Fix result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by User (29-01-2018 15:48:53) Run:1
Running from D:\Users\Desktop
Loaded Profiles: User (Available Profiles: User)
Boot Mode: Normal
==============================================
fixlist content:
*****************
VirusTotal: C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe;C:\Users\User\AppData\Local\Temp\jow2dzfa.dll
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\spoolsvc.lnk [2017-12-04]
ShortcutTarget: spoolsvc.lnk -> C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe (No File)
Task: {DEB54F2F-08A7-4B1C-B63C-7C4845FA1934} - System32\Tasks\App Explorer => C:\Users\User\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [2017-12-22] (SweetLabs, Inc) <==== ATTENTION
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {2ae92697-92cb-11e7-8180-ccb0dad6d454} - "G:\AutoRun.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {5dc65b0b-3086-11e7-8029-ccb0dad6d454} - "F:\AutoRun.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {68be13b2-14f3-11e7-bfbc-ccb0dad6d454} - "F:\StartUse.exe"
HKU\S-1-5-21-176347147-2586957089-2691104427-1001\...\MountPoints2: {ce574921-2505-11e7-bff5-ccb0dad6d454} - "F:\Setup.exe" /s
*****************
VirusTotal: C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe =>
https://www.virustotal.com/file/c1a248a1227900a11c1a2c32a80af50f1482b18099374f3e7464ddc216ec345f/analysis/1516973612/VirusTotal: C:\Users\User\AppData\Local\Temp\jow2dzfa.dll =>
https://www.virustotal.com/file/e423663fdd4cfce9ed88fd4c7a9c6a754271ae1c8a7c59b173e1065ffbc9c8b5/analysis/1517212137/C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\spoolsvc.lnk => moved successfully
C:\Users\User\AppData\Roaming\Kaspersky Internet Security 2017\spoolsvc.exe => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DEB54F2F-08A7-4B1C-B63C-7C4845FA1934} => could not remove key. ErrorCode1: 0x00000002
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEB54F2F-08A7-4B1C-B63C-7C4845FA1934}" => removed successfully
C:\Windows\System32\Tasks\App Explorer => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\App Explorer" => removed successfully
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ae92697-92cb-11e7-8180-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{2ae92697-92cb-11e7-8180-ccb0dad6d454} => key not found
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5dc65b0b-3086-11e7-8029-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{5dc65b0b-3086-11e7-8029-ccb0dad6d454} => key not found
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{68be13b2-14f3-11e7-bfbc-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{68be13b2-14f3-11e7-bfbc-ccb0dad6d454} => key not found
"HKU\S-1-5-21-176347147-2586957089-2691104427-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce574921-2505-11e7-bff5-ccb0dad6d454}" => removed successfully
HKLM\Software\Classes\CLSID\{ce574921-2505-11e7-bff5-ccb0dad6d454} => key not found
==== End of Fixlog 15:49:07 ====