Fix result of Farbar Recovery Scan Tool (x64) Version: 14-05-2017 Ran by PAUL (17-05-2017 16:18:26) Run:1 Running from C:\Users\PAUL\Desktop\FRST Loaded Profiles: PAUL (Available Profiles: PAUL & Guest) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: CreateRestorePoint: Task: {7059FA19-9555-4BD3-82FC-62BB24E037B0} - \PowerWord-SCT-JT -> No File <==== ATTENTION FirewallRules: [{EC64E54A-EEC4-4809-BE0C-3297B21A54A3}] => (Allow) C:\Program Files (x86)\Dayglad\Application\chrome.exe FirewallRules: [{A99FBE2E-9D2A-41C0-9DA6-9EE056BD0968}] => (Allow) C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe FirewallRules: [{DD66645C-CBB2-435D-B02F-29D1EEA18A7F}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe RemoveDirectory: C:\Program Files (x86)\Dayglad RemoveDirectory: C:\Users\Arekcipa\AppData\Roaming\Dayglad RemoveDirectory: C:\Users\Arekcipa\AppData\Local\Dayglad RemoveDirectory: C:\Program Files (x86)\Firefox RemoveDirectory: C:\Users\Arekcipa\AppData\Roaming\Firefox RemoveDirectory: C:\Users\Arekcipa\AppData\Local\Firefox HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-21-1375163193-2629173629-2764439304-1001\...\Run: [background_fault] => C:\Users\PAUL\AppData\Local\background_fault\aswRD.exe [1419576 2017-05-04] (AVAST Software) <===== ATTENTION C:\Users\PAUL\AppData\Local\background_fault\aswRD.exe HKU\S-1-5-21-1375163193-2629173629-2764439304-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKU\S-1-5-21-1375163193-2629173629-2764439304-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-1375163193-2629173629-2764439304-1001 -> {D06DC6CD-B472-42C3-AB78-A57BF968D205} URL = Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File CHR DefaultSearchURL: Default -> hxxp://www.ourluckysites.com/search/?type=ds&ts=1493718706&z=88d84c001f4b1f3960a3f9cgczbt2c0m8g9b1m8g2z&from=ypid&uid=TOSHIBAXMQ01ABD100_6357P3XATXX6357P3XAT&q={searchTerms} CHR DefaultSearchKeyword: Default -> ourluckysites R1 {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64; C:\WINDOWS\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys [61016 2014-06-06] (StdLib) S4 sptd; \SystemRoot\System32\Drivers\sptd.sys [X] U3 pxrdapod; \??\C:\Users\PAUL\AppData\Local\Temp\pxrdapod.sys [X] <==== ATTENTION EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7059FA19-9555-4BD3-82FC-62BB24E037B0} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7059FA19-9555-4BD3-82FC-62BB24E037B0} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PowerWord-SCT-JT => key removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EC64E54A-EEC4-4809-BE0C-3297B21A54A3} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A99FBE2E-9D2A-41C0-9DA6-9EE056BD0968} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DD66645C-CBB2-435D-B02F-29D1EEA18A7F} => value removed successfully "C:\Program Files (x86)\Dayglad" => not found. "C:\Users\Arekcipa\AppData\Roaming\Dayglad" => not found. "C:\Users\Arekcipa\AppData\Local\Dayglad" => not found. "C:\Program Files (x86)\Firefox" => not found. "C:\Users\Arekcipa\AppData\Roaming\Firefox" => not found. "C:\Users\Arekcipa\AppData\Local\Firefox" => not found. HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully HKU\S-1-5-21-1375163193-2629173629-2764439304-1001\Software\Microsoft\Windows\CurrentVersion\Run\\background_fault => value removed successfully C:\Users\PAUL\AppData\Local\background_fault\aswRD.exe => moved successfully HKU\S-1-5-21-1375163193-2629173629-2764439304-1001\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE => value removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully HKU\S-1-5-21-1375163193-2629173629-2764439304-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKU\S-1-5-21-1375163193-2629173629-2764439304-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D06DC6CD-B472-42C3-AB78-A57BF968D205} => key removed successfully HKCR\CLSID\{D06DC6CD-B472-42C3-AB78-A57BF968D205} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found. Chrome DefaultSearchURL => removed successfully Chrome DefaultSearchKeyword => removed successfully {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64 => Unable to stop service. HKLM\System\CurrentControlSet\Services\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64 => key removed successfully {a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64 => service removed successfully HKLM\System\CurrentControlSet\Services\sptd => key removed successfully sptd => service removed successfully HKLM\System\CurrentControlSet\Services\pxrdapod => key removed successfully pxrdapod => service removed successfully =========== EmptyTemp: ========== BITS transfer queue => 41943040 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 13834200 B Java, Flash, Steam htmlcache => 1073 B Windows/system/drivers => 584738 B Edge => 0 B Chrome => 15775398 B Firefox => 378537298 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 200 B systemprofile32 => 455716 B LocalService => 7436 B NetworkService => 0 B PAUL => 118841232 B Guest => 26914 B RecycleBin => 0 B EmptyTemp: => 543.6 MB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 16:20:10 ====