Fix result of Farbar Recovery Scan Tool (x64) Version: 19-02-2017 Ran by HU Dylan (22-02-2017 10:02:04) Run:1 Running from C:\Users\HU Dylan\Desktop Loaded Profiles: HU Dylan (Available Profiles: HU Dylan) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: CHR Profile: C:\Users\HU Dylan\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-21] <==== ATTENTION HKLM-x32\...\Run: [] => [X] R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X] ShellExecuteHooks: No Name - {58AF6728-ECD0-11E6-BFEA-64006A5CFC23} - C:\Users\HU Dylan\AppData\Roaming\Climofabech\Gipphsaweght.dll -> No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487668368&z=cba1cbe5370ab10b921d607g6z7b9m2qbq2bec7m0b&from=che0812&uid=SAMSUNGXMZNTY128HDHP-00000_S2YMNY0H858817&q={searchTerms} [Country : US - 127.0.53.53] SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487668368&z=cba1cbe5370ab10b921d607g6z7b9m2qbq2bec7m0b&from=che0812&uid=SAMSUNGXMZNTY128HDHP-00000_S2YMNY0H858817&q={searchTerms} [Country : US - 127.0.53.53] SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487668368&z=cba1cbe5370ab10b921d607g6z7b9m2qbq2bec7m0b&from=che0812&uid=SAMSUNGXMZNTY128HDHP-00000_S2YMNY0H858817&q={searchTerms} [Country : US - 127.0.53.53] SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487668368&z=cba1cbe5370ab10b921d607g6z7b9m2qbq2bec7m0b&from=che0812&uid=SAMSUNGXMZNTY128HDHP-00000_S2YMNY0H858817&q={searchTerms} [Country : US - 127.0.53.53] SearchScopes: HKU\S-1-5-21-2191782336-4012611912-442011344-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487668368&z=cba1cbe5370ab10b921d607g6z7b9m2qbq2bec7m0b&from=che0812&uid=SAMSUNGXMZNTY128HDHP-00000_S2YMNY0H858817&q={searchTerms} [Country : US - 127.0.53.53] R2 bilibili; C:\Program Files (x86)\bilibili\bilibili.dll [124928 2017-02-14] () [File not signed] RemoveDirectory: C:\Program Files (x86)\bilibili 2017-02-10 15:02 - 2017-02-21 10:19 - 00000000 ____D C:\Program Files\U6RAOERUQI 2017-02-10 15:02 - 2017-02-21 10:19 - 00000000 ____D C:\Program Files\PSGZZKYBTX 2017-02-10 15:02 - 2017-02-21 10:19 - 00000000 ____D C:\Program Files (x86)\Gherwaspanasution EmptyTemp: end ***************** Error: (0) Failed to create a restore point. Processes closed successfully. C:\Users\HU Dylan\AppData\Local\Google\Chrome\User Data\ChromeDefaultData => moved successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully HKLM\System\CurrentControlSet\Services\ibtsiva => key removed successfully ibtsiva => service removed successfully HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23} => value removed successfully HKCR\CLSID\{58AF6728-ECD0-11E6-BFEA-64006A5CFC23} => key not found. HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => key removed successfully HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key removed successfully HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKU\S-1-5-21-2191782336-4012611912-442011344-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key removed successfully HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found. HKLM\System\CurrentControlSet\Services\bilibili => key removed successfully bilibili => service removed successfully "C:\Program Files (x86)\bilibili" => removed successfully. C:\Program Files\U6RAOERUQI => moved successfully C:\Program Files\PSGZZKYBTX => moved successfully C:\Program Files (x86)\Gherwaspanasution => moved successfully =========== EmptyTemp: ========== BITS transfer queue => 7792487 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 223155960 B Java, Flash, Steam htmlcache => 3079 B Windows/system/drivers => 4481869 B Edge => 296341215 B Chrome => 0 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 128 B systemprofile32 => 22232192 B LocalService => 0 B NetworkService => -658 B HU Dylan => 631956762 B RecycleBin => 0 B EmptyTemp: => 1.1 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 10:03:05 ====