Re: prosim o pomoc
Napsal: 02 srp 2014 17:01
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-07-2014 01
Ran by rado at 2014-08-02 17:58:37 Run:1
Running from C:\Users\rado\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\MountPoints2: N - N:\setup.exe
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\MountPoints2: {c27f0203-9a86-11db-95a2-806e6f6e6963} - E:\CheckID.exe
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5F262B949489CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://loa.r2games.com/game/play/?server=3562
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: No Name -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
C:\Program Files (x86)\Skype\Toolbars
C:\Program Files (x86)\Spybot - Search & Destroy 2
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 EverestDriver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
2014-07-31 10:46 - 2014-07-31 10:46 - 00112640 _____ (forum.viry.cz) C:\Users\rado\Desktop\FRSTLauncher.exe
2014-07-31 10:45 - 2014-07-31 10:45 - 00013087 _____ () C:\Users\rado\Desktop\FRST.txt
2014-07-28 09:10 - 2014-07-28 08:20 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-28 08:25 - 2014-07-28 09:11 - 00012713 _____ () C:\zoek-results.log
2014-07-28 08:20 - 2014-07-28 09:10 - 00000000 ____D () C:\zoek_backup
2014-07-28 08:19 - 2014-07-28 08:19 - 01287168 _____ () C:\Users\rado\Desktop\zoek.exe
2014-07-27 11:47 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-27 11:46 - 2014-07-27 11:48 - 00000000 ____D () C:\AdwCleaner
2014-07-27 11:45 - 2014-07-27 11:45 - 01354223 _____ () C:\Users\rado\Desktop\adwcleaner_3.216.exe
2014-07-27 11:36 - 2014-07-27 11:36 - 00009137 _____ () C:\Users\rado\Desktop\JRT.txt
2014-07-27 11:09 - 2014-07-27 11:09 - 00000000 ____D () C:\Windows\ERUNT
2014-07-27 11:07 - 2014-07-27 11:07 - 01016261 _____ (Thisisu) C:\Users\rado\Desktop\JRT.exe
2014-07-26 01:28 - 2014-07-26 01:28 - 00084862 _____ () C:\Users\rado\Desktop\Extras.Txt
2014-07-26 01:09 - 2014-07-26 01:09 - 00180116 _____ () C:\Users\rado\Desktop\OTL.Txt
2014-07-25 22:19 - 2014-07-25 22:19 - 00000512 _____ () C:\PhysicalMBR.bin
2014-07-25 21:53 - 2014-07-25 21:53 - 00602112 _____ (OldTimer Tools) C:\Users\rado\Desktop\OTL.exe
2014-07-25 20:28 - 2014-07-25 20:28 - 00000000 ____D () C:\rsit
2014-07-25 20:28 - 2014-07-25 20:28 - 00000000 ____D () C:\Program Files\trend micro
2014-07-24 18:55 - 2014-07-24 21:05 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-07-24 18:55 - 2014-07-24 18:55 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-07-24 18:54 - 2014-07-24 18:54 - 00002189 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-07-24 18:54 - 2014-07-24 18:54 - 00002177 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-07-24 18:54 - 2014-07-24 18:54 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-24 18:54 - 2009-01-25 12:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
Task: {3FE9120F-DE1F-4D34-96CA-86BB353065D7} - \GoforFilesUpdate No Task File <==== ATTENTION
Hosts:
Reboot:
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SDTray => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon" => Key not found.
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value deleted successfully.
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value deleted successfully.
"HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-2103325229-1255119138-1366225161-1001" => Key not found.
"HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c27f0203-9a86-11db-95a2-806e6f6e6963}" => Key deleted successfully.
"HKCR\CLSID\{c27f0203-9a86-11db-95a2-806e6f6e6963}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
"HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => Key deleted successfully.
"HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => Key deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => Moved successfully.
c2cautoupdatesvc => Service stopped successfully.
c2cautoupdatesvc => Service deleted successfully.
c2cpnrsvc => Service stopped successfully.
c2cpnrsvc => Service deleted successfully.
SDScannerService => Service not found.
SDUpdateService => Service not found.
SDWSCService => Service not found.
C:\Program Files (x86)\Skype\Toolbars => Moved successfully.
"C:\Program Files (x86)\Spybot - Search & Destroy 2" => File/Directory not found.
dgderdrv => Service deleted successfully.
EagleX64 => Service deleted successfully.
EverestDriver => Service deleted successfully.
nvvad_WaveExtensible => Service deleted successfully.
pccsmcfd => Service deleted successfully.
VGPU => Service deleted successfully.
xhunter1 => Service deleted successfully.
C:\Users\rado\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Users\rado\Desktop\FRST.txt => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\rado\Desktop\zoek.exe => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\rado\Desktop\adwcleaner_3.216.exe => Moved successfully.
C:\Users\rado\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\rado\Desktop\JRT.exe => Moved successfully.
C:\Users\rado\Desktop\Extras.Txt => Moved successfully.
C:\Users\rado\Desktop\OTL.Txt => Moved successfully.
C:\PhysicalMBR.bin => Moved successfully.
C:\Users\rado\Desktop\OTL.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk" => File/Directory not found.
"C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk" => File/Directory not found.
"C:\Program Files (x86)\Spybot - Search & Destroy 2" => File/Directory not found.
"C:\Windows\system32\sdnclean64.exe" => File/Directory not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\ProgramData\TEMP => ":D1B5B4F1" ADS removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3FE9120F-DE1F-4D34-96CA-86BB353065D7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FE9120F-DE1F-4D34-96CA-86BB353065D7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate" => Key deleted successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
The system needed a reboot.
==== End of Fixlog ====
Ran by rado at 2014-08-02 17:58:37 Run:1
Running from C:\Users\rado\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\MountPoints2: N - N:\setup.exe
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\...\MountPoints2: {c27f0203-9a86-11db-95a2-806e6f6e6963} - E:\CheckID.exe
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5F262B949489CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://loa.r2games.com/game/play/?server=3562
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: No Name -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
C:\Program Files (x86)\Skype\Toolbars
C:\Program Files (x86)\Spybot - Search & Destroy 2
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 EverestDriver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
2014-07-31 10:46 - 2014-07-31 10:46 - 00112640 _____ (forum.viry.cz) C:\Users\rado\Desktop\FRSTLauncher.exe
2014-07-31 10:45 - 2014-07-31 10:45 - 00013087 _____ () C:\Users\rado\Desktop\FRST.txt
2014-07-28 09:10 - 2014-07-28 08:20 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-07-28 08:25 - 2014-07-28 09:11 - 00012713 _____ () C:\zoek-results.log
2014-07-28 08:20 - 2014-07-28 09:10 - 00000000 ____D () C:\zoek_backup
2014-07-28 08:19 - 2014-07-28 08:19 - 01287168 _____ () C:\Users\rado\Desktop\zoek.exe
2014-07-27 11:47 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-27 11:46 - 2014-07-27 11:48 - 00000000 ____D () C:\AdwCleaner
2014-07-27 11:45 - 2014-07-27 11:45 - 01354223 _____ () C:\Users\rado\Desktop\adwcleaner_3.216.exe
2014-07-27 11:36 - 2014-07-27 11:36 - 00009137 _____ () C:\Users\rado\Desktop\JRT.txt
2014-07-27 11:09 - 2014-07-27 11:09 - 00000000 ____D () C:\Windows\ERUNT
2014-07-27 11:07 - 2014-07-27 11:07 - 01016261 _____ (Thisisu) C:\Users\rado\Desktop\JRT.exe
2014-07-26 01:28 - 2014-07-26 01:28 - 00084862 _____ () C:\Users\rado\Desktop\Extras.Txt
2014-07-26 01:09 - 2014-07-26 01:09 - 00180116 _____ () C:\Users\rado\Desktop\OTL.Txt
2014-07-25 22:19 - 2014-07-25 22:19 - 00000512 _____ () C:\PhysicalMBR.bin
2014-07-25 21:53 - 2014-07-25 21:53 - 00602112 _____ (OldTimer Tools) C:\Users\rado\Desktop\OTL.exe
2014-07-25 20:28 - 2014-07-25 20:28 - 00000000 ____D () C:\rsit
2014-07-25 20:28 - 2014-07-25 20:28 - 00000000 ____D () C:\Program Files\trend micro
2014-07-24 18:55 - 2014-07-24 21:05 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-07-24 18:55 - 2014-07-24 18:55 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-07-24 18:54 - 2014-07-24 18:54 - 00002189 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-07-24 18:54 - 2014-07-24 18:54 - 00002177 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-07-24 18:54 - 2014-07-24 18:54 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-07-24 18:54 - 2009-01-25 12:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
Task: {3FE9120F-DE1F-4D34-96CA-86BB353065D7} - \GoforFilesUpdate No Task File <==== ATTENTION
Hosts:
Reboot:
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SDTray => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon" => Key not found.
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value deleted successfully.
HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value deleted successfully.
"HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-2103325229-1255119138-1366225161-1001" => Key not found.
"HKU\S-1-5-21-2103325229-1255119138-1366225161-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c27f0203-9a86-11db-95a2-806e6f6e6963}" => Key deleted successfully.
"HKCR\CLSID\{c27f0203-9a86-11db-95a2-806e6f6e6963}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
"HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}" => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => Key deleted successfully.
"HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => Key deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => Moved successfully.
c2cautoupdatesvc => Service stopped successfully.
c2cautoupdatesvc => Service deleted successfully.
c2cpnrsvc => Service stopped successfully.
c2cpnrsvc => Service deleted successfully.
SDScannerService => Service not found.
SDUpdateService => Service not found.
SDWSCService => Service not found.
C:\Program Files (x86)\Skype\Toolbars => Moved successfully.
"C:\Program Files (x86)\Spybot - Search & Destroy 2" => File/Directory not found.
dgderdrv => Service deleted successfully.
EagleX64 => Service deleted successfully.
EverestDriver => Service deleted successfully.
nvvad_WaveExtensible => Service deleted successfully.
pccsmcfd => Service deleted successfully.
VGPU => Service deleted successfully.
xhunter1 => Service deleted successfully.
C:\Users\rado\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Users\rado\Desktop\FRST.txt => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\rado\Desktop\zoek.exe => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\rado\Desktop\adwcleaner_3.216.exe => Moved successfully.
C:\Users\rado\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\rado\Desktop\JRT.exe => Moved successfully.
C:\Users\rado\Desktop\Extras.Txt => Moved successfully.
C:\Users\rado\Desktop\OTL.Txt => Moved successfully.
C:\PhysicalMBR.bin => Moved successfully.
C:\Users\rado\Desktop\OTL.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk" => File/Directory not found.
"C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk" => File/Directory not found.
"C:\Program Files (x86)\Spybot - Search & Destroy 2" => File/Directory not found.
"C:\Windows\system32\sdnclean64.exe" => File/Directory not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\ProgramData\TEMP => ":D1B5B4F1" ADS removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3FE9120F-DE1F-4D34-96CA-86BB353065D7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FE9120F-DE1F-4D34-96CA-86BB353065D7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate" => Key deleted successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
The system needed a reboot.
==== End of Fixlog ====