Fix result of Farbar Recovery Scan Tool (x64) Version:17-08-2015 Ran by Ilona (2015-08-19 13:23:50) Run:1 Running from C:\Users\Ilona\Desktop\frst Loaded Profiles: UpdatusUser & Ilona (Available Profiles: UpdatusUser & Ilona) Boot Mode: Normal ============================================== fixlist content: ***************** Task: {571D9061-DEC6-4BC1-97F1-DCC2FC1C7B68} - \snf -> No File <==== ATTENTION Task: {852AF476-E5AA-4FDB-9185-87F46F862876} - \snp -> No File <==== ATTENTION Task: {BCE6A675-A41A-4029-A77C-BB2CE726371F} - \APSnotifierPP1 -> No File <==== ATTENTION Task: {C4EE912F-3A69-47B3-9B46-74C2CA732C38} - System32\Tasks\{1D20848B-9FF4-4D69-ABF2-BF8599D68F2F} => pcalua.exe -a C:\Users\Ilona\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=cmi C:\ProgramData\Tristip AppInit_DLLs: C:\ProgramData\Tristip\tiaqgh20.dll => C:\ProgramData\Tristip\tiaqgh20.dll [136192 2015-08-19] () AppInit_DLLs-x32: C:\ProgramData\Tristip\x4wgamir.dll => C:\ProgramData\Tristip\x4wgamir.dll [119808 2015-08-19] () SearchScopes: HKU\S-1-5-21-2456979592-2387919666-1884685256-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = FF DefaultSearchEngine: findit OPR StartupUrls: "hxxp://www.mystartsearch.com/?type=hp&ts=1439294669&z=411cb8de5382f65c2712562g2zbc4t3oftez6w5b6b&from=cvs&uid=ST1000LM014-SSHD-8GB_W3812N51XXXXW3812N51" S2 Application Hosting; C:\ProgramData\Application Hosting\Application Hosting.exe [X] R2 Tristip; C:\ProgramData\Tristip\Tristip [X] C:\WINDOWS\Minidump\*.dmp Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f C:\ProgramData\Tristips C:\Users\Ilona\Downloads\SpyHunter-Installer.exe C:\WINDOWS\System32\Tasks\{1D20848B-9FF4-4D69-ABF2-BF8599D68F2F} C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 C:\ProgramData\7b24ec7cc000461ebe26d116b88142c8 C:\ProgramData\Application Hosting C:\Users\Ilona\AppData\Local\Microsoft\Windows\INetCache\IE\THHMD8KF\zd71854y.exe EmptyTemp: ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{571D9061-DEC6-4BC1-97F1-DCC2FC1C7B68}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{571D9061-DEC6-4BC1-97F1-DCC2FC1C7B68}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\snf => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{852AF476-E5AA-4FDB-9185-87F46F862876}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{852AF476-E5AA-4FDB-9185-87F46F862876}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\snp => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BCE6A675-A41A-4029-A77C-BB2CE726371F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCE6A675-A41A-4029-A77C-BB2CE726371F}" => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1 => key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C4EE912F-3A69-47B3-9B46-74C2CA732C38}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4EE912F-3A69-47B3-9B46-74C2CA732C38}" => key removed successfully C:\WINDOWS\System32\Tasks\{1D20848B-9FF4-4D69-ABF2-BF8599D68F2F} => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1D20848B-9FF4-4D69-ABF2-BF8599D68F2F}" => key removed successfully "C:\ProgramData\Tristip" folder move: Could not move "C:\ProgramData\Tristip" => Scheduled to move on reboot. "C:\ProgramData\Tristip\tiaqgh20.dll" => Value data removed successfully. "C:\ProgramData\Tristip\x4wgamir.dll" => Value data removed successfully. "HKU\S-1-5-21-2456979592-2387919666-1884685256-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. Firefox DefaultSearchEngine removed successfully Opera StartupUrls removed successfully Application Hosting => service removed successfully Tristip => Unable to stop service. Tristip => service removed successfully C:\WINDOWS\Minidump\*.dmp => moved successfully. ========= reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= ERROR: The system was unable to find the specified registry key or value. ========= End of Reg: ========= C:\ProgramData\Tristips => moved successfully. C:\Users\Ilona\Downloads\SpyHunter-Installer.exe => moved successfully. "C:\WINDOWS\System32\Tasks\{1D20848B-9FF4-4D69-ABF2-BF8599D68F2F}" => File/Folder not found. C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => moved successfully. C:\ProgramData\7b24ec7cc000461ebe26d116b88142c8 => moved successfully. "C:\ProgramData\Application Hosting" => File/Folder not found. C:\Users\Ilona\AppData\Local\Microsoft\Windows\INetCache\IE\THHMD8KF\zd71854y.exe => moved successfully. EmptyTemp: => 11.9 GB temporary data Removed. Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-08-19 13:26:37)<= C:\ProgramData\Tristip => Is moved successfully ==== End of Fixlog 13:26:37 ====