![]() |
Hab versucht SkyHunter4 mit SkyHunter Killer zu löschen, aber alles hängt sich auf Hallo, Wieder ein neuer ohne viel Ahnung..ähmmm, räusper, hust. Habe Windows 7 :pfeiff: Nachdem meine Frau sich den CTB locker eingefangen hat, habe ich mit meinem PC versucht etwas zu finden, dabei hab ich dummerweise den SpyHunter 4 installiert. Nach den Tips bei "Chip" habe ich nacheinander den GeekUnistaller und den SpyHunter Killer installiert, nichts geht. Geek startet gar nicht und bei dem Killer hängt sich der PC auf und bei SpyHunter läuft währenddessen weiter. In der Systemsteuerung läst er sich auch nicht deinstallieren. Was hilft wirklich? Gibts Tips? (Hoffentlich) Danke skaltas |
:hallo: Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...:abklatsch:
![]() Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean :daumenhoc bekommst. Los geht's: Schritt 1 http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() Lesestoff Posten in CODE-Tags: So gehts... Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert uns massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
Download geht nicht Hallo Jürgen, vielen Dank das du mir helfen willst, aber es geht schon mit dem Download los. FRST Download FRST 32-Bit | FRST 64-Bit. Das 64er kann ich installieren, aber mein PC ist 32bit. Wenn ich das versuche, kommt sofort mein AV Programm Avast und verhindert den Download, jetzt wird bei erneutem Versuch jedesmal die Verbindung unterbrochen...? Erledigt, hab den Avast abgeschaltet, jetzt konnte ich FRST32 installieren. |
FRST Logfile: [CODE]Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2015 Ran by Admin (administrator) on XTREME-4GMTJ68T on 19-04-2015 12:56:25 Running from C:\Users\Admin\Desktop Loaded Profiles: UpdatusUser & Admin (Available profiles: UpdatusUser & Admin) Platform: Microsoft Windows 7 Максимальная Powered © by XTreme.ws™ Service Pack 1 (X86) OS Language: Russisch (Russische Föderation) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHAE.EXE (Bandoo Media Inc.) C:\Users\Admin\AppData\Local\iLivid\iLivid.exe (Koyote-Lab inc) C:\Program Files\Cheapster\msilnk.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5075104 2014-02-24] (ESET) HKLM\...\Run: [Ulead AutoDetector v2] => C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2004-11-26] (Ulead Systems, Inc.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-30] (AVAST Software) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1 HKU\S-1-5-21-1407664867-4041839907-3860151249-1002\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHAE.EXE [249440 2014-08-11] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Run: [iLivid] => C:\Users\Admin\AppData\Local\iLivid\iLivid.exe [8146632 2014-12-15] (Bandoo Media Inc.) HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Run: [Cheapster] => C:\Program Files\Cheapster\msilnk.exe [288768 2014-12-30] (Koyote-Lab inc) HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Policies\Explorer: [HideSCAHealth] 1 ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKU\S-1-5-21-1407664867-4041839907-3860151249-1002\Software\Microsoft\Internet Explorer\Main,Start Page = Íîâûå áåñïëàòíûå ïðîãðàììû äëÿ Windows 7, 8 è XP íà ðóññêîì ÿçûêå. SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> DefaultScope {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {0D2A7A60-29A4-4856-B4CA-32208604BF05} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&ie8=1 SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {7FB19D89-12F4-41D4-83A0-393D93AFCE10} URL = hxxp://yandex.ru/yandsearch?text={searchTerms}&from=os SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> DefaultScope {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {0D2A7A60-29A4-4856-B4CA-32208604BF05} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&ie8=1 SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {7FB19D89-12F4-41D4-83A0-393D93AFCE10} URL = hxxp://yandex.ru/yandsearch?text={searchTerms}&from=os SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-27] (AVAST Software) BHO: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> No File BHO: No Name -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> No File BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File Toolbar: HKLM - No Name - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2012-04-26] (Adobe Systems, Inc.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-13] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-13] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation) FF Plugin: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\searchplugins\google-images.xml [2015-04-19] FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\searchplugins\google-maps.xml [2015-04-19] FF Extension: Segurança do navegador Avira - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\Extensions\abs@avira.com [2014-11-19] FF Extension: Cliqz Beta - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\Extensions\cliqz@cliqz.com [2015-04-19] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-03] FF HKLM\...\Firefox\Extensions: [ocr@babylon.com] - C:\Program Files\Babylon\Babylon-Pro\Utils\ocr@babylon.com FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-07-01] FF HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> CHR StartupUrls: Default -> "hxxp://google.de/" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google :inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}s ugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-01] CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-01] CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-01] CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-01] CHR Extension: (Bookmark Manager) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14] CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-01] CHR Extension: (Bitdefender QuickScan) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2014-11-18] CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-01] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-27] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-27] (AVAST Software) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1343408 2014-02-24] (ESET) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed] R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed] R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [771456 2015-04-17] (Enigma Software Group USA, LLC.) R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-04-03] (Crawler.com) R2 SysMain; C:\Windows\system32\sysmain.dll [1167872 2012-07-13] (Microsoft Corporation) [File not signed] R2 Themes; C:\Windows\system32\themeservice.dll [37376 2009-07-14] (Microsoft Corporation) [File not signed] S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [35840 2012-07-13] (Microsoft Corporation) [File not signed] S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-11-27] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2014-11-27] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-11-27] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-11-27] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2014-11-27] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2014-11-27] (AVAST Software) S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [91496 2014-11-27] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206248 2014-11-27] () R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [188808 2013-09-17] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [37416 2013-09-17] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [49240 2013-09-17] (ESET) R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [16432 2015-04-17] (Enigma Software Group USA, LLC.) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2015-04-17] () R0 oem-drv86; C:\Windows\System32\DRIVERS\oem-drv86.sys [28160 2015-04-19] (secr9tos) [File not signed] R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-19 12:56 - 2015-04-19 12:56 - 00017631 _____ () C:\Users\Admin\Desktop\FRST.txt 2015-04-19 12:56 - 2015-04-19 12:56 - 00000000 ____D () C:\FRST 2015-04-19 12:53 - 2015-04-19 12:53 - 01137664 _____ (Farbar) C:\Users\Admin\Desktop\FRST.exe 2015-04-19 12:46 - 2015-04-19 12:46 - 02098176 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe 2015-04-19 11:48 - 2015-04-19 11:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Cliqz 2015-04-19 11:48 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\system32\dhRichClient3.dll 2015-04-19 11:48 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\system32\sqlite36_engine.dll 2015-04-19 11:47 - 2015-04-19 11:51 - 02585251 _____ () C:\Users\Admin\Downloads\geek_1.3.3.45.zip 2015-04-19 11:46 - 2015-04-19 11:46 - 01203488 _____ () C:\Users\Admin\Downloads\GeekUninstaller - CHIP-Installer.exe 2015-04-17 20:30 - 2015-04-17 20:33 - 00007040 _____ () C:\Users\Admin\Desktop\Rkill.txt 2015-04-17 19:41 - 2015-04-17 19:41 - 00001240 _____ () C:\Users\Admin\Desktop\SpyHunter.lnk 2015-04-17 19:41 - 2015-04-17 19:41 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Enigma Software Group 2015-04-17 19:41 - 2015-04-17 19:41 - 00000000 ____D () C:\sh4ldr 2015-04-17 19:37 - 2015-04-17 19:37 - 00019984 _____ () C:\Windows\system32\Drivers\EsgScanner.sys 2015-04-17 19:36 - 2015-04-17 19:36 - 00000000 ____D () C:\Program Files\Enigma Software Group 2015-04-16 08:24 - 2015-04-16 08:25 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-16 08:24 - 2015-04-16 08:24 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-16 00:13 - 2015-04-16 00:13 - 00000000 ___RD () C:\Program Files\Skype 2015-04-16 00:13 - 2015-04-16 00:13 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-04-15 10:44 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-15 10:44 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-15 10:44 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-04-15 10:44 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-15 10:44 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-15 10:44 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-15 10:44 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-15 10:44 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-15 10:44 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-15 10:44 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-15 10:44 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-15 10:44 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-15 10:44 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-15 10:44 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-15 10:44 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-15 10:44 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-04-15 10:43 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-15 10:42 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-04-15 10:42 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-04-15 10:42 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-04-15 10:42 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-04-15 10:42 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-04-15 10:42 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-04-15 10:42 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-04-15 10:42 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-04-15 10:42 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-04-15 10:42 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-04-15 10:42 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-04-15 10:42 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-04-15 10:42 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-04-15 10:42 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-04-15 10:42 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-04-15 10:42 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-04-15 10:42 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-04-15 10:42 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-04-15 10:42 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-04-15 10:42 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-04-15 10:42 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-04-15 10:42 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-04-15 10:42 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-04-15 10:42 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-04-15 10:42 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-04-15 10:42 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-04-15 10:42 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-04-15 10:42 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-04-15 10:42 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-04-15 10:42 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-04-15 10:42 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-04-15 10:41 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-15 10:41 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-15 10:41 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-15 10:41 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-15 10:41 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-15 10:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-04-15 10:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-04-15 10:40 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-04 16:14 - 2015-04-04 16:14 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-03 23:19 - 2015-04-03 23:19 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-04-03 12:09 - 2015-04-03 12:10 - 00000000 ____D () C:\GEZ 2015-04-03 11:29 - 2015-04-04 09:55 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2015-03-30 12:24 - 2015-04-19 12:02 - 00000000 ____D () C:\VPS Scanner 2015-03-24 01:17 - 2015-03-28 18:16 - 00000000 ____D () C:\Ford Mondeo 2015-03-21 22:23 - 2015-04-03 23:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-19 12:52 - 2009-07-14 06:34 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-19 12:52 - 2009-07-14 06:34 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-19 12:26 - 2014-07-01 14:04 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-19 12:21 - 2012-07-13 23:23 - 00000896 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-19 12:12 - 2014-06-29 16:40 - 00000000 ____D () C:\Program Files\Opera 2015-04-19 12:10 - 2014-06-28 13:35 - 01206259 _____ () C:\Windows\WindowsUpdate.log 2015-04-19 12:07 - 2014-07-01 14:04 - 00000954 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-19 12:07 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-19 12:06 - 2014-11-18 14:41 - 00011032 _____ () C:\Windows\setupact.log 2015-04-19 12:06 - 2014-08-18 23:34 - 00000000 ____D () C:\Users\Все пользователи\NVIDIA 2015-04-19 12:06 - 2014-06-28 14:31 - 00028160 _____ (secr9tos) C:\Windows\system32\Drivers\oem-drv86.sys 2015-04-19 11:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2015-04-18 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat 2015-04-18 14:38 - 2014-08-20 16:27 - 00000000 ____D () C:\Ira 2015-04-17 19:41 - 2014-06-28 13:39 - 00000000 ____D () C:\Users\Admin 2015-04-17 18:41 - 2014-11-18 15:16 - 00000000 ____D () C:\Users\Все пользователи\Spyware Terminator 2015-04-17 12:55 - 2014-06-30 20:20 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\vlc 2015-04-16 12:16 - 2014-07-22 11:37 - 00000000 ____D () C:\Projekt AP&S Group 2015-04-16 11:54 - 2014-06-28 13:38 - 00000000 ____D () C:\Windows\rescache 2015-04-16 09:30 - 2014-07-01 14:05 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-04-16 08:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-04-16 08:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ru-RU 2015-04-16 08:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2015-04-16 00:17 - 2014-06-29 14:45 - 00000000 ____D () C:\Users\Все пользователи\Microsoft Help 2015-04-16 00:16 - 2011-04-12 00:46 - 00719098 _____ () C:\Windows\system32\perfh019.dat 2015-04-16 00:16 - 2011-04-12 00:46 - 00151344 _____ () C:\Windows\system32\perfc019.dat 2015-04-16 00:16 - 2010-11-20 23:01 - 02451100 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-16 00:13 - 2014-06-30 00:12 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-04-16 00:13 - 2014-06-30 00:12 - 00000000 ____D () C:\Users\Все пользователи\Skype 2015-04-15 11:22 - 2012-07-13 23:23 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-04-15 11:22 - 2012-07-13 23:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-04-10 15:54 - 2014-09-03 11:51 - 00000000 ____D () C:\Ebay 2015-04-10 15:03 - 2014-06-30 00:13 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype 2015-04-09 14:33 - 2014-07-25 16:21 - 00000030 _____ () C:\Windows\Iedit_.INI 2015-04-05 18:56 - 2015-01-24 14:51 - 00012473 _____ () C:\Users\Admin\Documents\Rückstand Miete Fettah 2014.odt 2015-04-04 18:12 - 2014-06-29 16:39 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-04-04 09:20 - 2014-11-27 16:11 - 00003900 _____ () C:\Windows\PFRO.log 2015-03-24 01:07 - 2014-08-13 18:26 - 00000000 ____D () C:\Bilder ==================== Files in the root of some directories ======= 2014-08-14 11:34 - 2014-08-14 11:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Program Files\mbam-setup-2.0.2.1012.exe 2014-08-14 22:52 - 2014-11-10 13:02 - 0003584 _____ () C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Files to move or delete: ==================== C:\Users\Администратор\javafx-windows-i586__Vlatest.exe Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe [2010-11-20 23:29] - [2010-11-20 23:29] - 0026624 ____A (Microsoft Corporation) 9FCF19DFE8E2D11B0D0855A389D4DBE6 C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-04-2015 --- --- --- |
OK... :) |
Code: Platform: Microsoft Windows 7 Максимальная Powered © by XTreme.ws™ Service Pack 1 (X86) OS Language: Russisch (Russische Föderation) |
FRST Logfile: FRST Logfile: [CODE]Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2015 Ran by Admin (administrator) on XTREME-4GMTJ68T on 19-04-2015 12:56:25 Running from C:\Users\Admin\Desktop Loaded Profiles: UpdatusUser & Admin (Available profiles: UpdatusUser & Admin) Platform: Microsoft Windows 7 Максимальная Powered © by XTreme.ws™ Service Pack 1 (X86) OS Language: Russisch (Russische Föderation) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHAE.EXE (Bandoo Media Inc.) C:\Users\Admin\AppData\Local\iLivid\iLivid.exe (Koyote-Lab inc) C:\Program Files\Cheapster\msilnk.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5075104 2014-02-24] (ESET) HKLM\...\Run: [Ulead AutoDetector v2] => C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2004-11-26] (Ulead Systems, Inc.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-30] (AVAST Software) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1 HKU\S-1-5-21-1407664867-4041839907-3860151249-1002\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHAE.EXE [249440 2014-08-11] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Run: [iLivid] => C:\Users\Admin\AppData\Local\iLivid\iLivid.exe [8146632 2014-12-15] (Bandoo Media Inc.) HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Run: [Cheapster] => C:\Program Files\Cheapster\msilnk.exe [288768 2014-12-30] (Koyote-Lab inc) HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Policies\Explorer: [HideSCAHealth] 1 ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKU\S-1-5-21-1407664867-4041839907-3860151249-1002\Software\Microsoft\Internet Explorer\Main,Start Page = Íîâûå áåñïëàòíûå ïðîãðàììû äëÿ Windows 7, 8 è XP íà ðóññêîì ÿçûêå. SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> DefaultScope {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {0D2A7A60-29A4-4856-B4CA-32208604BF05} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&ie8=1 SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {7FB19D89-12F4-41D4-83A0-393D93AFCE10} URL = hxxp://yandex.ru/yandsearch?text={searchTerms}&from=os SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-1002 -> {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> DefaultScope {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {0D2A7A60-29A4-4856-B4CA-32208604BF05} URL = hxxp://go.mail.ru/search?q={searchTerms}&utf8in=1&ie8=1 SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {7FB19D89-12F4-41D4-83A0-393D93AFCE10} URL = hxxp://yandex.ru/yandsearch?text={searchTerms}&from=os SearchScopes: HKU\S-1-5-21-1407664867-4041839907-3860151249-500 -> {A834C867-5B83-4535-9B04-DF182E0BBD0F} URL = hxxp://www.google.ru/search?hl=ru&q={searchTerms} BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-27] (AVAST Software) BHO: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> No File BHO: No Name -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> No File BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File Toolbar: HKLM - No Name - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2012-04-26] (Adobe Systems, Inc.) FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-13] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-13] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation) FF Plugin: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-06-03] (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\searchplugins\google-images.xml [2015-04-19] FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\searchplugins\google-maps.xml [2015-04-19] FF Extension: Segurança do navegador Avira - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\Extensions\abs@avira.com [2014-11-19] FF Extension: Cliqz Beta - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\Extensions\cliqz@cliqz.com [2015-04-19] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-03] FF HKLM\...\Firefox\Extensions: [ocr@babylon.com] - C:\Program Files\Babylon\Babylon-Pro\Utils\ocr@babylon.com FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2014-07-01] FF HKU\S-1-5-21-1407664867-4041839907-3860151249-500\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\4pki1pxk.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> CHR StartupUrls: Default -> "hxxp://google.de/" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google :inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}s ugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-01] CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-01] CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-01] CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-01] CHR Extension: (Bookmark Manager) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-16] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14] CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-01] CHR Extension: (Bitdefender QuickScan) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2014-11-18] CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-01] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-27] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-27] (AVAST Software) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1343408 2014-02-24] (ESET) R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed] R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed] R2 MDM; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [771456 2015-04-17] (Enigma Software Group USA, LLC.) R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-04-03] (Crawler.com) R2 SysMain; C:\Windows\system32\sysmain.dll [1167872 2012-07-13] (Microsoft Corporation) [File not signed] R2 Themes; C:\Windows\system32\themeservice.dll [37376 2009-07-14] (Microsoft Corporation) [File not signed] S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [35840 2012-07-13] (Microsoft Corporation) [File not signed] S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-11-27] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2014-11-27] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-11-27] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-11-27] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2014-11-27] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2014-11-27] (AVAST Software) S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [91496 2014-11-27] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206248 2014-11-27] () R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [188808 2013-09-17] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [37416 2013-09-17] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [49240 2013-09-17] (ESET) R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [16432 2015-04-17] (Enigma Software Group USA, LLC.) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2015-04-17] () R0 oem-drv86; C:\Windows\System32\DRIVERS\oem-drv86.sys [28160 2015-04-19] (secr9tos) [File not signed] R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-19 12:56 - 2015-04-19 12:56 - 00017631 _____ () C:\Users\Admin\Desktop\FRST.txt 2015-04-19 12:56 - 2015-04-19 12:56 - 00000000 ____D () C:\FRST 2015-04-19 12:53 - 2015-04-19 12:53 - 01137664 _____ (Farbar) C:\Users\Admin\Desktop\FRST.exe 2015-04-19 12:46 - 2015-04-19 12:46 - 02098176 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe 2015-04-19 11:48 - 2015-04-19 11:48 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Cliqz 2015-04-19 11:48 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\system32\dhRichClient3.dll 2015-04-19 11:48 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\system32\sqlite36_engine.dll 2015-04-19 11:47 - 2015-04-19 11:51 - 02585251 _____ () C:\Users\Admin\Downloads\geek_1.3.3.45.zip 2015-04-19 11:46 - 2015-04-19 11:46 - 01203488 _____ () C:\Users\Admin\Downloads\GeekUninstaller - CHIP-Installer.exe 2015-04-17 20:30 - 2015-04-17 20:33 - 00007040 _____ () C:\Users\Admin\Desktop\Rkill.txt 2015-04-17 19:41 - 2015-04-17 19:41 - 00001240 _____ () C:\Users\Admin\Desktop\SpyHunter.lnk 2015-04-17 19:41 - 2015-04-17 19:41 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Enigma Software Group 2015-04-17 19:41 - 2015-04-17 19:41 - 00000000 ____D () C:\sh4ldr 2015-04-17 19:37 - 2015-04-17 19:37 - 00019984 _____ () C:\Windows\system32\Drivers\EsgScanner.sys 2015-04-17 19:36 - 2015-04-17 19:36 - 00000000 ____D () C:\Program Files\Enigma Software Group 2015-04-16 08:24 - 2015-04-16 08:25 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-16 08:24 - 2015-04-16 08:24 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-16 00:13 - 2015-04-16 00:13 - 00000000 ___RD () C:\Program Files\Skype 2015-04-16 00:13 - 2015-04-16 00:13 - 00000000 ____D () C:\Program Files\Common Files\Skype 2015-04-15 10:44 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-15 10:44 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-15 10:44 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-15 10:44 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-04-15 10:44 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-15 10:44 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-15 10:44 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-15 10:44 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-15 10:44 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-15 10:44 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-15 10:44 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-15 10:44 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-15 10:44 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-15 10:44 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-15 10:44 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-15 10:44 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-15 10:44 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-15 10:44 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-15 10:44 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-04-15 10:43 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-15 10:42 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-04-15 10:42 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-04-15 10:42 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-04-15 10:42 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-04-15 10:42 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-04-15 10:42 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-04-15 10:42 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-04-15 10:42 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-04-15 10:42 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-04-15 10:42 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-04-15 10:42 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-04-15 10:42 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-04-15 10:42 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-04-15 10:42 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-04-15 10:42 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-04-15 10:42 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-04-15 10:42 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-04-15 10:42 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-04-15 10:42 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-04-15 10:42 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-04-15 10:42 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-04-15 10:42 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-04-15 10:42 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-04-15 10:42 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-04-15 10:42 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-04-15 10:42 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-04-15 10:42 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-04-15 10:42 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-04-15 10:42 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-04-15 10:42 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-04-15 10:42 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-04-15 10:41 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-15 10:41 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-15 10:41 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-15 10:41 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-15 10:41 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-15 10:40 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-15 10:40 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-04-15 10:40 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-04-15 10:40 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-04 16:14 - 2015-04-04 16:14 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-03 23:19 - 2015-04-03 23:19 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-04-03 12:09 - 2015-04-03 12:10 - 00000000 ____D () C:\GEZ 2015-04-03 11:29 - 2015-04-04 09:55 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2015-03-30 12:24 - 2015-04-19 12:02 - 00000000 ____D () C:\VPS Scanner 2015-03-24 01:17 - 2015-03-28 18:16 - 00000000 ____D () C:\Ford Mondeo 2015-03-21 22:23 - 2015-04-03 23:31 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-19 12:52 - 2009-07-14 06:34 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-19 12:52 - 2009-07-14 06:34 - 00026768 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-19 12:26 - 2014-07-01 14:04 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-19 12:21 - 2012-07-13 23:23 - 00000896 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-19 12:12 - 2014-06-29 16:40 - 00000000 ____D () C:\Program Files\Opera 2015-04-19 12:10 - 2014-06-28 13:35 - 01206259 _____ () C:\Windows\WindowsUpdate.log 2015-04-19 12:07 - 2014-07-01 14:04 - 00000954 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-19 12:07 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-19 12:06 - 2014-11-18 14:41 - 00011032 _____ () C:\Windows\setupact.log 2015-04-19 12:06 - 2014-08-18 23:34 - 00000000 ____D () C:\Users\Все пользователи\NVIDIA 2015-04-19 12:06 - 2014-06-28 14:31 - 00028160 _____ (secr9tos) C:\Windows\system32\Drivers\oem-drv86.sys 2015-04-19 11:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp 2015-04-18 22:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat 2015-04-18 14:38 - 2014-08-20 16:27 - 00000000 ____D () C:\Ira 2015-04-17 19:41 - 2014-06-28 13:39 - 00000000 ____D () C:\Users\Admin 2015-04-17 18:41 - 2014-11-18 15:16 - 00000000 ____D () C:\Users\Все пользователи\Spyware Terminator 2015-04-17 12:55 - 2014-06-30 20:20 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\vlc 2015-04-16 12:16 - 2014-07-22 11:37 - 00000000 ____D () C:\Projekt AP&S Group 2015-04-16 11:54 - 2014-06-28 13:38 - 00000000 ____D () C:\Windows\rescache 2015-04-16 09:30 - 2014-07-01 14:05 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-04-16 08:39 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-04-16 08:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ru-RU 2015-04-16 08:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2015-04-16 00:17 - 2014-06-29 14:45 - 00000000 ____D () C:\Users\Все пользователи\Microsoft Help 2015-04-16 00:16 - 2011-04-12 00:46 - 00719098 _____ () C:\Windows\system32\perfh019.dat 2015-04-16 00:16 - 2011-04-12 00:46 - 00151344 _____ () C:\Windows\system32\perfc019.dat 2015-04-16 00:16 - 2010-11-20 23:01 - 02451100 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-16 00:13 - 2014-06-30 00:12 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-04-16 00:13 - 2014-06-30 00:12 - 00000000 ____D () C:\Users\Все пользователи\Skype 2015-04-15 11:22 - 2012-07-13 23:23 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-04-15 11:22 - 2012-07-13 23:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-04-10 15:54 - 2014-09-03 11:51 - 00000000 ____D () C:\Ebay 2015-04-10 15:03 - 2014-06-30 00:13 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype 2015-04-09 14:33 - 2014-07-25 16:21 - 00000030 _____ () C:\Windows\Iedit_.INI 2015-04-05 18:56 - 2015-01-24 14:51 - 00012473 _____ () C:\Users\Admin\Documents\Rückstand Miete Fettah 2014.odt 2015-04-04 18:12 - 2014-06-29 16:39 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-04-04 09:20 - 2014-11-27 16:11 - 00003900 _____ () C:\Windows\PFRO.log 2015-03-24 01:07 - 2014-08-13 18:26 - 00000000 ____D () C:\Bilder ==================== Files in the root of some directories ======= 2014-08-14 11:34 - 2014-08-14 11:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Program Files\mbam-setup-2.0.2.1012.exe 2014-08-14 22:52 - 2014-11-10 13:02 - 0003584 _____ () C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Files to move or delete: ==================== C:\Users\Администратор\javafx-windows-i586__Vlatest.exe Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe [2010-11-20 23:29] - [2010-11-20 23:29] - 0026624 ____A (Microsoft Corporation) 9FCF19DFE8E2D11B0D0855A389D4DBE6 C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-04-2015 --- --- --- --- --- --- Jürgen ich komme hier mit der Reihenfolge der Beiträge noch nicht so klar ;) Mein PC war vor einiger Zeit komplett down. Hatte ihn dann mitgenommen zu meinem Stiefsohn in die Ukraine, der hat mir das Windows 7 neu installiert, war aber wohl eine russische Version, deshalb sind einige Worte in russisch, konnte er nicht vermeiden trotz vieler Mühe das ganze in Deutsch zu installieren. Hoffe es geht trotzdem. |
Also für mich sieht das so aus, als ob das keine legale Windows-Version ist, irre mich aber gerne. http://www.trojaner-board.de/95393-c...-software.html Daher auch nur eine grobe Anleitung zum Entfernen der Adware/Malware damit Du dann in Ruhe Daten sichern und ggf. Windows neu installieren kannst. Schritt 1 Bitte deinstalliere folgende Programme: Cheapster for Firefox SpyHunter 4 Spyware Terminator 2012 iLivid Avast Free Antivirus Lade Dir bitte Revo Uninstallerhttp://deeprybka.trojaner-board.de/b...ninstaller.pnghier herunter. Entpacke die zip-Datei auf den Desktop. Anleitung
Danach würde ich Scans mit Malwarebytes und Deinem ESET machen. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 04:48 Uhr. |
Copyright ©2000-2025, Trojaner-Board