Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2014 Ran by Donkey Kong at 2014-03-16 16:01:39 Run:3 Running from C:\Users\Donkey Kong\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** Start HKU\S-1-5-21-2481818962-1579234034-314252365-1000\...\Run: [AVG-Secure-Search-Update_0214c] - C:\Users\Donkey Kong\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=6b41cd4637bc47d6bec6cd2623af957a-493bcf5fa01f10de510906c30c444cd282f6d840 /CMPID=0214c HKLM\...\Run: [New Value #2] - 田tfmon・任TFMON.EXE・ BHO-x32: safe asavE - {E8923E6B-A808-8214-0061-0C631B3A04EB} - No File CHR Plugin: (Google Update) - C:\Users\Donkey Kong\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.40.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Donkey Kong\AppData\Local\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Native Client) - C:\Users\Donkey Kong\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Users\Donkey Kong\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll No File S2 HPSLPSVC; C:\Users\DONKEY~1\AppData\Local\Temp\7zS3B02\hpslpsvc64.dll [X] S2 ioloSystemService; "C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe" [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 efavdrv; \??\C:\Windows\system32\drivers\efavdrv.sys [X] S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X] S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X] S3 sj; \??\E:\AeriaGames\EdenEternal\EdenEternal\sjcs64.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 usj; \??\E:\EdenEternal\avital\ussjcs64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] S3 X6va008; \??\C:\Windows\SysWOW64\Drivers\X6va008 [X] S3 XBCD; system32\DRIVERS\XBCD.sys [X] C:\Users\Donkey Kong\AppData\Local\Temp\$avantbrowser$.update.exe C:\Users\Donkey Kong\AppData\Local\Temp\GakuenNTR_inst.exe C:\Users\Donkey Kong\AppData\Local\Temp\KansenComp_inst.exe C:\Users\Donkey Kong\AppData\Local\Temp\NSISUtils.dll C:\Users\Donkey Kong\AppData\Local\Temp\ntdll_dump.dll C:\Users\Donkey Kong\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Donkey Kong\AppData\Local\Temp\nvStInst.exe C:\Users\Donkey Kong\AppData\Local\Temp\Quarantine.exe testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION! End ***************** HKU\S-1-5-21-2481818962-1579234034-314252365-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AVG-Secure-Search-Update_0214c => Value deleted successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\New Value #2 => Value deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8923E6B-A808-8214-0061-0C631B3A04EB} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{E8923E6B-A808-8214-0061-0C631B3A04EB} => Key deleted successfully. C:\Users\Donkey Kong\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll not found. C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll not found. C:\Windows\SysWOW64\npDeployJava1.dll not found. C:\Windows\system32\Adobe\Director\np32dsw.dll not found. C:\Users\Donkey Kong\AppData\Local\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll not found. C:\Users\Donkey Kong\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll not found. C:\Users\Donkey Kong\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll not found. HPSLPSVC => Service deleted successfully. ioloSystemService => Service deleted successfully. EagleX64 => Service deleted successfully. efavdrv => Service deleted successfully. MREMPR5 => Service deleted successfully. MRENDIS5 => Service deleted successfully. sj => Service deleted successfully. Synth3dVsc => Service deleted successfully. tsusbhub => Service deleted successfully. usj => Service deleted successfully. VGPU => Service deleted successfully. VMnetAdapter => Service deleted successfully. X6va008 => Service deleted successfully. XBCD => Service deleted successfully. C:\Users\Donkey Kong\AppData\Local\Temp\$avantbrowser$.update.exe => Moved successfully. C:\Users\Donkey Kong\AppData\Local\Temp\GakuenNTR_inst.exe => Moved successfully. C:\Users\Donkey Kong\AppData\Local\Temp\KansenComp_inst.exe => Moved successfully. C:\Users\Donkey Kong\AppData\Local\Temp\NSISUtils.dll => Moved successfully. C:\Users\Donkey Kong\AppData\Local\Temp\ntdll_dump.dll => Moved successfully. C:\Users\Donkey Kong\AppData\Local\Temp\nvSCPAPI.dll => Moved successfully. C:\Users\Donkey Kong\AppData\Local\Temp\nvStInst.exe => Moved successfully. C:\Users\Donkey Kong\AppData\Local\Temp\Quarantine.exe => Moved successfully. The operation completed successfully. ==== End of Fixlog ====