Fix result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by valentin at 2015-06-27 14:13:37 Run:1 Running from C:\Users\valentin\Desktop Loaded Profiles: valentin (Available Profiles: valentin) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: Hosts: RemoveProxy: EmptyTemp: C:\Program Files (x86)\TuneUp Utilities 2014 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2013-10-20] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3106311008-3794818424-3365676790-1000 -> URL http://search.conduit.com/Results.aspx?ctid=CT3322287&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPDC65D9D7-9946-4072-A41B-BD9597A7B4BE&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-3106311008-3794818424-3365676790-1000 -> SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} BHO: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll [2010-09-01] (TechSmith Corporation) BHO-x32: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll [2010-09-01] (TechSmith Corporation) Toolbar: HKLM - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll [2010-09-01] (TechSmith Corporation) Toolbar: HKLM-x32 - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll [2010-09-01] (TechSmith Corporation) FF Extension: Positive Finds - C:\Users\valentin\AppData\Roaming\Mozilla\Firefox\Profiles\ofs2o43p.default\Extensions\{0230da46-e7bc-478c-8d43-7299576ae73f}.xpi [2015-06-16] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01] FF Extension: No Name - C:\Users\valentin\AppData\Roaming\Mozilla\Firefox\Profiles\ofs2o43p.default\extensions\cacaoweb@cacaoweb.org [not found] FF Extension: No Name - C:\Users\valentin\AppData\Roaming\Mozilla\Firefox\Profiles\ofs2o43p.default\extensions\extension@linkeyproject.com [not found] FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-04-10] <==== ATTENTION CHR HKLM-x32\...\Chrome\Extension: [akcfgabgnifcaiiechgancgabendhaco] - https://clients2.google.com/service/update2/crx S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X] 2014-07-28 23:03 - 2014-07-28 23:03 - 0590872 _____ (ClickMeIn Limited) C:\Users\valentin\AppData\Local\nsv4971.tmp cmd:netsh winsock reset end ***************** Restore point was successfully created. Processes closed successfully. Hosts restored successfully. ========= RemoveProxy: ========= "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully HKU\S-1-5-21-3106311008-3794818424-3365676790-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\S-1-5-21-3106311008-3794818424-3365676790-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully ========= End of RemoveProxy: ========= "C:\Program Files (x86)\TuneUp Utilities 2014" => File/Folder not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk not found. C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe not found. "HKLM\SOFTWARE\Policies\Google" => key removed successfully HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => key removed successfully HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully HKU\S-1-5-21-3106311008-3794818424-3365676790-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value removed successfully HKU\S-1-5-21-3106311008-3794818424-3365676790-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value removed successfully "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}" => key removed successfully "HKCR\CLSID\{00C6482D-C502-44C8-8409-FCE54AD9C208}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}" => key removed successfully "HKCR\Wow6432Node\CLSID\{00C6482D-C502-44C8-8409-FCE54AD9C208}" => key removed successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} => value removed successfully "HKCR\CLSID\{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" => key removed successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} => value removed successfully "HKCR\Wow6432Node\CLSID\{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" => key removed successfully C:\Users\valentin\AppData\Roaming\Mozilla\Firefox\Profiles\ofs2o43p.default\Extensions\{0230da46-e7bc-478c-8d43-7299576ae73f}.xpi => moved successfully. C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => moved successfully. C:\Users\valentin\AppData\Roaming\Mozilla\Firefox\Profiles\ofs2o43p.default\extensions\cacaoweb@cacaoweb.org not found. C:\Users\valentin\AppData\Roaming\Mozilla\Firefox\Profiles\ofs2o43p.default\extensions\extension@linkeyproject.com not found. C:\Program Files (x86)\mozilla firefox\firefox.cfg => moved successfully. "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\akcfgabgnifcaiiechgancgabendhaco" => key removed successfully EsgScanner => Service removed successfully C:\Users\valentin\AppData\Local\nsv4971.tmp => moved successfully. ========= netsh winsock reset ========= Le catalogue Winsock a ‚t‚ r‚initialis‚ correctement. Vous devez red‚marrer l'ordinateur afin de finaliser la r‚initialisation. ========= End of CMD: ========= EmptyTemp: => 445.6 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 14:14:30 ====