Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-11-2013 02 Ran by HaPe at 2013-11-19 10:07:05 Run:1 Running from C:\Users\HaPe\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKCU\...\Run: [minerd] - "C:\Users\HaPe\AppData\Roaming\minerd\nircmd.exe" exec hide "C:\Users\HaPe\AppData\Roaming\minerd\start.bat" C:\Users\HaPe\AppData\Roaming\minerd HKCU\...\Run: [svchost] - "C:\ProgramData\svchost0\nnkzcpsaq.exe" C:\ProgramData\svchost0 Task: {3791EDCE-E73B-4F3C-9B55-41B79CAF12F2} - \RegClean Pro_UPDATES No Task File Task: {6F9ED8DB-A837-4FE3-BE1E-30EF0A414141} - \DigitalSite No Task File Task: {7C46A5D6-5120-498D-8467-7A3677E1205B} - \Windows Update Check - 0x0C290301 No Task File Task: {E1FA9DAD-CE82-440D-8E80-7A46E31DBF5C} - \RegClean Pro_DEFAULT No Task File IMEO\mbam.exe: [Debugger] utzxq_.exe IMEO\mbamgui.exe: [Debugger] uthqt_.exe IMEO\MSASCui.exe: [Debugger] ufhpd_.exe IMEO\MsMpEng.exe: [Debugger] isyun_.exe IMEO\msseces.exe: [Debugger] ttdas_.exe IMEO\rstrui.exe: [Debugger] uex_.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = S2 Util WebConnect; "C:\Program Files (x86)\WebConnect\bin\utilWebConnect.exe" [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] 2013-10-27 22:25 - 2013-07-31 00:30 - 00386923 _____ C:\Windows\system32\ApnDatabase.xml C:\Users\HaPe\AppData\Local\Temp\aria.exe C:\Users\HaPe\AppData\Local\Temp\duznffnqdua.exe C:\Users\HaPe\AppData\Local\Temp\Extract.exe C:\Users\HaPe\AppData\Local\Temp\nircmd.exe C:\Users\HaPe\AppData\Local\Temp\setup.exe C:\Users\HaPe\AppData\Local\Temp\SP61277.exe C:\Users\HaPe\AppData\Local\Temp\SP62765.exe C:\Users\HaPe\AppData\Local\Temp\SP63283.exe C:\Users\HaPe\AppData\Local\Temp\SP63286.exe C:\Users\HaPe\AppData\Local\Temp\SP63287.exe C:\Users\HaPe\AppData\Local\Temp\SP63340.exe C:\Users\HaPe\AppData\Local\Temp\SP63752.exe C:\Users\HaPe\AppData\Local\Temp\ztjtebhzezr.exe ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\minerd => Value deleted successfully. C:\Users\HaPe\AppData\Roaming\minerd => Moved successfully. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\svchost => Value deleted successfully. C:\ProgramData\svchost0 => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3791EDCE-E73B-4F3C-9B55-41B79CAF12F2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3791EDCE-E73B-4F3C-9B55-41B79CAF12F2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F9ED8DB-A837-4FE3-BE1E-30EF0A414141} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F9ED8DB-A837-4FE3-BE1E-30EF0A414141} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7C46A5D6-5120-498D-8467-7A3677E1205B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C46A5D6-5120-498D-8467-7A3677E1205B} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Update Check - 0x0C290301 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E1FA9DAD-CE82-440D-8E80-7A46E31DBF5C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1FA9DAD-CE82-440D-8E80-7A46E31DBF5C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbam.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mbamgui.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe => Key deleted successfully. HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\rstrui.exe => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. Util WebConnect => Service deleted successfully. EagleX64 => Service deleted successfully. C:\Windows\system32\ApnDatabase.xml => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\aria.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\duznffnqdua.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\Extract.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\nircmd.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\setup.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\SP61277.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\SP62765.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\SP63283.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\SP63286.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\SP63287.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\SP63340.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\SP63752.exe => Moved successfully. C:\Users\HaPe\AppData\Local\Temp\ztjtebhzezr.exe => Moved successfully. ==== End of Fixlog ====