Fix result of Farbar Recovery Scan Tool (x64) Version:18-04-2016 Ran by TOSHIBA (2016-04-24 11:35:16) Run:3 Running from C:\Users\TOSHIBA\Desktop Loaded Profiles: TOSHIBA (Available Profiles: TOSHIBA) Boot Mode: Safe Mode (minimal) ============================================== fixlist content: ***************** start CloseProcesses: CreateRestorePoint: 2016-04-22 03:31 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2016-04-22 03:31 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2016-04-22 03:31 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2016-04-22 03:31 - 2000-08-31 02:00 - 00098816 _____ C:\windows\sed.exe 2016-04-22 03:31 - 2000-08-31 02:00 - 00080412 _____ C:\windows\grep.exe 2016-04-22 03:31 - 2000-08-31 02:00 - 00068096 _____ C:\windows\zip.exe C:\Windows\SysWOW64\runouce.exe C:\Windows\SysWOW64\wmicuclt.exe IE restricted site: HKU\.DEFAULT\...\1sexparty.com -> www.1sexparty.com IE restricted site: HKU\.DEFAULT\...\1sms.de -> www.1sms.de IE restricted site: HKU\.DEFAULT\...\1spybot.com -> www.1spybot.com IE restricted site: HKU\.DEFAULT\...\1stantivirus.com -> www.1stantivirus.com IE restricted site: HKU\.DEFAULT\...\1stpagehere.com -> www.1stpagehere.com IE restricted site: HKU\.DEFAULT\...\1stsearchportal.com -> www.1stsearchportal.com IE restricted site: HKU\.DEFAULT\...\2-2005-search.com -> www.2-2005-search.com IE restricted site: HKU\.DEFAULT\...\2006ooo.com -> www.2006ooo.com IE restricted site: HKU\.DEFAULT\...\2007-download.com -> www.2007-download.com IE restricted site: HKU\.DEFAULT\...\2008-search-destroy.com -> www.2008-search-destroy.com IE restricted site: HKU\.DEFAULT\...\2008-viewer.com -> www.2008-viewer.com IE restricted site: HKU\.DEFAULT\...\2008firefox.com -> www.2008firefox.com IE restricted site: HKU\.DEFAULT\...\2008search-destroy.com -> spybot.2008search-destroy.com IE restricted site: HKU\.DEFAULT\...\2009--access.com -> www.2009--access.com IE restricted site: HKU\.DEFAULT\...\2009-box.com -> firefox.2009-box.com IE restricted site: HKU\.DEFAULT\...\2009-edition.com -> www.2009-edition.com IE restricted site: HKU\.DEFAULT\...\2009-phone.com -> www.2009-phone.com IE restricted site: HKU\.DEFAULT\...\2009-version.info -> www.2009-version.info IE restricted site: HKU\.DEFAULT\...\2009antivirpro.com -> www.2009antivirpro.com EmptyTemp: hosts: Reboot: end ***************** Processes closed successfully. Error: Restore point can only be created in normal mode. C:\windows\NIRCMD.exe => moved successfully C:\windows\SWREG.exe => moved successfully C:\windows\SWSC.exe => moved successfully C:\windows\sed.exe => moved successfully C:\windows\grep.exe => moved successfully C:\windows\zip.exe => moved successfully C:\Windows\SysWOW64\runouce.exe => moved successfully C:\Windows\SysWOW64\wmicuclt.exe => moved successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1sexparty.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1sms.de" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1spybot.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1stantivirus.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1stpagehere.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1stsearchportal.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2-2005-search.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2006ooo.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2007-download.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2008-search-destroy.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2008-viewer.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2008firefox.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2008search-destroy.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2009--access.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2009-box.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2009-edition.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2009-phone.com" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2009-version.info" => key removed successfully "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\2009antivirpro.com" => key removed successfully C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. EmptyTemp: => 27.5 MB temporary data Removed. The system needed a reboot. ==== End of Fixlog 11:35:18 ====