-b338-d825e61b3cd0}: [DhcpNameServer] 192.168.5.1 Tcpip\..\Interfaces\{95f0d466-ea7c-405a-8f7c-0a6d47e7133b}: [DhcpNameServer] 4.2.2.2 4.2.2.1 Tcpip\..\Interfaces\{d8f76dd7-955c-4c6b-9186-506db6c48210}: [DhcpNameServer] 4.2.2.2 4.2.2.1 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_aftdwn_17_19¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0F0C0A0AtCyEzzyC0AtByBtDtDyDzyzztN0D0Tzu0StCzyyDzytN1L2XzutAtFtBzytFtAtFyByDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StB0F0E0FyBtDtD0EtGyC0C0A0BtGtCyBtCzytGtDyEyByCtGyBzy0EtBtCtDtA0DtB0ByC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0FyEyCtB0EyD0FtGyE0CyCzytGyEyBtDzytGzz0AzzyBtGyCyDyCtAyDyE0Bzzzy0Azz0B2QtN0A0LzutB%26cr%3D1902081554%26a%3Dwbf_aftdwn_17_19%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_aftdwn_17_19¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0F0C0A0AtCyEzzyC0AtByBtDtDyDzyzztN0D0Tzu0StCzyyDzytN1L2XzutAtFtBzytFtAtFyByDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StB0F0E0FyBtDtD0EtGyC0C0A0BtGtCyBtCzytGtDyEyByCtGyBzy0EtBtCtDtA0DtB0ByC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0FyEyCtB0EyD0FtGyE0CyCzytGyEyBtDzytGzz0AzzyBtGyCyDyCtAyDyE0Bzzzy0Azz0B2QtN0A0LzutB%26cr%3D1902081554%26a%3Dwbf_aftdwn_17_19%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_aftdwn_17_19¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0F0C0A0AtCyEzzyC0AtByBtDtDyDzyzztN0D0Tzu0StCzyyDzytN1L2XzutAtFtBzytFtAtFyByDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StB0F0E0FyBtDtD0EtGyC0C0A0BtGtCyBtCzytGtDyEyByCtGyBzy0EtBtCtDtA0DtB0ByC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0FyEyCtB0EyD0FtGyE0CyCzytGyEyBtDzytGzz0AzzyBtGyCyDyCtAyDyE0Bzzzy0Azz0B2QtN0A0LzutB%26cr%3D1902081554%26a%3Dwbf_aftdwn_17_19%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_aftdwn_17_19¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0F0C0A0AtCyEzzyC0AtByBtDtDyDzyzztN0D0Tzu0StCzyyDzytN1L2XzutAtFtBzytFtAtFyByDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StB0F0E0FyBtDtD0EtGyC0C0A0BtGtCyBtCzytGtDyEyByCtGyBzy0EtBtCtDtA0DtB0ByC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0FyEyCtB0EyD0FtGyE0CyCzytGyEyBtDzytGzz0AzzyBtGyCyDyCtAyDyE0Bzzzy0Azz0B2QtN0A0LzutB%26cr%3D1902081554%26a%3Dwbf_aftdwn_17_19%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_aftdwn_17_19¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0F0C0A0AtCyEzzyC0AtByBtDtDyDzyzztN0D0Tzu0StCzyyDzytN1L2XzutAtFtBzytFtAtFyByDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StB0F0E0FyBtDtD0EtGyC0C0A0BtGtCyBtCzytGtDyEyByCtGyBzy0EtBtCtDtA0DtB0ByC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0FyEyCtB0EyD0FtGyE0CyCzytGyEyBtDzytGzz0AzzyBtGyCyDyCtAyDyE0Bzzzy0Azz0B2QtN0A0LzutB%26cr%3D1902081554%26a%3Dwbf_aftdwn_17_19%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms} SearchScopes: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_aftdwn_17_19¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0F0C0A0AtCyEzzyC0AtByBtDtDyDzyzztN0D0Tzu0StCzyyDzytN1L2XzutAtFtBzytFtAtFyByDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StB0F0E0FyBtDtD0EtGyC0C0A0BtGtCyBtCzytGtDyEyByCtGyBzy0EtBtCtDtA0DtB0ByC0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0FyEyCtB0EyD0FtGyE0CyCzytGyEyBtDzytGzz0AzzyBtGyCyDyCtAyDyE0Bzzzy0Azz0B2QtN0A0LzutB%26cr%3D1902081554%26a%3Dwbf_aftdwn_17_19%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms} BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File CHR HomePage: Profile 1 -> mysearch.avg.com CHR NewTab: Profile 1 -> Not-active:"chrome-extension://mallpejgeafdahhflmliiahjdpgbegpk/stubby.html", Not-active:"chrome-extension://obnljkamlkedffammjddflhjepplhnoj/stubby.html" CHR DefaultSearchURL: Profile 1 -> hxxps://mysearch.avg.com/search?rvt=1&sap=dsp&q={searchTerms} CHR DefaultSearchKeyword: Profile 1 -> hxxps://mysearch.avg.com CHR DefaultSuggestURL: Profile 1 -> hxxps://toolbar.avg.com/acp?q={searchTerms}&o=1 CHR Extension: (AVG Secure Search) - C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2016-03-01] CHR Extension: (AVG Secure Search) - C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2015-05-09] CHR Extension: (ShopAtHome.com: Deals + Cash Back) - C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmhdchlgkaelnphlklcdddpigfiblbhb [2017-06-02] CHR Extension: (HowToSuite) - C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\obnljkamlkedffammjddflhjepplhnoj [2017-05-16] R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [69368 2013-10-23] (Bitdefender) S3 fileHiders; C:\WINDOWS\System32\DRIVERS\fileHiders.sys [32696 2015-08-13] () <==== ATTENTION R1 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [148696 2013-04-22] (BitDefender LLC) U3 idsvc; no ImagePath 2017-06-03 03:38 - 2017-06-03 03:38 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2015-06-07 00:18 - 2015-06-07 00:18 - 0245226 _____ () C:\ProgramData\1433660781.bdinstall.bin 2015-08-12 11:51 - 2015-08-12 11:51 - 0037823 _____ () C:\ProgramData\1439405470.bdinstall.bin 2015-08-12 11:53 - 2015-08-12 11:53 - 0097979 _____ () C:\ProgramData\1439405471.bdinstall.bin 2015-08-12 19:18 - 2015-08-12 19:18 - 0237460 _____ () C:\ProgramData\1439431394.bdinstall.bin 2015-10-24 10:35 - 2015-10-24 10:37 - 0177506 _____ () C:\ProgramData\1445708147.bdinstall.bin 2015-10-24 10:40 - 2015-10-24 10:40 - 0037838 _____ () C:\ProgramData\1445708403.bdinstall.bin 2015-10-24 10:45 - 2015-10-24 10:45 - 0094105 _____ () C:\ProgramData\1445708404.bdinstall.bin 2015-10-25 12:29 - 2015-10-25 12:29 - 0237090 _____ () C:\ProgramData\1445764663.bdinstall.bin 2015-10-26 19:38 - 2015-10-26 19:38 - 0037602 _____ () C:\ProgramData\1445913537.bdinstall.bin 2015-10-26 19:42 - 2015-10-26 19:42 - 0177336 _____ () C:\ProgramData\1445913538.bdinstall.bin 2015-10-28 19:44 - 2015-10-28 19:44 - 0037839 _____ () C:\ProgramData\1446086681.bdinstall.bin 2015-10-28 19:50 - 2015-10-28 19:50 - 0094780 _____ () C:\ProgramData\1446086682.bdinstall.bin 2015-10-30 18:51 - 2015-10-30 18:51 - 0003690 _____ () C:\ProgramData\1446256276.bdinstall.bin 2015-10-30 18:51 - 2015-10-30 18:51 - 0003690 _____ () C:\ProgramData\1446256283.bdinstall.bin 2015-10-30 18:51 - 2015-10-30 18:51 - 0003690 _____ () C:\ProgramData\1446256294.bdinstall.bin 2015-10-30 18:54 - 2015-10-30 18:54 - 0003690 _____ () C:\ProgramData\1446256444.bdinstall.bin 2015-10-30 23:39 - 2015-10-30 23:39 - 0003690 _____ () C:\ProgramData\1446273582.bdinstall.bin 2015-10-30 23:42 - 2015-10-30 23:42 - 0003690 _____ () C:\ProgramData\1446273755.bdinstall.bin 2015-10-30 23:42 - 2015-10-30 23:42 - 0003690 _____ () C:\ProgramData\1446273762.bdinstall.bin 2015-10-30 23:42 - 2015-10-30 23:42 - 0003690 _____ () C:\ProgramData\1446273773.bdinstall.bin 2015-10-30 23:42 - 2015-10-30 23:42 - 0003690 _____ () C:\ProgramData\1446273776.bdinstall.bin 2015-10-30 23:43 - 2015-10-30 23:43 - 0003690 _____ () C:\ProgramData\1446273781.bdinstall.bin 2015-11-01 17:30 - 2015-11-01 17:30 - 0003690 _____ () C:\ProgramData\1446424215.bdinstall.bin 2015-11-16 20:26 - 2015-11-16 20:26 - 0003690 _____ () C:\ProgramData\1447730794.bdinstall.bin 2015-11-16 20:26 - 2015-11-16 20:26 - 0003690 _____ () C:\ProgramData\1447730807.bdinstall.bin 2017-05-11 18:56 - 2017-05-11 18:56 - 0003690 _____ () C:\ProgramData\1494554175.bdinstall.bin 2017-05-11 18:58 - 2017-05-11 18:58 - 0003690 _____ () C:\ProgramData\1494554291.bdinstall.bin 2017-05-11 19:12 - 2017-05-11 19:12 - 0003690 _____ () C:\ProgramData\1494555155.bdinstall.bin 2017-05-12 14:20 - 2017-05-12 14:20 - 0003690 _____ () C:\ProgramData\1494624048.bdinstall.bin 2017-05-12 14:29 - 2017-05-12 14:29 - 0003690 _____ () C:\ProgramData\1494624587.bdinstall.bin 2017-05-13 09:19 - 2017-05-13 09:19 - 0003690 _____ () C:\ProgramData\1494692397.bdinstall.bin 2017-05-16 18:22 - 2017-05-16 18:22 - 0047689 _____ () C:\ProgramData\agent.1494984163.bdinstall.bin 2017-05-16 18:23 - 2017-05-16 18:23 - 0028694 _____ () C:\ProgramData\agent.1494984168.bdinstall.bin 2017-05-16 18:39 - 2017-05-16 18:39 - 0029167 _____ () C:\ProgramData\agent.1494985175.bdinstall.bin C:\Users\Administrator\NTUSER (2).DAT C:\Windows\Tasks\{400080EE-6B69-4339-B529-DCEB0B42ACB6}.job C:\Program Files\Bitdefender CMD: for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1" ***************** C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe => Could not close process HKU\S-1-5-21-2720924552-1951368585-1981068937-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => value removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => value removed successfully C:\WINDOWS\system32\GroupPolicy\User => moved successfully C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer => value removed successfully HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6a56ca7a-dd21-4fc4-b338-d825e61b3cd0}\\DhcpNameServer => value removed successfully HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{95f0d466-ea7c-405a-8f7c-0a6d47e7133b}\\DhcpNameServer => value removed successfully HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d8f76dd7-955c-4c6b-9186-506db6c48210}\\DhcpNameServer => value removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKLM\Software\Wow6432Node\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKU\S-1-5-21-2720924552-1951368585-1981068937-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} => key not found. HKLM\Software\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => key not found. Chrome HomePage => removed successfully Chrome NewTab => removed successfully Chrome DefaultSearchURL => not found. Chrome DefaultSearchKeyword => not found. Chrome DefaultSuggestURL => not found. C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn => not found C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof => not found C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmhdchlgkaelnphlklcdddpigfiblbhb => moved successfully C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\obnljkamlkedffammjddflhjepplhnoj => moved successfully gzserv => Unable to stop service. HKLM\System\CurrentControlSet\Services\gzserv => key could not remove, key could be protected fileHiders => service not found. gzflt => Unable to stop service. HKLM\System\CurrentControlSet\Services\gzflt => key could not remove, key could be protected HKLM\System\CurrentControlSet\Services\idsvc => key removed successfully idsvc => service removed successfully C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk => moved successfully "C:\ProgramData\1433660781.bdinstall.bin" => not found. "C:\ProgramData\1439405470.bdinstall.bin" => not found. "C:\ProgramData\1439405471.bdinstall.bin" => not found. "C:\ProgramData\1439431394.bdinstall.bin" => not found. "C:\ProgramData\1445708147.bdinstall.bin" => not found. "C:\ProgramData\1445708403.bdinstall.bin" => not found. "C:\ProgramData\1445708404.bdinstall.bin" => not found. "C:\ProgramData\1445764663.bdinstall.bin" => not found. "C:\ProgramData\1445913537.bdinstall.bin" => not found. "C:\ProgramData\1445913538.bdinstall.bin" => not found. "C:\ProgramData\1446086681.bdinstall.bin" => not found. "C:\ProgramData\1446086682.bdinstall.bin" => not found. "C:\ProgramData\1446256276.bdinstall.bin" => not found. "C:\ProgramData\1446256283.bdinstall.bin" => not found. "C:\ProgramData\1446256294.bdinstall.bin" => not found. "C:\ProgramData\1446256444.bdinstall.bin" => not found. "C:\ProgramData\1446273582.bdinstall.bin" => not found. "C:\ProgramData\1446273755.bdinstall.bin" => not found. "C:\ProgramData\1446273762.bdinstall.bin" => not found. "C:\ProgramData\1446273773.bdinstall.bin" => not found. "C:\ProgramData\1446273776.bdinstall.bin" => not found. "C:\ProgramData\1446273781.bdinstall.bin" => not found. "C:\ProgramData\1446424215.bdinstall.bin" => not found. "C:\ProgramData\1447730794.bdinstall.bin" => not found. "C:\ProgramData\1447730807.bdinstall.bin" => not found. "C:\ProgramData\1494554175.bdinstall.bin" => not found. "C:\ProgramData\1494554291.bdinstall.bin" => not found. "C:\ProgramData\1494555155.bdinstall.bin" => not found. "C:\ProgramData\1494624048.bdinstall.bin" => not found. "C:\ProgramData\1494624587.bdinstall.bin" => not found. "C:\ProgramData\1494692397.bdinstall.bin" => not found. C:\ProgramData\agent.1494984163.bdinstall.bin => moved successfully C:\ProgramData\agent.1494984168.bdinstall.bin => moved successfully C:\ProgramData\agent.1494985175.bdinstall.bin => moved successfully C:\Users\Administrator\NTUSER (2).DAT => moved successfully C:\Windows\Tasks\{400080EE-6B69-4339-B529-DCEB0B42ACB6}.job => moved successfully C:\Program Files\Bitdefender => moved successfully ========= for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1" ========= Failed to clear log Microsoft-Windows-LiveId/Analytic. Access is denied. Failed to clear log Microsoft-Windows-LiveId/Operational. Access is denied. Failed to clear log Microsoft-Windows-USBVideo/Analytic. The instance name passed was not recognized as valid by a WMI data provider. ========= End of CMD: ========= Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 17-06-2017 21:41:52) Result of scheduled keys to remove after reboot: HKLM\System\CurrentControlSet\Services\gzserv => key could not remove, key could be protected HKLM\System\CurrentControlSet\Services\gzflt => key could not remove, key could be protected ==== End of Fixlog 21:41:52 ====