Code:
Alles auswählen Aufklappen ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-07-2014
Ran by Sasha at 2014-07-30 12:57:57 Run:3
Running from C:\Users\Sasha\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S2 楗敳潂瑯獁楳瑳湡tN"; 㩄停潲牧浡䘠汩獥⠠㡸⤶坜獩履楗敳䌠牡㘳尵潂瑯楔敭攮數 [X]
C:\Windows\SysWOW64\AI_RecycleBin
C:\Users\Sasha\AppData\Local\Temp\DELFFE2.EXE
C:\Users\Sasha\AppData\Local\Temp\GLB1A2B.EXE
C:\Users\Sasha\AppData\Local\Temp\Quarantine.exe
C:\Users\Sasha\AppData\Local\Temp\_is221E.exe
Task: {0622A6E1-7393-4400-AF56-142A935D38E0} - \YourFile DownloaderUpdate No Task File <==== ATTENTION
Task: {15EDBE52-69C7-4D5C-B0CB-EB0CE25D97DA} - \Lyrics-Monkey Update No Task File <==== ATTENTION
Task: {5937FA66-25F8-4F51-A687-F1159F78F67D} - System32\Tasks\4677 => Wscript.exe C:\Users\Sasha\AppData\Local\Temp\launchie.vbs //B
Task: {71E43983-38AD-405F-96B9-D5984E47B506} - \Software Updater Ui No Task File <==== ATTENTION
Task: {82D97326-731F-4387-A4F6-09CA5F8AE192} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {871B93B5-4B7E-4915-993B-A801351A68DA} - \SecUpd No Task File <==== ATTENTION
Task: {8EB2DCA7-C0E9-4EE5-942E-15164596EE82} - \Desk 365 RunAsStdUser No Task File <==== ATTENTION
Task: {C4583FA5-0194-4A7D-AC68-A6C28FC4639D} - \Software Updater No Task File <==== ATTENTION
Task: {FADC85E6-B273-4910-A6DC-61AFF9D29E51} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {FB16CB8A-2333-432F-B8D3-6447DF3536F5} - System32\Tasks\0 => Iexplore.exe
*****************
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
楗敳潂瑯獁楳瑳湡tN" => Service deleted successfully.
C:\Windows\SysWOW64\AI_RecycleBin => Moved successfully.
C:\Users\Sasha\AppData\Local\Temp\DELFFE2.EXE => Moved successfully.
C:\Users\Sasha\AppData\Local\Temp\GLB1A2B.EXE => Moved successfully.
C:\Users\Sasha\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Sasha\AppData\Local\Temp\_is221E.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0622A6E1-7393-4400-AF56-142A935D38E0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0622A6E1-7393-4400-AF56-142A935D38E0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile DownloaderUpdate" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{15EDBE52-69C7-4D5C-B0CB-EB0CE25D97DA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15EDBE52-69C7-4D5C-B0CB-EB0CE25D97DA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lyrics-Monkey Update" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5937FA66-25F8-4F51-A687-F1159F78F67D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5937FA66-25F8-4F51-A687-F1159F78F67D}" => Key deleted successfully.
C:\Windows\System32\Tasks\4677 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4677" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{71E43983-38AD-405F-96B9-D5984E47B506}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71E43983-38AD-405F-96B9-D5984E47B506}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Updater Ui" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{82D97326-731F-4387-A4F6-09CA5F8AE192}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82D97326-731F-4387-A4F6-09CA5F8AE192}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{871B93B5-4B7E-4915-993B-A801351A68DA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{871B93B5-4B7E-4915-993B-A801351A68DA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SecUpd" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8EB2DCA7-C0E9-4EE5-942E-15164596EE82}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EB2DCA7-C0E9-4EE5-942E-15164596EE82}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C4583FA5-0194-4A7D-AC68-A6C28FC4639D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4583FA5-0194-4A7D-AC68-A6C28FC4639D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Updater" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FADC85E6-B273-4910-A6DC-61AFF9D29E51}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FADC85E6-B273-4910-A6DC-61AFF9D29E51}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FB16CB8A-2333-432F-B8D3-6447DF3536F5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB16CB8A-2333-432F-B8D3-6447DF3536F5}" => Key deleted successfully.
C:\Windows\System32\Tasks\0 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0" => Key deleted successfully.
==== End of Fixlog ====