Alter....was ist da denn noch alles :eek: FRST-Fix Virenscanner jetzt bitte komplett deaktivieren, damit sichergestellt ist, dass der Fix sauber durchläuft!
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Extension: MediaPlayersvideos 1.1 - C:\Users\Andi\AppData\Roaming\Mozilla\Firefox\Profiles\y8szgoz2.default\Extensions\b6e4f54065ff48dd97db30ca@c9b45f807bf54a45a4669e51c.com [2015-02-21]
FF Extension: buuYandbrowwSSE - C:\Users\Andi\AppData\Roaming\Mozilla\Firefox\Profiles\y8szgoz2.default\Extensions\yuR@D.net [2015-02-02]
FF Extension: c151d79ee61b4a90a8875a46d38fba99 - C:\Users\Andi\AppData\Roaming\Mozilla\Firefox\Profiles\y8szgoz2.default\Extensions\{c151d79e-e61b-4a90-a887-5a46d38fba99} [2015-02-19]
CHR HomePage: Default -> hxxp://www.istartsurf.com/?type=hppp&ts=1424032548&from=tugs&uid=HGSTXHTS725050A7E630_RC250ACB0D8S9J0D8S9JX
CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hppp&ts=1424032548&from=tugs&uid=HGSTXHTS725050A7E630_RC250ACB0D8S9J0D8S9JX"
CHR DefaultSearchKeyword: Default -> istartsurf
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-02-13] ()
R2 lhOYKYn; C:\ProgramData\rJDRDPLhi\lhOYKYn.exe [2733544 2015-02-15] (Time Lapse Solutions)
S2 cae99edb; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\Super Optimizer\SupOptCrash.dll",ENT
Task: {5C9944EA-E447-4204-918D-27A756562761} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
Task: {6DE1B0F0-4A78-4BAD-8E35-0291BF5300D3} - \avaxvyyvyf No Task File <==== ATTENTION
Task: {961C6AB4-CFBF-4FFF-BB96-DD8B6E3FD9FD} - System32\Tasks\MPNIT => C:\Users\Andi\AppData\Roaming\MPNIT.exe [2015-02-25] (RadioCanyonv2V25.02) <==== ATTENTION
Task: {A1ADADA1-DF9A-41CE-BE00-1D1438BFCA33} - System32\Tasks\PC-Mechanic Subscription => C:\Program Files (x86)\Uniblue\PC-Mechanic\pc-mechanic.exe
Task: {A5C88AD9-278C-4961-BB27-B6F43AC2DD36} - System32\Tasks\KKZ => C:\Users\Andi\AppData\Roaming\KKZ.exe [2015-02-25] (RadioCanyonv2V25.02) <==== ATTENTION
Task: C:\Windows\Tasks\KKZ.job => C:\Users\Andi\AppData\Roaming\KKZ.exe <==== ATTENTION
Task: C:\Windows\Tasks\MPNIT.job => C:\Users\Andi\AppData\Roaming\MPNIT.exe <==== ATTENTION
C:\Windows\Tasks\MPNIT.job
C:\Windows\Tasks\KKZ.job
C:\Program Files (x86)\SuperPlusRadio v2.1V25.02
C:\Users\Andi\AppData\Roaming\MPNIT.exe
C:\Users\Andi\AppData\Roaming\KKZ.exe
C:\Windows\System32\Tasks\MPNIT
C:\Windows\System32\Tasks\KKZ
C:\Program Files (x86)\1498dc0a-f4d9-4408-be95-19affbd6d965
C:\Program Files (x86)\PlusBrowSRAps2.5
C:\Windows\System32\Tasks\SpyHunter4Startup
C:\Windows\system32\Drivers\EsgScanner.sys
C:\sh4ldr
C:\Program Files (x86)\Uniblue
C:\ProgramData\rJDRDPLhi
C:\Users\Andi\Downloads\Microsoft.Windows.XP.7in1.German.inkl.SP3-Lidl
C:\Users\Andi\AppData\Roaming\MPNIT
C:\Users\Andi\AppData\Roaming\MPNIT.exe
C:\Users\Andi\Downloads\XP.Home.Edition.OEM.SP3.GER-RHB.rar.part
C:\Program Files (x86)\buuYandbrowwSSE
C:\Program Files (x86)\buyyandbirrowaSe
C:\Program Files (x86)\Cinemax Plus 1.9cV15.02
C:\Program Files (x86)\4bf237b8-803c-4cad-8ece-2db7514c4a71
C:\ProgramData\{8841397d-393c-30ac-8841-1397d393e5f4}
C:\Users\Andi\AppData\Roaming\KKZ.exe
C:\Program Files\Enigma Software Group
C:\Program Files (x86)\MedPlayV3.1
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
c:\Program Files (x86)\Super Optimizer
C:\Users\Andi\AppData\Local\ZombieInvasion
EmptyTemp:
Hosts:
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
- Starte nun FRST erneut und klicke den Entfernen Button.
- Das Tool erstellt eine Fixlog.txt.
- Poste mir deren Inhalt.
|