Fix result of Farbar Recovery Scan Tool (x64) Version:27-04-2016
Ran by evenh (2016-04-29 18:47:45) Run:1
Running from C:\Users\evenh\Desktop
Loaded Profiles: evenh (Available Profiles: evenh)
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
AppInit_DLLs-x32: AirfoilInjector_3_7.dll => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Tcpip\..\Interfaces\{d5e60bb0-5347-408f-9c31-b5b2f8840054}: [DhcpNameServer] 82.163.143.171
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\npQMExtensionsMozilla.dll [2016-04-29] (Tencent Technology (Shenzhen) Company Limited)
R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQPCRTP.exe [313936 2016-04-29] (Tencent)
U2 QQRepair251a; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair251a [140608 2016-04-29] ()
S2 QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepairFixSVC [140608 2016-04-29] ()
R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys [184952 2016-04-18] (Tencent)
R1 softaal; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys [44664 2016-04-29] (Tencent)
R1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [172664 2016-04-29] ()
R3 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys [99480 2016-04-29] (Tencent)
R2 TAOKernelDriver; C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys [143992 2016-04-29] (Tencent Technology(Shenzhen) Company Limited)
R3 TS888x64; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TS888x64.sys [38520 2016-04-29] (Tencent)
S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TSDefenseBT64.sys [28984 2016-04-29] (Tencent)
R2 tsnethlpx64; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys [57976 2016-04-29] ()
R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QQSysMonX64.sys [154744 2016-04-29] (????)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [97400 2016-04-29] (????)
R1 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TSSysKit64.sys [96888 2016-04-29] (????)
2016-04-29 15:44 - 2016-04-29 15:44 - 00097400 _____ (????) C:\WINDOWS\system32\Drivers\TFsFltX64.sys
2016-04-29 15:43 - 2016-04-29 15:43 - 00114632 _____ (?????????????) C:\Users\evenh\AppData\Roaming\xldl.dll
2016-04-29 15:43 - 2016-04-29 15:43 - 0114632 _____ (?????????????) C:\Users\evenh\AppData\Roaming\xldl.dll
AV: ???????? (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5}
AS: ???????? (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48}
2016-04-29 16:35 - 2016-04-29 16:35 - 00768248 _____ (Reimage®) C:\Users\evenh\Downloads\ReimageRepair.exe
2016-04-29 16:19 - 2016-04-29 16:19 - 00038520 _____ (Tencent) C:\WINDOWS\SysWOW64\Drivers\TS888x64.sys
2016-04-29 15:45 - 2016-04-29 15:45 - 00413439 _____ C:\ProgramData\xdo.zip
2016-04-29 15:45 - 2016-04-26 23:03 - 01253376 _____ (eee) C:\ProgramData\apptj.exe
2016-04-29 15:44 - 2016-04-29 16:18 - 00000000 ____D C:\ProgramData\TXQMPC
2016-04-29 15:44 - 2016-04-29 15:53 - 00000000 ____D C:\Users\evenh\AppData\Roaming\Tencent
2016-04-29 15:44 - 2016-04-29 15:50 - 00000000 ____D C:\ProgramData\Tencent
2016-04-29 15:44 - 2016-04-29 15:44 - 00143992 _____ (Tencent Technology(Shenzhen) Company Limited) C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys
2016-04-29 15:44 - 2016-04-29 15:44 - 00099480 _____ (Tencent) C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys
2016-04-29 15:44 - 2016-04-29 15:44 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-04-29 15:44 - 2016-04-29 15:44 - 00000000 ____D C:\Program Files (x86)\Tencent
2016-04-29 15:43 - 2016-04-29 15:43 - 00000000 ____D C:\Users\Public\Thunder Network
2016-04-29 15:43 - 2016-04-29 15:43 - 00000000 ____D C:\Users\evenh\AppData\Roaming\download
2016-04-29 15:43 - 2016-04-29 15:43 - 00000000 ____D C:\ProgramData\Thunder Network
Task: {033916B4-0899-449D-8E4F-3F9F3D0F6694} - \{7F0C7D47-0C0D-7E7A-0911-7E057D09110F} -> No File <==== ATTENTION
Task: {58140C7E-385F-459A-B45C-A56E4F4C883B} - System32\Tasks\{DA608A7F-3D54-D701-9E09-F9D9310DBA45} => Regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\4f871b43\2eafea31.dll" <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service"
C:\Program Files (x86)\Tencent
C:\Users\evenh\AppData\Roaming\Tencent
C:\Program Files (x86)\Common Files\Tencent
C:\ProgramData\a.bat
C:\ProgramData\adb.exe
C:\ProgramData\AdbWinApi.dll
C:\ProgramData\AdbWinUsbApi.dll
C:\ProgramData\apptj.exe
C:\ProgramData\fastboot.exe
C:\PROGRA~3\4f871b43
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: bitsadmin /reset /allusers
*****************
Restore point was successfully created.
"AirfoilInjector_3_7.dll" => Value data removed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d5e60bb0-5347-408f-9c31-b5b2f8840054}\\DhcpNameServer => value removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@qq.com/QQPCMgr" => key removed successfully
C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\npQMExtensionsMozilla.dll => moved successfully
QQPCRTP => Unable to stop service.
QQPCRTP => service removed successfully
QQRepair251a => service removed successfully
QQRepairFixSVC => service removed successfully
QMUdisk => Unable to stop service.
QMUdisk => service removed successfully
softaal => Unable to stop service.
softaal => service removed successfully
SRepairDrv => Unable to stop service.
SRepairDrv => service removed successfully
TAOAccelerator => Unable to stop service.
TAOAccelerator => service removed successfully
TAOKernelDriver => Unable to stop service.
TAOKernelDriver => service removed successfully
TS888x64 => Unable to stop service.
TS888x64 => service removed successfully
TSDefenseBt => service removed successfully
tsnethlpx64 => Unable to stop service.
tsnethlpx64 => service removed successfully
QQSysMonX64 => Unable to stop service.
QQSysMonX64 => service removed successfully
TFsFlt => Unable to stop service.
TFsFlt => service removed successfully
TSSysKit => Unable to stop service.
TSSysKit => service removed successfully
C:\WINDOWS\system32\Drivers\TFsFltX64.sys => moved successfully
C:\Users\evenh\AppData\Roaming\xldl.dll => moved successfully
"C:\Users\evenh\AppData\Roaming\xldl.dll" => not found.
AV: ???????? (Enabled - Up to date) {6F9C3F92-B625-0E47-F0B1-447602EC65F5} => removed successfully
AS: ???????? (Enabled - Up to date) {D4FDDE76-901F-01C9-CA01-7F04796B2F48} => removed successfully
C:\Users\evenh\Downloads\ReimageRepair.exe => moved successfully
C:\WINDOWS\SysWOW64\Drivers\TS888x64.sys => moved successfully
C:\ProgramData\xdo.zip => moved successfully
C:\ProgramData\apptj.exe => moved successfully
C:\ProgramData\TXQMPC => moved successfully
"C:\Users\evenh\AppData\Roaming\Tencent" folder move:
Could not move "C:\Users\evenh\AppData\Roaming\Tencent" => Scheduled to move on reboot.
"C:\ProgramData\Tencent" folder move:
Could not move "C:\ProgramData\Tencent" => Scheduled to move on reboot.
C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys => moved successfully
C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys => moved successfully
"C:\Program Files\Common Files\Tencent" folder move:
Could not move "C:\Program Files\Common Files\Tencent" => Scheduled to move on reboot.
"C:\Program Files (x86)\Tencent" folder move:
Could not move "C:\Program Files (x86)\Tencent" => Scheduled to move on reboot.
C:\Users\Public\Thunder Network => moved successfully
C:\Users\evenh\AppData\Roaming\download => moved successfully
C:\ProgramData\Thunder Network => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{033916B4-0899-449D-8E4F-3F9F3D0F6694}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{033916B4-0899-449D-8E4F-3F9F3D0F6694}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7F0C7D47-0C0D-7E7A-0911-7E057D09110F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58140C7E-385F-459A-B45C-A56E4F4C883B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58140C7E-385F-459A-B45C-A56E4F4C883B}" => key removed successfully
C:\WINDOWS\System32\Tasks\{DA608A7F-3D54-D701-9E09-F9D9310DBA45} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DA608A7F-3D54-D701-9E09-F9D9310DBA45}" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP" => key removed successfully
"C:\Program Files (x86)\Tencent" folder move:
Could not move "C:\Program Files (x86)\Tencent" => Scheduled to move on reboot.
"C:\Users\evenh\AppData\Roaming\Tencent" folder move:
Could not move "C:\Users\evenh\AppData\Roaming\Tencent" => Scheduled to move on reboot.
C:\Program Files (x86)\Common Files\Tencent => moved successfully
C:\ProgramData\a.bat => moved successfully
C:\ProgramData\adb.exe => moved successfully
C:\ProgramData\AdbWinApi.dll => moved successfully
C:\ProgramData\AdbWinUsbApi.dll => moved successfully
"C:\ProgramData\apptj.exe" => not found.
C:\ProgramData\fastboot.exe => moved successfully
C:\PROGRA~3\4f871b43 => moved successfully
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
Operasjonen er utf›rt.
========= End of Reg: =========
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
Operasjonen er utf›rt.
========= End of Reg: =========
========= RemoveProxy: =========
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-1389706129-1160737656-1141877127-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-1389706129-1160737656-1141877127-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
========= End of RemoveProxy: =========
========= netsh advfirewall reset =========
Ok.
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Ok.
========= End of CMD: =========
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
========= netsh winsock reset catalog =========
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
========= End of CMD: =========
========= netsh int ip reset c:\resetlog.txt =========
Resetting Global, OK!
Resetting Interface, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting , failed.
Ingen tilgang.
Resetting , OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= ipconfig /release =========
Windows IP Configuration
No operation can be performed on Bluetooth Network Connection while it has its media disconnected.
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . : getinternet.no
IPv6 Address. . . . . . . . . . . : 2a02:fe0:c310:99c0:18f1:a546:d2c9:26f5
IPv6 Address. . . . . . . . . . . : 2a02:fe0:c310:99c1:18f1:a546:d2c9:26f5
Temporary IPv6 Address. . . . . . : 2a02:fe0:c310:99c0:60fe:5988:20f9:107b
Temporary IPv6 Address. . . . . . : 2a02:fe0:c310:99c1:60fe:5988:20f9:107b
Link-local IPv6 Address . . . . . : fe80::18f1:a546:d2c9:26f5%6
Default Gateway . . . . . . . . . : fe80::9284:dff:fed3:ae41%6
fe80::9484:dff:fede:420f%6
Ethernet adapter Bluetooth Network Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
========= End of CMD: =========
========= ipconfig /renew =========
Windows IP Configuration
No operation can be performed on Bluetooth Network Connection while it has its media disconnected.
Ethernet adapter Ethernet:
Connection-specific DNS Suffix . : getinternet.no
IPv6 Address. . . . . . . . . . . : 2a02:fe0:c310:99c0:18f1:a546:d2c9:26f5
IPv6 Address. . . . . . . . . . . : 2a02:fe0:c310:99c1:18f1:a546:d2c9:26f5
Temporary IPv6 Address. . . . . . : 2a02:fe0:c310:99c0:60fe:5988:20f9:107b
Temporary IPv6 Address. . . . . . : 2a02:fe0:c310:99c1:60fe:5988:20f9:107b
Link-local IPv6 Address . . . . . : fe80::18f1:a546:d2c9:26f5%6
IPv4 Address. . . . . . . . . . . : 10.0.1.5
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : fe80::9284:dff:fed3:ae41%6
fe80::9484:dff:fede:420f%6
10.0.1.1
Ethernet adapter Bluetooth Network Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
IPv6 Address. . . . . . . . . . . : 2001:0:9d38:90d7:cf9:1e3a:f5ff:fefa
Link-local IPv6 Address . . . . . : fe80::cf9:1e3a:f5ff:fefa%10
Default Gateway . . . . . . . . . :
Tunnel adapter isatap.getinternet.no:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : getinternet.no
========= End of CMD: =========
========= netsh int ipv4 reset =========
Resetting Interface, OK!
Resetting , failed.
Ingen tilgang.
Restart the computer to complete this action.
========= End of CMD: =========
========= netsh int ipv6 reset =========
Resetting Interface, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting , failed.
Ingen tilgang.
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.8.10586 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
{FE40548D-6A59-4E7A-8353-40966F0A841B} canceled.
{F8C07D57-E357-4BFE-B72A-FB9B147A95B8} canceled.
{03DA1D83-26EF-4696-87EA-76D7DA9D42AC} canceled.
{9247CF7A-0E74-41E6-A187-0A65EB56F328} canceled.
{74406E0B-52ED-4CEF-90BF-3D0A38AD4C16} canceled.
{6DB977D9-BFFF-4432-8FB1-2E2578DCE82A} canceled.
{C0681BFB-C89A-43D0-B7F3-EFCF64CCA968} canceled.
{0736C7AB-02FF-418F-9C38-0539B20FD633} canceled.
{FCC9CA45-19CC-46D3-8011-3E9E1CA42CFF} canceled.
{7587382A-79B7-4F80-862C-117D688205A7} canceled.
{089232CF-AF84-4F6E-AB04-C4C2F07E29D4} canceled.
{87057218-A326-4E1B-8D90-0E41C9FC2A9A} canceled.
{F6711DF3-7D8B-4151-8AF7-495094B91926} canceled.
{EDFF53E9-58A3-4806-A5DC-4B349E126972} canceled.
{95D91362-83D7-4A54-B565-4D43C0E59692} canceled.
{2224F903-DB83-4ED8-A9EC-C26B9EFD9B7C} canceled.
{15A91ECF-EF42-4F93-98A7-E7118B34FEBB} canceled.
{20235839-788F-447A-AE5B-9A2DF399067D} canceled.
{DCA3F026-3CE9-46D1-9923-735C7B147EE9} canceled.
{B120FAE3-438F-4F14-90C9-2D9B3C0E4CBC} canceled.
{C01E5F8C-AB3C-4051-94D9-B2B1A74882A6} canceled.
{0DF3808D-5D7B-4431-B23D-E08F09C60883} canceled.
22 out of 22 jobs canceled.
========= End of CMD: =========
EmptyTemp: => 501.4 MB temporary data Removed.