Jak w temacie.
Poniżej raport z FRST.
http://wklej.org/id/1650581/
Pozdrawiam
dziuravy
Reg: reg delete "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f
Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f
C:\Users\Rafal\AppData\Local\genienext
C:\Program Files (x86)\Mobogenie
C:\Windows\system32\Drivers\EsgScanner.sys
C:\Windows\System32\Tasks\SpyHunter4Startup
C:\Users\Rafal\Desktop\SpyHunter.lnk
C:\Users\Rafal\AppData\Roaming\Enigma Software Group
C:\sh4ldr
C:\Program Files\Enigma Software Group
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-02-25] ()
C:\Windows\System32\DRIVERS\EsgScanner.sys
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026432 2015-02-25] (Enigma Software Group USA, LLC.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
HKU\S-1-5-21-3828753850-3312781531-3475161732-1001\...\MountPoints2: {409c0400-8222-11e3-b7af-806e6f6e6963} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.html
HKU\S-1-5-21-3828753850-3312781531-3475161732-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Rafal\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
C:\Users\Rafal\AppData\Local\Akamai\netsession_win.exe
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
EmptyTemp:
poland.com
poland.com
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 6 gości