dawnieando
Posts: 24 +0
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-01-2015
Ran by Dawn Anderson at 2015-01-14 09:13:30 Run:1
Running from C:\Users\Dawn Anderson\Desktop
Loaded Profile: Dawn Anderson (Available profiles: Dawn Anderson & UpdatusUser & Classic .NET AppPool & DefaultAppPool)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-688939681-313738502-1202394865-1000\...\Run: [IBP] => [X]
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKU\S-1-5-21-688939681-313738502-1202394865-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ZoneAlarm Security Engine Registrar -> {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} -> C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKU\.DEFAULT -> No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
Toolbar: HKU\S-1-5-21-688939681-313738502-1202394865-1000 -> ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKU\S-1-5-21-688939681-313738502-1202394865-1000 -> No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
CHR HKLM-x32\...\Chrome\Extension: [lphidcjgkfcoaafemgpheibnllgmmdpc] - C:\Users\Dawn Anderson\AppData\LocalLow\DownloadManager\AppData\Chrome.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [niaogoecelkfjkgmdlefgifgomobeamj] - C:\Users\Dawn Anderson\AppData\LocalLow\iBryte\Implementations\playbryte\Chrome.crx [Not Found]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
C:\Users\Dawn Anderson\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpww0zzb.dll
C:\Users\Dawn Anderson\AppData\Local\Temp\Quarantine.exe
C:\Users\Dawn Anderson\AppData\Local\Temp\sqlite3.dll
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8ABED4F1-34E7-420B-9BD1-FD6FFC0BDDE1}"
Reg: reg delete "HKEY_USERS\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64101aeb-5300-459b-a2fb-c88cabc326d7}"
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Run\\IBP => value deleted successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}" => Key deleted successfully.
"HKCR\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => value deleted successfully.
"HKCR\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => value deleted successfully.
"HKCR\Wow6432Node\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}" => Key deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => value deleted successfully.
HKCR\CLSID\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => Key not found.
HKU\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => value deleted successfully.
HKCR\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => Key not found.
HKU\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => value deleted successfully.
HKCR\CLSID\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lphidcjgkfcoaafemgpheibnllgmmdpc" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niaogoecelkfjkgmdlefgifgomobeamj" => Key deleted successfully.
catchme => Service deleted successfully.
MSICDSetup => Service deleted successfully.
NTIOLib_1_0_C => Service deleted successfully.
"C:\Users\Dawn Anderson\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpww0zzb.dll" => File/Directory not found.
C:\Users\Dawn Anderson\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Dawn Anderson\AppData\Local\Temp\sqlite3.dll => Moved successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => Key deleted successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => Key deleted successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully.
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8ABED4F1-34E7-420B-9BD1-FD6FFC0BDDE1}" =========
Permanently delete the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8ABED4F1-34E7-420B-9BD1-FD6FFC0BDDE1} (Yes/No)? The operation completed successfully.
========= End of Reg: =========
========= reg delete "HKEY_USERS\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64101aeb-5300-459b-a2fb-c88cabc326d7}" =========
Permanently delete the registry key HKEY_USERS\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64101aeb-5300-459b-a2fb-c88cabc326d7} (Yes/No)? The operation completed successfully.
========= End of Reg: =========
The system needed a reboot.
==== End of Fixlog 09:13:48 ====
Ran by Dawn Anderson at 2015-01-14 09:13:30 Run:1
Running from C:\Users\Dawn Anderson\Desktop
Loaded Profile: Dawn Anderson (Available profiles: Dawn Anderson & UpdatusUser & Classic .NET AppPool & DefaultAppPool)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-688939681-313738502-1202394865-1000\...\Run: [IBP] => [X]
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKU\S-1-5-21-688939681-313738502-1202394865-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ZoneAlarm Security Engine Registrar -> {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} -> C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKU\.DEFAULT -> No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
Toolbar: HKU\S-1-5-21-688939681-313738502-1202394865-1000 -> ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll No File
Toolbar: HKU\S-1-5-21-688939681-313738502-1202394865-1000 -> No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
CHR HKLM-x32\...\Chrome\Extension: [lphidcjgkfcoaafemgpheibnllgmmdpc] - C:\Users\Dawn Anderson\AppData\LocalLow\DownloadManager\AppData\Chrome.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [niaogoecelkfjkgmdlefgifgomobeamj] - C:\Users\Dawn Anderson\AppData\LocalLow\iBryte\Implementations\playbryte\Chrome.crx [Not Found]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
C:\Users\Dawn Anderson\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpww0zzb.dll
C:\Users\Dawn Anderson\AppData\Local\Temp\Quarantine.exe
C:\Users\Dawn Anderson\AppData\Local\Temp\sqlite3.dll
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Dawn Anderson\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8ABED4F1-34E7-420B-9BD1-FD6FFC0BDDE1}"
Reg: reg delete "HKEY_USERS\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64101aeb-5300-459b-a2fb-c88cabc326d7}"
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Run\\IBP => value deleted successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}" => Key deleted successfully.
"HKCR\CLSID\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => value deleted successfully.
"HKCR\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => value deleted successfully.
"HKCR\Wow6432Node\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}" => Key deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => value deleted successfully.
HKCR\CLSID\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => Key not found.
HKU\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => value deleted successfully.
HKCR\CLSID\{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} => Key not found.
HKU\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => value deleted successfully.
HKCR\CLSID\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lphidcjgkfcoaafemgpheibnllgmmdpc" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niaogoecelkfjkgmdlefgifgomobeamj" => Key deleted successfully.
catchme => Service deleted successfully.
MSICDSetup => Service deleted successfully.
NTIOLib_1_0_C => Service deleted successfully.
"C:\Users\Dawn Anderson\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpww0zzb.dll" => File/Directory not found.
C:\Users\Dawn Anderson\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Dawn Anderson\AppData\Local\Temp\sqlite3.dll => Moved successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}" => Key deleted successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => Key deleted successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}" => Key deleted successfully.
"HKU\S-1-5-21-688939681-313738502-1202394865-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully.
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8ABED4F1-34E7-420B-9BD1-FD6FFC0BDDE1}" =========
Permanently delete the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8ABED4F1-34E7-420B-9BD1-FD6FFC0BDDE1} (Yes/No)? The operation completed successfully.
========= End of Reg: =========
========= reg delete "HKEY_USERS\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64101aeb-5300-459b-a2fb-c88cabc326d7}" =========
Permanently delete the registry key HKEY_USERS\S-1-5-21-688939681-313738502-1202394865-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\{64101aeb-5300-459b-a2fb-c88cabc326d7} (Yes/No)? The operation completed successfully.
========= End of Reg: =========
The system needed a reboot.
==== End of Fixlog 09:13:48 ====