Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-07-2014
Ran by Tepan at 2014-07-19 21:50:27 Run:1
Running from C:\Users\Tepan\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [uTorrent] => C:\Users\Tepan\AppData\Roaming\uTorrent\uTorrent.exe [1322832 2014-07-04] (BitTorrent Inc.)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [key] => wscript.exe //B "C:\Users\Tepan\AppData\Roaming\key.vbs"
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [45cd603ee23d7c7a771df421f5721e99] => C:\Users\Tepan\AppData\Local\Temp\win.exe [138240 2014-07-19] () <===== ATTENTION
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1dc-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1e7-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\MountPoints2: {b1f4c1fd-5803-11e3-9023-d43d7e500c5b} - G:\AutoRun.exe
Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\45cd603ee23d7c7a771df421f5721e99.exe ()
Startup: C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar =
http://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL =
http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKCU - DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL =
http://www.bing.com/search?q={searchTer ... DF&PC=AV01
BHO: Shop_an_Upi_1.6 -> {11111111-1111-1111-1111-110411281122} -> C:\Program Files (x86)\Shop_an_Upi_1.6\Shop_an_Upi_1.6-bho64.dll No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
DisableService: Nero BackItUp Scheduler 3
R2 SpyHunter 4 Service; C:\Program Files (x86)\Enigma Software Group\SpyHunter\SH4Service.exe [770432 2013-06-27] (Enigma Software Group USA, LLC.)
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X]
S3 esgiguard; C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [13088 2011-03-02] ()
S3 EsgScanner; C:\Windows\SysWOW64\DRIVERS\EsgScanner.sys [19984 2012-06-22] ()
S3 cpuz130; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz130\cpuz_x64.sys [X]
S3 cpuz134; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 cpuz135; \??\C:\Users\Tepan\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
S2 SPDRIVER_1.37.0.199; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.199\jsdrv.sys [X]
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs
C:\Users\Tepan\AppData\Roaming\key.vbs
C:\Program Files (x86)\ShopperPro
C:\Users\Tepan\AppData\Local\Temp\win.exe
C:\Program Files\Reimage
C:\Program Files (x86)\Enigma Software Group
2014-07-19 19:02 - 2014-05-18 18:47 - 00102663 _____ () C:\Users\Tepan\AppData\Roaming\key.vbs
2014-07-18 23:07 - 2014-07-18 22:16 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-18 22:39 - 2014-07-18 23:13 - 00031966 _____ () C:\zoek-results.log
2014-07-18 22:16 - 2014-07-18 23:02 - 00000000 ____D () C:\zoek_backup
2014-07-18 22:14 - 2014-07-18 22:14 - 01287168 _____ () C:\Users\Tepan\Desktop\zoek.exe
2014-07-18 18:51 - 2014-07-18 18:51 - 00002248 _____ () C:\Users\Tepan\Desktop\SpyHunter.lnk
2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-07-18 18:51 - 2014-07-18 18:51 - 00000000 ____D () C:\sh4ldr
2014-07-18 16:39 - 2014-07-18 16:39 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
2014-07-18 15:33 - 2014-07-18 16:44 - 00000000 ____D () C:\Program Files\Enigma Software Group
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\Windows\Tasks\Oxy.job => C:\Users\Tepan\AppData\Roaming\Oxy\Updater.exe
Task: C:\Windows\Tasks\ReimageUpdater.job => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
Task: C:\Windows\Tasks\RunAsStdUser Task.job => C:\Users\Tepan\AppData\Local\Oxy\Application\oxy.exe
Task: C:\Windows\Tasks\SPBIW_UpdateTask_Time_313137363632353534382d50552d6c455a37575a417834.job => C:\ProgramData\ShopperPro\spbihe.js" spbiu.exe
Task: C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe
AlternateDataStreams: C:\Temp:pid1
AlternateDataStreams: C:\Temp:pid2
AlternateDataStreams: C:\Temp:srv
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
Hosts:
Reboot:
End
*****************
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver => Value not found.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\key => value deleted successfully.
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\45cd603ee23d7c7a771df421f5721e99 => value deleted successfully.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1dc-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1dc-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1e7-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1e7-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
'HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b1f4c1fd-5803-11e3-9023-d43d7e500c5b}' => Key deleted successfully.
'HKCR\CLSID\{b1f4c1fd-5803-11e3-9023-d43d7e500c5b}'=> Key not found.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\45cd603ee23d7c7a771df421f5721e99.exe => Moved successfully.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs => Moved successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}' => Key deleted successfully.
'HKCR\Wow6432Node\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}'=> Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411281122}' => Key deleted successfully.
'HKCR\CLSID\{11111111-1111-1111-1111-110411281122}' => Key deleted successfully.
'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully.
'HKCU\SOFTWARE\Policies\Google' => Key deleted successfully.
Nero BackItUp Scheduler 3 service was disabled
SpyHunter 4 Service => Service stopped successfully.
SpyHunter 4 Service => Service deleted successfully.
ReimageRealTimeProtector => Service not found.
esgiguard => Service deleted successfully.
EsgScanner => Service deleted successfully.
cpuz130 => Service deleted successfully.
cpuz134 => Service deleted successfully.
cpuz135 => Service deleted successfully.
SPDRIVER_1.37.0.199 => Service deleted successfully.
"C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\key.vbs" => File/Directory not found.
Could not move "C:\Users\Tepan\AppData\Roaming\key.vbs" => Scheduled to move on reboot.
"C:\Program Files (x86)\ShopperPro" => File/Directory not found.
C:\Users\Tepan\AppData\Local\Temp\win.exe => Moved successfully.
"C:\Program Files\Reimage" => File/Directory not found.
C:\Program Files (x86)\Enigma Software Group => Moved successfully.
Could not move "C:\Users\Tepan\AppData\Roaming\key.vbs" => Scheduled to move on reboot.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Tepan\Desktop\zoek.exe => Moved successfully.
C:\Users\Tepan\Desktop\SpyHunter.lnk => Moved successfully.
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter => Moved successfully.
C:\sh4ldr => Moved successfully.
"C:\Program Files (x86)\Enigma Software Group" => File/Directory not found.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\avast! Emergency Update.job => Moved successfully.
C:\Windows\Tasks\Oxy.job not found.
C:\Windows\Tasks\ReimageUpdater.job not found.
C:\Windows\Tasks\RunAsStdUser Task.job not found.
C:\Windows\Tasks\SPBIW_UpdateTask_Time_313137363632353534382d50552d6c455a37575a417834.job => Moved successfully.
C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => Moved successfully.
C:\Temp => ":pid1" ADS removed successfully.
C:\Temp => ":pid2" ADS removed successfully.
C:\Temp => ":srv" ADS removed successfully.
C:\ProgramData\TEMP => ":373E1720" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-07-19 21:51:48)<=
C:\Users\Tepan\AppData\Roaming\key.vbs => Is moved successfully.
C:\Users\Tepan\AppData\Roaming\key.vbs => Is moved successfully.
==== End of Fixlog ====