Hi,
Someone shall do the kind translate if nessesery.
Are you aware for the presence of keylogger in your system?
The following FixList shall target the bad 'things' but not the keylogger itself untill you give me the freen light for that.
1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating systemStart
File: C:\ProgramData\DatacardService\HWDeviceService64.exe
File: C:\Program Files (x86)\iSafe\iSafeSvc.exe
Reboot:
C:\Users\Eliecer\AppData\Local\Temp
CMD: bitsadmin /reset /allusers
Hosts:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3004103921-1991663305-3280852458-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3004103921-1991663305-3280852458-1001\...\MountPoints2: {3a3b4b1a-cb3d-11e2-be71-089e017b95ce} - "E:\Startme.exe"
HKU\S-1-5-21-3004103921-1991663305-3280852458-1001\...\MountPoints2: {56437c76-bd24-11e3-be8a-806e6f6e6963} - "E:\AutoRun.exe"
HKU\S-1-5-21-3004103921-1991663305-3280852458-1001\...\MountPoints2: {56437d6a-bd24-11e3-be8a-089e017b95ce} - "E:\AutoRun.exe"
HKU\S-1-5-21-3004103921-1991663305-3280852458-1001\...\MountPoints2: {56438187-bd24-11e3-be8a-089e017b95ce} - "E:\AutoRun.exe"
HKU\S-1-5-21-3004103921-1991663305-3280852458-1001\...\MountPoints2: {980020bb-bd7c-11e3-be8c-089e017b95ce} - "E:\AutoRun.exe"
SearchScopes: HKCU - {6510F333-17B8-4B4B-8837-7C66F574C9D5} URL =
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Task: {95C8A45E-B6C9-4910-9491-FDFA86E4B20F} - System32\Tasks\Rocket Updater => C:\Users\Eliecer\AppData\Roaming\ROCKET~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\windows\Tasks\Rocket Updater.job => C:\Users\Eliecer\AppData\Roaming\ROCKET~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
End
2. Save notepad as
fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.3. Run
FRST/FRST64 and press the
Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.The tool will make a log on the Desktop (
Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.