Skocz do zawartości


Zdjęcie

SpyHunter 4 prośba o pomoc w usunięciu


  • Zamknięty Temat jest zamknięty
4 odpowiedzi w tym temacie

#1 turas01

turas01

    Nowy

  • 3 postów

Napisano 22 02 2015 - 18:29

Witam,

 

Również stałem się ofiarą tego programu i podpinam się pod temat.

Czytając powyższe instrukcje załączam pliki.

Bardzo proszę o pomoc.


Załączone pliki

  • Załączony plik  FRST.txt   42,01 KB   271 Ilość pobrań
  • Załączony plik  Addition.txt   32,84 KB   315 Ilość pobrań

Użytkownik pawel315 edytował ten post 22 02 2015 - 20:06
pod cudze tematy się nie podponamy

  • 0

#2 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 22 02 2015 - 20:13

Witaj.

Pobierz plik z załącznika, umieść go obok narzędzia FRST, po czym uruchom FRST i kliknij w nim "Fix". Jeśli potrzebny będzie restart wyraź zgodę. Po pomyślnym wykonaniu Fixa utworzy się plik fixlog.txt jego zawartość podaj na forum.

Następnie

  • Wejdź w "Odinstaluj i zień program" i dobij wpis po SpyHunterze klikając a niego
  • Podaj nowe logi z FRST


Załączone pliki


  • 0

#3 turas01

turas01

    Nowy

  • 3 postów

Napisano 22 02 2015 - 20:50

Bardzo dziękuje, wygląda na to, że wszystko przebiegło pomyślnie. Poniżej fixlog.txt:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 22-02-2015
Ran by Artur at 2015-02-22 19:32:20 Run:1
Running from C:\Users\Artur\Downloads
Loaded Profiles: UpdatusUser & Artur (Available profiles: UpdatusUser & Artur)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Task: {E1375916-19E4-4A43-870F-08F06389FE60} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-02-21] (Enigma Software Group USA, LLC.)
HKU\S-1-5-21-1013891439-1649906484-3979277060-1001\...\Run: [Pokki] => C:\WINDOWS\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
HKU\S-1-5-21-1013891439-1649906484-3979277060-1002\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-02-21] ()
C:\Windows\System32\DRIVERS\EsgScanner.sys
C:\Users\Artur\AppData\Roaming\Enigma Software Group
C:\autoexec.bat
C:\WINDOWS\System32\Tasks\SpyHunter4Startup
C:\Users\Artur\Desktop\SpyHunter.lnk
C:\sh4ldr
Unlock: C:\Program Files\Enigma Software Group
C:\Program Files\Enigma Software Group
C:\Users\Artur\Downloads\SpyHunter-Installer.exe
C:\Users\Artur\AppData\Local\Temp\avgnt.exe
C:\Users\Artur\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppraqyw.dll
C:\Users\Artur\AppData\Local\Temp\nsm17DE.tmp.exe
C:\Users\Artur\AppData\Local\Temp\oct1553.tmp.exe
C:\Users\Artur\AppData\Local\Temp\oct7540.tmp.exe
C:\Users\Artur\AppData\Local\Temp\oct8541.tmp.exe
C:\Users\Artur\AppData\Local\Temp\octADAC.tmp.exe
C:\Users\Artur\AppData\Local\Temp\octC02A.tmp.exe
C:\Users\Artur\AppData\Local\Temp\octC0A5.tmp.exe
C:\Users\Artur\AppData\Local\Temp\octC4D7.tmp.exe
C:\Users\Artur\AppData\Local\Temp\octD309.tmp.exe
C:\Users\Artur\AppData\Local\Temp\safeguard.exe
C:\Users\Artur\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Artur\AppData\Local\Temp\SPSetup.exe
C:\Users\Artur\AppData\Local\Temp\utt46.tmp.exe
C:\Users\Artur\AppData\Local\Temp\_is15D5.exe
C:\Users\Artur\AppData\Local\Temp\_is2536.exe
C:\Users\Artur\AppData\Local\Temp\_is9A39.exe
C:\Users\Artur\AppData\Local\Temp\_isB3E1.exe
C:\Users\Artur\AppData\Local\Temp\_isB53D.exe
EmptyTemp:

*****************

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E1375916-19E4-4A43-870F-08F06389FE60}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1375916-19E4-4A43-870F-08F06389FE60}" => Key deleted successfully.
C:\Windows\System32\Tasks\SpyHunter4Startup => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup" => Key deleted successfully.
HKU\S-1-5-21-1013891439-1649906484-3979277060-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Pokki => value deleted successfully.
HKU\S-1-5-21-1013891439-1649906484-3979277060-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Pokki => value deleted successfully.
EsgScanner => Service deleted successfully.
C:\Windows\System32\DRIVERS\EsgScanner.sys => Moved successfully.
C:\Users\Artur\AppData\Roaming\Enigma Software Group => Moved successfully.
C:\autoexec.bat => Moved successfully.
"C:\WINDOWS\System32\Tasks\SpyHunter4Startup" => File/Directory not found.
C:\Users\Artur\Desktop\SpyHunter.lnk => Moved successfully.
C:\sh4ldr => Moved successfully.
"C:\Program Files\Enigma Software Group" => File/Directory unlocked successfully.

"C:\Program Files\Enigma Software Group" directory move:

C:\Program Files\Enigma Software Group\SpyHunter\Brazilian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Common.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\cos.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Czech.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Danish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Defman.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Dutch.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\English.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\EsgScanner.inf => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\EsgScanner.sys => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\ExecutionGuard.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Finnish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\French.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\gas.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\German.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\gil.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Italian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Japanese.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\license.txt => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Lithuanian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\native.exe => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Norwegian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Portuguese.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\purl.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Russian.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\safeol.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\scanlog.log => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\ShScanner.dll => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Spanish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.com => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\supportlog.txt => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Swedish.lng => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\unkcache.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\autoexec.bat.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\hosts.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\system.ini.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\mon\win.ini.bk => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150221_225303.log => Moved successfully.
Could not move "C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150222_161049.log" => Scheduled to move on reboot.
C:\Program Files\Enigma Software Group\SpyHunter\defs\2015022001.def => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\defs\def.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Data\dns.dat => Moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Data\proxy.dat => Moved successfully.
Could not move "C:\Program Files\Enigma Software Group" directory. => Scheduled to move on reboot.

"C:\Users\Artur\Downloads\SpyHunter-Installer.exe" => File/Directory not found.
C:\Users\Artur\AppData\Local\Temp\avgnt.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppraqyw.dll => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\nsm17DE.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\oct1553.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\oct7540.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\oct8541.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\octADAC.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\octC02A.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\octC0A5.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\octC4D7.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\octD309.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\safeguard.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\SkypeSetup.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\SPSetup.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\utt46.tmp.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\_is15D5.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\_is2536.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\_is9A39.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\_isB3E1.exe => Moved successfully.
C:\Users\Artur\AppData\Local\Temp\_isB53D.exe => Moved successfully.
EmptyTemp: => Removed 21.2 GB temporary data.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-02-22 19:35:43)<=

C:\Program Files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20150222_161049.log => Is moved successfully.
C:\Program Files\Enigma Software Group => Is moved successfully.

==== End of Fixlog 19:35:43 ====

Użytkownik pawel315 edytował ten post 22 02 2015 - 20:52
Umieszczam w tag [code]

  • 0

#4 pawel315

pawel315

    Uzależniony od forum

  • 1 553 postów

Napisano 22 02 2015 - 20:54

Poszło sprawnie. Wykonaj jeszcze "Fix" z załącznika, następnie usuń folder C:\FRST

Załączone pliki


  • 0

#5 turas01

turas01

    Nowy

  • 3 postów

Napisano 22 02 2015 - 21:08

Jeszcze raz wielkie dzięki. Problem rozwiązany. Pozdrawiam.



  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych