Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by nicolas at 2015-06-26 22:19:26 Run:1 Running from C:\Users\nicolas\Desktop\Téléchargements Loaded Profiles: nicolas (Available Profiles: UpdatusUser & nicolas) Boot Mode: Normal ============================================== fixlist content: ***************** start CloseProcesses: CreateRestorePoint: (Akamai Technologies, Inc.) C:\Users\nicolas\AppData\Local\Akamai\netsession_win.exe C:\Users\nicolas\AppData\Local\Akamai\netsession_win.exe HKU\S-1-5-21-1075306282-704854533-380126294-1002\...\Run: [Akamai NetSession Interface] => C:\Users\nicolas\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.) CHR HKU\S-1-5-21-1075306282-704854533-380126294-1002\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms} HKU\S-1-5-21-1075306282-704854533-380126294-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006 HKU\S-1-5-21-1075306282-704854533-380126294-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006 SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_tele_15_08&cd=2XzuyEtN2Y1L1QzuyDyC0F0DyDtB0D0D0AyC0EyDyD0E0AyBtN0D0Tzu0StCtCyEyDtN1L2XzutAtFyBtFyBtFtCtDtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyB0EyC0Bzzzz0AyCtG0DyBzyyBtGzytA0EyBtGtC0AtDyEtGyC0DtByCyCyDtA0CtDyB0B0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyEyB0FtBtCzyzztGtByCzy0AtGyEtBzzzztG0BtC0D0FtGtB0A0FzytDtByEtCzyyBtC0D2Q&cr=115821938&ir= SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1075306282-704854533-380126294-1002 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-1075306282-704854533-380126294-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_tele_15_08&cd=2XzuyEtN2Y1L1QzuyDyC0F0DyDtB0D0D0AyC0EyDyD0E0AyBtN0D0Tzu0StCtCyEyDtN1L2XzutAtFyBtFyBtFtCtDtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2SyB0EyC0Bzzzz0AyCtG0DyBzyyBtGzytA0EyBtGtC0AtDyEtGyC0DtByCyCyDtA0CtDyB0B0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyEyB0FtBtCzyzztGtByCzy0AtGyEtBzzzztG0BtC0D0FtGtB0A0FzytDtByEtCzyyBtC0D2Q&cr=115821938&ir= SearchScopes: HKU\S-1-5-21-1075306282-704854533-380126294-1002 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKU\S-1-5-21-1075306282-704854533-380126294-1002 -> {E88608A0-CDCD-465E-B9A7-6BD03796E7FF} URL = SearchScopes: HKU\S-1-5-21-1075306282-704854533-380126294-1002 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms} BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File 2015-06-25 19:15 - 2014-12-02 20:15 - 00000316 _____ C:\WINDOWS\Tasks\WSE_Vosteran.job 2014-02-01 21:16 - 2015-04-14 09:30 - 0000147 _____ () C:\Users\nicolas\AppData\Roaming\WB.CFG 2015-02-19 16:26 - 2015-02-19 16:26 - 0234679 _____ () C:\Users\nicolas\AppData\Local\dsi1.dat 2015-02-19 16:26 - 2015-02-19 16:26 - 0161916 _____ () C:\Users\nicolas\AppData\Local\dsi2.dat Task: {CADA6174-F973-4786-9260-D1A419FFB262} - System32\Tasks\WSE_Vosteran => C:\Users\nicolas\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION C:\Users\nicolas\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE C:\WINDOWS\Tasks\WSE_Vosteran.job C:\Users\nicolas\AppData\Roaming\WB.CFG C:\Users\nicolas\AppData\Local\dsi1.dat C:\Users\nicolas\AppData\Local\dsi2.dat Task: {EABF92C1-0937-45EF-90A7-F310141AA80A} - \AutoKMSCustom No Task File <==== ATTENTION Task: C:\WINDOWS\Tasks\WSE_Vosteran.job => C:\Users\nicolas\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION FirewallRules: [TCP Query User{1760622A-B23A-4C02-8C5A-5A4DA54AFCD1}C:\users\nicolas\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\nicolas\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{99F9B76E-9C13-4503-AD3D-60BBAF908CDB}C:\users\nicolas\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\nicolas\appdata\local\akamai\netsession_win.exe FirewallRules: [{796232C9-7563-4E68-930C-8042ABC640E9}] => (Block) C:\users\nicolas\appdata\local\akamai\netsession_win.exe FirewallRules: [{023A2AE0-DD1B-495A-AB6C-BACDD710D87E}] => (Block) C:\users\nicolas\appdata\local\akamai\netsession_win.exe EmptyTemp: end Read more at http://www.cjoint.com/c/EFAogLSaQr5#oDosSRoBAHYuyX54.99 ***************** Processes closed successfully. Restore point was successfully created. C:\Users\nicolas\AppData\Local\Akamai\netsession_win.exe => No running process found C:\Users\nicolas\AppData\Local\Akamai\netsession_win.exe => moved successfully. HKU\S-1-5-21-1075306282-704854533-380126294-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => value removed successfully "HKU\S-1-5-21-1075306282-704854533-380126294-1002\SOFTWARE\Policies\Google" => key removed successfully HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully HKU\S-1-5-21-1075306282-704854533-380126294-1002\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-1075306282-704854533-380126294-1002\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => key removed successfully HKCR\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully HKCR\Wow6432Node\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found. HKU\S-1-5-21-1075306282-704854533-380126294-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\S-1-5-21-1075306282-704854533-380126294-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. "HKU\S-1-5-21-1075306282-704854533-380126294-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => key removed successfully HKCR\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} => key not found. "HKU\S-1-5-21-1075306282-704854533-380126294-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E88608A0-CDCD-465E-B9A7-6BD03796E7FF}" => key removed successfully HKCR\CLSID\{E88608A0-CDCD-465E-B9A7-6BD03796E7FF} => key not found. "HKU\S-1-5-21-1075306282-704854533-380126294-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}" => key removed successfully HKCR\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}" => key removed successfully HKCR\Wow6432Node\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found. HKCR\Wow6432Node\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value not found. HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found. C:\WINDOWS\Tasks\WSE_Vosteran.job => moved successfully. C:\Users\nicolas\AppData\Roaming\WB.CFG => moved successfully. C:\Users\nicolas\AppData\Local\dsi1.dat => moved successfully. C:\Users\nicolas\AppData\Local\dsi2.dat => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CADA6174-F973-4786-9260-D1A419FFB262}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CADA6174-F973-4786-9260-D1A419FFB262}" => key removed successfully C:\Windows\System32\Tasks\WSE_Vosteran => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WSE_Vosteran" => key removed successfully "C:\Users\nicolas\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE" => File/Folder not found. "C:\WINDOWS\Tasks\WSE_Vosteran.job" => File/Folder not found. "C:\Users\nicolas\AppData\Roaming\WB.CFG" => File/Folder not found. "C:\Users\nicolas\AppData\Local\dsi1.dat" => File/Folder not found. "C:\Users\nicolas\AppData\Local\dsi2.dat" => File/Folder not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EABF92C1-0937-45EF-90A7-F310141AA80A}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EABF92C1-0937-45EF-90A7-F310141AA80A}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMSCustom" => key removed successfully C:\WINDOWS\Tasks\WSE_Vosteran.job not found. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1760622A-B23A-4C02-8C5A-5A4DA54AFCD1}C:\users\nicolas\appdata\local\akamai\netsession_win.exe => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{99F9B76E-9C13-4503-AD3D-60BBAF908CDB}C:\users\nicolas\appdata\local\akamai\netsession_win.exe => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{796232C9-7563-4E68-930C-8042ABC640E9} => value removed successfully HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{023A2AE0-DD1B-495A-AB6C-BACDD710D87E} => value removed successfully Read more at http://www.cjoint.com/c/EFAogLSaQr5#oDosSRoBAHYuyX54.99 => Error: No automatic fix found for this entry. EmptyTemp: => 234.5 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 22:20:30 ====