Fix result of Farbar Recovery Scan Tool (x64) Version: 17-10-2016 Ran by louisa-jeaninne (23-10-2016 16:16:09) Run:1 Running from C:\Users\louisa-jeaninne\Desktop Loaded Profiles: louisa-jeaninne (Available Profiles: louisa-jeaninne) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: Task: {A771EFB6-2C21-4CD6-989A-88842E9D8EA2} - \Start Registry Reviver Schedule -> No File <==== ATTENTION Task: {C31BE3CA-4855-4E94-9CE5-ABAFB391BCED} - \Start Registry Reviver Update -> No File <==== ATTENTION AlternateDataStreams: C:\Windows:AstInfo [0] AlternateDataStreams: C:\Windows:nlsPreferences [0] ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} HKU\S-1-5-21-547428184-218225385-153729512-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508 HKU\S-1-5-21-547428184-218225385-153729512-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-547428184-218225385-153729512-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} SearchScopes: HKU\S-1-5-21-547428184-218225385-153729512-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mylucky123.com/search/?type=ds&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508&q={searchTerms} Edge HomeButtonPage: HKU\S-1-5-21-547428184-218225385-153729512-1001 -> hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508 CHR StartupUrls: Default -> "hxxp://www.jigsawplanet.com/","hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508" U0 aswVmm; no ImagePath S3 dbx; system32\DRIVERS\dbx.sys [X] C:\WINDOWS\SysWOW64\xaabbbbbbb C:\Users\Default\AppData\Roaming\TuneUp Software C:\Users\Default User\AppData\Roaming\TuneUp Software C:\Program Files (x86)\uvconvrx_00000000 C:\Users\louisa-jeaninne\AppData\Roaming\AVAST Software C:\ProgramData\UvConverter EmptyTemp: end ***************** Restore point was successfully created. Processes closed successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A771EFB6-2C21-4CD6-989A-88842E9D8EA2}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A771EFB6-2C21-4CD6-989A-88842E9D8EA2}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Start Registry Reviver Schedule => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C31BE3CA-4855-4E94-9CE5-ABAFB391BCED}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C31BE3CA-4855-4E94-9CE5-ABAFB391BCED}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Start Registry Reviver Update => key not found. C:\Windows => ":AstInfo" ADS removed successfully. C:\Windows => ":nlsPreferences" ADS removed successfully. "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-547428184-218225385-153729512-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-547428184-218225385-153729512-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKU\S-1-5-21-547428184-218225385-153729512-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\S-1-5-21-547428184-218225385-153729512-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKU\S-1-5-21-547428184-218225385-153729512-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main\\HomeButtonPage => value removed successfully Chrome StartupUrls => removed successfully aswVmm => service removed successfully dbx => service removed successfully C:\WINDOWS\SysWOW64\xaabbbbbbb => moved successfully C:\Users\Default\AppData\Roaming\TuneUp Software => moved successfully "C:\Users\Default User\AppData\Roaming\TuneUp Software" => not found. C:\Program Files (x86)\uvconvrx_00000000 => moved successfully C:\Users\louisa-jeaninne\AppData\Roaming\AVAST Software => moved successfully C:\ProgramData\UvConverter => moved successfully =========== EmptyTemp: ========== BITS transfer queue => 2208788 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 102914069 B Java, Flash, Steam htmlcache => 2331 B Windows/system/drivers => 7801314 B Edge => 60490998 B Chrome => 460696745 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 50384 B NetworkService => 29536 B louisa-jeaninne => 6388399 B RecycleBin => 26135435 B EmptyTemp: => 635.8 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 16:16:25 ====